Security, privacy and audit requirements · C0899
Which password hashing method does the specification call for?
Designed, not yet built
Short answer
No. The specification describes it, but the pilot does not include it. REQ-4605 says password hashing must use Argon2id with at least 64 MiB memory and t>=3, or an equivalent tuned for the server. Its acceptance check: parameter check on deploy.
This is designed, not built.
- Specification item
- REQ-4605
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How often would encryption keys be rotated? Designed
- Is the cryptography designed to be swapped out later, for example for post-quantum methods? Designed
- How would key ceremonies be run and recorded? Designed
See it in context: Key management · Search the help center · Ask a question