Passwork: Oświadczenie o przejrzystości

Secure password sharing for teams and businesses

Control shared credentials with granular role-based access, audit logs, and instant revocation. Deploy self-hosted or in our secure sovereign EU cloud to meet strict NIS2 and ISO 27001 compliance standards.

Trusted by 10,000+ companies worldwide

Maxon Kinder not Hilfe Deutsche Post Orange TDK Victoria Police

Dlaczego wiodące firmy wybierają Passwork

  • Wyprodukowane w Europie

    Opracowane w Europie, z pełną zgodnością z RODO i NIS2 oraz suwerennością danych

  • Certyfikat ISO 27001

    Rozwój i infrastruktura spełniają międzynarodowe standardy bezpieczeństwa informacji

  • Zaufany przez sektor publiczny

    Wybierany przez agencje rządowe i silnie regulowane branże w całej Europie

  • Ochrona klasy korporacyjnej

    Wdrożenie lokalne oznacza, że Twoje hasła nigdy nie opuszczają Twojej infrastruktury

  • Niezależne badania pokazują 30% oszczędności w porównaniu z konkurencją

Where credential sharing breaks down
Six insecure channels prohibited by your security policy that employees use anyway

  • Slack and Teams DMs

    Credentials shared in chat exist outside access policies and audit trails. A single workspace compromise exposes your entire sharing history.

    2.4%

    of corporate Slack channels contain leaked sensitive secrets

    GitGuardian, 2025

  • Email threads

    Forwarded credentials create uncontrolled copies across mailboxes for years. A single compromised inbox exposes an entire archive of passwords.

    68%

    of data breaches involve a human element and credential sharing

    Verizon DBIR, 2024

  • Google Docs, Notion, Jira

    Credentials stored in shared documents and wikis inherit broad access rights. These unsecured records outlast employees, contractors, and projects.

    38%

    of incidents in collaboration tools are classified as highly critical

    GitGuardian, 2025

  • Shared spreadsheets

    Zero access control, no audit logs, and no way to revoke access. This setup is a guaranteed failure in any ISO 27001, SOC 2, or NIS2 audit.

    A.5.17

    mandates secure management of authentication information

    ISO 27001:2022

  • Browser-saved passwords

    Built-in browser managers are prime targets for infostealers. A single compromised endpoint exposes every saved credential.

    30%

    of compromised managed devices contain corporate credentials

    Verizon DBIR, 2025

  • Shared admin accounts

    Sharing privileged credentials destroys individual accountability. Doing so triggers an automatic control deficiency in SOC 2, ISO 27001, and NIS2 audits.

    70%

    of users reuse exposed passwords across multiple accounts

    SpyCloud, 2025

What credential failures cost the business
Independent breach economics and named incidents from 2024 to 2026. Each one traces to credentials shared without proper control.

€4.3M

Average breach cost when stolen credentials are the entry point. It takes an average of 246 days to detect and contain the breach.

IBM Cost of a Data Breach Report, 2025

39%

of all data breaches involve stolen or abused credentials across the full attack chain.

Verizon DBIR, 2026

95 days

Median time from an initial credential leak to ransomware deployment.

Verizon DBIR, 2026

€375M

Record fine imposed on Coupang in June 2026 after a former employee retained access and leaked customer data.

PIPC (Personal Information Protection Commission), 2026

2024 breach

Snowflake / UNC5537

Over 160 customer environments compromised, exposing 500M+ records.

Root cause: Credential theft targeting accounts without MFA.

November 2025

Nikkei Slack

An infostealer infection exposed Slack credentials for over 17,000 employees and external partners.

Root cause: Lack of credential rotation and session monitoring.

2024 to 2025

Coupang and KiranaPro

Former employees retained active credentials after departure and deleted critical company data.

Root cause: Incomplete offboarding and unrevoked access rights.

What EU regulators now require
Specific article-level controls. Each one carries documented evidence requirements at audit.

  • NIS2 / NIS2UmsuCG

    Article 21(2)(j)

    MFA for privileged, remote, and sensitive access. Germany's NIS2UmsuCG binding from 6 December 2025. About 29,500 companies in scope (BSI).

  • DORA

    Article 9(4)(c) and (d)

    In force since 17 January 2025. Least privilege, strong authentication, explicit controls against shared credentials for privileged access.

