Passwork: 透明性に関する声明

Secure password sharing for teams and businesses

Control shared credentials with granular role-based access, audit logs, and instant revocation. Deploy self-hosted or in our secure sovereign EU cloud to meet strict NIS2 and ISO 27001 compliance standards.

Trusted by 10,000+ companies worldwide

Maxon Kinder not Hilfe Deutsche Post Orange TDK Victoria Police

なぜリーディングカンパニーが選ぶのか Passwork

  • ヨーロッパ製

    ヨーロッパで開発され、GDPRおよびNIS2に完全準拠し、データ主権を確保

  • ISO 27001認証取得

    開発およびインフラは、情報セキュリティの国際基準を満たしています

  • 公共部門にも信頼されています

    ヨーロッパ全域の政府機関や厳しく規制された業界に選ばれています

  • エンタープライズグレードの保護

    オンプレミス導入により、パスワードがインフラから外部に出ることはありません

  • 独立調査により、競合他社と比べて30%のコスト削減が示されています

Where credential sharing breaks down
Six insecure channels prohibited by your security policy that employees use anyway

  • Slack and Teams DMs

    Credentials shared in chat exist outside access policies and audit trails. A single workspace compromise exposes your entire sharing history.

    2.4%

    of corporate Slack channels contain leaked sensitive secrets

    GitGuardian, 2025

  • Email threads

    Forwarded credentials create uncontrolled copies across mailboxes for years. A single compromised inbox exposes an entire archive of passwords.

    68%

    of data breaches involve a human element and credential sharing

    Verizon DBIR, 2024

  • Google Docs, Notion, Jira

    Credentials stored in shared documents and wikis inherit broad access rights. These unsecured records outlast employees, contractors, and projects.

    38%

    of incidents in collaboration tools are classified as highly critical

    GitGuardian, 2025

  • Shared spreadsheets

    Zero access control, no audit logs, and no way to revoke access. This setup is a guaranteed failure in any ISO 27001, SOC 2, or NIS2 audit.

    A.5.17

    mandates secure management of authentication information

    ISO 27001:2022

  • Browser-saved passwords

    Built-in browser managers are prime targets for infostealers. A single compromised endpoint exposes every saved credential.

    30%

    of compromised managed devices contain corporate credentials

    Verizon DBIR, 2025

  • Shared admin accounts

    Sharing privileged credentials destroys individual accountability. Doing so triggers an automatic control deficiency in SOC 2, ISO 27001, and NIS2 audits.

    70%

    of users reuse exposed passwords across multiple accounts

    SpyCloud, 2025

What credential failures cost the business
Independent breach economics and named incidents from 2024 to 2026. Each one traces to credentials shared without proper control.

€4.3M

Average breach cost when stolen credentials are the entry point. It takes an average of 246 days to detect and contain the breach.

IBM Cost of a Data Breach Report, 2025

39%

of all data breaches involve stolen or abused credentials across the full attack chain.

Verizon DBIR, 2026

95 days

Median time from an initial credential leak to ransomware deployment.

Verizon DBIR, 2026

€375M

Record fine imposed on Coupang in June 2026 after a former employee retained access and leaked customer data.

PIPC (Personal Information Protection Commission), 2026

2024 breach

Snowflake / UNC5537

Over 160 customer environments compromised, exposing 500M+ records.

Root cause: Credential theft targeting accounts without MFA.

November 2025

Nikkei Slack

An infostealer infection exposed Slack credentials for over 17,000 employees and external partners.

Root cause: Lack of credential rotation and session monitoring.

2024 to 2025

Coupang and KiranaPro

Former employees retained active credentials after departure and deleted critical company data.

Root cause: Incomplete offboarding and unrevoked access rights.

What EU regulators now require
Specific article-level controls. Each one carries documented evidence requirements at audit.

  • NIS2 / NIS2UmsuCG

    Article 21(2)(j)

    MFA for privileged, remote, and sensitive access. Germany's NIS2UmsuCG binding from 6 December 2025. About 29,500 companies in scope (BSI).

