

August 27, 2026
GigaOm Radar: Enterprise Password Management
Paul Stringfellow
1. Market Context
Enterprise password management (EPM) has outgrown its name. The 23 platforms assessed in this Radar still store, fill, and share workforce credentials, but the evaluation now turns on what surrounds the vault: passwordless login paths, machine and AI-agent credential delivery, breach intelligence, and the administrative machinery to govern all of it at scale. The field arrives from every direction. Open-source cores compete beside consumer-heritage products moving upmarket, workforce modules of privileged-access and identity platforms, directory-platform add-ons, and sovereignty-first designs that keep the vendor out of the credential path entirely.
Two pressures dominate. The first is architectural: the master password, the category’s founding primitive, is being engineered out of the product by part of the field while remaining mandatory at the rest. The second is scope. Privileged access management, secrets management, and identity platforms all press against the workforce vault’s boundary, and roughly half the roster now sells EPM as one module of a larger suite. The six themes below capture where these pressures are separating the field.
The Passwordless Split
Passkey support now has two distinct halves, and the field divides cleanly on the harder one. Managing third-party passkeys (storing, syncing, filling, and sharing credentials for other sites) is broadly delivered; even small products ship it. Removing the master password from the vault’s own front door is rarer. A minority of platforms offer a genuinely master-password-free deployment, through SSO unlock that participates in key management, device-bound hardware keys, or WebAuthn login. Across much of the field, SSO users still create and keep a permanent vault password, which preserves exactly the credential the product exists to eliminate. One platform ships FIDO2-based login while offering no third-party passkey storage at all; another supports passkeys everywhere except its own unlock.
What this means for buyers: Ask two separate questions in every evaluation: can my users store passkeys, and can my organization retire the master password? Vendors answer the first loudly and the second quietly. If a passwordless end state is on your identity roadmap, the vault’s own key architecture, not its passkey checkbox, is the criterion that decides.
Credential Governance for AI Agents and Machines
Agentic and non-human identity governance is the youngest capability in this evaluation and one of its weakest field-wide, yet the shipped implementations are genuinely new. Generally available agent access tokens now exist with mandatory expiry, vault- or item-scoped grants, and encrypted access-reason logging. One platform brokers credentials to browser-driving agents without exposing plaintext. Official MCP servers have appeared, with folder scoping and masked fields, alongside an alpha agent-brokering SDK elsewhere. Most of the field, though, still routes automation through API tokens attached to human accounts, or offers no non-interactive path at all. The gap between the front and the floor is wider here than on any established criterion.
What this means for buyers: If AI agents will access credentials in your environment, they should have their own identities. These should be scoped, expiring, individually revocable, and audited separately from their human sponsors. A vault that allows an agent to use only its owner’s identity may make it harder to establish exactly who, or what, performed an action during an audit. For everyone else, this criterion is a roadmap signal: the vendors investing here are declaring where they think the category goes.
The PAM Boundary Presses In
A substantial share of this roster sells workforce password management as a module of a privileged-access suite, an identity-security platform, or a directory platform. The module inheritance is real: platform-grade availability, tenant isolation, compliance certifications, and identity plumbing that standalone vaults rarely match. So are the module boundaries. Capsule evidence documents rotation, secrets access, passkey storage, and FIDO2 login policy living in adjacent SKUs; breach monitoring and advanced audit sold as add-ons; and successor-product transitions that leave the assessed module waiting on capabilities its sibling already ships. Standalone vaults answer with self-contained coverage and, increasingly, their own privilege-adjacent ambitions.
What this means for buyers: Price the SKU, not the platform. When a vault is a module, establish in writing which capabilities sit in the license you are buying and which require sibling products or add-ons; the capsules in this report flag these boundaries vendor by vendor. Platform buyers already committed to the surrounding suite get strong economics; standalone buyers evaluating a module on its own should assume the demo showed the platform.
Sovereignty and the Self-Hosted Trust Model
The field divides almost evenly on who runs the infrastructure: twelve platforms offer a self-hosted or customer-held deployment path, and eleven are SaaS-only. The self-hosted half spans full on-premises installations, containerized open-source stacks, customer-cloud appliances, and one design that eliminates the vendor-side vault entirely by syncing encrypted databases through storage the customer already owns. The SaaS half competes on residency instead: region selection at signup, EU-only or single-jurisdiction hosting with domestic subprocessors, isolated government clouds, and federal authorizations. Data-sovereignty requirements (jurisdiction, subprocessor nationality, works-council telemetry expectations) are now purchase-deciding criteria in a way generic cloud compliance language does not satisfy.
What this means for buyers: Decide the trust-model question before building a shortlist, because it eliminates half the field either way. Self-hosting buys control and residency at the price of operating the service and absorbing thinner managed-experience polish. SaaS buys currency and adoption machinery at the price of trusting the vendor’s isolation and jurisdiction story, so read the tenant-isolation and residency evidence, not the certification logos.
Cryptographic Assurance Becomes Legible
The field’s strongest platforms have made vault cryptography inspectable. They publish specifications detailed enough for reimplementation, name the authenticated ciphers and key-derivation parameters they use, and document key custody for each path. They also undergo repeated public audits, with remediation status published alongside the findings. The weakest have not. Capsule evidence across the field documents unnamed cipher modes, unpublished KDF parameters, server-side designs in which the operator can reach plaintext, and, in one peer-reviewed case, unauthenticated encryption acknowledged and only partially remediated. This is no longer an academic distinction; it separated vendors throughout the evaluation. At the frontier, one vendor has shipped hybrid post-quantum key exchange combining classical elliptic-curve cryptography with ML-KEM, the first in this field.
What this means for buyers: Treat cryptographic legibility as the assurance criterion: a vendor that names its cipher modes, publishes its parameters, and commissions public audits is making a falsifiable claim, and one that says “military-grade encryption” is not. For long-retention credential data, ask each vendor for its post-quantum position in writing. The migration will take years, and this cycle produced its first shipped answer.
From Vault to Credential Intelligence
The product is becoming a monitoring system. The field’s stronger implementations pair tenant-wide credential-health scoring (weak, reused, aged, and breached counts with per-user drill-down) with external breach correlation from named sources, dark-web monitoring that extends beyond vault contents to every address on a verified company domain, and detection of credentials typed outside the vault on managed devices. Exposure events stream to SIEM platforms, and policy-driven responses now include user nudges, forced resets, and automated containment scripts. The floor is equally visible: platforms with no external breach corpus at all, health reports that reach end users but never aggregate for administrators, and AI-assisted risk analysis that remains deterministic rule-matching nearly everywhere.
What this means for buyers: Score the intelligence loop from end to end. Look at the detection source, the visibility available to administrators, and the actions the platform can actually execute. A health dashboard without a remediation path documents risk without reducing it. And treat “AI-powered” claims skeptically. Weighted risk scoring and behavioral anomaly detection are rare in shipped products, and the capsules identify where they genuinely exist.
2. Radar Graphic
Plot Overview
The evaluation covers 23 vendor–product pairs. Ring distribution: 8 Leaders, 15 Challengers. Quadrant distribution: 4 Enduring Innovators, 4 Disruptive Pioneers, 9 Foundation Builders, 6 Agile Optimizers. Velocity distribution: 5 Outpacing, 12 Fast Following, 6 Slow Following. Ring distance indicates relative capability depth and maturity, while dot color indicates velocity: Outpacing, Fast Following, or Slow Following.
Figure 1. GigaOm Radar for Enterprise Password Management, Version 5.
Notable Patterns
The plot leans toward the operational half of the market. Fifteen of the 23 vendor-product pairs sit on the Operational Focus side (nine Foundation Builders and six Agile Optimizers), while the Strategic side holds eight, split evenly between four Enduring Innovators and four Disruptive Pioneers. On the change-posture axis the field tilts stability-centered, thirteen pairs to ten. The distribution says something specific about how EPM is bought. The largest single cluster is Foundation Builders, the quadrant of continuity, audit evidence, and data ownership. Most of this market still sells credential storage as load-bearing infrastructure for teams protecting what they already run, not as an instrument of organizational change.
The Leader ring cuts across that density rather than following it. All four quadrants produce at least one of the seven Leaders (three Enduring Innovators, two Agile Optimizers, one Foundation Builder, one Disruptive Pioneer), so no single buying posture owns the front of this market. The Strategic side converts at a higher rate, placing four of its eight pairs in the Leader ring against three of the Operational side’s fifteen, but operational buyers are not left choosing among Challengers the way a more polarized market would force.
Velocity is where the field’s direction shows. Four of the five Outpacing vendors sit on the Strategic side of the plot, and none sits among the Foundation Builders; the fifth is the open-development standout of the Agile Optimizers. Four of the six Slow Following marks land in Foundation Builders, the quadrant whose buyers penalize change the least: a coherent pairing, though not a harmless one. The mirror cases are the instructive ones: one proposed Leader carries a Slow Following mark, one Outpacing vendor remains a Challenger, and one Disruptive Pioneer trails on velocity, its novel architecture outrunning the small-vendor pace of everything around it. Quadrant, ring, and velocity are measuring genuinely different things here, and the capsules are where the three readings reconcile.
3. Tech Buying Triad
The quadrant descriptions and decision framework orient buyers to read this Radar from the enterprise procurement seat. The Radar plots solutions on two axes (Operational Focus ←→ Strategic Focus and Stability-Centered ↑↓ Evolution-Centered), so placement signals both what outcome a product is meant to deliver and how it approaches change. Decision responsibility is mapped to the Tech Buying Triad: the CIO owns Brown Money tradeoffs, the CTO owns Green Money tradeoffs, and the CISO owns GRCS tradeoffs (See Table 1); Emerging Technology inputs are treated as consulted advice across the Triad. This framework is the neutral lens the rest of the report uses to explain vendor capabilities and buyer implications.
Role | Bucket | What the bucket means | Responsibilities in the procurement |
CIO | Brown Money | Operational and infrastructure value: capabilities tied to operational reliability, cost containment and table-stakes function. | Admin Automation, Adoption Telemetry, Availability and Failover, Browser and Application Coverage, Credential Health Monitoring, Deployment Migration Automation, Enterprise UX Adoption Platform, IdP Reconciliation. |
CTO | Green Money | Innovation and growth value: capabilities tied to revenue generation, growth and competitive differentiation. | Developer API Ecosystem, Identity Integration Extensibility, Modular Vault Architecture, Passwordless and Passkey Support, Secrets Management Integration, Tenant Isolation and Access Segregation. |
CISO | GRCS | Governance, risk, compliance and security: the controls required to operate the technology safely and within policy. | Audit Trail and Forensic Logging, Compliance Certifications, Data Residency Retention and Deletion, FIDO Attestation Audit, Scoped Recovery and Escrow, Vault Cryptography Architecture. |
All three (consulted) | Emerging Technology | Forward-looking capabilities that signal where the market is moving; not owned by any single role. | Input on Agentic Non-Human Identity Credential Governance, AI-Assisted Credential Intelligence, Credential Exposure Breach, to inform trade-offs across Brown Money, Green Money and GRCS. |
Table 1. Tech Buying Triad
Quadrants
Enduring Innovators are Strategic + Stability. These are long-horizon strategic bets: vendors whose value compounds over a decade rather than a quarter, often through deep architectural decisions that are expensive to reverse. The buyer in this quadrant accepts a long time-to-value and slow visible change in exchange for step-change strategic outcomes when the bet pays off. It’s a rare quadrant, but transformational when the choice is right. In the realm of Enterprise Password Management, the Enduring Innovators quadrant is characterized by buyers who seek robust, reliable solutions that not only enhance security but also integrate seamlessly with existing systems. These buyers prioritize platforms that offer long-term stability and scalability, ensuring that their password management strategies can evolve without compromising on governance or user experience.
