I haven't found any details on the libraries you use, especially for cryptography, nor the steps you have taken to secure your software. Where can we find more info?
I haven't found any details on the libraries you use, especially for cryptography, nor the steps you have taken to secure your software. Where can we find more info?
However, we have addressed the most sensitive part of the product -- the approach we use to store and sync hosts, passwords and keys: https://docs.termius.com/termius-handbook/synchronization#ho.... Syncing of keys/passwords can be turned off when your policy does not allow it to be stored elsewhere. We also support 2FA and Yubikey for authentification.
One example, before I sign up for a critical vendor, I like to ensure I can set up secure 2fa with no sms recovery (because sms recovery is broken by design)
A security whitepaper of sorts will probably go a long way on this type of product