All TOTP secrets are stored in Invantive Keychain.
The contents of the Invantive Keychain are stored in an encrypted file `invantive-own-v2.keychain` located in `%USERPROFILE%\invantive`. The environment variable `INVANTIVE_CONFIGURATION_KEYCHAIN_FOLDER` places the file elsewhere; see [[Folders]]. Invantive Keychain uses the KDBX database format found with other password managers. The TOTP-accounts reside in a separate branch and can be exported and imported using Invantive Authenticator.
The data is encrypted using a user and device specific key. Therefore, the database can not be used on another device. Use the export/import options to easily transport accounts between devices.
Originally, Invantive Keychain used keys managed by Microsoft Windows, but these were deemed not reliable. As of 2023, the key management is provided by Invantive software.
## Shared Across Products
One Invantive Keychain is used by all Invantive products of a user on a workstation. Invantive Authenticator holds its TOTP-accounts in it, while the other products hold the log on codes and passwords of data containers in it. Several products can be open at the same time and use the same file.