Independently tested product security

Reviewed by SySS: Password Depot 19

Password Depot 19 was reviewed by SySS GmbH as part of an independent penetration test. In the certificate, SySS confirms that no critical security vulnerabilities were identified within the agreed test period and scope.

Independent assessment 12/2025 Retest recommended
Key finding

The key finding

SySS confirms for Password Depot 19.0.0 that the test object was subjected to simulated attacks during the specified period and at the intended test depth. According to the certificate, no critical security vulnerabilities were identified.

Tester SySS GmbH
Test object Password Depot 19
Test duration 01–23 Dec 2025
Recommendation Retest after changes

Independent assessment

The security assessment was conducted externally by a company specializing in penetration testing.

Realistic attack scenarios

Typical attack paths relevant from the perspective of potential attackers were tested.

Security as a process

A penetration test is a point-in-time technical assessment. That is why we focus on continuous improvement rather than one-time statements.

Test scope

Scope of the penetration test

According to the certificate, the following attack scenarios were simulated, among others:

The detailed report additionally explains that the focus of the test was on Password Depot for Windows and Password Depot Enterprise Server with REST API. Android, iOS, macOS, and a web client were included to a limited extent.

  • Cryptographic attacks
  • Rogue client attacks
  • Rogue server attacks
  • Machine-in-the-middle attacks
  • Input validation attacks

Test process

Project period: 01.12.2025 to 23.12.2025

Test scope: 10 person-days

Conducted by: Two IT security consultants from SySS

Recommendation from SySS: Retest after every significant change or at least once a year.

Transparency

What we deliberately do not disclose publicly

A detailed pentest report contains technical findings, attack paths, and security-relevant detailed information. Such content does not belong on a public website.

That is why this page focuses on the confirmed test scope, the overall conclusion, and the independent execution of the test.

Important context

A penetration test is always an assessment within a defined scope, time frame, and test budget. It does not replace ongoing security work, but it is an important external validation of a product’s technical security review.

Proof for customers and partners

For tenders, security assessments, and procurement processes, we provide the official SySS certificate as proof of the external assessment.

Certificate available as a PDF – suitable for procurement documents, audits, and security assessments.