Password server

Centralized password and secrets management in your infrastructure

Run Password Depot Enterprise Server on-premises, in your private cloud, or in your Azure tenant. Users access centrally managed vaults via Windows, macOS, Linux, iOS, Android, or the web client – protected by AES-256, TLS 1.3, MFA, roles, audit logs, and server-side policies.

Enterprise password server

Control data centrally

Manage passwords, credentials, and documents centrally. Assign permissions down to the database, folder, and individual entry levels, and record every action.

Full data sovereignty: On-premises or in your own cloud – with no reliance on third-party servers.

The key highlights at a glance

100% under your control

Deployment in your own data center, in a private cloud, or in your own Azure tenant – without a vendor cloud in the chain of trust.

AD, Entra ID, OIDC, and SSO

Integrate Active Directory, Microsoft Entra ID, OpenID Connect, and Kerberos SSO. Groups, roles, and users can be centrally synchronized and managed.

MFA and passwordless login

Supports TOTP, email one-time codes, FIDO2/WebAuthn, Windows Hello, and passkeys – depending on the security policy and environment.

Permissions down to the entry level

Permissions apply at the server, database, folder, and individual entry levels. This means users see only the secrets for which they are actually authorized.

Sharing with multi-person approval

Critical secrets can be shared subject to approval – including supervisor approval, expiration time, usage restrictions, and logging.

High availability and recovery

Mirror servers, automated backups, and recovery of databases and server settings support resilient operation.

REST API v2.0 for automation

The REST API enables integration with DevOps, internal tools, and automation–with centralized authentication, authorization, and auditing.

Tamper-evident audit trail

Security-relevant server actions are logged in a cryptographically chained and signed audit trail – subsequent changes or deletions become detectable. Export to SIEM systems (Splunk, Microsoft Sentinel, Elastic) via Syslog over UDP, TCP, or encrypted TLS.

Architecture for controlled enterprise operations

Password Depot Enterprise Server runs as a 64-bit Windows service in your infrastructure. Clients, web interface, Server Manager, and REST API access the same centrally managed security context.

Architecture diagram: clients for Windows, macOS, Linux, iOS, Android, and web connect to Password Depot Enterprise Server via TLS 1.3 (on-premises, private cloud, or your own Azure tenant); connected components include Server Manager, Active Directory, Microsoft Entra ID and OIDC, SIEM via syslog, the REST API, and a mirror server for high availability.

Server operation in your infrastructure

The enterprise server is operated on-premises, in a private cloud, or in your Azure tenant. Data residency, backup strategy, and network access remain under your control.

Centralized administration

Password Depot Server Manager clearly separates the administrative interface from the end-user client. Administrators manage users, groups, databases, shares, policies, certificates, logs, reports, and mirroring.

Multiple access methods

Users can work on Windows, macOS, Linux, iOS, Android, or through the web client. The web client uses the same security and authorization logic as the native clients.

Encrypted communication

Client-server connections are secured with TLS 1.3. Certificates can be managed using the integrated certificate wizard.

Identity integration for existing enterprise environments

Integrate Password Depot into existing identity and security structures–from traditional Active Directory to modern identity providers.

Active Directory and LDAP

Users and groups can be imported from Active Directory and synchronized. Nested groups and existing organizational structures can also be mapped.

Microsoft Entra ID

Microsoft Entra ID can be integrated for user and group management. This allows changes to users and groups to be centrally reflected in password management.

OpenID Connect

OIDC (OpenID Connect) enables integration with modern identity providers such as Entra ID, Auth0, PingIdentity or other compatible systems. Authentication is hardened and validated on the server side (signature and audience checks of the tokens).

MFA and passwordless access

FIDO2/WebAuthn, passkeys, Windows Hello, TOTP, and one-time codes via email support strong authentication depending on the risk profile.

Control permissions, policies, and shares on the server side

Password Depot Enterprise Server centrally enforces permissions and security rules–not just in individual clients.

Screenshot of the Password Depot Server Manager: permissions dialog with fine-grained rights for users and groups down to folder and entry level.
Server Manager: permissions for users and groups – down to folder and entry level

Role-based administration

Administrative rights can be separated according to responsibilities, for example for servers, databases, groups or specific administrative areas. Dedicated roles for audit, security and backup (Audit Reader, Security Officer, Backup Operator) enable clean separation of duties without granting access to content.

Three permission levels

Permissions can be granted globally, per database, and at folder and entry level. These include read, edit, add, delete, export, print, Auto-Fill, share, and seal.

Server-wide security policies

Password rules, default permissions, permitted entry types, export restrictions, storage locations, and client behavior can be defined centrally.

