Passwork: Transparency Statement

Zero-knowledge secrets vault for your CI/CD pipelines

Centralize and secure credentials for GitLab CI, GitHub Actions, Kubernetes, Jenkins, and Bitbucket. Keep complete control by self-hosting on your infrastructure, or deploy in our secure EU cloud. Fully ISO 27001 certified, NIS2, and DORA compliant.

Trusted by 10,000+ companies worldwide

Maxon Kinder not Hilfe Deutsche Post Orange TDK Victoria Police

Why leading enterprises choose Passwork

  • Made in Europe

    Developed in Europe, with full GDPR and NIS2 compliance and data sovereignty

  • ISO 27001 certified

    Development and infrastructure meet the international benchmark for information security

  • Trusted by public sector

    Chosen by government agencies and highly regulated industries across Europe

  • Enterprise‑grade protection

    On‑premise deployment means your passwords never leave your infrastructure

  • Independent research shows 30% savings compared to competitors

The growing cost of unsecured CI/CD pipelines
Key security insights and industry data from GitGuardian, Verizon, and IBM

  • 28.65M

    New hardcoded secrets leaked to public GitHub in 2025, representing a 34% increase year over year.

    GitGuardian SoSS 2026

  • 94 days

    Median time to revoke a leaked GitHub secret. Most secrets are still valid weeks after the leak is reported.

    Verizon DBIR 2025

  • €3.87M

    Average cost of a data breach in Germany. Industrial sector reaches €6.67M.

    IBM CODB 2025

  • 59%

    Share of compromised machines in supply-chain attacks targeting CI/CD runners.

    GitGuardian SoSS 2026

Major credential leaks in EU enterprises

Leaving credentials outside a secure vault is the common denominator, typically occurring when they are hardcoded in scripts, leaked in memory dumps, or left active past their expiration date.

December 2024

A cloud misconfiguration at Cariad exposed sensitive data linked to hundreds of thousands of Volkswagen Group electric vehicles. The leaked datasets included real-time vehicle status, owner contact details, and precise live location data for cars across Europe.

Root cause

Hardcoded AWS access keys remained exposed within a public memory dump for several months, granting unauthorized access to the cloud storage buckets used by Cariad systems.

Impact

Security researchers from the Chaos Computer Club discovered the leak, which compromised data from approximately 800,000 electric vehicles, including precise GPS coordinates for 460,000 of them.

Mercedes-Benz

January 2024

A Mercedes-Benz employee accidentally published a GitHub personal access token (PAT) in a public repository. This token granted full access to the company’s internal GitHub Enterprise Server, exposing private repositories and proprietary engineering data.

Root cause

A GitHub personal access token was committed to a public repository and remained accessible for several months before being discovered and revoked.

Impact

The exposed token granted unrestricted access to internal source code, cloud credentials, database connection strings, API keys, SSO passwords, blueprints, and design documents.

tj-actions

March 2025

A popular GitHub Action was compromised in a software supply chain attack. Attackers hijacked version tags, forcing workflows that rely on this action to execute malicious code during automated CI/CD runs.

Root cause

Attackers re-pointed multiple GitHub Action version tags to a malicious commit, enabling unauthorized code execution directly inside repository workflows.

Impact

CI/CD secrets leaked into GitHub Actions logs. Over 23,000 repositories were affected, including public projects where exposed logs revealed tokens, API keys, and other credentials.

How Passwork closes the gap
Four architectural principles for secure secrets management.

On-premise or cloud, same product

Passwork is delivered as a self-hosted product or as a managed instance in our sovereign EU cloud. The Zero-knowledge architecture, API, Passwork CLI, and Python SDK are identical in both deployment models. Air-gapped deployments are supported for the self-hosted edition.

One vault for humans and machines

Passwork has no separate "secret" entity. Any password record can act as a credential for users and automated pipelines alike. Developers, administrators, and CI service accounts share the same vault structure, RBAC, and audit log. Every read, write, and delete action is logged with a user, timestamp, and action type.