  • ISO 27001:2022

    Annex A.5.17

    Authentication information shall not be shared, easily guessed, or left in cleartext. Audit evidence required.

  • GDPR

    Article 32

    Organizations must ensure data confidentiality and restrict access. Sharing credentials without individual accountability violates Article 32 traceability requirements.

What a secure password manager actually does
Six controls that eliminate key credential security risks

Passwork vault access settings with role-based permissions

Centralize credential storage and manage access by roles or groups. Exactly what auditors look for during access reviews.

Passwork activity log with user actions and timestamps

Track every password action in real time. Simplify audits with detailed logs and maintain clear ownership of every change.

Passwork user management screen for access revocation

Revoke all password permissions automatically by disabling the user in your IdP. Close critical offboarding gaps and ensure seamless compliance.

Passwork SSO and MFA settings

Secure your vaults with SSO and phishing-resistant MFA. Fully meet the strict requirements of NIS2 Article 21(2)(j) for privileged access.

Passwork private and shared vaults separated in the interface

Keep personal passwords strictly private for users. For shared credentials, maintain strict control with designated owners, access scopes, and detailed activity logs.

Passwork on-premise installation wizard

Keep all credentials inside your local infrastructure. Host Passwork on-premise to comply with internal security policies, external auditors, and regulatory mandates.

Password and secrets manager built in the EU for teams and businesses

Passwork stores, shares, and audits credentials in one place, providing the exact controls required by NIS2 and ISO 27001. Deploy on-premises in your own data center, in a secure EU cloud, or within a dedicated cloud enterprise environment. Fully GDPR compliant and trusted by 10,000+ businesses across Europe.

  • Shared vaults with role and group permissions

    Replicate your organizational structure. Scope access precisely by team or project.

  • Full audit log of every access event

    Track who accessed what, when, and from where.

  • Revoke access in one click when an employee leaves

    Deactivate in your IdP, Passwork revokes access. No orphan accounts.

Passwork preview
  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • SAML
  • SCIM
  • LDAP / Active Directory

Zarządzanie sekretami, nie tylko hasłami
DevOps automation API bez cen HashiCorp

Wszystkie funkcje DevOps →

The answers that look right but aren't enough
Five widespread security myths and the evidence-based facts that disprove them

Three ways to deploy, one security model

Deploy on your own infrastructure, run in a secure sovereign EU cloud, or scale with our enterprise cloud platform while maintaining identical security standards

  • Self-hosted on-prem

    Run Passwork within your private data center and network. This option supports air-gapped environments for regulated industries, satisfying strict auditor requirements for complete local data control.

  • EU cloud

    Host your data in a secure EU cloud with default GDPR compliance. This German-hosted infrastructure ensures all credential stores remain strictly within European jurisdiction.

  • Cloud enterprise

    Scale across multiple regions with a primary EU deployment. This configuration provides international teams with high availability and guaranteed EU residency for sensitive credentials.

Firmy obdarzają nas zaufaniem
na całym świecie

Jeden menedżer haseł. Na każdym urządzeniu.
Korzystaj z Passwork wszędzie — w przeglądarce, na urządzeniu mobilnym lub na komputerze

Rozszerzenie przeglądarki

Wyszukuj, automatycznie uzupełniaj i twórz dane uwierzytelniające bez opuszczania przeglądarki. Działa z Chrome, Firefox, Edge i Safari.

  • Autouzupełnianie jednym kliknięciem na każdej stronie logowania
  • Wyszukiwanie we wszystkich sejfach z poziomu rozszerzenia
  • Natychmiastowe tworzenie i zapisywanie nowych poświadczeń
  • Generowanie silnych haseł na bieżąco
Dostępne
Browser extension password editing screenshot
Browser extension password generator screenshot
Browser extension password card screenshot
Browser extension settings screenshot

Aplikacja mobilna

Szybki dostęp do firmowych haseł z urządzenia mobilnego

Dostępne

Aplikacja mobilna 2FA

Wygodna weryfikacja logowania za pomocą aplikacji uwierzytelniającej Passwork

Dostępne

Aplikacja desktopowa

Pełna funkcjonalność zarządzania hasłami w natywnej aplikacji desktopowej

Dostępne

Wybierz swój plan
Długoterminowe koszty posiadania 30% mniej niż średnia w branży

Porównaj plany Passwork

Zobacz różnice między planami i wybierz odpowiedni poziom bezpieczeństwa oraz kontroli dla swojego zespołu.