Secrets requiring approval

Critical credentials can be protected with approval workflows, for example using multiple supervisors, expiration times, and limits on concurrent use.

Secure storage – with support for Article 32 of the GDPR.

End-to-end protected: AES-256 for data, transport over TLS 1.3 with Perfect Forward Secrecy and certificates. Server-side user passwords are hashed with Argon2id. Roles, logging and encryption support technical and organisational measures pursuant to Art. 32 GDPR.

Request a quote

Prepared for stable operation

Backup, mirroring, logging, and recovery are critical for production enterprise environments.

Mirror Server and failover

A Mirror Server can mirror the Principal Server and take over in the event of a failure. This supports high availability without reliance on external SaaS.

Automated backups

Backups can be created on startup and at configurable intervals. Retention based on number or age supports recovery and compliance concepts.

Centralized logs

Logins, access, changes, admin actions, and approval events are logged for traceability.

Predictable operation

System requirements, network ports, and resource needs can be planned precisely before rollout.

Recoverable keys

Configuration and audit keys are stored in recoverable Key Vaults rather than being tied permanently to the machine. With Recovery Keys, the encrypted configuration remains usable even during a server migration or hardware replacement.

Monitoring and escalation

Automatic escalations warn of critically low storage space, repeated backup failures, blocked synchronisation, or an impending licence expiry.

API, audit, and SIEM integration

Secrets should not end up in scripts, prompts, or local configuration files. Password Depot makes access controllable and auditable in a tamper-evident way.

Screenshot of the Password Depot Server Manager: server log with events, users, timestamps, and filter options for audits.
Server Manager: server log – filterable and exportable for audits

REST API v2.0

The REST API enables integration with CI/CD, internal tools, scheduled jobs, and automation. Access remains centrally authorized and logged.

OAuth2, service accounts, and SSO

API access can be secured using bearer tokens, service accounts, or Windows SSO.

Tamper-evident audit trail

All security-relevant actions – logins, database, folder and entry access, sharing, and administrative and configuration changes – are logged in a cryptographically chained and signed form. Integrity can be checked on demand, on a schedule, and independently using the supplied verification tool.

Separate audit roles

The Audit Reader, Security Officer and Backup Operator roles let you delegate audit and backup tasks without granting access to database content.

Syslog/SIEM export

The audit trail and server log can be sent in real time to Syslog and SIEM systems (Splunk, Microsoft Sentinel, Elastic) – via UDP, TCP, or encrypted over TLS.

Event-based notifications

Administrators can be notified of security-related events, such as failed logins, structural changes, sharing activity, or suspicious bulk actions.

Clear separation between Server Manager and client

Complex security, straightforward to administer

The Server Manager clearly separates administration from day-to-day use. Administrators centrally manage policies, permissions, and logs, while users work with familiar clients.

View feature overview

When you need the Enterprise Server

The right solution for your security requirements

Secure management

Replace insecure management methods with centralized, secure databases with controlled access and complete logging.

Available anywhere

Authorized users can access it from a desktop or mobile device. Strong passwords, MFA, and policies ensure a high level of security.

GDPR support

On-premises/private cloud – your data remains within your infrastructure. Strong encryption, role-based access, and audit logs support the requirements under Article 32 GDPR.

ISO/IEC 27001

Roles, logging, and encryption support relevant Annex A controls (e.g., access, cryptography, operations) within your ISMS.

Transparency note: GDPR and ISO/IEC 27001 compliance depends on your overall organization and the specific configuration. Software can support implementation; however, ISO/IEC 27001 certification always relates to your ISMS, not to an individual product.

Technical reference

64-bit Windows Server.

At least 2 CPU cores; 4 CPU cores for larger environments or cryptography-intensive use. RAM requirements depend on the number and size of entries.

Server communication uses port 25019 for TCP and UDP by default. Additional ports may be required for LDAP/LDAPS, HTTPS, SMTP, DNS, Entra ID, OIDC, or updates.

Windows, macOS, Linux, iOS, Android, and web client.

Administration is handled via the Password Depot Server Manager, a separate administration application for users, groups, databases, policies, certificates, logs, backups, and mirroring.

TLS certificates can be managed using the integrated certificate wizard. Common certificate formats for server operation are supported.
TeleTrusT Made in Germany

Security software “Made in Germany” – supports your compliance with GDPR requirements: Password Depot has been developed in Darmstadt, the City of Science, for more than 20 years.

Do you have any further questions?

Email sales@password-depot.de or call us at +49 6151 136500. We would be happy to show you the server in a brief, free webinar.

Book a webinar