Zero-knowledge architecture

Encryption and decryption happen strictly client-side within the browser, Passwork CLI, or the Python SDK. The server stores only encrypted ciphertext. Even with server and database access, a system administrator cannot read secret values, attachment contents, or encryption keys.

One CLI, every pipeline

The Passwork CLI utility pulls secrets at runtime in GitLab CI, GitHub Actions, Bitbucket Pipelines, and Kubernetes (using init container or sidecar patterns). Each invocation fetches fresh data from the server without caching, decrypts it locally, and injects it into environment variables for the duration of the command.

Pipeline integration reference
Production-grade snippets from our documentation. Just copy, configure, and run.

See all integrations in the docs

One vault for folders, RBAC, and audit logs

Your CI service accounts are managed alongside developer credentials. With the same folders, permissions, and logs, a platform engineer can audit every secret access from a single dashboard.

  • Folder hierarchy by environment and service
  • Service accounts with scoped, read-only access
  • Comprehensive audit log detailing the user, timestamp, and action type
Passwork activity log dashboard showing user actions, timestamps, and directories

How a secret reaches your runner

The Passwork server and transit networks see only encrypted ciphertext. The secret exists in plaintext strictly within your runner, decrypted locally by Passwork CLI for the duration of the deployment command. This security model remains identical across self-hosted and sovereign EU cloud deployments.

Diagram showing encrypted secret flow from Passwork to CI runner and target systems with audit logging

Built for EU and DACH compliance

The security controls required under NIS2, DORA, ISO 27001, BSI IT-Grundschutz, and PCI DSS map directly to Passwork features. Use this reference table for your next Statement of Applicability review or supplier security questionnaire.

Requirement
Cryptography and key lifecycle
MFA and strong authentication
Identity for humans and machines
Authentication info handling
Source code access
Dev/test/prod separation
Kubernetes pipeline secrets
No hardcoded secrets
Third-party ICT oversight
EU and DACH compliance mapping for Passwork features
Source How Passwork helps
NIS2 Art. 21(2)(h) DORA Art. 9(4)(d) ISO 27001 A.8.24
Client-side encryption, automated rotation scripts, and per-key audit logging
NIS2 Art. 21(2)(j) ISO 27001 A.8.5
Per-account MFA and dedicated security policies for service accounts
ISO 27001 A.5.16 DORA RTS 2024/1774
Service accounts restricted by least-privilege folder permissions
ISO 27001 A.5.17 Secure credential provisioning, rotation, and revocation in a single workflow
ISO 27001 A.8.4 Repository and SSO credentials managed in the same vault as CI/CD secrets
ISO 27001 A.8.31 Isolated folders and separate service accounts to prevent cross-environment access
BSI APP.4.4 Native support for init container and sidecar patterns
PCI DSS 8.2 / 8.6 Runtime secret retrieval via Passwork CLI or Python SDK
DORA Art. 28 On-premises deployment eliminates external ICT third parties, cloud is managed within sovereign EU infrastructure

Get the compliance mapping

A detailed table mapping NIS2, DORA, ISO 27001, BSI IT-Grundschutz, and PCI DSS clauses directly to Passwork features.

Self-hosted or cloud

Two deployment models, one product. Choose the option that aligns with your operational capabilities and compliance requirements.

Comparison of Passwork self-hosted and EU cloud deployment models
Dimension Passwork self-hosted
Data residency Your data center, your VPC, or an air-gapped network
Ciphertext access Restricted to your infrastructure
Plaintext decryption Decrypted client-side only; inaccessible to anyone outside your team
DORA third-party scope None, you operate it
Best fit Regulated industries, air-gapped systems, and BSI IT-Grundschutz compliance
Time to first secret Days (self-managed installation)
Pricing model Per-user (perpetual or annual license)

If your auditor asks who can read your production database password, the answer should be a list of people, not a list of vendors. Self-hosted Passwork gives you that answer.

