End-to-end encrypted · open standards

Your two-factor codes,
behind a moat.

Moat keeps your 2FA codes and passwords encrypted on your device — and end-to-end encrypted in the cloud. No tracking. No one can read them but you.

No account required No tracking, ever Works offline
G S I A
Moat showing live two-factor codes

Generates codes for thousands of services that support two-factor authentication

G
G
M
A
I
A
C
S

Personalize

Make it unmistakably yours.

Four hand-crafted app icons and full light/dark theming. A small touch that makes a security app feel like it belongs to you.

  • Default, Midnight, Ocean & Gold icons
  • Organize accounts into folders
  • Instant search across every code
Moat app icon and theme picker

Passwords too

One secure home for logins as well.

An optional password vault lives right alongside your codes — encrypted in the iOS Keychain, revealed only after Face ID.

  • Stored in the Keychain, never in plain text
  • Reveal or copy only after Face ID
  • Built-in strong password generator
Moat password vault

Switch in a minute

Bring everything over, fast.

Move from Google Authenticator in one scan, then keep everything safe across devices with optional encrypted backup.

  • Import Google Authenticator exports, otpauth:// links & photos
  • End-to-end encrypted backup & sync
  • Face ID lock & App Switcher blur
Moat welcome screen

Security, in plain terms

Protection you can actually verify.

No vague promises. Here's exactly how your data is protected — and why even we can't read it.

Encrypted on your device

2FA secrets and passwords live in the iOS Keychain, protected by device encryption and excluded from unencrypted backups. They never leave in readable form.

End-to-end encrypted sync

Turn on backup and everything is encrypted on-device before upload with AES-256-GCM. Our servers only ever store ciphertext.

Keys derived from your recovery key

Your key is derived with PBKDF2-SHA256 at 210,000 iterations (current OWASP guidance), with random salts. Keys never leave your device.

Zero-knowledge by design

We have no ability to read your secrets or passwords. Lose your recovery key and not even we can restore them — that's the point.

No tracking, no ads

No analytics SDKs, no advertising, no web beacons, no third-party logo fetches. We don't sell or share your data — there's nothing to sell.

Open, published standards

Codes follow TOTP (RFC 6238) and HOTP (RFC 4226), so they work with thousands of services worldwide.

We collect nothing.
Your data is yours alone.

No sign-up required. No analytics, no trackers, no ads. The only data that ever leaves your device is end-to-end encrypted — and we can't read it. Read our privacy policy →

Protect every account in minutes.

Free to start. Upgrade anytime for unlimited accounts, encrypted backup, and sync across your devices.

Download on the App Store
◷ Launching soon on the App Store