Password platform
Operate Passbolt and supported dependencies on controlled versions.
WZ-IT operates Passbolt as a central password manager with secured access, backups, updates and documented recovery.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: Passbolt (Passbolt S.A.). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
Passbolt encrypts passwords at user level and helps teams share credentials selectively. Permissions and key material are therefore part of the operating concept.
We configure the platform, mail delivery, TLS, backups and monitoring and plan user migration, SSO or directory integration for the selected edition.
A technical backup does not replace users' personal recovery kits. We document both recovery paths and test server-side restoration.
SSO, directory sync and other functions may require a commercial Passbolt edition. Vendor licences are quoted separately.
Application, database, mail, encryption keys, browser clients and recovery procedures must be managed as one security system.
Operate Passbolt and supported dependencies on controlled versions.
Define MFA, groups, recovery kits and offboarding procedures.
Protect database, server keys and configuration consistently.
Monitor updates, mail delivery, certificates, backups and restore tests.
WZ-IT operates the platform; users and customer administrators remain responsible for their secrets and recovery material.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Passbolt platform | WZ-IT | Deployment, database, mail integration, monitoring and updates. |
| Server keys and backups | WZ-IT | Protected storage and documented recovery of platform components. |
| SSO, MFA and groups | Shared | We configure supported controls; the customer defines users and policies. |
| Recovery process | Shared | Technical steps and organisational custody are agreed together. |
| Passwords and user keys | Customer | Users and customer administrators own secret content and personal recovery items. |
| Custom integrations | Optional WZ-IT service | Provisioning, APIs and enterprise features are assessed separately. |
Store credentials with end-to-end encryption and decrypt them only for authorised users.
Configure accounts, multi-factor authentication and administrative roles in a controlled manner.
Share passwords with selected users or groups and assign permissions transparently.
Review changes and sharing actions with the available event and audit capabilities.
Provide browser extensions, mobile clients, CLI and API for the required workflows.
Connect SSO and user directories depending on edition and target architecture.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Passbolt. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Passbolt. Contact us for a technical assessment.
One managed standard Passbolt application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Passbolt. We assess infrastructure, integration, and ongoing operations.
User count, shared resources, audit volume, mail and identity integration determine the operational profile.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small team | S | Standard sharing, mail and regular use. |
| Several teams and groups | M | More users, permissions and audit events. |
| SSO or provisioning | Integration assessment | Edition, identity provider and lifecycle flows are tested. |
| Security-critical deployment | Recovery and governance design | MFA, custody, restore and emergency access are agreed. |
Enterprise features, complex SSO and special recovery requirements are assessed separately.
The platform can be hosted centrally or kept close to internal identity and network services.
Dedicated instance on European infrastructure.
Operate in your account with existing controls.
Local deployment in your protected network.
Central platform connected to identity through controlled routes.
Administrative access and recovery material are separated from normal user access.
Browser extension, web interface and approved clients.
Secure access, MFA and separate operational paths.
Least-privilege sharing and controlled lifecycle.
Encrypted credential sharing, audit and team management.
Encrypted resources, users, permissions and audit state.
Protected server material and consistent recovery copies.
Invitations, notifications and optional central authentication.
A server backup alone does not replace user recovery kits and documented offboarding procedures.
Answers about encryption, recovery, SSO and operations.
Passbolt is designed around client-side encryption. Platform administrators operate the service but should not receive users' private keys or recovery phrases.
Database, server keys, configuration and required files are protected together and restored through a documented procedure.
Depending on edition and target setup, supported identity integration can be implemented after review.
We can plan controlled import and onboarding, while users validate ownership and access.
Yes. We can deploy and operate it inside your infrastructure.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Passbolt, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with Passbolt
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.