  • DORA

    Article 9(4)(c) and (d)

    In force since 17 January 2025. Least privilege, strong authentication, explicit controls against shared credentials for privileged access.

  • ISO 27001:2022

    Annex A.5.17

    Authentication information shall not be shared, easily guessed, or left in cleartext. Audit evidence required.

  • GDPR

    Article 32

    Organizations must ensure data confidentiality and restrict access. Sharing credentials without individual accountability violates Article 32 traceability requirements.

What a secure password manager actually does
Six controls that eliminate key credential security risks

Passwork vault access settings with role-based permissions

Centralize credential storage and manage access by roles or groups. Exactly what auditors look for during access reviews.

Passwork activity log with user actions and timestamps

Track every password action in real time. Simplify audits with detailed logs and maintain clear ownership of every change.

Passwork user management screen for access revocation

Revoke all password permissions automatically by disabling the user in your IdP. Close critical offboarding gaps and ensure seamless compliance.

Passwork SSO and MFA settings

Secure your vaults with SSO and phishing-resistant MFA. Fully meet the strict requirements of NIS2 Article 21(2)(j) for privileged access.

Passwork private and shared vaults separated in the interface

Keep personal passwords strictly private for users. For shared credentials, maintain strict control with designated owners, access scopes, and detailed activity logs.

Passwork on-premise installation wizard

Keep all credentials inside your local infrastructure. Host Passwork on-premise to comply with internal security policies, external auditors, and regulatory mandates.

Password and secrets manager built in the EU for teams and businesses

Passwork stores, shares, and audits credentials in one place, providing the exact controls required by NIS2 and ISO 27001. Deploy on-premises in your own data center, in a secure EU cloud, or within a dedicated cloud enterprise environment. Fully GDPR compliant and trusted by 10,000+ businesses across Europe.

  • Shared vaults with role and group permissions

    Replicate your organizational structure. Scope access precisely by team or project.

  • Full audit log of every access event

    Track who accessed what, when, and from where.

  • Revoke access in one click when an employee leaves

    Deactivate in your IdP, Passwork revokes access. No orphan accounts.

Passwork preview
  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • SAML
  • SCIM
  • LDAP / Active Directory

パスワードだけでなく、シークレット管理も
HashiCorpの価格なしでDevOps自動化APIを利用可能

すべてのDevOps機能 →

The answers that look right but aren't enough
Five widespread security myths and the evidence-based facts that disprove them

Three ways to deploy, one security model

Deploy on your own infrastructure, run in a secure sovereign EU cloud, or scale with our enterprise cloud platform while maintaining identical security standards

  • Self-hosted on-prem

    Run Passwork within your private data center and network. This option supports air-gapped environments for regulated industries, satisfying strict auditor requirements for complete local data control.

  • EU cloud

    Host your data in a secure EU cloud with default GDPR compliance. This German-hosted infrastructure ensures all credential stores remain strictly within European jurisdiction.

  • Cloud enterprise

    Scale across multiple regions with a primary EU deployment. This configuration provides international teams with high availability and guaranteed EU residency for sensitive credentials.

企業から信頼されています 世界中で

1つのパスワードマネージャー。あらゆるデバイスで。
Passworkを どこでも — ブラウザ、モバイル、またはデスクトップで

ブラウザ拡張機能

ブラウザを離れることなく、検索、自動入力、認証情報の作成が可能です。Chrome、Firefox、Edge、Safariに対応しています。

  • あらゆるログインページでワンクリック自動入力
  • 拡張機能からすべてのvaultを検索
  • 新しい認証情報を即座に作成・保存
  • その場で強力なパスワードを生成
利用可能
Browser extension password editing screenshot
Browser extension password generator screenshot
Browser extension password card screenshot
Browser extension settings screenshot