Disruptive Pioneers are Strategic + Evolution. These vendors are reshaping what the category even means: leading-edge technology, fast-moving roadmaps, novel primitives that did not previously exist as commercial products. The buyer accepts elevated risk, frequent change, and immature operational maturity in exchange for capability that simply was not previously available. The right bet here can redefine a buyer’s strategic position; the wrong one is expensive. In the realm of Enterprise Password Management, the Disruptive Pioneers quadrant is characterized by organizations that are rethinking traditional security paradigms. These buyers are not just looking for tools to manage passwords; they seek innovative solutions that can redefine user authentication and access management, leveraging emerging technologies like biometrics and AI to enhance security and user experience.
Foundation Builders are Operational + Stability. These vendors deliver the core infrastructure and systems of record that keep the business running, the load-bearing technology that other software depends on. The buyer in this quadrant values predictability, dependability, and low-risk continuity over rapid iteration. Change here is the risk, not the reward, so vendors are evaluated on hardening, longevity, and operational excellence rather than novelty. In the context of Enterprise Password Management, the Foundation Builders quadrant emphasizes the need for stable and reliable systems that ensure secure access to sensitive information. Buyers in this quadrant prioritize operational efficiency and risk mitigation, seeking solutions that integrate seamlessly into their existing infrastructure while providing predictable performance and compliance with regulatory standards.
Agile Optimizers are Operational + Evolution. These are the day-to-day operational systems that are actively improving through incremental iteration on a known mission. The buyer wants compounding gains on workflows that already work (better automation, better user experience, better integrations), not a wholesale platform replacement. Vendors win this quadrant by shipping useful changes frequently without disrupting the operational rhythm the buyer has already built around them. In the Agile Optimizers quadrant for Enterprise Password Management, buyers are focused on modernizing their identity and access management processes to enhance security and streamline user experiences. They seek solutions that can be integrated into existing workflows, allowing for iterative improvements without the need for a complete overhaul of their systems.
Axes
The X-axis: Operational Focus ←→ Strategic Focus describes intent of value. Solutions placed toward the Operational Focus side are bought to keep the business running. They minimize day-to-day operational risk and administrative effort on workflows the organization already depends on. Solutions toward the Strategic Focus side are bought to change the organization’s position: their value compounds through architectural commitments rather than immediate operational relief.
The Y-axis: Stability-Centered ↑↓ Evolution-Centered describes change posture. Stability-centered placements favor proven behavior, predictability, and low-risk continuity; change is the risk to be minimized. Evolution-centered placements treat change as the reward being purchased: frequent, useful iteration on a known mission, or a fast-moving roadmap that reshapes what the category covers.
Ring System (Leader Versus Challenger)
The Radar’s concentric rings communicate overall capability depth and maturity independent of quadrant.
Leader denotes vendors whose offerings combine broad feature depth, production-grade engineering, and sufficient operational documentation and ecosystem integration to be referenceable at scale.
The Challenger ring denotes solid capability with important areas of growth. They are useful in many deployments but likely to require more integration effort, operational validation, or feature road-mapping for specific enterprise requirements.
Use ring position as a procurement heuristic. The inner-ring placements reduce integration and validation effort when the buyer’s requirements align with the vendor’s strengths; outer-ring placements demand more architectural validation, clearer SLAs during procurement, and potential pilot programs. Ring position does not change what quadrant a product targets. It only signals how far a given product’s implementation goes toward covering the full set of buyer requirements in this market.
Archetype Variants
Different buyer archetypes shift weight across the Tech Buying Triad’s accountability map. Regulated-industry buyers tilt toward GRCS, and the CISO’s accountabilities dominate procurement. Growth-led buyers shift toward Green Money and CTO leadership. Cost-pressured buyers elevate Brown Money and the CIO’s accountabilities. Succeeding with any selection in this category requires explicit Triad alignment up front: agree which bucket holds the tie-breaking veto, and define the acceptance tests that prove the deployment meets its governance and operational requirements before it carries production credentials.
Decision Matrix: Which Quadrant Fits Your Organization?
Use the per-quadrant profile in Table 2 below to self-identify the quadrant whose buyer most resembles your organization. Each quadrant lists the buyer who typically lands there: who they are, what they’re trying to do, how mature they are, how they think about risk, the speed they expect, and how they fund the work. Read the column that sounds like your team. That’s the quadrant whose vendors deserve your closest read.
Buyer profile | Foundation Builders | Agile Optimizers | Enduring Innovators | Disruptive Pioneers |
Likely buyer | CIO, CFO-influenced procurement, CISO when compliance-driven. | CIO, COO, VP Engineering, Director of Operations. | CTO with risk-aware lens, CIO partnered with business strategy, Chief Strategy Officer. | CTO, Chief Digital Officer, business-unit GMs with P&L authority, founders. |
Strategic intent | Cost reduction, governance, risk minimization, regulatory compliance. Buyer wants the lights to stay on. | Modernize and automate existing operations; faster cycle times; do more with the same team. | Build durable, defensible advantage; platforms that scale safely; governed innovation. | Transform business models; capture new markets; bet on emerging tech. |
Organizational maturity | Established operations with mature processes; risk-averse change management; success measured by reliability and uptime. | Mature operations seeking efficiency gains without rebuilding; iterative improvers. | Mature with strategic ambition; balances innovation with operational discipline; defensive moat thinking. | Innovation-forward; tolerant of operational disruption; fast learners; success defined by market reshape. |
Risk posture | Governance-first. Prefers proven, audited solutions over leading-edge. | Balanced: willing to adopt newer tools when ROI is clear and disruption is bounded. | Calculated risk: pursues differentiation but with strong governance and proof points. | Risk-seeking: willing to accept failure rate for breakthrough upside. |
Time horizon | 12–24 month payback expectation; multi-year vendor relationships. | 6–18 month payback; favors incremental wins over big bets. | 18–36 month strategic horizon; willing to invest now for compounding returns. | 6–12 month aggressive cycle; iterates fast; expects rapid scale-up if signal is strong. |
Budget posture | Cost-defensive: prove ROI on the cost base before investing. | Efficiency-driven: invests when efficiency math is clear. | Outcome-driven: funds initiatives that compound competitive position. | Strategic-bet: funds high-variance bets when thesis is clear. |
Table 2. Per-quadrant profile
4. Vendor Capsules by Quadrant
Enduring Innovators
In enterprise password management, Enduring Innovators sell the vault as one commitment inside a larger controls architecture. The three vendor/product pairs here are workforce modules of broader privileged-access and identity-security platforms, and the purchase is correspondingly structural: consolidating vaulting, privileged access, secrets, and remote connectivity onto a single architecture, or converging identity-security spend onto one strategic vendor. Once integrated with directories, session brokering, and approval workflow, these deployments become expensive to unpick, which is precisely the point. Assurance leads the pitch: certification estates, federal authorizations, audit evidence, and fixed cryptographic models that constrain how fast the architecture can move. The buyer is a CISO or security architect making a multi-year platform bet for a large, often regulated enterprise, accepting deliberate, compliance-gated change in exchange for a governance posture that compounds over years.
BeyondTrust
Leader | Enduring Innovator | Fast Following
Summary:
BeyondTrust Password Safe is the credential authority inside BeyondTrust’s privileged-access platform, administered from the BeyondInsight console it ships with, carrying Secrets Safe for machine credentials and Workforce Passwords for employee credentials. It deploys self-hosted on U-Series appliances against an external Microsoft SQL Server instance, or as Password Safe Cloud on Azure in a dedicated siloed tenant; on-premises deployments can hand credential-encryption keys to a PKCS#11 HSM. Licensing boundaries matter here. Breach and dark-web detection and behavioural analytics sit in the separately licensed Identity Security Insights, NHI Governance and Workload Credentials are separate Early Access modules, and FIPS mode is supported only on-premises, not in Cloud.
Assessment: The machine-credential surface is the most thoroughly built part of the product. Secrets Safe holds credential, file and text secrets with version history and rollback. Machine identity is a distinct principal, not a repurposed user account. Application users are documented as service accounts for CI/CD, tooling and AI agents, cannot log into the console, and authenticate under OAuth client credentials with secret expiry defaulting to 365 days. PSRUN substitutes a retrieved credential into a command’s environment, and Smart Rules with the Propagation Service rotate service-account passwords and update dependent Windows services and scheduled tasks unattended. A versioned public REST API, first-party client libraries and a public Terraform provider make it automatable, though no OpenAPI specification or compatibility guarantee accompanies them.
Organizations operating under audit are offered strong benefits. The assurance framework runs to ISO/IEC 27001:2022 and ISO/IEC 27701:2019 organization-wide, SOC 2 Type II scoped to Password Safe Cloud on Azure, and FedRAMP High that arrives inside a partner’s authorized platform rather than as a standalone BeyondTrust package. Credentials are protected at rest with AES256 under application-level keys. Failover is a real operator runbook, with database mirroring, heartbeat-driven promotion and Secrets Cache serving last-known-good credentials when the service is unreachable, though no failover objective is published and RTO and RPO are stated as situation specific. Taken together this describes a platform built to be operated under scrutiny.
The workforce-vault surface is thinner as fill happens only through a browser extension on Chrome, Edge and Firefox, so there is no Safari support, no desktop fill client, and no mobile autofill. Workforce Passwords stores three secret types (credentials with a TOTP field, files and text), which leaves no room for passkey storage or policy, and FIDO2 passwordless login covers console sign-in for local BeyondInsight users only, with no authenticator model retained. Health reporting inside Password Safe covers password age and expiry, so weak and reused credentials surface only when someone goes looking; breach and dark-web exposure is detected in Identity Security Insights, which is licensed separately.
The combined picture is a platform built around machine and privileged access under audit, and strongest exactly there. Buyers wanting Safari support, desktop fill or passkey storage might need to look outside Workforce Passwords for it.
Keeper Security
Leader | Enduring Innovator | Outpacing
Summary:
KeeperPAM packages Keeper’s enterprise password management pillar with the Secrets Manager and Connection Manager add-ons in a single SKU, delivered as SaaS across six isolated regions (US, US GovCloud, EU, Australia, Japan, Canada) with a FedRAMP High government cloud. Clients span six browsers, Windows, macOS, and Linux desktops, iOS and Android credential providers, the web vault, and the Commander CLI.
Assessment: Keeper’s strength is breadth albeit with a few caveats. Credential health monitoring pairs a published enterprise Security Score with BreachWatch breach correlation, per-user drill-down, trend charts, and health telemetry reachable through the CLI and pushed to more than a dozen SIEMs. Client coverage has no structural gaps, running across five managed-deployment planes with passkeys in both the browser extension and the mobile apps. Identity integration is equally mature, with SCIM 2.0, SSO Connect Cloud key exchange that removes the master password, cryptographic account transfer during offboarding, and a documented break-glass account.
Organizations consolidating workforce vaulting with machine credentials have the strongest case for it. Secrets management is the standout, with scoped machine identities, seven-language SDKs, CI/CD and Terraform coverage, Kubernetes injection, and audited per-identity retrieval. Tenant isolation reaches per-Managed-Company key derivation with no provider decryption path, and agentic and non-human identity governance runs through an official MCP server with folder scoping and masked fields. Around those sit admin automation, admin-side org-wide LastPass migration, adoption telemetry, a vault cryptographic architecture with fully named primitives, per-path custody statements and a dated CMVP validation, compliance certifications, and scoped recovery.
FIDO attestation is the outlier: no AAGUID retention, no attestation verification, and no authenticator-model policy anywhere, corroborated in the open-source client code and conspicuous alongside the strong passkey audit events elsewhere. Credential intelligence is solid but deterministic, and behavioral-baseline anomaly detection reaches PAM sessions rather than the workforce vault. Retention windows are fixed rather than admin-configurable, and while the Windows and macOS clients do auto-update, the vendor documentation contradicts itself on Linux, and there is no version pinning or staged rollout to manage either. The rest turns on licensing: tamper-evident audit arrives with the Advanced Reporting and Alerts Module, an immutable append-only event log sold as an add-on, and BreachWatch and Compliance Reports are add-ons too, so what a buyer gets depends on the SKU.
