Passwork: Declaración de transparencia
Para empresas de España
Equipo en Barcelona y en Valencia

Secure password sharing for teams and businesses

Control shared credentials with granular role-based access, audit logs, and instant revocation. Deploy self-hosted or in our secure sovereign EU cloud to meet strict NIS2 and ISO 27001 compliance standards.

Para empresas de España
Equipo en Barcelona y en Valencia

Trusted by 10,000+ companies worldwide

Maxon Kinder not Hilfe Deutsche Post Orange TDK Victoria Police

Por qué Passwork encaja en las empresas españolas

  • Equipo en Barcelona

    Desarrollado en Europa, con pleno cumplimiento del RGPD y NIS2 y soberanía de los datos

  • Compatible con ENS
    (RD 311/2022)

    El desarrollo y la infraestructura cumplen con los estándares internacionales de seguridad de la información

  • RGPD + LOPDGDD:
    control y auditoría

    Elegido por agencias gubernamentales e industrias altamente reguladas en toda Europa

  • Ideal para equipos de seguridad

    Controla accesos y terceros con mínimo privilegio, caducidad y auditoría.

  • Demo en vivo, piloto rápido y ayuda en la implantación, adaptados a tu escenario.

Where credential sharing breaks down
Six insecure channels prohibited by your security policy that employees use anyway

  • Slack and Teams DMs

    Credentials shared in chat exist outside access policies and audit trails. A single workspace compromise exposes your entire sharing history.

    2.4%

    of corporate Slack channels contain leaked sensitive secrets

    GitGuardian, 2025

  • Email threads

    Forwarded credentials create uncontrolled copies across mailboxes for years. A single compromised inbox exposes an entire archive of passwords.

    68%

    of data breaches involve a human element and credential sharing

    Verizon DBIR, 2024

  • Google Docs, Notion, Jira

    Credentials stored in shared documents and wikis inherit broad access rights. These unsecured records outlast employees, contractors, and projects.

    38%

    of incidents in collaboration tools are classified as highly critical

    GitGuardian, 2025

  • Shared spreadsheets

    Zero access control, no audit logs, and no way to revoke access. This setup is a guaranteed failure in any ISO 27001, SOC 2, or NIS2 audit.

    A.5.17

    mandates secure management of authentication information

    ISO 27001:2022

  • Browser-saved passwords

    Built-in browser managers are prime targets for infostealers. A single compromised endpoint exposes every saved credential.

    30%

    of compromised managed devices contain corporate credentials

    Verizon DBIR, 2025

  • Shared admin accounts

    Sharing privileged credentials destroys individual accountability. Doing so triggers an automatic control deficiency in SOC 2, ISO 27001, and NIS2 audits.

    70%

    of users reuse exposed passwords across multiple accounts

    SpyCloud, 2025

What credential failures cost the business
Independent breach economics and named incidents from 2024 to 2026. Each one traces to credentials shared without proper control.

€4.3M

Average breach cost when stolen credentials are the entry point. It takes an average of 246 days to detect and contain the breach.

IBM Cost of a Data Breach Report, 2025

39%

of all data breaches involve stolen or abused credentials across the full attack chain.

Verizon DBIR, 2026

95 days

Median time from an initial credential leak to ransomware deployment.

Verizon DBIR, 2026

€375M

Record fine imposed on Coupang in June 2026 after a former employee retained access and leaked customer data.

PIPC (Personal Information Protection Commission), 2026

2024 breach

Snowflake / UNC5537

Over 160 customer environments compromised, exposing 500M+ records.

Root cause: Credential theft targeting accounts without MFA.

November 2025

Nikkei Slack

An infostealer infection exposed Slack credentials for over 17,000 employees and external partners.

Root cause: Lack of credential rotation and session monitoring.

2024 to 2025

Coupang and KiranaPro

Former employees retained active credentials after departure and deleted critical company data.

Root cause: Incomplete offboarding and unrevoked access rights.

What EU regulators now require
Specific article-level controls. Each one carries documented evidence requirements at audit.

  • NIS2 / NIS2UmsuCG

    Article 21(2)(j)

    MFA for privileged, remote, and sensitive access. Germany's NIS2UmsuCG binding from 6 December 2025. About 29,500 companies in scope (BSI).