モバイルアプリ

モバイルデバイスから企業パスワードへ迅速にアクセス

利用可能

2FAモバイルアプリ

Passwork認証アプリによる便利なログイン確認

利用可能

デスクトップアプリ

ネイティブデスクトップアプリで完全なパスワード管理機能を提供

利用可能

プランを選択
長期的な所有コスト 30%安い 業界平均より

Passworkのプランを比較

各プランの違いを確認し、チームに最適なセキュリティレベルと管理機能を選択してください。

  • Standard

    中小企業の安全な成長を支援する基本機能

    3€
    月額 /
    ユーザーごと
    年額請求
    • 主要機能をすべて備えたクイックスタート
    • シンプルで安全、管理負担が少ない
    • 共有ボールト、簡単にアクセス可能、トレーニング不要
  • Advanced 人気

    大規模なセキュリティおよび管理ニーズ向けの高度な機能

    4,5€
    月額 /
    ユーザーごと
    年額請求
    • SSO、LDAPグループのマッピング、ロールベースモデル
    • クラスタリング、フェイルオーバー対応およびバックアップ
    • 専任マネージャーと優先テクニカルサポート
  • ライフタイムオファー ベストバリュー

    一度の支払いで、サブスクリプションは不要:価格、アップデート、サポートがそのまま保証されます

    一括払い
    個別の見積もりを取得
    • 永久アップデートと優先サポート
    • 長期サブスクリプションと比較して最大50%お得
    • 承認は一度だけ、更新はゼロ

Govern every credential. Audit every access.

A 30-minute demo covers the audit log, the offboarding revoke, deployment options, and the controls your NIS2 auditor will ask about.

No credit card required
Full feature access
GDPR compliant
Enterprise-level support

Frequently Asked Questions

Secure credential sharing requires a dedicated password vault with role-based permissions, full audit logging, and single sign-on (SSO) with multi-factor authentication (MFA). Centralized vaults satisfy both ISO 27001:2022 Annex A.5.17, which prohibits sharing authentication information in cleartext, and NIS2 Article 21(2)(j), which mandates MFA for privileged access.

SSO secures integrated enterprise applications, leaving other access vectors open. Research shows 96% of email logins and 91% of AI tools operate outside the SSO perimeter. Service accounts, legacy infrastructure, vendor portals, and shadow SaaS require a dedicated credential store. Industry data confirms that 74% of security professionals view SSO alone as an incomplete access control solution.

NIS2 prohibits unencrypted, untraceable credential sharing. Under Article 21(2)(j) and (g), organizations must secure access control and maintain strict cybersecurity hygiene. This requires that any shared corporate credentials are encrypted, restricted to authorized users via least privilege, and fully audited. Sharing passwords through plaintext channels — such as chat apps or spreadsheets — violates these requirements, as it prevents auditors from identifying which individual actually accessed the system.

DORA Article 9(4)(c) and (d) require financial entities and their critical ICT providers to apply least privilege, strong authentication, and explicit controls against shared credentials for privileged access. Regulators demand documented evidence of these access controls. Implementing a centralized vault with role-based access, MFA, and audit logs provides the necessary compliance documentation.

Annex A.5.17 states that authentication information must remain confidential, secure, and protected against unauthorized sharing. When shared credentials are unavoidable for non-personal entities, organizations must restrict them to authorized personnel through documented controls. Auditors require verifiable evidence — including permission logs, access reviews, and signed acceptable-use policies — which static documents and chat histories cannot generate.

Yes. Passwork supports on-premises deployment within your private data center, including air-gapped environments for regulated industries. We also offer a secure cloud option hosted in Germany and a multi-region enterprise cloud platform with a primary EU deployment. All three options are GDPR compliant and support ISO 27001 compliance framework requirements.

Disabling a user in your identity provider or marking them as a leaver in Passwork revokes all vault access instantly. The platform immediately terminates active sessions and records the event in the audit log, detailing who held access and when it was revoked. This automated workflow directly addresses the offboarding gaps exposed in the Coupang and KiranaPro security incidents.

Chat messages, email threads, and browser stores lack access controls and encryption standards. Browser-saved credentials are the primary target for infostealer malware, with corporate credentials appearing in 30% of managed and 46% of unmanaged compromised devices. These informal channels fail to enforce least privilege, log access events, or support instant revocation, directly violating ISO 27001 A.5.17.

Got any questions? — Help center