Website Review
What is Passbolt?
Passbolt is an open-source password and secret manager built primarily for teams. Rather than a personal vault, it is designed around sharing credentials across an organisation, so administrators can control who sees which passwords and keep an audit trail of that access.
Its stated positioning is "any business, any size," with the page noting it suits a team of 5 or an organisation of 5000. The audience it targets is security-conscious IT teams, but the product is presented as simple enough for company-wide rollout. It can be installed on-premises or used via a cloud option.
What it emphasises
- Open source code, with an audited security posture (the page cites SOC 2 Type II and GDPR compliance, and notes it is made in Europe).
- Collaboration: teams share credentials rather than passing them around informally.
- Administrative control and compliance reporting for organisations that need oversight.
- Adaptability to existing workflows ("modelled for your workflows").
- Deployment choice: on-premises installation or a hosted cloud option.
Who tends to use it
The page lists 50,000+ organisations, with named examples spanning government, defence, IT services and universities — for instance Bosch, the French Ministère de l'Intérieur, GLS, Humboldt-Universität zu Berlin, TU Graz and CTIE in Luxembourg. That mix suggests the strongest fit is organisations with a compliance or sovereignty requirement, or IT departments managing shared infrastructure credentials.
How it compares conceptually
| Approach | Typical fit |
|---|---|
| Personal password manager | One person's logins, minimal admin overhead |
| Team-oriented secret manager like Passbolt | Shared credentials, role-based access, audit needs |
| Enterprise privileged access suite | Large-scale privileged account governance, heavier setup |
Practical next step
If you are evaluating it, decide two things first: whether you need on-premises control (which points to the self-hosted install) or would rather avoid running infrastructure (the cloud option), and how many people will share credentials. Then check the pricing page for the current tiers, since the site references subscription-based pricing without listing amounts here.
For a concrete scenario: a 30-person IT team that currently keeps shared admin passwords in a spreadsheet would use Passbolt to move those into a controlled vault with per-user permissions and an access log — a meaningful governance gain over a spreadsheet, though it requires an initial setup and user onboarding effort.
How does Passbolt differ from other team password managers?
Passbolt's main difference is that it is built as an open-source credential platform for teams, with a strong emphasis on self-hosting and IT control. According to its own page, it is "built-first for security-conscious IT teams" but intended to remain simple enough for organisation-wide adoption. It also states that it is open source, audited, SOC 2 Type II compliant, GDPR-aligned, made in Europe, and a member of the FIDO Alliance. Those claims matter most to organisations that need to inspect, host or govern the software themselves rather than rely entirely on a vendor's cloud.
In practical terms, that positions it differently from many mainstream team password managers, which are typically closed-source SaaS products. Passbolt's page explicitly offers both "Install on-prem" and "Try Passbolt Cloud", so it does not force a single deployment model. Its stated scale range is also unusually broad: a team of 5 or an organisation of 5000. The page cites 50,000+ organisations worldwide, including governments, defence agencies and IT companies, with named examples such as Bosch, the French Ministère de l'intérieur, GLS, Humboldt-Universität zu Berlin, TU Graz, ZIT-RLP, Hochschule Ruhr West, Information Services and CTIE. That is a useful signal for public-sector, university and regulated buyers who care about sovereignty and procurement fit.
A second difference is workflow modelling. Passbolt says it helps teams share credentials securely and describes itself as "modelled for your workflows", aligning productivity and security goals. That is a collaboration-focused pitch rather than a purely personal vault pitch. The trade-off is that self-hosting and open-source governance can demand more internal IT effort than a fully managed cloud service; teams without that capacity may prefer the cloud option or a simpler hosted competitor.
If you are deciding, start with two questions: must you control where secrets are hosted, and do you need to audit or extend the code? If yes, Passbolt is a strong candidate. If you mainly want the least administrative effort, compare it with hosted alternatives. For official details, see Passbolt.
Can Passbolt be self-hosted on-premises?
