Totally understand. As Termius turned from a pet project to our main focus we made security transparency our immediate objective. We are working on the detailed documentation on cryptography, SOC2, and periodic security tests done by 3rd party security professionals.
However, we have addressed the most sensitive part of the product -- the approach we use to store and sync hosts, passwords and keys: https://docs.termius.com/termius-handbook/synchronization#ho.... Syncing of keys/passwords can be turned off when your policy does not allow it to be stored elsewhere. We also support 2FA and Yubikey for authentification.