Server platform
Operate Bitwarden components, proxy, data services and mail.
We install and operate Bitwarden on your infrastructure - including organisations, SSO and directory integration, backups, updates, monitoring and secure maintenance access.
Companies worldwide trust WZ-IT
Bitwarden is a trademark of Bitwarden, Inc. WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with Bitwarden, Inc. We install and operate self-hosted Bitwarden environments on customer infrastructure; required vendor licences are itemised separately.
A self-hosted Bitwarden instance brings together personal vaults, organisations, collections and administration. Availability, encryption, mail, identity integration and recovery must therefore be designed as one security model.
We install the official Bitwarden server platform in your environment, provide maintenance and monitoring and connect SSO, SCIM or Directory Connector where supported by your edition. WZ-IT does not need access to vault contents.
Self-hosting and some organisation, SSO or directory capabilities may require an appropriate Bitwarden licence. Vendor licence, infrastructure and WZ-IT operations are itemised separately.
Bitwarden and Vaultwarden are different server implementations. We explicitly determine which platform, client compatibility and vendor support profile fits your security requirements.
Platform operations protect availability and configuration without giving WZ-IT access to decrypted vault contents.
Operate Bitwarden components, proxy, data services and mail.
Implement roles, collections and policies with the customer.
Connect SSO, directories, clients and approved endpoints.
Control updates, monitoring, backups and restart.
WZ-IT operates infrastructure and application; master passwords, client-side key material and vault contents remain exclusively with users and your organisation.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Bitwarden server and infrastructure | WZ-IT | Installation, hardening, updates, monitoring and technical maintenance. |
| Backups and restore | WZ-IT | Encrypted backup of agreed components and recovery tests. |
| SSO and directory | Shared | WZ-IT integrates technically; the customer defines identity sources and groups. |
| Organisations and policies | Shared | Technical implementation of an approved role and policy model. |
| Vault contents and master passwords | Customer | Content, sharing and recovery keys remain the customer's responsibility. |
| Migration and rollout | Optional WZ-IT service | Import, pilot group, client distribution and user training as a separate project. |
Use passwords, secure notes and other credentials through official clients.
Structure shared access around teams, roles and areas of responsibility.
Integrate identity providers, SCIM or Directory Connector according to edition and target design.
Connect Web Vault, browsers, apps, SMTP and approved endpoints reliably.
Back up server data, attachments and configuration consistently and document restart.
Control component versions, certificates, mail flow, resources and availability.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Bitwarden. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Bitwarden. Contact us for a technical assessment.
One managed standard Bitwarden application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Bitwarden. We assess infrastructure, integration, and ongoing operations.
User count, organisation structure, attachments, SSO, synchronisation load and recovery objectives determine the operating design.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small team | Dedicated single environment | Standard clients, few organisations and predictable use. |
| Mid-sized organisation | Assess redundant platform components | SSO, directory, mail and attachments are considered. |
| Many users or sites | User and integration assessment | Synchronisation, rollout and support processes are designed. |
| Specific recovery or compliance targets | Security assessment | Keys, audit, backup isolation and emergency access are scoped. |
Bitwarden edition, user scope, identity integration, migration and recovery objectives are clarified before quotation. Vendor licences are not hidden in infrastructure pricing.
The official self-hosted platform runs in your cloud or data centre; WZ-IT receives documented technical operations access only.
Operations within your networks, accounts and security policies.
The platform in your own data centre or server room.
Isolated resources and clearly bounded data storage.
Self-hosted platform with external identity provider and distributed clients.
Clients encrypt and decrypt vault data; the server synchronises encrypted data and controls organisation capabilities.
Browser, desktop and mobile with personal master passwords.
Protected web access, certificates and restricted administration paths.
Plan-dependent identity and organisation integration.
Web Vault, API, identity, attachments and synchronisation.
Encrypted vault data and platform state.
Invitations, confirmations and supported client communication.
Availability, components, certificates and recovery.
Self-hosting does not replace an organisational password strategy. Roles, emergency access, recovery codes and offboarding are designed alongside technical operations.
Answers about licensing, access, migration, SSO and backup.
No. Operations require access to servers and encrypted storage, not master passwords or decrypted vault contents.
That depends on user count and organisation, SSO, SCIM and directory capabilities. We map technical needs to the current vendor editions.
No. Bitwarden Server is the official vendor platform; Vaultwarden is an independent compatible implementation. Their operations and support profiles differ.
We support export/import planning, piloting, organisation structure and client rollout. Highly sensitive exports are performed by authorised customer staff.
We back up agreed server data, attachments and configuration and test the technical restore. We cannot replace user master passwords or missing recovery codes.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Bitwarden, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with Bitwarden
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.