Keeper is, in the end, one platform doing three jobs: workforce vaulting, secrets management, and machine-identity governance, held together by deep SIEM and infrastructure-as-code integration. Buyers who need FIDO authenticator provenance, or who want the vault self-hosted, may find it does not reach that far, and the budget has to cover the add-on modules for the platform to perform as described.
Palo Alto Networks*
Leader | Enduring Innovator | Outpacing
Summary:
Idira Workforce Password Management (WPM) is the workforce vault module of Palo Alto Networks’ Idira identity security platform, with authoritative documentation still hosted on CyberArk domains. WPM is licensed within the Idira Identity platform, stores credentials in the Idira Identity Cloud or an optional customer-hosted PAM Self-Hosted vault, and is consumed through browser extensions (Chrome, Edge, Firefox, Safari), a server-hosted user portal, and a mobile app. There is no WPM desktop client; that role belongs to the separately procured Idira Secure Browser.
Assessment: Idira’s strengths are inherited from the platform rather than built into the vault. Availability and failover is thoroughly evidenced: a published four-nines SLA, named cross-region DR pairs with continuous replication, and a documented five-minute RTO and RPO explicitly covering vault credential retrieval, though cross-region DR is an add-on license. Tenant isolation reaches per-tenant key hierarchies rooted in AWS KMS, organization-scoped delegated administration, and per-customer MSP operator assignment. Compliance certifications span ISO 27001/27017/27018, SOC 2, Common Criteria, PCI DSS, and FedRAMP High for the containing package. Identity integration and IdP reconciliation are both strong, with SCIM 2.0, dynamic attribute-driven roles, configurable ownership transfer on offboarding, and authentication rules evaluated at credential-access time. Admin automation adds hierarchical policy sets, a declarative policy-write endpoint, and a named-approver, time-windowed access-request workflow. Credential health monitoring names its breach source and enforces policy-driven blocking of launch, share, and auto-login on compromised credentials, and the selectable self-hosted vault backend gives the modular architecture somewhere to go.
Organizations already standardizing on Idira or CyberArk PAM are the intended buyer. The vault arrives with the platform identity, resilience and governance machinery already attached, so the work of proving availability, isolation and compliance has largely been done elsewhere and inherited. This is a module chosen as part of a stack rather than on its own.
The vault’s own surface is narrower than the platform around it. Fill runs through browser extensions for Chrome, Edge, Firefox, and Safari, a server-hosted user portal, and a mobile app, so an employee who wants a desktop client is directed to the separately procured Idira Secure Browser rather than to WPM itself. Resilience follows the same pattern: the cross-region disaster recovery that carries the four-nines commitment is an add-on license rather than something the module arrives with.
What Idira offers at the vault layer is the platform around it: enterprise-grade identity, resilience and governance, arriving as inheritance rather than as product. Buyers wanting a self-contained password manager with rotation, passkeys and developer tooling in the box might need to consider something built for that job.
Segura
Challenger | Enduring Innovator | Fast Following
Summary:
MySafe is the workforce password-management module of the Segura platform (rebranded from senhasegura in 2024, with documentation still served under the legacy domain), delivered as a self-hosted virtual or physical appliance across major hypervisors and clouds, or as a multi-region SaaS on Google Cloud; MySafe is enabled by module selection within the same platform deployment as PAM Core and DevOps Secret Manager. End-user access is a web vault, extensions for Chrome, Edge, Opera, Brave, and Firefox, and a mobile app; there is no desktop client.
Assessment: Segura’s strength is the platform MySafe sits inside. Recovery is a Shamir-split master key held by two to ten customer guardians under a configurable M-of-N quorum, with MFA-gated ceremonies and a per-guardian attestation record for each one. The vault architecture pairs HSM and KMS adapters for Entrust, Google Cloud, and Dinamo with Galera replication, active-active topologies, and a DR runbook an operator can execute. Identity integration runs through SAML and OIDC, a SCIM 2.0 endpoint with Okta group push, Active Directory group-to-access-group mapping, CEF and syslog schemas, and ordered fallback authentication providers. Secrets management arrives with the DevOps Secret Manager module on the same deployment, bringing machine identities, an injection CLI, CI/CD plugins, and External Secrets Operator support. A zero-knowledge model keeps credential values from administrators while still scoring each credential on a multi-factor composite health measure, ranking users and items by risk, and surfacing weak, reused, and leaked credentials on an administrator dashboard. Purge intervals are admin-configurable, with contractual deletion timeframes attached.
Existing Segura customers benefit most here. MySafe is enabled by module selection inside the same deployment as PAM Core and DevOps Secret Manager, so the recovery ceremony, residency controls, identity plumbing, and machine-credential tooling are in place before the workforce vault is switched on, and it runs on the hypervisor or cloud the organization already operates.
The workforce edge is the thinnest part of MySafe, and the client footprint sets the boundary. Fill reaches the web vault, extensions for Chrome, Edge, Opera, Brave, and Firefox, and a mobile app, which leaves Safari users and anyone wanting a desktop client without a credential path, and mobile autofill and managed extension rollout without documented guidance to follow; fill detection carries constraints of its own. Passwordless sign-in stops at device biometrics, so passkeys are not yet a credential type MySafe stores or governs, and FIDO attestation is early-stage. Automation reaches individual items and stops there, with the API covering item CRUD while folders, sharing, audit, and administrative actions sit outside its documented surface, and no MySafe-scoped CLI or SDK to reach past it. Audit, tenant isolation, and exposure reporting are read from platform-wide surfaces rather than from the module itself, and credential import covers three primary sources.
MySafe is best read as an extension of a platform rather than a vault chosen on its own merits. Organizations already running Segura inherit the recovery ceremony, residency controls, and identity machinery, and gain a workforce module that fits the deployment they already operate. A standalone buyer starts without that inheritance, and may find the client coverage, the passkey story, and the automation surface thinner than they need.
Disruptive Pioneers
Disruptive Pioneers in this market are redefining what the category covers rather than improving vaulting. The four vendor/product pairs here each sell a thesis: extended access management that gates application access on device trust and discovers the SaaS and shadow credentials identity platforms never see; an AI-led credential-risk layer built on continuous detection and behavioral intervention rather than storage; an architecture that removes the master password entirely, with the user’s phone as the cryptographic key; and a sovereignty position (end-to-end encrypted, single-jurisdiction, vendor-cannot-read-your-data) spanning a whole productivity suite. The common trade is definitional for the quadrant: capability that was not previously purchasable, delivered on fast-moving roadmaps by vendors whose enterprise administration, integration, and assurance surfaces are still filling in behind the thesis. The buyer is betting, not optimizing, and accepts a product boundary that is still settling.
1Password*
Leader | Disruptive Pioneer | Outpacing
Summary:
1Password’s subscription covers clients for Windows, macOS, Linux, iOS, and Android, extensions for all major browsers, the op CLI, SDKs, Connect server, and service accounts. Extended Access Management, SaaS Manager, Privileged Access, and Credential Broker are separately licensed add-ons and are not part of this assessment. Buyers select a hosting region (US, EU, or Canada) at signup, and data does not move between regions automatically.
Assessment: 1Password’s strength is depth on two axes, developer tooling and identity integration. The developer surface carries published OpenAPI specifications, maintained Go, JavaScript and Python SDKs, a Terraform provider, a Kubernetes operator, and an explicit version-support and compatibility statement. Identity integration backs it up: OIDC Unlock with SSO participates in key management, with device-key-encrypted credential bundles and IdP policy evaluated at every unlock, supported by SCIM 2.0 provisioning and documented IdP-outage procedures. Adoption is well served, with dual provisioning paths, broad importers, adoption reporting and quantified customer references, and passwordless support reaches a generally available master-password-free deployment through device-bound SSO unlock, with full passkey lifecycle management under admin policy.
This suits an organization that wants the vault participating in identity rather than sitting beside it. The cryptographic architecture rests on two-secret key derivation, SRP, and per-vault keys, and has been examined in recurring public audits and academic cryptanalysis. Compliance certifications, data residency and tenant isolation are all strong, as are client coverage, deployment and migration automation, and the governance of AI agents through scoped service accounts and Agentic Autofill’s non-plaintext credential brokering. This is a vault built to be wired into things.
Credential-lifecycle intelligence is where the depth runs out. There is no weighted risk scoring and no behavioral anomaly detection for the vault, so risk analysis is something a buyer brings rather than something the product performs. FIDO attestation is minimal: WebAuthn registration events are logged and exportable, but no AAGUID or authenticator-model data is retained. Audit logging has a rich event taxonomy and sixteen SIEM destinations, though the log store carries no tamper-evidence and delivery is pull-based only. IdP reconciliation does not handle nested groups and offboarding runs off a manual checklist, and admin automation has neither a declarative policy surface nor an in-product access-approval workflow. Availability, breach response, recovery and modular architecture are all solid without standing out.
For an organization that wants its vault wired into identity and developer workflow rather than sitting alongside it, 1Password is built for the job. Buyers whose priority is model-driven risk analytics may need to pair it with something else.
Dashlane*
Leader | Disruptive Pioneer | Outpacing
Summary:
Omnix Password Management is Dashlane’s workforce vault, sold SaaS-only under the Omnix platform branding in three purchasable units: Password Management (the former Business plan), the Credential Protection add-on, and Omnix Enterprise combining both. Data resides by default in an EU West AWS region, with US East available at team creation through sales. Clients comprise extensions for Chrome, Edge, Firefox, Safari, and Chromium AI browsers, native iOS and Android apps, a maintained CLI, and the web app; there’s no Windows desktop client, and the macOS app runs at reduced function. Confidential SSO, hosted in AWS Nitro Enclaves, removes the master password entirely for SSO users.
Assessment: Dashlane’s strength is credential intelligence. A tenant-wide password health score carries trends alongside per-user weak, reused, and compromised counts on hourly sync, org-wide dark web insights with CSV export, and credential risk detection that catches unvaulted credentials typed on managed devices and discovers shadow credentials. Breach response sits close behind, pairing k-anonymity correlation with policy-driven Slack and in-browser nudges and streaming exposure events to Splunk, Sentinel, Datadog, and CrowdStrike. Weighted health scoring, generally available risk-notification campaigns, and a natural-language advisor in beta push the same work further. Around that sit activation states, event-level autofill telemetry, a capable CLI with secrets injection, and onboarding through SCIM, CSV, and managed extension rollout. Identity integration runs Confidential SSO as a participant in key management, with an on-premises Active Directory sync agent and an audit-log schema behind it, and the vault itself is client-side and fully parameterized, using AES-256-CBC with HMAC and Argon2d, with export blocked by default.
Security teams that measure credential risk are a key user base. The product is SaaS-only with nothing to host, and its centre of gravity is the dashboard and the nudge rather than the vault: it finds exposed and unvaulted credentials, scores them, tells the employee, and sends the event to the SIEM. Confidential SSO, hosted in AWS Nitro Enclaves, removes the master password for SSO users, so the credential the security team is watching is one the employee never types.
Dashlane finds credential problems and tells someone; fixing them is left to the person who receives the prompt. Policy lands org-wide, so an administrator wanting a rule for a single group, or a template to reuse, works around the product rather than with it. The public API is a reporting interface rather than a control plane, four read-only endpoints that stop short of vault operations, its OpenAPI specification and polished tooling notwithstanding. Region choice is made once at team creation and holds, and the replication and failover architecture behind it stays unstated. Machine access borrows device keys attached to human accounts, which is as close as the product comes to giving a workload an identity, and passkey support, broad as it is, arrives ahead of the governance an enterprise would want around sharing, policy, and inventory. FIDO attestation is early, and the authenticator’s AAGUID is not among what Dashlane retains.
