Security controls · C0120
How are passwords stored?
In the pilot (v0.2.0, synthetic data)
Short answer
Hashed with PBKDF2-SHA256 at 100,000 iterations in the pilot. The design target is Argon2id with a hardware-held pepper, which is an open item.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How are temporary passwords handled? Pilot
- Is there a breached-password check? Open
- Is single sign-on available? Designed
- Can two people share one login? Designed
See it in context: Sign-in, MFA and sessions · Search the help center · Ask a question