Security
EverCode Security: Zero-Knowledge 2FA
Read EverCode’s zero-knowledge 2FA architecture, Rust cryptographic core, Argon2id key derivation, limits and public standards.
Cryptographic Commitments & Boundaries
- End-to-end encryption protects data in transit and at rest, but cannot protect an unlocked device already compromised by active malware.
- If you forget your master password and have no unlocked approved device or Emergency Recovery Kit, support cannot recover your encrypted vault.
- Time-based codes can still be intercepted by real-time phishing proxies; always verify the destination domain in your browser.
Cryptographic Commitments & Boundaries
Cryptographic algorithms use published standards (Argon2id, XChaCha20-Poly1305, Ed25519, X25519). No independent security audit has been completed or published yet; this page is not a product certification.
Public standards and references
The references below document the open standards used by EverCode. They describe the protocols; they are not an independent product certification.