  • Standard

    Podstawowe funkcje dla małych i średnich przedsiębiorstw wspierające bezpieczny rozwój

    3€
    miesięcznie /
    za użytkownika
    rozliczane rocznie
    • Szybki start z wszystkimi podstawowymi funkcjami
    • Prosty, bezpieczny i o niskim nakładzie administracyjnym
    • Wspólne sejfy, łatwy dostęp, brak potrzeby szkolenia
  • Advanced Popularny

    Zaawansowane funkcje dla rozbudowanych potrzeb w zakresie bezpieczeństwa i zarządzania

    4,5€
    miesięcznie /
    za użytkownika
    rozliczane rocznie
    • SSO, mapowanie grup LDAP, model oparty na rolach
    • Clustering, obsługa failover i kopie zapasowe
    • Dedykowany opiekun i priorytetowe wsparcie techniczne
  • Oferta Lifetime Najlepsza wartość

    Jedna płatność, bez subskrypcji: Twoja cena, aktualizacje i wsparcie są gwarantowane

    Płatność jednorazowa
    Uzyskaj spersonalizowaną wycenę
    • Dożywotnie aktualizacje i priorytetowe wsparcie
    • Oszczędź do 50% w porównaniu z długoterminową subskrypcją
    • Jedna zgoda, zero odnowień

Govern every credential. Audit every access.

A 30-minute demo covers the audit log, the offboarding revoke, deployment options, and the controls your NIS2 auditor will ask about.

No credit card required
Full feature access
GDPR compliant
Enterprise-level support

Frequently Asked Questions

Secure credential sharing requires a dedicated password vault with role-based permissions, full audit logging, and single sign-on (SSO) with multi-factor authentication (MFA). Centralized vaults satisfy both ISO 27001:2022 Annex A.5.17, which prohibits sharing authentication information in cleartext, and NIS2 Article 21(2)(j), which mandates MFA for privileged access.

SSO secures integrated enterprise applications, leaving other access vectors open. Research shows 96% of email logins and 91% of AI tools operate outside the SSO perimeter. Service accounts, legacy infrastructure, vendor portals, and shadow SaaS require a dedicated credential store. Industry data confirms that 74% of security professionals view SSO alone as an incomplete access control solution.

NIS2 prohibits unencrypted, untraceable credential sharing. Under Article 21(2)(j) and (g), organizations must secure access control and maintain strict cybersecurity hygiene. This requires that any shared corporate credentials are encrypted, restricted to authorized users via least privilege, and fully audited. Sharing passwords through plaintext channels — such as chat apps or spreadsheets — violates these requirements, as it prevents auditors from identifying which individual actually accessed the system.

DORA Article 9(4)(c) and (d) require financial entities and their critical ICT providers to apply least privilege, strong authentication, and explicit controls against shared credentials for privileged access. Regulators demand documented evidence of these access controls. Implementing a centralized vault with role-based access, MFA, and audit logs provides the necessary compliance documentation.

Annex A.5.17 states that authentication information must remain confidential, secure, and protected against unauthorized sharing. When shared credentials are unavoidable for non-personal entities, organizations must restrict them to authorized personnel through documented controls. Auditors require verifiable evidence — including permission logs, access reviews, and signed acceptable-use policies — which static documents and chat histories cannot generate.

Yes. Passwork supports on-premises deployment within your private data center, including air-gapped environments for regulated industries. We also offer a secure cloud option hosted in Germany and a multi-region enterprise cloud platform with a primary EU deployment. All three options are GDPR compliant and support ISO 27001 compliance framework requirements.

Disabling a user in your identity provider or marking them as a leaver in Passwork revokes all vault access instantly. The platform immediately terminates active sessions and records the event in the audit log, detailing who held access and when it was revoked. This automated workflow directly addresses the offboarding gaps exposed in the Coupang and KiranaPro security incidents.

Chat messages, email threads, and browser stores lack access controls and encryption standards. Browser-saved credentials are the primary target for infostealer malware, with corporate credentials appearing in 30% of managed and 46% of unmanaged compromised devices. These informal channels fail to enforce least privilege, log access events, or support instant revocation, directly violating ISO 27001 A.5.17.

Got any questions? — Help center