Yes. Passbolt is built to be installed on-premises, and that is one of the two main ways it is offered: self-hosted ("Install on-prem") or as a hosted cloud service. The on-premises route is aimed at security-conscious IT teams that want to keep credential data inside their own infrastructure rather than with a vendor.
What on-premises hosting gives you
- Data stays in your environment. Credentials and the server they live on are under your control, which matters if policy, sovereignty or compliance rules restrict where secrets can be stored.
- You manage the operational side. Installation, upgrades, backups, TLS certificates and availability become your team's responsibility. That is the main trade-off: more control, more maintenance.
- Team-oriented sharing from the start. The product is designed around sharing credentials within teams rather than as a single-user vault, so it fits organisations where several people need the same accounts.
- Scale is not the deciding factor. The site positions it for anything from a team of about 5 to an organisation of 5000, so a small IT department and a large public body use the same model.
Who tends to choose it
The customer examples on the page lean heavily toward the public sector, universities and larger IT organisations — government ministries, national IT services, research universities and industrial companies. If your organisation resembles those, on-premises deployment is likely to be the expected option rather than the cloud one. The page also notes audit and compliance signals such as SOC 2 Type II and GDPR alignment, which are the kinds of checks procurement teams ask about before approving a self-hosted rollout.
How to decide
Ask three questions before committing:
- Does policy require secrets to remain on infrastructure you control? If yes, on-premises is the natural fit.
- Do you have someone who can own patching, backups and certificate renewal? If not, the hosted option removes that burden.
- How many people need shared access, and do they sit inside one network boundary or across several? On-premises is simplest when the user base is fairly contained.
A practical next step is to run a small pilot: install it on a test server, add one team that shares a handful of credentials, and let your IT staff judge the setup and upgrade effort before rolling it out more widely. Official details are at Passbolt. For background on why teams often standardise on a shared vault instead of ad-hoc sharing, see OWASP guidance on credential and secret management.
How does Passbolt support compliance with SOC 2 and GDPR?
Passbolt supports SOC 2 and GDPR compliance in two different ways: one through an audited security report, and the other through where and how the software can be deployed.
SOC 2 Type II — Passbolt states it has an audited SOC 2 Type II report. A Type II report covers how controls operated over a period of time, not just a point-in-time snapshot. For a buyer, that matters because it gives your own auditors and security reviewers evidence to rely on when Passbolt sits inside a system that handles credentials. It is useful supporting evidence for your compliance program, not a substitute for your own controls and policies.
GDPR — Passbolt lists GDPR compliance and describes itself as made in Europe. Because it can be installed on-premises, your organisation can keep credential data inside its own infrastructure and choose the jurisdiction and processors involved. That reduces the number of third parties in scope and makes data-residency and transfer questions easier to answer. If you use the cloud option, the deployment model changes, so confirm hosting location, subprocessors and data-processing terms directly with Passbolt.
Practical decision criteria
- If your auditors ask for independent assurance, ask for the SOC 2 Type II report and check the audit period and scope.
- If data residency is the driver, on-premises installation gives you the most control; cloud shifts responsibility to the vendor.
- If you handle government or defence-adjacent work, note the page mentions ANSSI CSPN certification is in process, which is progress, not a completed certification.
- Compliance is a shared effort: Passbolt can supply evidence and deployment control, but access reviews, joiner/leaver processes and least-privilege sharing remain your responsibility.
As a next step, request the SOC 2 report and a data-processing agreement, then map Passbolt's controls against the specific SOC 2 trust criteria and GDPR obligations your organisation must evidence. You can start from Passbolt.
Is Passbolt suitable for small teams or only large enterprises?
Passbolt is designed for both: the page states it is "built-first for security-conscious IT teams, yet simple enough for company-wide adoption" and that it delivers "for a team of 5, or an organisation of 5000." So a small team is within its intended audience, not an edge case.
That said, "suitable" depends on what your small team actually needs.
