Independent assessment
The security assessment was conducted externally by a company specializing in penetration testing.
Password Depot 19 was reviewed by SySS GmbH as part of an independent penetration test. In the certificate, SySS confirms that no critical security vulnerabilities were identified within the agreed test period and scope.
SySS confirms for Password Depot 19.0.0 that the test object was subjected to simulated attacks during the specified period and at the intended test depth. According to the certificate, no critical security vulnerabilities were identified.
The security assessment was conducted externally by a company specializing in penetration testing.
Typical attack paths relevant from the perspective of potential attackers were tested.
A penetration test is a point-in-time technical assessment. That is why we focus on continuous improvement rather than one-time statements.
According to the certificate, the following attack scenarios were simulated, among others:
The detailed report additionally explains that the focus of the test was on Password Depot for Windows and Password Depot Enterprise Server with REST API. Android, iOS, macOS, and a web client were included to a limited extent.
Project period: 01.12.2025 to 23.12.2025
Test scope: 10 person-days
Conducted by: Two IT security consultants from SySS
Recommendation from SySS: Retest after every significant change or at least once a year.
A detailed pentest report contains technical findings, attack paths, and security-relevant detailed information. Such content does not belong on a public website.
That is why this page focuses on the confirmed test scope, the overall conclusion, and the independent execution of the test.
A penetration test is always an assessment within a defined scope, time frame, and test budget. It does not replace ongoing security work, but it is an important external validation of a product’s technical security review.
For tenders, security assessments, and procurement processes, we provide the official SySS certificate as proof of the external assessment.