XChaCha20-Poly1305
Authenticated encryptionAuthenticated encryption for all data. The same cipher used by Signal, WireGuard and Cloudflare.
- 256-bit keys with 192-bit extended nonces
- Poly1305 tag detects any tampering
- A unique nonce for every operation
- FIPS fallback: AES-256-GCM