What this adds up to is a security-intelligence platform with a vault attached, well matched to organizations that value visibility, breach response, and user adoption above infrastructure control. Buyers who want administration driven through an API, or the vault self-hosted, will want to weigh how much of that has to come from elsewhere in the stack.
heylogin*
Challenger | Disruptive Pioneer | Slow Following
Summary:
heylogin Enterprise is a SaaS-only, passwordless-by-design workforce password manager from a small German vendor, hosted exclusively in Germany (Hetzner production and standby sites, IONOS backups) with a DPA executed at signature and German-only subprocessors. The Business tier adds user, team, and directory management; Enterprise adds the audit log, Pwnitoring breach monitoring, and an optional on-premises backup. Clients are extensions for Chrome, Edge, Firefox, and Safari plus native iOS and Android apps; there is no desktop vault client.
Assessment: heylogin’s strength is its cryptography. The design names its AEADs, XSalsa20-Poly1305 and ChaCha20-Poly1305, states its Argon2id parameters, sets an explicit TLS floor, and replaces the master password with a hardware-wrapped seed, and an independent FZI assessment measured it against the BSI password-manager criteria. Isolation is handled with the same care, through scope-limited Team-Admins, per-organization policy, and a managed-organizations construct for partners. Login is master-password-free on PRF-backed FIDO2 keys. Rollout runs on Entra ID group sync, more than a dozen named importers, and silent GPO force-install of the extension on Windows, and the hosting topology carries geo-separated replication with RTO, RPO, and uptime targets attached. Assurance rests on an ISO 27001 certification and a self-service trust centre.
heylogin is a closed product: the phone, the extension and the console are the whole surface, and nothing behind it is exposed as an API, a CLI, an SDK or a webhook. That boundary holds the developer surface, secrets-management integration, and agentic and non-human identity governance at their baseline, and it constrains administration to what the console offers. Identity integration arrives in an unusual order, with directory provisioning shipping today while SAML and OIDC single sign-on is still to come and Entra SSO sits on the roadmap. Third-party passkey management is an extension-only public beta. Audit logging covers a limited set of event types and ends inside the product, with export and SIEM paths yet to be documented, and adoption telemetry, credential health, and credential intelligence stop at binary leak flags, a seat count, and the Pwnitoring domain-breach report. Residency is exemplary in jurisdiction, though retention windows come without documented controls. One caveat runs through this: much of the public record is German-only and marketing-shaped, so parts of this picture are harder to verify from public documentation alone.
Taken together, heylogin is a privacy-forward, phone-centric vault, well matched to German and EU organizations that prize data sovereignty, hardware-bound passwordless login, and the minimal telemetry a works council will accept. Buyers who need automation, integration surfaces, or audit depth are likely to find it thin.
Proton Pass*
Challenger | Disruptive Pioneer | Fast Following
Summary:
Proton Pass for Business is Proton’s newest enterprise product line, sold as Pass Professional or within the Proton Workspace bundles and delivered exclusively from Proton-owned servers in Switzerland, Germany, and Norway under Swiss law. This restricts region selection and self-hosting. It ships open-source clients across five browser extensions, Windows, macOS, and Linux desktop apps, iOS and Android credential providers, a web app, and a first-party Rust CLI.
Assessment: Proton Pass’s strength is its privacy engineering. The vault uses AES-GCM throughout a user, vault, and item key hierarchy, with two external audits behind it, by Cure53 and Recurity Labs, and export blocking enforced by policy. Agent access is the standout: generally available AI access tokens create agent principals with mandatory expiry, vault- or item-scoped grants, encrypted access-reason logging, and masked just-in-time injection. Breach response pairs identity-level dark-web monitoring, with Constella Intelligence among its named sources, with severity-banded findings and admin-executed session revocation. Rollout and adoption run on SCIM and CSV onboarding, full client parity, a vendor-maintained CLI with secrets injection, per-user Pass Monitor and Usage reports, and quantified customer references, and adoption telemetry distinguishes item use from item read. Client coverage carries no structural gaps, including a supported Linux desktop with unconditional offline access.
Organizations that want the vault out of the vendor’s reach are its natural buyers. Everything runs on Proton-owned servers in Switzerland, Germany, and Norway under Swiss law, with no region selection to make and no self-hosting to run, the clients are open source, and agent principals are a first-class object rather than a repurposed user account.
The identity layer is the youngest part of Proton Pass. Vault access begins and ends with a Proton password: single sign-on authenticates the user but does not unlock the vault, so an SSO user keeps a permanent password, and passkeys, handled well, are something the product manages for other sites rather than a way into itself. Directory integration reaches users but stops before group-to-vault provisioning rules, attribute mapping is sparse, and unlock carries no policy of its own. Automation runs through the CLI, which is the whole of the programmatic surface. Administration works with six org-wide policies and no finer grain, tenant isolation reports across the whole tenant rather than per container, retention windows are fixed, and audit records stay inside the product. FIDO attestation and credential intelligence are both early.
Put together, this is a privacy-first vault maturing quickly, suited to organizations that value Swiss jurisdiction, open-source clients, and a forward-leaning position on agent credentials. Buyers who need administration driven from the directory, or automation over a REST API, will want to weigh how much of the enterprise identity layer is still being filled in.
Foundation Builders
Foundation Builders is this market’s largest quadrant, and its character describes how most EPM is still bought. The nine vendor/product pairs here are credential systems of record for IT operations: self-hosted vaults running on the customer’s own infrastructure, storage-you-own designs that keep the vendor out of the credential path, suite-attached utility vaults, and long-lived products whose buyers specifically do not want them to change. The arguments are continuity, audit evidence, data ownership, on-prem control, and low blast radius; several placements rest on post-incident hardening or decades of installed familiarity rather than new capability. Roadmaps are deliberate and upgrades are cautious, because in this quadrant change is the risk being managed, not the reward being purchased. The buyer is an IT operations or compliance-led team hardening what already runs: cost-defensive, governance-first, and measuring success in reliability and audit outcomes.
Bravura Security*
Challenger | Foundation Builder | Slow Following
Summary:
Bravura Safe is a documented fork of Bitwarden’s open-source code, delivered as vendor-hosted SaaS on AWS. The enterprise capabilities the Bravura name implies, identity lifecycle management and mature APIs among them, belong to sibling products in the broader Security Fabric, Pass, Identity, and Privilege, rather than to this vault. Clients cover extensions for Chrome, Edge, and Safari, Windows and macOS desktop apps, native iOS and Android apps, and a CLI. Standard and premium subscriptions carry monthly availability SLAs of 99.9% and 99.99% respectively, on multi-AZ, multi-region AWS hosting, with daily backups retained for 35 days.
Assessment: Bravura Safe’s strength is what the fork brought with it. Three browser extensions, desktop clients on Windows and macOS, native mobile autofill on both platforms with biometric unlock and passkey storage, and a CLI carry credentials to where they are needed. Login can bypass the master password through a log-in-with-device path, and passkeys can be created, autofilled, and shared at team level across the desktop browsers. Isolation runs on the inherited Teams, Collections, and Groups model with per-team policies, reports, and event logs, and the audit taxonomy that came with it records per-item view and copy events. Availability rests on a monthly SLA, redundant AWS topology, and offline access. Recovery covers both administrator reset and an emergency-access workflow with explicit approval.
Organizations already committed to the Bravura Security Fabric are the main market. Safe is the credential vault beside Pass, Identity, and Privilege, so the identity lifecycle machinery this vault does not carry is bought elsewhere in the same estate, and what remains is a familiar Bitwarden client experience under one vendor and one contract.
Bravura Safe has stayed close to the code it forked, and the age shows. Safe carries no SCIM endpoint of its own, and the CLI, unchanged since 2022, is the whole programmatic surface, with the vault reachable through it rather than through a REST API.Credential health reaches the end user rather than an organization-wide administrator view, adoption reporting is slight, and residency follows the vendor’s hosting rather than a customer choice. Audit stays inside the product, forwarded to no SIEM and protected by no tamper controls. Firefox and managed extension deployment are the two holes in an otherwise complete client set, and the emerging-technology ground, credential intelligence, FIDO attestation, and agentic and non-human identity governance, is unaddressed.
The combined picture is a serviceable Bitwarden-derived vault, and the right fit for organizations already committed to the Bravura Security Fabric. Standalone buyers are likely to want to weigh aging tooling and a reliance on sibling products for identity lifecycle before committing.
Click Studios*
Challenger | Foundation Builder | Slow Following
Summary:
Passwordstate is a self-hosted enterprise password and privileged-credential management platform that runs exclusively on customer-operated Windows, IIS, and SQL Server infrastructure; there is no vendor-hosted SaaS offering. The core product is a web application, with no installed desktop vault client on any operating system, complemented by browser extensions for Chrome, Edge, Firefox, and Brave, native iOS and Android apps with an encrypted offline cache, and separately licensed modules such as Remote Session Management and the Password Reset Portal.
Assessment: Passwordstate’s strength is operational. Reusable password-list templates propagate settings across lists, forty-five discrete Security Administrator roles carry segregation of duties, a REST API of roughly seventy-one endpoints opens the product to scripting, and request-and-approval access is time-bound, with permissions removed automatically at expiry. Identity work runs through SAML single sign-on against the major providers, with sub-hour directory sync and configurable deprovisioning. Resilience rests on active/active high-availability topologies with a promotion runbook to follow. Audit covers more than a hundred and ten event types with syslog forwarding and tamper-detection alerts, and adoption reporting, the modular vault layering, and identity integration all hold up without gaps.
Windows-centric operations teams are who this is built for. The platform installs on infrastructure the organization already runs, Windows, IIS, and SQL Server, and the delegation machinery, forty-five roles, reusable templates, and approval workflows, is built for a team that administers credentials as a daily job rather than configuring a vault once.
The trust model is where a buyer has a decision to make. Passwordstate’s split-key design keeps one key tier on the server, so an administrator holding both tiers can recover plaintext, and item metadata is stored in the clear. Assurance rests on the vendor’s own regular penetration testing. Credentials reach users through the web application and four browser extensions, which leaves Safari users, anyone wanting an installed client, and any administrator hoping to push the extension by policy to find another way round; capable fill customization and RDP and SSH credential injection carry the load instead. The API is broad but ships without an OpenAPI specification or a vendor-maintained SDK, so integration work starts from the documentation rather than from generated clients. Passkeys are generally available in four browsers and no user memorizes a master password, though provisioning and governing them on mobile falls outside the product, and FIDO attestation and credential intelligence are both minimal.
Depth of administration, not reach, is what Passwordstate sells: a deeply automatable, operations-first vault for Windows-centric organizations that want self-hosted control and serious delegation machinery. Buyers who cannot accept the server-side trust model, or who need Safari and a desktop client, are likely to want a different shape of product.
Enpass
Challenger | Foundation Builder | Fast Following
Summary:
Enpass Business is the platform’s single workforce tier, layering SSO, SCIM provisioning, UEM and MDM deployment, SIEM forwarding, and the Enpass Hub’s security audit, access recovery, and vault sharing over the personal client’s vault and item model; above it sits only a negotiated large-enterprise agreement covering account management, solution design, and PoC support rather than additional product function. SAML SSO, event logging, and SIEM integration are gated to the Business Enterprise tier, and Enterprise event logging requires Microsoft 365 or Google Workspace as the storage backend. Customers do not choose a vendor hosting region, because encrypted vault files remain in the organization’s own Microsoft 365 tenant, on OneDrive or SharePoint, or in Google Workspace, and only vault and user metadata, encrypted cryptographic material, and aggregated audit statistics reach Enpass Hub, which can itself be self-hosted on Enterprise plans for data-residency or network-isolation requirements. Licensing is per user. Clients cover seven browser extensions, Windows on x64 and ARM64, macOS, and 64-bit Linux desktop apps, iOS and Android with native autofill, and both Apple Watch and Wear OS companions.