Trusted by businesses
worldwide

Our applications
Use Passwork anywhere — in your browser, on mobile, or on desktop

Browser extension

Search, autofill, and create credentials without leaving the browser. Works with Chrome, Firefox, Edge, and Safari.

  • One-click autofill on any login page
  • Search across all vaults from the extension
  • Create and save new credentials instantly
  • Generate strong passwords on the fly
Available for
Browser extension password editing screenshot
Browser extension password generator screenshot
Browser extension password card screenshot
Browser extension settings screenshot

Mobile app

Quick access to your corporate passwords from your mobile device

Available in

2FA mobile app

Convenient login verification using the Passwork authenticator app

Available in

Desktop app

Full password management functionality in a native desktop application

Available for

Choose your plan
Long-term ownership costs 30% less than the industry average

Compare Passwork plans

See the differences between plans and choose the right level of security and control for your team.

  • Standard

    Essential features for small and medium businesses to support secure growth

    3€
    per month /
    per user
    billed annually
    • Quick start with all core features
    • Simple, secure, and low admin overhead
    • Shared vaults, easy access, no training
  • Advanced Popular

    Advanced capabilities for large-scale security and management needs

    4,5€
    per month /
    per user
    billed annually
    • SSO, Mapping LDAP groups, role-based model
    • Clustering, failover support and backups
    • Personal manager and priority technical support
  • Custom

    Tailored to your infrastructure, security standards, and unique business needs

    Individual pricing
    Contact expert for details
    • Enterprise-grade security and compliance
    • Flexible deployment and integration
    • Dedicated onboarding and support

Ready to secure your business?

Join thousands of IT professionals who trust Passwork to manage their passwords securely. Start your free trial today or schedule a personalized demo.

No credit card required
Full feature access
GDPR compliant
Enterprise-level support

Frequently Asked Questions

Revoke the token immediately in the service account settings. The audit log will show exactly which secrets were accessed while the token was active. Once identified, rotate the affected credentials and issue a new token from a clean service account. We recommend using a dedicated service account per pipeline to prevent a single leak from cascading across your infrastructure.

No vendor with a true Zero-Knowledge architecture can perform server-side rotation, as the server does not hold the required decryption keys. Instead, Passwork provides rotation scripts that you run within your own environment: passwork-cli update for shell scripts, and Python SDK examples for PostgreSQL, MySQL, and API keys. You schedule the rotation via Cron or any other orchestrator, and Passwork safely stores the newly generated values.

For self-hosted deployments, we have no access to your infrastructure or data under any circumstances. For our sovereign EU cloud, we see nothing but encrypted ciphertext. Because of our Zero-Knowledge architecture, all sensitive metadata is encrypted client-side before it is sent to the server. Passwork cloud administrators have zero visibility into your credentials, encryption keys, or audit logs.

Yes. The self-hosted edition requires no outbound network connections. Software updates and license activations can be managed entirely offline. Multiple enterprise customers in the DACH region operate Passwork within completely isolated, disconnected networks.

Each pipeline is assigned a dedicated service account. The runner authenticates using an access token scoped to a specific folder, which is stored as a protected CI/CD variable. The master key is never exposed to or handled by the runner during typical CI/CD workflows.

Please refer to our compliance section. Vaulting and cryptographic policies map directly to NIS2 Art. 21(2)(h) and DORA Art. 9(4)(d). MFA and strong authentication align with NIS2 Art. 21(2)(j) and ISO 27001 A.8.5. Service accounts with least-privilege access fulfill the requirements of ISO 27001 A.5.16 and BSI APP.4.4. We can walk you through these specific controls during a technical demo.

Passwork acts as a secure credential vault for team members and automated pipelines, complete with granular RBAC and full audit logging. It is designed to coexist with traditional PAM solutions like CyberArk or Delinea. You can continue using those platforms for privileged session brokering, just-in-time elevation, or session recording where required.

Export your source vault to JSON or YAML. You can then run our Python SDK migration template to automatically map your existing fields to Passwork records, folders, and tags. Our team will provide the necessary scripts and assist you with a dry run before the final cutover.

Got any questions? — Help center