Feature Overview Password Depot Enterprise Server

All security, integration and administration features at a glance – so you can verify whether Password Depot fits your infrastructure.

Made in Germany ISO 27001 certified GDPR-compliant

Security & Authentication

Secure connections (TLS 1.3 – Transport Layer Security)

All client-server communication is encrypted with TLS 1.3. Before being used, certificates are checked against their private key and for validity; expired certificates are no longer served (fallback to the integrated default certificate).

Two-factor authentication (2FA)

2FA via TOTP (Time-based One-Time Password) authenticators, email codes, and FIDO2-compatible devices such as USB tokens, Windows Hello and smartphones.

Flexible authentication

Support for classic credentials (username/password), Windows credentials, Integrated Windows Authentication with SSO (Single Sign-On), Entra ID / Azure AD, other OIDC (OpenID Connect) providers, and WebAuthn/Passkey.

Password hashing with Argon2id

User passwords are hashed server-side with Argon2id – a memory-hard method aligned with the current state of the art.

Hardened REST API tokens

API session tokens use a fresh signing key for each login; logout or a server restart immediately invalidates active tokens. Token validation is fixed to HS256.

Brute-force protection per IP

Repeated failed logins are reliably throttled and blocked per IP address. Lockout events are written to the activity log and to connected SIEM systems.

Certificate Wizard

Integrated wizard for generating and installing root and server certificates directly on the server.

Server policies

Central definition of security and usage policies: default access rights, password generation rules, allowed record types, and more.

Identity & Integration

Active Directory integration

Import users and security groups from Active Directory across multiple domains in a forest; synchronisation manually or automatically on a schedule. Databases are created automatically for newly detected subgroups.

Entra ID / Azure AD integration

Import and synchronise users and groups from Entra ID / Azure AD. Authentication is hardened: ID tokens are checked for signature and audience before being trusted, insecure methods are rejected, and key rotations are adopted immediately. In Multi-Tenant synchronisation, a faulty tenant no longer aborts the others.

Other identity providers (OIDC)

Import and synchronization of users and groups from third-party identity providers that support OIDC (OpenID Connect).

Multi-platform access

64-bit Windows server service providing concurrent access for all client platforms (Windows, macOS, iOS, Android, Linux) plus browser access via a dedicated web interface.

Administration & Operations

Group properties
Configure groups in detail – set name, department and type, manage members and synchronize with Active Directory when needed.
Server roles (RBAC – role-based access control)

Assign specific server roles to administrators who connect via Server Manager to manage defined partitions, databases or groups.

Separation of duties: audit, security and backup roles

Three dedicated roles – Audit Reader, Security Officer and Backup Operator – delegate audit, security and backup tasks without granting access to database content (Separation of Duties).

High availability / mirroring

Real-time mirroring to a secondary server instance that stays synchronized with the primary and can take over in case of failures.

Server Manager (administration console)

64-bit Windows administration application (Server Manager) for local or remote management of the server.

Shared databases

Central, online access to shared team databases and private vaults for passwords, notes, documents, access keys, certificates and other sensitive data types.

Automated backup

Multiple options for scheduled, automatic backups of all databases and configuration files.

Recoverable Key Vaults & Recovery Keys

Configuration and audit keys are stored in separate, recoverable Key Vaults instead of being tied to the machine. Recovery Keys can be used to rebind the encrypted configuration on a new server – server migration and hardware replacement remain possible.

Monitoring & escalations

Escalations for critically low storage space, repeated backup failures, blocked synchronisation and impending licence expiry. Failed directory synchronisations are recorded in the audit trail.

Users, groups and inheritance

Classic user/group model with inheritance of permissions from parent groups for consistent access control.

Granular access rights & time restrictions

Fine-grained permissions for databases, folders and individual records, including optional time-limited access.

Shared secrets & approval workflows

Controlled sharing of records (passwords, notes, documents) between users with options such as supervisor approval (N-of-M quorum), limits on concurrent use, automatic expiration, etc.

Governance, Logging & Interfaces

Tamper-evident audit trail

A cryptographically chained and signed log of all security-relevant actions. Subsequent changes become detectable; integrity can be checked on demand, on a schedule and independently using the command-line tool (pd_audit_verify). A dedicated audit area in Server Manager provides filters, detail view and export to NDJSON/CSV – audit export also via REST API v2.0.

REST API v2.0

REST API v2.0 for automating administrative tasks and direct server access from your own applications – including audit export. Access remains centrally authorised, logged and secured with hardened tokens.

Comprehensive logging

Detailed master log for auditing user and administrator actions; internal events can be written to the Windows Event Log and/or dedicated log files.

SIEM/Syslog forwarding

Real-time forwarding of audit trail and server log to Syslog/SIEM servers in RFC 5424 format – over UDP, TCP (RFC 6587) or encrypted over TLS (RFC 5425), with enforced certificate validation.

Notification and alerting

Email notifications to designated administrators for relevant events: successful or failed logins, configuration or policy changes, access to specific databases or entries, and more.

Reporting

Extensive reporting capabilities in Server Manager for all relevant server, security and usage data.

Client security in the Windows client

Authenticated encryption (AES-GCM)

In the Windows client, new local databases use AES-GCM by default (authenticated encryption via Windows CNG). The classic AES-CBC mode remains available; existing databases open unchanged.

Cryptographically secure generators

Password and passphrase generators source every character and word from a cryptographically secure random source via Windows CNG.

Ready to test Password Depot in your environment?

Set up roles, databases and security policies – in a realistic 30-day trial with full functionality.