Assessment: Enpass’s strength is that the customer holds the vault. The cryptographic design names its primitives, the keys are customer-held by design, two Cure53 audits carry fix verification, and export blocking is enforced by policy. Client coverage matches it, with extensions for seven browsers, native clients across Windows, macOS, Linux, iOS, and Android, and a local vault that keeps working with no vendor connectivity at all. Recovery is unusually well built for a vendor this size, with a dedicated Recovery Admin role, dual approval that requires the admin’s own unlocked vault, time-limited recovery links, and a logged Recovery event category. Migration automation, a four-stage onboarding funnel with its own Adoption Summary API endpoint, credential health monitoring, availability and failover, and certifications spanning ISO 27001, SOC 3 across all five Trust Services Criteria, ISO 27701, and TISAX all land solidly.
Organizations that will not let credentials leave their own tenancy are the buyers this serves. Encrypted vault files stay in the customer’s Microsoft 365 or Google Workspace tenant, the Hub can be self-hosted on Enterprise plans, and only metadata, encrypted key material, and aggregated statistics ever reach the vendor. The master password is the encryption key, so there is no vendor-side route to the plaintext.
Everything in Enpass happens when a person unlocks a vault on a device, and the vendor operates only the Hub. That shape accounts for most of what a larger organization would find missing. Retrieval is interactive by design, so a workload or an agent has nobody to unlock a vault on its behalf, which leaves secrets-management integration and agentic and non-human identity governance with nothing to assess. The API reports rather than acts, read-only across three endpoints, though an OAuth-authenticated MCP server sits alongside it. The master password is the encryption key, so unlock itself stays password-based, and passkey support reaches the credentials Enpass holds for other sites, managed well across six browsers and both mobile platforms, rather than the vault login. Single sign-on governs the Admin Console, the one component the vendor runs, which holds identity reconciliation short; delegation stops at a Super and Standard admin model; and authenticator provenance sits outside what the audit trail records.
Enpass trades automation depth for architectural assurance. Organizations that want credentials kept inside their own storage tenancy, and that can accept admin-only single sign-on and little in the way of machine-credential capability, are well served. Where DevOps secrets delivery or passwordless vault access drives the requirement, buyers will want to weigh how much of that Enpass is built to do.
LastPass
Leader | Foundation Builder | Fast Following
Summary:
LastPass Business Max is the top workforce tier of the LastPass SaaS platform, layering Advanced SSO, Advanced MFA, and the SaaS Monitoring and SaaS Protect capabilities over the Business plan’s vault, policy library, and reporting. Customers choose a hosting region at account creation, including US, Europe, Australia, Singapore, India, or Canada, with a documented migration path afterward. Clients cover five browser extensions, Windows and macOS desktop apps, iOS and Android with native autofill, and an Apple Watch client; there is no Linux desktop client.
Assessment: LastPass’s strength is adoption machinery. A purpose-built Adoption Dashboard reports enrollment and utilization over configurable ranges, with one-click re-invite and inactivity-reminder actions, two years of user activity history, and a quantified customer adoption outcome behind it. Onboarding runs automated SCIM and directory provisioning across five identity providers, a Starter Kit checklist, and customizable risk-warning nudges. Client coverage has no structural gaps, with four managed deployment planes and capable per-site fill and URL-rule administration. Federated login participates in key management through split-knowledge key derivation, FIDO2 passwordless vault login is certified and generally available, and passkey management shipped with an admin policy of its own. Certifications span SOC 2, SOC 3, BSI C5, ISO 27001, and ISO 27701, with a self-service compliance centre.
Everything here points at a rollout being measured. The product is built around getting people enrolled and keeping them there: the dashboard counts who has adopted, the nudges chase the rest, and federated login means an employee signs in with the identity they already have. Six hosting regions, chosen at account creation with a migration path afterwards, keep that rollout inside whatever jurisdiction the organization answers to.
Cryptography is where a buyer should look hardest. Vault items are encrypted with unauthenticated AES-CBC, a design a peer-reviewed academic analysis showed to be attackable under a malicious-server model; LastPass has acknowledged the finding and remediated part of it. The programmable surface tells a similar story of reach without depth: the Enterprise API covers administration and provisioning, arriving with a versioned OpenAPI 3.0 specification and a scoped API-key framework but leaving vault operations outside it and SDK work to the customer, and the CLI authenticates local accounts rather than the federated users a Business Max deployment is made of. Those same federated users work online only, since the offline vault is available to everyone else. Secrets management is thin, and FIDO attestation, agentic and non-human identity governance, and tenant isolation are the weaker ground, the last of these because a super admin’s reach runs org-wide and keys are held per tenant rather than per business unit.
What LastPass is built to do is get a large workforce onto a vault and keep it there, and federated login, usage analytics and policy breadth all serve that job. Buyers with hard requirements on the encryption design, or on developer automation, will want to weigh the AES-CBC finding and the reach of the API before committing.
ManageEngine
Challenger | Foundation Builder | Slow Following
Summary:
Password Manager Pro ships as a Windows or Linux server installation in Standard, Premium, and Enterprise editions; there is no vendor-hosted cloud edition. High availability is bundled into Premium and Enterprise, several capabilities (custom roles, SIEM output, compliance report packs, query reports) are Enterprise-gated, and a separate MSP edition serves multi-organization use. Buyers get bundled PostgreSQL or external MS SQL Server backends, BYOL images on the AWS and Azure marketplaces, and browser extensions for Chrome, Firefox, and Edge.
Assessment: PMP’s strength is on the server side. Availability rests on named PostgreSQL and MS SQL high-availability architectures, automatic transparent failover, a DR restore runbook, and admin-governed, time-limited offline access. Administration is deep: custom roles assembled from more than a hundred discrete operations, an approval workflow carrying multi-administrator sign-off, timed windows, ticketing validation and post-checkin forced reset, and reporting that can be scheduled and exported. The vault layers are separable, with swappable database backends and vendor migration tooling, two HSM integrations, and customer-supplied cryptography. Machine credentials are served by certificate- and key-authenticated API users alongside Jenkins, Ansible, Chef, and Puppet plugins. Certifications cover ISO/IEC 27001, SOC 2 Type II, and ISO 27701, with clause-mapped PCI DSS, ISO A.9, and NERC CIP report packs.
This is a product for teams that run their own servers. PMP installs on Windows or Linux against a bundled PostgreSQL or an external MS SQL Server, or from a BYOL image on the AWS and Azure marketplaces, and the capabilities that matter most, the failover architecture, the hundred-operation role model, the approval workflow, are all things an operations team configures and owns. A separate MSP edition extends the same machinery to multi-organization use.
The employee side of PMP is relatively thin, and the reason is that the product was built for administrators. Credentials reach users through extensions for Chrome, Firefox and Edge, which is the whole of the client story: Safari users, anyone wanting an installed application, and anyone expecting autofill on a phone sit outside it, and the extension arrives by hand rather than by policy. Login stops at smart-card and SAML federation, so FIDO2, WebAuthn and passkeys sit outside the product too, and YubiKey works as Yubico OTP rather than as an attested authenticator. The server decrypts by design, which is the architectural choice behind much of the above. Breach checking against a credential corpus belongs to a different ManageEngine product rather than this one. Provisioning is done by hand, since the identity integration covers authentication rather than lifecycle, leaving SCIM, attribute mapping and deprovisioning workflows to the administrator; credential intelligence runs on fixed event triggers; and administrators can selectively purge the audit trail. Adoption telemetry, the developer surface, residency and retention controls, tenant isolation, and non-human identity governance all sit at baseline.
PMP is an administrator’s tool that happens to hold employee credentials. Organizations wanting self-hosted control of a credential system of record are well served, and the operational depth behind that is real. Buyers who need a modern workforce password manager, with passkeys, zero-knowledge cryptography and breach monitoring, are likely to want a second product alongside it.
Passwork*
Challenger | Foundation Builder | Slow Following
Summary:
Passwork Enterprise is a primarily self-hosted password manager installed via Docker on customer Linux or Windows Server infrastructure, with a managed alternative, Passwork Cloud, hosted exclusively in Germany. The contracting entity is Passwork Europe S.L., operating under Spanish and EU law with a transitional agreement from a UAE entity, and the vendor holds ISO 27001 certification. Clients cover Chrome, Firefox, Edge, and Safari extensions, Windows, macOS, and Linux desktop apps, and iOS and Android apps; the Enterprise license gates LDAP and AD sync and related advanced features.
Assessment: Passwork’s strength is what an administrator can automate. Vault Types work as reusable policy templates that auto-assign administrators, custom roles are unlimited and sit alongside vault-scoped delegation, and the REST API claims full coverage, with a vendor Python SDK, a CLI, and a Docker image behind it. Machine credentials run through dedicated service accounts carrying multiple independently revocable, rotatable API tokens, a CLI exec command that injects secrets into process environments, and documented GitLab, GitHub Actions, and Kubernetes patterns. Isolation rests on vault-scoped administrators and a per-vault key hierarchy, and the audit trail carries roughly one hundred and twenty named event codes with severity values, emitted in CEF to syslog with a device-type field that tells API clients from human ones. Identity integration pairs SAML single sign-on with a rule-driven LDAP engine mapping directory groups to roles, with auto-deactivation. Availability is built out for a self-hosted product, with stateless app servers behind a load balancer, MongoDB replica sets across datacenters, and passwordless WebAuthn vault login shipped with a passkey-specific role policy.
Teams that automate their own infrastructure will find it fits. Passwork installs from a Docker image onto Linux or Windows Server the organization already runs, or arrives as a managed service hosted in Germany, and the automation depth above sits at a tier a smaller engineering team can reach. This is a vault built to be scripted against rather than clicked through.
The cryptography is where the trust model shows. Vault items are encrypted with AES-CBC and CFB modes, and an on-premises administrator can adjust the zero-knowledge configuration, so what a buyer actually gets depends on how the deployment is set up rather than on the design alone; the audits behind it are held internally. Zero-knowledge access still rests on a master password, even where sign-in arrives through SSO or LDAP. Credential monitoring watches for credentials needing an update after an access change rather than correlating against external breach corpora, and secrets rotation is a manual procedure the vendor documents rather than a scheduled one the product runs. Migration reaches three import formats. Third-party passkey storage, AI-assisted credential intelligence, and FIDO provenance sit on the roadmap.
Passwork gets more out of a self-hosted deployment than its tier suggests: real administrative depth, automation surfaces, and an audit trail an operations team can route into a SIEM. Buyers who require authenticated encryption guarantees, or breach intelligence, are likely to want a different product, and the trust model and provenance history are worth reading closely before committing.
Psono
Challenger | Foundation Builder | Fast Following
Summary: Psono’s argument is engineering depth at open-source economics: nine separately published component images in a documented three-layer architecture, NaCl primitives (XSalsa20-Poly1305, Curve25519) validated by publicly downloadable X41 and Cure53 audits, and identity integration spanning eleven-plus IdPs, an unusually strong result for a vendor this size. The tradeoff is admin polish: delegated administration is limited to the Group Admin and Share Admin scopes with no custom roles, and AI-assisted credential intelligence, FIDO attestation, and agentic governance are all thin. It’s a fit for self-hosting organizations that want auditable cryptography and containerized modularity; buyers requiring granular admin delegation may find this falls short.
Psono Enterprise Edition is the commercial tier of an open-source, self-hosted password manager from German vendor esaqa GmbH, deployed via officially published Docker images against a customer-operated PostgreSQL database (a hosted option also exists). The Enterprise license adds the compliance policy surface, audit logging, SCIM provisioning, central security reports, support for LDAP/SAML/OIDC, and the admin console. Clients cover Chrome, Edge, and Firefox extensions (Safari is explicitly unsupported), native desktop apps on Windows, macOS, and Linux, and iOS/Android apps with OS autofill.
