3FA

Security

3FA is built so that even we can't read your secrets. Here's exactly how, and how to report a problem.

Cryptography

Access control

What we can't protect against

No client software can defend a fully compromised operating system (e.g. a kernel-level keylogger active while you unlock) or a coerced user. 3FA limits blast radius — it does not claim to be magic.

Reporting a vulnerability

Email security@threefa.app. Please include reproduction steps and avoid accessing other users' data. We aim to acknowledge reports within 72 hours. See our machine-readable policy at/.well-known/security.txt.