Argon2id
A memory-hard password-hashing algorithm, and how it differs from the algorithms currently used by VULK accounts and managed application backends.
Argon2id
Argon2id is a password-hashing algorithm designed to make password guessing expensive in both computation and memory. OWASP recommends Argon2id for new password-storage implementations. Its memory and time settings need to be chosen and measured for the service that runs it; an algorithm name alone does not establish the security of an authentication system.
Current VULK implementation
VULK's managed API engine currently uses PBKDF2-HMAC-SHA-256 for application passwords. VULK account registration and password recovery use bcrypt. These are separate authentication systems; this glossary definition is not a claim that either service currently stores passwords with Argon2id.
Apps that use an external authentication provider or a custom backend follow that implementation's configuration. See Secure Your App for the scope and checks to consider before publication.
AWS KMS Envelope Encryption
A two-layer encryption pattern where each piece of data is encrypted with a unique data key, and that data key is itself encrypted by a master key in AWS KMS. Combines KMS's audit / rotation guarantees with the throughput of local encryption.
Support Levels
Support options and response times for each VULK plan.