Assessment: Psono’s strength is the architecture underneath it. Nine separately built component images sit in a three-layer design, with five object-storage backends, a component-level fileserver shard-and-cluster API, and HA sizing with read replicas. The cryptography rests on NaCl primitives, XSalsa20-Poly1305 and Curve25519, with stated script parameters, per-path key custody including a server-escrow default for SSO users, export blocking enforced by policy, and X41 and Cure53 audits behind it. Assurance adds ISO 27001, OWASP ASVS control mapping, and roughly thirty-five named policy settings applied per group with priority ordering. Identity integration spans SAML and OIDC across more than eleven providers with editable attribute mapping, SCIM, auto-provisioned groups and shared folders, and an LDAP gateway that derives encryption keys from directory parameters. Credential health aggregates centrally, with the Enterprise edition able to require client-side security reports covering complexity, duplicates, age and breach status, rendered in a Security Reports view with an org-wide overview, a per-user table, and per-entry drill-down. Around that sit the adoption platform, Intune force-install with version-pinned containers, an audit trail of more than four hundred event codes pushed to Splunk, Logstash, or S3, OpenTelemetry support, and passkey support.
Psono is shaped for the team that will operate it. It deploys from Docker images against a customer-operated PostgreSQL database, each component versioned and pinnable on its own, with five object-storage backends and HA sizing to build against; a hosted option exists, but the product assumes an operator rather than a subscriber.
Administration is where the engineering thins out. Delegation runs through two named scopes, Group Admin and Share Admin, applied per group, so an organization wanting a role of its own shape works within those, and central server administration stays all-or-nothing. The console reports registrations rather than behaviour, which leaves per-user activity and credential usage outside an administrator’s view. Recovery is the strict consequence of the cryptography: there is no administrative path to vault contents, a guarantee to some buyers and a risk to others. Residency follows wherever the deployment sits, and retention is left to the operator rather than handled by the platform. Credential intelligence, FIDO attestation, and agentic governance are all minimal, with authenticator AAGUIDs going unretained.
On balance, Psono offers engineering depth at open-source economics: cryptography, modularity and identity plumbing well ahead of the price, for organizations that will run it themselves. Buyers who need granular administrative delegation, or a recovery path into vault contents, are likely to find it short of what they need.
RoboForm
Challenger | Foundation Builder | Fast Following
Summary:
RoboForm Enterprise is Siber Systems’ top business tier, layering a custom SLA, dedicated onboarding, and a self-hosting option above one thousand seats onto the RoboForm for Business feature set; the tiers are otherwise commercially rather than functionally differentiated. The service is hosted on US servers, with an Amsterdam server available to EU customers through a dedicated EU signup. The client story is offline-first: an installed Windows client (with Win32 application fill), a macOS app, extensions for Chrome, Edge, Firefox, Opera, Safari, and Brave, and iOS/Android credential providers; Linux is extension-only.
Assessment: RoboForm’s strength is what reaches the end user. Passkey unlock is generally available and replaces the master password at login on desktop and mobile, third-party passkey management covers native iOS and Android credential-provider integration and sharing, and admin policies are written specifically for passkeys, though the key architecture itself still rests on a master password. Breach response pairs “Have I Been Pwned” correlation with email breach monitoring that reaches beyond the vault, sorted into critical and non-critical severity classes, with policy-driven notifications and admin-executed suspension. Credential health runs on an org-wide dashboard carrying per-user and per-group security scores, ranked insights, and drill-down. Client coverage has no structural gaps, with all three enterprise controls in place, MSI, GPO, and Intune deployment among them, alongside out-of-browser Windows application fill. Rollout is served by SCIM, an Active Directory connector with configurable deprovisioning, CSV bulk onboarding, and two dozen importers.
The natural buyer administers from a console. An installed Windows client with Win32 application fill, a macOS app, six browser extensions, and iOS and Android credential providers put credentials where employees already work, and the offline-first design keeps the vault reachable when the network is not. This is a product shaped around the end user and the administrator rather than the platform it sits inside.
RoboForm is administered from its console, with no programmable surface behind it: there is no vault API, no CLI, and the vendor states that no SDK exists. That boundary accounts for most of what a larger organization would miss, leaving secrets-management integration and agentic and non-human identity governance with nothing to work with, and capping administration at fixed admin levels that cannot be scoped or driven programmatically. Availability rests on the offline-first client rather than on a stated service topology or recovery objective. Residency is a choice of US or EU (Amsterdam) server made at signup, and retention is not admin-configurable. Audit logging records account access and setting changes, so activity on individual credentials goes unrecorded, and there is no path into a SIEM. The vault hierarchy is client-side with no escrow, under a PBKDF2 default of 1,000,000 iterations that the user can change. FIDO attestation and AI-assisted credential intelligence are both minimal, and assurance rests on penetration-test summaries.
Read as a whole, RoboForm is a cost-effective, end-user-friendly vault with modern passkey and breach-response capability, suited to US-based organizations that administer from a console and need no automation. Buyers who require APIs, audit depth, or formal attestations are likely to want more than this offers.
Zoho
Challenger | Foundation Builder | Fast Following
Summary:
Zoho Vault Enterprise is the top edition of Zoho’s SaaS workforce vault, layering SIEM integration, Active Directory provisioning, custom alerts, and unlimited webhooks over the Professional tier’s dashboards, scheduled reports, and user-group sharing. The service runs host-proof: all encryption and decryption happen in the browser under a master password Zoho never stores, with a per-organization key hierarchy, hosting across eleven data centers globally assigned at signup (migratable on request), and a published 99.9% monthly SLA specific to Vault. Clients span eight named browser extensions, Windows and macOS desktop apps, iOS and Android with native autofill, and a first-party CLI.
Assessment: Zoho Vault’s strength is knowing the state of its own credentials. All four core health signals are covered, with “Have I Been Pwned” as a named breach source, per-user drill-down, ranked top-ten and bottom-ten users, PDF export, console-driven reset nudges, and health data reaching thirteen SIEM destinations. Assurance runs deeper than the price suggests: ISO 27001, 27017, 27018 and 27701, annual SOC 2 Type II with Vault named in scope, self-service report access, and framework capability mappings. Administration combines named password-policy templates, request-and-approval access with admin approvers, and scheduled emailed reports, and recovery pairs four distinct models with a bounded Emergency Access workflow carrying a twenty-four-hour buffer, org-wide notification, and forcible termination. Client coverage has no structural gaps, reaching well beyond the core browser set, WebAuthn unlocks the vault alongside shareable third-party passkeys, and the audit trail is tamper-proof and non-deletable with thirteen SIEM push paths. Adoption reporting, residency, directory reconciliation, and the developer API, with full vault CRUD, audit endpoints and a first-party CLI, all clear their bars.
The clearest case is an organization already inside Zoho. Vault is priced aggressively and sold as the top edition of a suite such a buyer is likely to hold already, so the reporting depth above arrives without a separate procurement or a separate console to learn.
Machine access is where Zoho Vault stops short. Non-human identity runs on an OAuth model tied to a user account, so a workload borrows a person’s identity rather than holding one of its own, and CI/CD integration sits outside what the product covers. Fleet deployment is a manual exercise: the standard resource set carries no MSI, ADMX or MDM guidance, and migration is handled one user at a time. Administrative roles follow a fixed structural model, so delegation cannot be scoped to the shape an organization wants.
Zoho Vault answers the compliance question better than the automation one: health visibility, audit depth and certification breadth are all here, at a price that undercuts most of the field. Buyers who need fleet-managed deployment, or credentials that machines can hold in their own right, will find those edges unfinished.
Agile Optimizers
Agile Optimizers modernize the method while keeping the mission: better credential operations on workflows the buyer has already built. The six vendor/product pairs here span an open-source core with a high, visible release cadence steadily widening into secrets management, passkeys, and passwordless SSO; a directory-platform module that removes a separate tool for teams already on the platform; a consumer-heritage product competing on adoption speed and administrative lightness; an API- and CLI-first design wired into existing DevOps pipelines; a consolidation suite collapsing several point tools into one lower-cost license; and a deliberately narrow shared-credential tool that improves its one job steadily. What unites them is efficiency math (cost per seat, admin effort removed, quick payback), pursued through frequent, useful change that never asks the buyer to absorb structural disruption. The buyer is a hands-on operations team, often lean, that wants compounding gains on the toolchain it already operates.
Bitwarden
Leader | Agile Optimizer | Outpacing
Summary:
Bitwarden Enterprise Password Manager is open-source and available as vendor-hosted SaaS in separate US and EU environments, or fully self-hosted via Docker or the official Helm chart. The Enterprise tier is what unlocks SSO decryption options, Key Connector for self-hosted SSO login, custom roles, account recovery, and the Access Intelligence risk console. Secrets Manager runs as a capability within the same organization but carries its own subscription. Clients cover nine named browsers; Windows, macOS, and Linux desktops; iOS and Android; and a maintained CLI.
Assessment: Bitwarden’s strength is architectural. The vault cryptography carries annual Cure53 audits and an academic cryptanalysis with a tracked remediation status, export controls enforced by policy, and clients whose source is open. The deployment is modular in the same way: services deploy independently under the official Helm chart, two production database backends are supported, and Key Connector reaches Azure Key Vault, AWS KMS, Google Cloud KMS, HashiCorp Vault, and PKCS#11 HSMs. Client coverage has no structural gaps, with nine individually named browser extensions, managed force-install deployment, offline access, and per-site fill customization. Single sign-on over SAML and OIDC participates in key management through Trusted Device Encryption and Key Connector, SCIM 2.0 handles nested groups through Directory Connector, and offboarding follows a documented runbook. Credential health monitoring, compliance certifications including SOC 3, tenant isolation, WebAuthn PRF login with a master-password-free SSO deployment, migration automation, and four distinct recovery models are all similarly strong.
Organizations that want to run the vault themselves are the natural fit. Self-hosting is a first-class path rather than a concession, through Docker or the official Helm chart, with a choice of two production databases and key custody handed to an HSM or a cloud KMS the organization already operates; the same cryptographic architecture runs whether the vault is taken as SaaS or hosted in-house.
Machine identity is where Bitwarden is still building. The vault-scoped machine account lives in Secrets Manager, which carries its own subscription, and the SDK that would broker access for an agent is in alpha, so an organization putting AI agents near credentials is buying a second product and an unfinished one. Credential intelligence stops at deterministic signals, short of weighted risk scoring and anomaly detection, and FIDO attestation keeps AAGUIDs server-side without ever showing them to an administrator. The programmable surface is narrower than the rest of the product suggests: the hosted API reaches administration only, and the Password Manager SDK ships with a disclaimer. Audit logging has a broad taxonomy and eight SIEM paths, though the log itself carries no tamper-evidence; administration covers policy but stops before approval workflows and scheduled certification; and availability is a single-region story, its recovery objective unstated and its high-availability guidance for self-hosters thin.
Bitwarden is a transparent, cryptographically credible platform with real deployment flexibility, and its natural buyer is the organization that wants to hold the keys: self-hosted, EU-resident, or working from source it can read. Buyers whose credentials are about to be handed to machines and agents may find that side of the product still maturing, and priced as a second subscription.
JumpCloud
Challenger | Agile Optimizer | Fast Following
Summary:
JumpCloud Password Manager is a module of the JumpCloud Platform, licensed and administered inside the same admin portal and enrolled by JumpCloud user group. Clients are broad: six browser extensions; Windows, macOS, and Linux desktop apps; and iOS/Android apps with native autofill. The product is in transition: JumpCloud Vault, from the VaultOne acquisition, is the mutually exclusive successor offered to new customers, and FIDO2 login policy and the secrets API live there rather than in the assessed module.
Assessment: JumpCloud’s strength is the decentralized design. Vaults live on the endpoint in device-native secure storage, so the vault reads and writes with no vendor service reachable, with admin-key-gated cloud backup restore as break-glass. Client coverage has no structural gaps, spanning six named extensions, three desktop operating systems, and OS-native mobile autofill. Recovery is carefully built, with three distinct routes, customer-held backup keys, and a two-party approval flow recorded as named audit events. Audit rides Directory Insights, carrying per-item copy, autofill and export events, JSON and CSV export, S3 archiving, and named Splunk, Sumo Logic, Datadog and Elastic paths. Directory reconciliation, adoption reporting, residency across US, EU and India regions, and the adoption platform all clear their bars through group-driven enrollment, per-user activation status, and wipe-on-deprovision.
