Server operation in your infrastructure
The enterprise server is operated on-premises, in a private cloud, or in your Azure tenant. Data residency, backup strategy, and network access remain under your control.
Run Password Depot Enterprise Server on-premises, in your private cloud, or in your Azure tenant. Users access centrally managed vaults via Windows, macOS, Linux, iOS, Android, or the web client – protected by AES-256, TLS 1.3, MFA, roles, audit logs, and server-side policies.
Manage passwords, credentials, and documents centrally. Assign permissions down to the database, folder, and individual entry levels, and record every action.
Full data sovereignty: On-premises or in your own cloud – with no reliance on third-party servers.
Deployment in your own data center, in a private cloud, or in your own Azure tenant – without a vendor cloud in the chain of trust.
Integrate Active Directory, Microsoft Entra ID, OpenID Connect, and Kerberos SSO. Groups, roles, and users can be centrally synchronized and managed.
Supports TOTP, email one-time codes, FIDO2/WebAuthn, Windows Hello, and passkeys – depending on the security policy and environment.
Permissions apply at the server, database, folder, and individual entry levels. This means users see only the secrets for which they are actually authorized.
Critical secrets can be shared subject to approval – including supervisor approval, expiration time, usage restrictions, and logging.
Mirror servers, automated backups, and recovery of databases and server settings support resilient operation.
The REST API enables integration with DevOps, internal tools, and automation–with centralized authentication, authorization, and auditing.
Security-relevant server actions are logged in a cryptographically chained and signed audit trail – subsequent changes or deletions become detectable. Export to SIEM systems (Splunk, Microsoft Sentinel, Elastic) via Syslog over UDP, TCP, or encrypted TLS.
Password Depot Enterprise Server runs as a 64-bit Windows service in your infrastructure. Clients, web interface, Server Manager, and REST API access the same centrally managed security context.
The enterprise server is operated on-premises, in a private cloud, or in your Azure tenant. Data residency, backup strategy, and network access remain under your control.
Password Depot Server Manager clearly separates the administrative interface from the end-user client. Administrators manage users, groups, databases, shares, policies, certificates, logs, reports, and mirroring.
Users can work on Windows, macOS, Linux, iOS, Android, or through the web client. The web client uses the same security and authorization logic as the native clients.
Client-server connections are secured with TLS 1.3. Certificates can be managed using the integrated certificate wizard.
Integrate Password Depot into existing identity and security structures–from traditional Active Directory to modern identity providers.
Users and groups can be imported from Active Directory and synchronized. Nested groups and existing organizational structures can also be mapped.
Microsoft Entra ID can be integrated for user and group management. This allows changes to users and groups to be centrally reflected in password management.
OIDC (OpenID Connect) enables integration with modern identity providers such as Entra ID, Auth0, PingIdentity or other compatible systems. Authentication is hardened and validated on the server side (signature and audience checks of the tokens).
FIDO2/WebAuthn, passkeys, Windows Hello, TOTP, and one-time codes via email support strong authentication depending on the risk profile.
Password Depot Enterprise Server centrally enforces permissions and security rules–not just in individual clients.

Administrative rights can be separated according to responsibilities, for example for servers, databases, groups or specific administrative areas. Dedicated roles for audit, security and backup (Audit Reader, Security Officer, Backup Operator) enable clean separation of duties without granting access to content.
Permissions can be granted globally, per database, and at folder and entry level. These include read, edit, add, delete, export, print, Auto-Fill, share, and seal.
Password rules, default permissions, permitted entry types, export restrictions, storage locations, and client behavior can be defined centrally.
Critical credentials can be protected with approval workflows, for example using multiple supervisors, expiration times, and limits on concurrent use.
End-to-end protected: AES-256 for data, transport over TLS 1.3 with Perfect Forward Secrecy and certificates. Server-side user passwords are hashed with Argon2id. Roles, logging and encryption support technical and organisational measures pursuant to Art. 32 GDPR.
Request a quoteBackup, mirroring, logging, and recovery are critical for production enterprise environments.
A Mirror Server can mirror the Principal Server and take over in the event of a failure. This supports high availability without reliance on external SaaS.
Backups can be created on startup and at configurable intervals. Retention based on number or age supports recovery and compliance concepts.
Logins, access, changes, admin actions, and approval events are logged for traceability.
System requirements, network ports, and resource needs can be planned precisely before rollout.
Configuration and audit keys are stored in recoverable Key Vaults rather than being tied permanently to the machine. With Recovery Keys, the encrypted configuration remains usable even during a server migration or hardware replacement.
Automatic escalations warn of critically low storage space, repeated backup failures, blocked synchronisation, or an impending licence expiry.
Secrets should not end up in scripts, prompts, or local configuration files. Password Depot makes access controllable and auditable in a tamper-evident way.

The REST API enables integration with CI/CD, internal tools, scheduled jobs, and automation. Access remains centrally authorized and logged.
API access can be secured using bearer tokens, service accounts, or Windows SSO.
All security-relevant actions – logins, database, folder and entry access, sharing, and administrative and configuration changes – are logged in a cryptographically chained and signed form. Integrity can be checked on demand, on a schedule, and independently using the supplied verification tool.
The Audit Reader, Security Officer and Backup Operator roles let you delegate audit and backup tasks without granting access to database content.
The audit trail and server log can be sent in real time to Syslog and SIEM systems (Splunk, Microsoft Sentinel, Elastic) – via UDP, TCP, or encrypted over TLS.
Administrators can be notified of security-related events, such as failed logins, structural changes, sharing activity, or suspicious bulk actions.
The Server Manager clearly separates administration from day-to-day use. Administrators centrally manage policies, permissions, and logs, while users work with familiar clients.
View feature overviewThe right solution for your security requirements
Replace insecure management methods with centralized, secure databases with controlled access and complete logging.
Authorized users can access it from a desktop or mobile device. Strong passwords, MFA, and policies ensure a high level of security.
On-premises/private cloud – your data remains within your infrastructure. Strong encryption, role-based access, and audit logs support the requirements under Article 32 GDPR.
Roles, logging, and encryption support relevant Annex A controls (e.g., access, cryptography, operations) within your ISMS.
Security software “Made in Germany” – supports your compliance with GDPR requirements: Password Depot has been developed in Darmstadt, the City of Science, for more than 20 years.
Email sales@password-depot.de or call us at +49 6151 136500. We would be happy to show you the server in a brief, free webinar.
Book a webinar