  • DORA

    Article 9(4)(c) and (d)

    In force since 17 January 2025. Least privilege, strong authentication, explicit controls against shared credentials for privileged access.

  • ISO 27001:2022

    Annex A.5.17

    Authentication information shall not be shared, easily guessed, or left in cleartext. Audit evidence required.

  • GDPR

    Article 32

    Organizations must ensure data confidentiality and restrict access. Sharing credentials without individual accountability violates Article 32 traceability requirements.

What a secure password manager actually does
Six controls that eliminate key credential security risks

Passwork vault access settings with role-based permissions

Centralize credential storage and manage access by roles or groups. Exactly what auditors look for during access reviews.

Passwork activity log with user actions and timestamps

Track every password action in real time. Simplify audits with detailed logs and maintain clear ownership of every change.

Passwork user management screen for access revocation

Revoke all password permissions automatically by disabling the user in your IdP. Close critical offboarding gaps and ensure seamless compliance.

Passwork SSO and MFA settings

Secure your vaults with SSO and phishing-resistant MFA. Fully meet the strict requirements of NIS2 Article 21(2)(j) for privileged access.

Passwork private and shared vaults separated in the interface

Keep personal passwords strictly private for users. For shared credentials, maintain strict control with designated owners, access scopes, and detailed activity logs.

Passwork on-premise installation wizard

Keep all credentials inside your local infrastructure. Host Passwork on-premise to comply with internal security policies, external auditors, and regulatory mandates.

Password and secrets manager built in the EU for teams and businesses

Passwork stores, shares, and audits credentials in one place, providing the exact controls required by NIS2 and ISO 27001. Deploy on-premises in your own data center, in a secure EU cloud, or within a dedicated cloud enterprise environment. Fully GDPR compliant and trusted by 10,000+ businesses across Europe.

  • Shared vaults with role and group permissions

    Replicate your organizational structure. Scope access precisely by team or project.

  • Full audit log of every access event

    Track who accessed what, when, and from where.

  • Revoke access in one click when an employee leaves

    Deactivate in your IdP, Passwork revokes access. No orphan accounts.

Passwork preview
  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • SAML
  • SCIM
  • LDAP / Active Directory

Gestión de secretos, no solo contraseñas
API de automatización DevOps sin el precio de HashiCorp

Todas las funciones de DevOps →

The answers that look right but aren't enough
Five widespread security myths and the evidence-based facts that disprove them

Three ways to deploy, one security model

Deploy on your own infrastructure, run in a secure sovereign EU cloud, or scale with our enterprise cloud platform while maintaining identical security standards

  • Self-hosted on-prem

    Run Passwork within your private data center and network. This option supports air-gapped environments for regulated industries, satisfying strict auditor requirements for complete local data control.

  • EU cloud

    Host your data in a secure EU cloud with default GDPR compliance. This German-hosted infrastructure ensures all credential stores remain strictly within European jurisdiction.

  • Cloud enterprise

    Scale across multiple regions with a primary EU deployment. This configuration provides international teams with high availability and guaranteed EU residency for sensitive credentials.

Con la confianza de empresas
en todo el mundo

Un gestor de contraseñas. Para todos los dispositivos.
Usa Passwork en cualquier lugar — en el navegador, en el móvil o en el escritorio

Extensión del navegador

Busque, autocompletar y cree credenciales sin salir del navegador. Funciona con Chrome, Firefox, Edge y Safari.

  • Autocompletado con un clic en cualquier página de inicio de sesión
  • Buscar en todas las bóvedas desde la extensión
  • Crear y guardar nuevas credenciales al instante
  • Generar contraseñas seguras al instante
Disponible
Browser extension password editing screenshot
Browser extension password generator screenshot
Browser extension password card screenshot
Browser extension settings screenshot

Aplicación móvil

Acceso rápido a las contraseñas corporativas desde su dispositivo móvil

Disponible

Aplicación móvil 2FA

Verificación de inicio de sesión cómoda con la aplicación de autenticación Passwork

Disponible

Aplicación de escritorio

Funcionalidad completa de gestión de contraseñas en una aplicación de escritorio nativa

Disponible

Elige tu plan
Costes de propiedad a largo plazo 30% menos que la media del sector

Comparar planes de Passwork

Consulta las diferencias entre los planes y elige el nivel adecuado de seguridad y control para tu equipo.