Everything here assumes the JumpCloud directory is already in place. The vault is a module inside the same admin portal, licensed there and enrolled by user group, so enrollment, deprovisioning and audit run on machinery the organization already operates rather than anything new to stand up.
The module boundary is what limits JumpCloud. The vault sits behind no programmable surface, so the platform APIs and SDKs reach everything except vault records, and the modular architecture has nowhere to go. Credential health and breach response stop at basic classification, leaving breach-corpus and dark-web correlation to whatever else the organization runs. Third-party passkey management is absent, which caps the passwordless story despite a login model that needs no master password. The cryptography is described as a per-device key hierarchy, and the independent validation behind it covers the platform rather than the vault. Credential intelligence and FIDO attestation are minimal, and identity integration reaches entitlement only: single sign-on, SCIM and conditional access govern the platform, not the unlock.
The value here is convenience for an estate that already runs the directory: group-based enrollment, unified audit, and a vault that keeps working when the network does not. Buyers who need a vault API or breach intelligence are likely to want more than this module offers, and the convergence with the successor Vault product is worth weighing before a rollout.
NordPass
Challenger | Agile Optimizer | Fast Following
Summary:
NordPass Enterprise is the top business tier of Nord Security’s SaaS password manager, hosted on AWS in a US or EU data center chosen at purchase, with migration between regions explicitly unsupported. The Enterprise tier adds SSO (Entra ID, AD FS, Okta), SCIM user and group provisioning, the Activity Logs API, and Splunk and Microsoft Sentinel integrations over the Business plan; Okta group provisioning notably requires the customer to run a self-hosted NordPass Encryption Service container to preserve the zero-knowledge design. Clients span five browser extensions, Windows, macOS, and Linux desktop apps, and iOS/Android credential providers.
Assessment: NordPass’s strength is what reaches the user. Client coverage has no structural gaps, spanning six browsers, Chrome, Firefox, Edge, Safari, Opera and Brave, three desktop operating systems, and native mobile autofill, with GPO and Intune force-install of the extension. Breach response is the differentiator: the Data Breach Scanner watches every address under a verified company domain rather than vault contents alone, classifies findings by severity, and renders a six-month trend, alongside a Password Health widget covering weak, reused and old credentials. Directory reconciliation carries named SCIM artifacts on Entra ID and Okta with group-to-folder entitlement mapping, and the adoption platform adds auto-applied group provisioning and SIEM-exportable telemetry. The vault uses XChaCha20-Poly1305 and Argon2id in a client-side hierarchy, with the organization keys held by the Owner. Certifications are current ISO 27001 and SOC 2 Type II, and audit, tenant isolation and residency are all adequately covered.
Speed of rollout is what this is built for. Browser extensions, desktop apps on three operating systems, and mobile credential providers, pushed out through GPO or Intune, put the vault in front of employees quickly, and SSO with SCIM provisioning lets the directory do the enrolment.
NordPass reaches the browser and stops there. Credentials arrive through the extension and the apps around it, with no path to them from anywhere else. Automation stops at telemetry and reporting: the API reports on the vault rather than operating it, and the CLI, SDK and service identity a machine would need are absent. Passkeys are managed well for other sites, but the vault itself still opens with a master password. Availability rests on an admin-controlled Offline Mode, with the architecture behind it, the service level and the recovery objective all unstated. Region choice is fixed at purchase and migration between regions is unsupported, and Okta group provisioning asks the customer to run a self-hosted Encryption Service container to keep the zero-knowledge design intact. FIDO attestation and credential intelligence are immature, administrative roles are fixed, and the one independent audit behind the cryptography is dated.
Quick to deploy and closely watched is what NordPass does well: broad client reach, force-install, and domain-level breach visibility. Buyers who need developer or machine-credential integration, or a passwordless end state, are likely to find hard limits here.
Passbolt*
Challenger | Agile Optimizer | Fast Following
Summary:
Passbolt Pro is the commercial tier of an open-source, OpenPGP-based password manager from a European vendor, deployable self-hosted (packages, version-pinned Docker images, an official Helm chart, an AWS Marketplace AMI) or as an EU-hosted cloud service with Belgian, German, and Luxembourg sovereign options. The Pro tier gates LDAP/AD directory sync, SCIM (beta, users-only), SSO, account-recovery escrow, activity logs, and the policy settings. The browser extension is architecturally mandatory, with six browsers covered plus iOS and Android autofill, while the only native desktop client is a beta Windows app.
Assessment: Passbolt’s strength is its cryptography. Secrets are encrypted per user under OpenPGP with no server-side vault key, the TLS suites are named exactly, and the design carries more than fourteen Cure53 engagements and a Quarkslab evaluation feeding an in-progress ANSSI CSPN certification, with cleartext export blocked by policy and clients whose source is open. Identity integration runs close behind: OIDC single sign-on participates in vault unlock, since an IdP login releases the passphrase-wrapping key and conditional access therefore gates decryption, with dual provisioning channels and a documented SSO-bypass resilience path. Recovery is carefully built, on customer-held organization recovery keys, user acceptance steps, and a cryptographic step-up on approval. The deployment is modular, with three database backends, an HA topology and an OpenAPI specification, and the developer surface is complete: a full vault-operations API, a first-party Go CLI with secrets injection, and an Ansible plugin, alongside the infrastructure-as-code artifacts that carry migration.
European and self-hosting organizations are the natural constituency. Passbolt deploys from packages, version-pinned Docker images, an official Helm chart or an AWS Marketplace AMI, or arrives as an EU-hosted cloud service with Belgian, German and Luxembourg sovereign options, and the product is open source throughout, so an organization that wants to run the vault on its own terms can.
Passbolt is built for the user at the keyboard rather than the administrator at the console. Credential health runs client-side, so the breach check and expiry policy reach individual users while an organization-wide view stays on the backlog, and adoption reporting is capped for the same reason. Availability depends on the service being reachable: the vendor’s own incident retrospective records a cloud-edge outage that left users without a fully operational vault, and offline mode is still in progress. FIDO2 and WebAuthn keys are unsupported and third-party passkey storage is roadmap-only, so the passwordless story stops at the SSO-gated unlock and attestation has nothing to record. Credential intelligence and agentic governance are minimal, with automation authenticating as dedicated human-style user accounts.
Passbolt is a sovereignty and cryptography product first, and an administrative console second: European and self-hosting organizations that value open source and infrastructure-as-code deployment above reporting dashboards are well served. Buyers who need admin health visibility, offline resilience, or passkeys will find those on the roadmap rather than in the product today.
Securden
Leader | Agile Optimizer | Fast Following
Summary:
Securden sells two relevant products: Password Vault for Enterprises, a standalone workforce credential vault, and Unified PAM, a privileged access management suite whose workforce password management module covers the same ground. Unified PAM is the product assessed here, because the capability set under evaluation is only fully available with a PAM purchase. Deployment is flexible: a self-hosted Windows Server binary against bundled PostgreSQL or MS SQL, private AWS or Azure instances, a vendor-hosted SaaS edition with a five-region customer residency choice made at both evaluation and production, and a multi-tenant MSP edition.
Assessment: Securden's strength is operational. Coverage is structurally complete, spanning a Securden-published Safari extension alongside Chrome, Firefox, and Edge; desktop autofill on Windows, macOS, and Linux; native mobile autofill; and managed rollout through GPO, Intune, Jamf, and SCCM. The more telling detail sits outside the browser, where a CLI, RDP/SSH launch and an offline mode keep credentials flowing to the administrators an extension never reaches. The same instinct shows in incident handling: breached-password findings feed an Event Listener that fires scripts or REST calls, making containment automated rather than advisory, with remediation and user nudges triggered directly from the organization-wide health view.
The fit is closest where buyers run their own infrastructure. Two swappable database backends with migration tooling, PKCS#11 HSM re-encryption, per-tenant databases and encryption keys, dual-controlled emergency access under customer-held custody, automatic failover, and version-pinned upgrades with backup-based rollback describe a product built to be operated, not merely subscribed to. The emerging-technology criteria run ahead of the field: machine identities carry assigned human owners; audit attribution distinct from the sponsoring user; approval gating and token scoping; and behavior analytics baselines for retrieval and checkout activity, with remediation executable from the console.
FIDO2 and WebAuthn registration flows are native and logged, but the solution lacks AAGUID capture, attestation verification, and authenticator-model policy. Cryptography is AES-256-GCM with TLS 1.3 enforced by default, and key custody is specified for both deployment models, yet a super-administrator plaintext path remains, which runs counter to the zero-knowledge positioning. Audit records are protected by access control rather than append-only or signed storage; SIEM delivery is generic CEF and RFC 5424 syslog rather than vendor-built connectors; and the API carries no versioning, with machine-readable specification covering a single endpoint. Compliance certifications, identity integration extensibility, and IdP reconciliation all sit mid-field, with reconciliation lacking attribute-expression mapping and any suspend-versus-delete offboarding policy.
The combined picture is a broad IT-operations vault that no longer trades end-user reach for back-office depth: organizations prioritizing break-glass rigor, self-hosted control, and machine-credential automation get strong capability at aggressive economics, now with a client footprint that supports daily-driver use.
TeamPassword*
Challenger | Agile Optimizer | Slow Following
Summary:
TeamPassword sells one product, a deliberately minimal SaaS-only team password vault, in two tiers. Standard covers unlimited records, shared groups, browser extensions, mobile apps, TOTP, and the activity log; Enterprise adds OIDC single sign-on with Microsoft Entra ID, one-time secrets, a view-only role, and larger attachments. Enterprise is the tier assessed here, because the identity and roles capability under evaluation is only available at that level. Deployment is not a variable: the service is vendor-hosted only, with no self-hosted, private-cloud, or MSP edition. Clients are browser extensions for Chrome/Chromium, Firefox, and Safari plus iOS and Android apps, with no desktop client and no documented mobile autofill. The product traces to a 2018 Jungle Disk acquisition and remains actively maintained, with recent SSO and passkey documentation.
Assessment: TeamPassword’s strength is its client footprint. Four extension listings include a genuine Mac App Store Safari extension, and, unusual for a product this size, the extension manages third-party passkeys, saving, syncing, and autofilling them with private keys encrypted client-side. That work also carries the passwordless story, alongside Enterprise single sign-on that is shipping and recently documented and organization-wide two-factor enforcement. Groups behave as real access containers with automatic assignment, and a member outside a group cannot see that its records exist, which gives tenant isolation and administrative automation a basic but functional foundation. The admin-scoped activity log, with filters and CSV export, supplies baseline audit and telemetry.
This is aimed squarely at small teams. Two tiers, nothing to host, group-based sharing that works on the first day, and a credential path that reaches the browsers and phones such teams actually use describe a product built to be subscribed to rather than operated. The narrowness is deliberate: the absence of a deployment decision, an infrastructure footprint, and a configuration surface is the value on offer, and for a small team sharing a dozen logins it is a defensible trade.
These limits share a cause. TeamPassword is a closed product, used through its own extension and web app, with no public API, CLI, or SDK behind it. That boundary accounts for most of what a larger organization would miss: the vault cannot be scripted against, connected to a secrets manager, or given a machine identity of its own, which is what the developer surface, secrets management, agentic governance, and modular architecture criteria each ask for. Provisioning runs the same way, with accounts created one at a time because neither SCIM nor directory sync is offered. Reporting stops at the same edge, recording what the vault holds but not what condition it is in, so weak, reused, or breached credentials surface when someone goes looking rather than when the system flags them.
The combined picture is a low-cost, low-friction shared vault that does not pretend to be a platform: small teams needing group-based credential sharing with single sign-on and passkey convenience are well served, at a price that reflects it. Organizations with automation requirements, user provisioning at scale, or any need for credential health visibility might need to consider a more fully enterprise-featured product.
