Architecture and migration
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
WZ-IT plans, installs and operates Vaultwarden as managed hosting, in your cloud or on premises. Depending on the target design, we also provide migration, secure network and identity integration, monitoring, backups, updates, integrations and further development.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: Vaultwarden (the Vaultwarden project (Daniel García)). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services. Bitwarden is a trademark of Bitwarden, Inc. WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with Bitwarden, Inc. We install and operate self-hosted Bitwarden environments on customer infrastructure; required vendor licences are itemised separately.
Vaultwarden is an alternative implementation of the Bitwarden client API written in Rust. We verify compatibility with the intended clients and capabilities for the selected version before production use.
Vaultwarden implements a large part of the Bitwarden client API with comparatively low resource requirements. As an unofficial implementation, required clients and capabilities are tested against the deployed versions.
We install, host and operate Vaultwarden for your company - either on our secure, privacy-focused infrastructure in Germany or other locations, as well as on-premise in your own environment.
We provide 24/7 monitoring, backups and maintenance for your Vaultwarden instance. Human response times and support coverage follow the selected service level.
Supports many official Bitwarden clients. Required apps, browser extensions and capabilities are verified by version.
Rust-based architecture requires significantly less RAM and CPU than the official Bitwarden solution.
Passwords, secure notes, credit cards, identities, and attachments - all securely encrypted and stored.
Collections, password sharing, member roles, groups, and event logs for professional team management.
Secure transmission of passwords and files with expiration times and access restrictions.
TOTP, Email, FIDO2 WebAuthn, YubiKey, and Duo for additional security of your Vaultwarden instance.
Web-based admin interface for user management, configuration, and system monitoring.
Optimized web interface that is directly included in the container images.
Allows trusted contacts to access your vault in emergency situations.
Professional installation on your infrastructure - on-premise, cloud or hybrid
In your data center
AWS, Azure, Hetzner & more
Advanced architecture after technical and licence assessment
Secure management of all passwords and credentials with end-to-end encryption
Shared password vaults for teams and departments with fine-grained access control
All official Bitwarden apps and browser extensions work seamlessly
Automatic synchronization across desktop, mobile and web with offline access
Secure sharing of texts and files with expiration date and password protection
Emergency access for trusted contacts with configurable waiting period
Secure access and access control for your installation
WireGuard, NetBird or Tailscale
Directly or through an upstream identity layer
Depends on application, edition and identity provider
Fail2Ban, Rate Limiting, IP Whitelisting
We set up secure VPN access to your installation - ideal for remote work and external employees.
Full-service installation with no hidden costs
We do more than provide an application. WZ-IT designs the technical architecture, integrates network and identity, operates the agreed scope and develops integrations when the standard product is not enough.
Sizing, target environment, data transfer, cutover and recovery are resolved before production operations.
SSO, secure access, internal systems and existing security components are integrated appropriately.
Updates, backups, technical monitoring and response paths follow a transparent operational scope.
APIs, automation and custom extensions can be delivered beyond basic deployment.
The exact scope depends on the application, edition, infrastructure and criticality. Vendor licences and non-standard components are quoted separately.
Identity platforms sit in the critical access path. Directory, policies, keys, target applications and emergency access must be designed together.
Internal and external identities sign in to connected services through defined flows.
TLS, firewall rules, reverse proxies or private network paths are designed around the platform's exposure.
Local accounts, SSO, directories, service accounts and emergency access are connected through clear roles.
Authentication, authorisation, policies, tokens and administrative access are controlled centrally.
Local accounts, LDAP/AD, groups, attributes and governed provisioning.
Secrets, signing keys, database, backups and documented emergency access.
OIDC, OAuth 2.0, SAML, LDAP or application-specific integrations.
The diagram is a resilient target model. Its implementation depends on edition, data flows, load, availability objectives and existing infrastructure.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.