BAYAuth Security Architecture — Zero-Knowledge Encryption Explained
How BAYAuth keeps your TOTP secrets safe: client-side AES-256-GCM encryption, Argon2id key derivation, zero-knowledge architecture, and recovery key model.
Architecture
How BAYAuth keeps your secrets safe
Every design decision in BAYAuth's security model serves one invariant: the server must never be able to decrypt a vault. Here is how that works in practice.
Client-Side AES-256-GCM Encryption
Every TOTP secret is encrypted in your browser using AES-256-GCM — the same encryption standard used by governments and banks. The encryption key is derived from your master password and never leaves your device. The server receives only ciphertext.
Argon2id Key Derivation
Your master password is not used directly as an encryption key. Instead, it goes through Argon2id — a memory-hard key derivation function that makes brute-force attacks computationally expensive. Each user's key is unique, salted, and slow to derive by design.
Zero-Knowledge Architecture
BAYAuth operates on a zero-knowledge principle: we cannot read your TOTP secrets, we cannot decrypt your vault, and we cannot recover your account if you lose your master password and recovery key. This is not a limitation — it is the security model.
Server Stores Only Ciphertext
Your encrypted vault is stored on our servers as an opaque blob of ciphertext. The server has no decrypt path — no code exists to read plaintext vault contents. Even a full database compromise would not expose any TOTP secret.
Recovery Key Model
During setup, BAYAuth generates a recovery key — a backup that can decrypt your vault if you forget your master password. You store this locally (printed, saved in a password manager, etc.). BAYAuth cannot access or recover it for you.
Cross-Device Sync Without Trust
Your encrypted vault syncs across devices, but decryption happens locally on each device. Switching from phone to laptop to tablet does not require trusting any particular device — the same encrypted blob is decrypted everywhere using your master password.
Encryption
AES-256-GCM: what it means and why it matters
AES-256-GCM is an authenticated encryption algorithm. The "AES" part means Advanced Encryption Standard — the algorithm the U.S. government uses for classified information. The "256" refers to the key size in bits: 2²⁵⁶ possible combinations, making brute-force attacks computationally infeasible with any known technology. The "GCM" part means Galois/Counter Mode — an authenticated mode that detects if the ciphertext has been tampered with.
In BAYAuth, this encryption happens entirely in your browser. Your TOTP secrets are encrypted before they leave your device. The server receives a blob of ciphertext that it cannot read, cannot decrypt, and cannot tamper with (because GCM authentication would detect any modification).
This is the same encryption used by Signal, WhatsApp (for message encryption), and major cloud storage providers. The difference is that BAYAuth applies it at the application level — the server never holds the key, unlike most cloud services where the provider holds decryption capability.
Transparency
What BAYAuth does not store
This is not a marketing claim — it is a verifiable architectural constraint. The server code has no decrypt path. Read the source:
vault/server.ts on GitHubRecovery
The recovery key model
Most authenticator apps solve the "lost phone" problem by backing up to a cloud account (Google, Apple, or the app vendor's own servers). This works, but it means trusting a third party with your 2FA secrets — the same secrets that protect your bank, email, and crypto accounts.
BAYAuth takes a different approach. During setup, you generate a recovery key — a single string that can decrypt your vault if you forget your master password. You store this however you like: printed on paper, saved in a password manager, written in a notebook. BAYAuth never sees it, never stores it, and cannot recover it for you.
This is the trade-off of zero-knowledge security: you get complete control over who can access your vault, but you also bear complete responsibility for not losing both your master password and recovery key. We believe this is the right trade-off for a product that guards your 2FA codes.
FAQ
Security questions
Can BAYAuth employees see my TOTP secrets?
No. Your secrets are encrypted in your browser with a key derived from your master password before anything is uploaded. The server only stores ciphertext. Even a full database breach would not expose any TOTP secret — the attacker would also need your master password, which is never transmitted.
What happens if BAYAuth's servers are hacked?
Because of the zero-knowledge design, a server compromise exposes only encrypted blobs. Without the user's master password (which exists only in the user's browser memory), the ciphertext is useless. This is the same security model used by password managers like 1Password and Bitwarden.
How does BAYAuth handle key derivation?
BAYAuth uses Argon2id — the winner of the Password Hashing Competition and the current industry standard. Argon2id is designed to be slow and memory-hard, making brute-force attacks impractical even with modern hardware. Each user's key is derived uniquely from their master password.
What is a recovery key and why do I need one?
Your recovery key is a backup that can decrypt your vault if you forget your master password. It is generated once during setup and stored locally by you. BAYAuth cannot recover it for you — this is by design, not a limitation. Without both your master password or recovery key, your vault remains encrypted forever.
Is BAYAuth audited by a third party?
BAYAuth has not yet undergone an independent security audit. We are transparent about this — over-claiming audit status would undermine the trust we are building. A formal audit is on our roadmap as the user base grows. In the meantime, our security architecture is based on well-established cryptographic primitives (AES-256-GCM, Argon2id, HKDF) that have been extensively analyzed by the research community.
How does BAYAuth compare to Google Authenticator's security?
Google Authenticator stores TOTP secrets in the app's local storage with device-level protection (biometrics, screen lock). If you back up to a Google Account, the secrets are encrypted at rest on Google's servers. BAYAuth uses a more explicit zero-knowledge model: you control the encryption key, and the server never has access to plaintext secrets. The trade-off is that BAYAuth requires you to manage your own recovery key.
Ready to take control of your 2FA?
BAYAuth is free, private, and works in any browser. Your secrets are encrypted before they leave your device.
Create Free Account