Where a small team benefits
- Shared credentials, not personal vaults. The page frames the core problem as teams that "can't stop sharing credentials" and positions Passbolt as a way to do that securely. If your team passes around a handful of shared logins, that's exactly the use case.
- Self-hosting control. The page offers "Install on-prem" alongside a cloud option, so a small team with an existing server or a preference for keeping secrets in-house can run it themselves.
- Compliance signals without an enterprise contract. Audited, SOC 2 Type II compliant, GDPR-aligned and made in Europe are all stated on the page. A small company selling to larger customers may value those labels even at low headcount.
Where a small team feels friction
- It is admin-shaped. "Built-first for security-conscious IT teams" suggests setup and policy management assume someone owns that job. A five-person startup with no IT function should expect to spend real time on installation and key management.
- Collaboration model matters. Team-oriented credential sharing is the point; if you mainly want a personal password manager with occasional sharing, a simpler consumer tool may be less overhead.
- On-prem means you own uptime. Choosing the self-hosted route trades subscription simplicity for maintenance work.
Quick comparison
| Situation | Passbolt fits well? |
|---|---|
| 5–50 people sharing service and infrastructure credentials | Yes — matches the stated design range |
| Small team with an IT/security owner who wants on-prem | Yes |
| Solo user wanting a personal vault | Probably more than you need |
| Small team with no one to run a server | Cloud option likely better than on-prem |
Next step
Decide first between on-prem and cloud, since that choice drives your real cost and effort far more than team size does. Then pilot with your most sensitive shared credentials — a production database or cloud admin account — rather than a low-stakes login, so you learn how key management and recovery work before rolling it out. If you want to compare the wider category, official sites such as Bitwarden and 1Password cover the same team-sharing ground with different hosting models.
How does Passbolt handle password sharing and access control for teams?
Passbolt is built around sharing credentials within a team rather than treating passwords as personal items. Its core model is a shared, encrypted vault: secrets are stored server-side in encrypted form, and access is granted per user or per group, so a colleague can use a credential without ever seeing the underlying password in plain text. The page positions this as its main differentiator — teams that cannot stop sharing credentials can at least do it under controlled, auditable conditions.
What that means in practice
- Sharing is a first-class action. Instead of pasting a password into chat, a user shares the credential itself. The recipient gets working access; the secret stays hidden.
- Access control is role- and group-based. Administrators decide who belongs to which team or group, and membership determines what is visible. This suits organisations that need to onboard and offboard people quickly.
- The target audience is security-conscious IT teams, with simpler day-to-day use for the wider company. The page explicitly frames it as fitting a team of 5 up to an organisation of 5000.
- Governance signals matter here. The page cites SOC 2 Type II, GDPR alignment, European origin, FIDO Alliance membership, and a pending ANSSI CSPN certification, plus named users such as Bosch, the French Ministère de l'intérieur, GLS, several universities and public IT bodies. Those references are aimed at buyers who must justify the choice to auditors, procurement or regulators.
Where it fits and where it doesn't
| Situation | Passbolt's approach | Trade-off |
|---|---|---|
| Small IT team sharing admin credentials | Group-based sharing with hidden secrets | Requires someone to set up and maintain groups |
| Regulated or public-sector buyer | On-premises install, audit and compliance signals | More operational overhead than a pure cloud tool |
| Company-wide rollout beyond IT | Simple enough for non-technical staff | Non-IT users still need onboarding and habits change |
| Teams wanting minimal administration | Cloud option available | Less control than self-hosting |
A useful next step
List your current credential-sharing habits — chat messages, spreadsheets, shared notes — and mark which ones involve people who should use a secret but never see it. That list is your test case. If most of it involves groups rather than individuals, and if you need an on-premises or European-hosted deployment, Passbolt's model lines up well. If your main need is personal password storage with occasional sharing, a lighter tool may be enough.
For the underlying model and deployment choices, see Passbolt. For a broader comparison of team-oriented managers, official documentation from Bitwarden and 1Password is worth reading alongside it.
User reviews (0)