  • Standard

    Funciones esenciales para pymes que apoyan un crecimiento seguro

    3€
    por mes /
    por usuario
    facturado anualmente
    • Inicio rápido con todas las funciones principales
    • Sencillo, seguro y con poca carga administrativa
    • Bóvedas compartidas, acceso fácil, sin formación
  • Advanced Popular

    Capacidades avanzadas para necesidades de seguridad y gestión a gran escala

    4,5€
    por mes /
    por usuario
    facturado anualmente
    • SSO, mapeo de grupos LDAP, modelo basado en roles
    • Clustering, soporte de failover y copias de seguridad
    • Gerente personal y soporte técnico prioritario
  • Oferta vitalicia Mejor valor

    Un solo pago, sin suscripción: su precio, las actualizaciones y el soporte quedan asegurados

    Pago único
    Obtenga un presupuesto personalizado
    • Actualizaciones de por vida y soporte prioritario
    • Ahorre hasta un 50 % en comparación con una suscripción a largo plazo
    • Una sola aprobación, cero renovaciones

Govern every credential. Audit every access.

A 30-minute demo covers the audit log, the offboarding revoke, deployment options, and the controls your NIS2 auditor will ask about.

No credit card required
Full feature access
GDPR compliant
Enterprise-level support

Frequently Asked Questions

Secure credential sharing requires a dedicated password vault with role-based permissions, full audit logging, and single sign-on (SSO) with multi-factor authentication (MFA). Centralized vaults satisfy both ISO 27001:2022 Annex A.5.17, which prohibits sharing authentication information in cleartext, and NIS2 Article 21(2)(j), which mandates MFA for privileged access.

SSO secures integrated enterprise applications, leaving other access vectors open. Research shows 96% of email logins and 91% of AI tools operate outside the SSO perimeter. Service accounts, legacy infrastructure, vendor portals, and shadow SaaS require a dedicated credential store. Industry data confirms that 74% of security professionals view SSO alone as an incomplete access control solution.

NIS2 prohibits unencrypted, untraceable credential sharing. Under Article 21(2)(j) and (g), organizations must secure access control and maintain strict cybersecurity hygiene. This requires that any shared corporate credentials are encrypted, restricted to authorized users via least privilege, and fully audited. Sharing passwords through plaintext channels — such as chat apps or spreadsheets — violates these requirements, as it prevents auditors from identifying which individual actually accessed the system.

DORA Article 9(4)(c) and (d) require financial entities and their critical ICT providers to apply least privilege, strong authentication, and explicit controls against shared credentials for privileged access. Regulators demand documented evidence of these access controls. Implementing a centralized vault with role-based access, MFA, and audit logs provides the necessary compliance documentation.

Annex A.5.17 states that authentication information must remain confidential, secure, and protected against unauthorized sharing. When shared credentials are unavoidable for non-personal entities, organizations must restrict them to authorized personnel through documented controls. Auditors require verifiable evidence — including permission logs, access reviews, and signed acceptable-use policies — which static documents and chat histories cannot generate.

Yes. Passwork supports on-premises deployment within your private data center, including air-gapped environments for regulated industries. We also offer a secure cloud option hosted in Germany and a multi-region enterprise cloud platform with a primary EU deployment. All three options are GDPR compliant and support ISO 27001 compliance framework requirements.

Disabling a user in your identity provider or marking them as a leaver in Passwork revokes all vault access instantly. The platform immediately terminates active sessions and records the event in the audit log, detailing who held access and when it was revoked. This automated workflow directly addresses the offboarding gaps exposed in the Coupang and KiranaPro security incidents.

Chat messages, email threads, and browser stores lack access controls and encryption standards. Browser-saved credentials are the primary target for infostealer malware, with corporate credentials appearing in 30% of managed and 46% of unmanaged compromised devices. These informal channels fail to enforce least privilege, log access events, or support instant revocation, directly violating ISO 27001 A.5.17.

Got any questions? — Help center