5. Velocity
Market-Level Velocity Story
Velocity on this Radar measures market momentum: the pace at which a vendor is shipping capability that moves the category, judged against the market’s direction of travel rather than feature count. It is rendered on the chart as the color of each vendor’s dot (Outpacing, Fast Following, or Slow Following), never as an arrow. Of the 23 vendors assessed, five earn Outpacing, twelve are Fast Following, and six are Slow Following. At 22% of the field, the Outpacing band sits inside the discipline this methodology imposes: the designation requires shipped, first-in-category evidence, not general health.
What the Outpacing five share is where the market is heading. The group holds the field’s first shipped post-quantum key exchange, its deepest agentic-credential records (agent SDKs, secure credential brokering to autonomous agents, MCP integration), the category’s largest platform investment event, an AI-led credential-risk layer sold as the product itself, and an open source release cadence that keeps widening into secrets management, passkeys, and passwordless SSO. These vendors are not merely executing well; each shipped something in the evidence window that the rest of the field now has to answer.
Fast Following is the market’s healthy center, and the label is not a consolation prize. The twelve vendors in this band shipped credible increments across the window (passkey rollouts, breach-monitoring expansions, SCIM and SIEM plumbing, suite broadening), and several lead the field outright on individual criteria, from break-glass rigor to health reporting to cryptographic transparency. Their pace tracks the leaders without setting the agenda on the emerging fronts where the Outpacing group is defining what comes next.
Slow Following, under this methodology, is never a euphemism for missing data; it requires affirmative trailing evidence. The pattern among the six is concrete: client tooling and connector releases unchanged for years; documentation estates that are out of date, partly inaccessible, or single-language; deliberately narrow products whose enterprise surface has stopped growing; and the absence of modern-authentication support that the rest of the field now treats as standard. For buyers, a trailing mark is a diligence instruction (verify the roadmap and the documentation currency), not a verdict on whether the installed product works today.
6. Ecosystem
Technical Support Quality and Responsiveness
Published support and availability commitments are the exception in this field. A handful of capsules document them: one platform publishes a four-nines SLA with named recovery objectives (the only documented recovery-time and recovery-point commitments in the evaluation), while others publish 99.9% or tiered monthly SLAs, quantified replication targets, or a product-specific uptime commitment. Much of the field publishes no SLA, no status page, and no recovery objectives at all, including several otherwise strong platforms. Self-service trust centers with downloadable compliance evidence are becoming the better-documented half of the support story. Buyers should treat support terms as a negotiation item, and ask for the recovery objectives in writing wherever the public record is silent.
Professional Services Depth
Formal professional-services practices are largely undocumented in this field’s public materials; what the capsules evidence instead is migration and onboarding machinery. Importer coverage is broad: one platform documents 2 dozen credential importers; another, 13-plus; and, on the admin side, organization-wide competitive migration tooling exists for moving off a rival vault wholesale. Structured onboarding shows up as starter-kit checklists, staged onboarding funnels with dedicated reporting endpoints, and dedicated onboarding attached to top-tier plans. At the self-hosted end, vendor-managed cloud alternatives serve buyers who want the product without the operations. Deployment and integration consulting depth is rarely published; organizations with complex estates should size service needs directly with vendors during evaluation.
Partner and Channel Ecosystem Breadth
The managed service channel is well built out. Capsules document dedicated MSP editions with multi-tenant consoles, per-managed-company key derivation that keeps tenants cryptographically separate, per-customer operator assignment, and partner-facing managed-organization constructs—a service-provider surface that is now a first-class product feature at several vendors. Cloud marketplace presence appears as bring-your-own-license images and machine images on the major clouds. Technology alliances cluster at three integration points: identity providers, where SCIM and SSO coverage across the major IdPs is near-universal; SIEM platforms, with the stronger vendors naming a dozen or more export destinations; and key infrastructure, where HSM and cloud KMS integrations let customers hold or supply their own key material.
Workforce Skills Availability
Skills availability splits along the open-source seam. Several of the field’s strongest cryptographic and architectural stories are open source, letting buyers inspect the code and hire against public technology rather than proprietary internals. Deployment skills transfer well at the self-hosted end: official Docker images, Helm charts, Terraform providers, Ansible tooling, and Kubernetes operators recur across the field, so infrastructure teams bring existing IaC practice to the vault. One product runs entirely on a standard Windows, IIS, and SQL Server estate, familiar territory for the teams that operate it. First-party CLIs are now common, several with secrets-injection semantics that slot into existing pipelines. The counterweight is API shape: OpenAPI specifications and maintained SDKs remain minority artifacts, so automation depth still varies sharply by vendor.
Training and Certification Programs
Formal training and certification programs are almost entirely undocumented in this field’s public record: no vendor capsule evidences a named certification path or curriculum. What the field ships instead is adoption machinery: purpose-built adoption dashboards reporting enrollment and utilization with one-click re-invite actions, staged onboarding funnels with dedicated reporting APIs, starter-kit rollout checklists, and policy-driven user nudges that do the enablement work inline. That machinery is unevenly distributed and genuinely differentiating: the strongest implementations include the only quantified customer adoption outcomes documented in the evaluation. Buyers planning large rollouts should request training catalogs directly and weight the in-product adoption tooling heavily, because for most of this field it is the enablement program.
Community Health
Community health in this market tracks transparency. The healthiest ecosystems publish their full security posture: complete third-party audit reports released annually, reimplementation-grade cryptographic specifications, academic cryptanalysis with published remediation status, and open-source clients that practitioners can read, build, and file issues against. A double-digit count of published audit engagements at one vendor sets the transparency bar. The contrast is stark. Elsewhere, the capsules document login-gated or partner-gated documentation, public portals that are out of date or unreadable, single-language documentation estates, repositories labeled legacy, and authoritative content still hosted on predecessor domains. Prospective buyers of the closed platforms have no practitioner commons to consult before engaging the vendor, and the assessment itself repeatedly found that opacity, not absence, was the binding constraint on what could be verified.
7. Architect’s Validation
No organization weights all 23 criteria in this evaluation equally. The placements in this report reflect the market’s center of gravity, not the buyer’s architecture. The table below indicates when to promote specific criteria to first-order requirements and when to let them recede.
Prioritize when… | Treat as secondary when… |
Vault cryptography architecture: Credential data is subject to hostile-review assumptions (regulated industries, high-value targets, or any environment where an unauthenticated cipher or vendor-reachable plaintext is a finding, not a footnote) | Your threat model centers on user behavior rather than vault compromise, and platform certifications satisfy your assurance bar |
Data residency, retention, and deletion: Jurisdiction, subprocessor nationality, or works-council agreements constrain where credential data and telemetry may live | You are a single-jurisdiction organization whose regulators accept major-cloud hosting with standard contractual terms |
Secrets management integration and developer API ecosystem: Engineering teams will draw credentials from pipelines, infrastructure-as-code, and workloads, and an unautomatable vault will simply be bypassed | Credential use is overwhelmingly interactive and browser-based, and machine secrets are governed by a dedicated tool elsewhere in the stack |
Passwordless and passkey support: A master-password-free end state is on your identity roadmap and the vault must not reintroduce the credential you are eliminating | Passwords remain your operating assumption and passkey storage for third-party sites covers the near-term need |
Agentic and non-human identity credential governance: AI agents or autonomous workloads will touch credentials, and scoped, expiring, auditable agent principals are a compliance requirement in waiting | No agent initiative exists, and this criterion serves as a roadmap signal rather than a purchase gate |
Enterprise UX and adoption platform: The deployment’s success is measured in voluntary enrollment across a large, non-technical workforce, where adoption telemetry and onboarding machinery decide the outcome | Users are technical, the rollout is mandated, and administrative depth matters more than enrollment friction |
Scoped recovery and escrow: Regulated continuity obligations demand dual-controlled, audited recovery ceremonies with customer-held key material | Account loss is an acceptable reset event and directory-driven reprovisioning covers your recovery posture |
Adapting the Radar to your organization: Start from your three or four non-negotiable criteria and reread the vendor capsules against those alone. Let that reading reorder the field before you consider overall placement. A vendor positioned modestly on this Radar may be the outright leader for your weighting, and the reverse is equally true.
8. Horizon
Capabilities Likely to Become Table Stakes (12–24 Months)
Several capabilities that still differentiate today are on a clear path to table stakes within 12 to 24 months. Third-party passkey management (storing, syncing, filling, and sharing passkeys alongside passwords) is already delivered across most of the field, including its smallest products, and will soon be assumed rather than evaluated. SCIM provisioning with group-driven entitlement mapping is heading the same way, as is SIEM export: named integration paths to the major log platforms now appear across the field, with the stronger implementations pushing a dozen or more destinations. External breach correlation against a named corpus has become the expected floor for credential health, and policy-enforced blocking of cleartext vault export is becoming standard among the platforms that take their own zero-knowledge claims seriously. Broad client coverage (the field’s strongest criterion on aggregate) is effectively commoditized at the top: multiple browsers, three desktop operating systems, and OS-native mobile autofill no longer separate leaders. Published third-party security audits are moving from differentiator to expectation as well; the platforms that publish full reports have made undisclosed-audit postures look like a gap rather than the norm.
Capabilities Likely to Emerge as Differentiators
The three youngest criteria in this evaluation drew the weakest field-wide results, and that is precisely why they will decide the next cycle’s separation. FIDO attestation and audit sits near the floor almost everywhere: authenticator provenance, AAGUID retention, and model-level policy are absent even from platforms whose passkey support is otherwise strong, leaving the field unable to answer which authenticators hold its credentials. AI-assisted credential intelligence remains deterministic nearly everywhere; weighted risk scoring and behavioral anomaly detection exist in shipped product at only a few vendors, and the first natural-language advisors are just reaching beta. Agentic and non-human identity governance shows the widest spread of any emerging criterion (genuine agent principals, MCP servers, and non-plaintext agent brokering at the front, nothing at all at the back), and every buyer conversation about AI in the enterprise now touches it. Post-quantum cryptography has its first shipped implementation and will become a standing diligence question long before it becomes common. Beneath all four runs the developer surface: vault-reaching APIs, SDKs, and secrets tooling divide the field more sharply than any established criterion, and they are the prerequisite for everything agentic. The master-password-free end state rounds out the set: the vendors that can retire the founding primitive will spend the next cycle selling that fact.
Expected Market Consolidation or Fragmentation
This roster is itself a consolidation record. The evidence window contains the category’s largest investment event: a $25 billion acquisition, the second-largest in cybersecurity history, that folded an established workforce vault into a platform vendor’s consolidated identity portfolio. Elsewhere, the lineages are older but visible: a vault that is a documented fork of a competitor’s open-source code, a product tracing to a 2018 acquisition, an acquired vault being superseded by a second acquired vault inside the same platform, a corporate rebrand whose documentation still lives on the legacy domain, and an acquisition that became a separately licensed SaaS-governance add-on. Product renaming ran through the field in this window as vendors repositioned vaults as platform modules.
For buyers, the costs of consolidation are observable in this report’s capsules rather than hypothetical: authoritative documentation still hosted on predecessor domains, open-source repositories labeled legacy with connector releases years stale, assessed modules whose newest capabilities ship first in a successor product, and capability that must be priced across module boundaries. Acquisition is not a defect; some of the field’s strongest platform inheritance comes from exactly these events. But an ownership change or a platform absorption should trigger explicit diligence on documentation currency, module boundaries, and the roadmap standing of the specific SKU you are buying. Expect the boundary pressure to continue: identity platforms, PAM suites, and directory vendors all treat the workforce vault as an attachable module, and the standalone half of the field is the smaller half already.
9. Value Chain
Enterprise password management sits in the middle of an identity value chain. It consumes identity and device context from systems the organization already runs, refines credentials into governed, monitored, deliverable secrets, and feeds the platforms where security operations and automation happen. No product in this report operates alone, and much of the differentiation lives at the two seams.
Upstream inputs | The EPM platform | Downstream consumers |
Identity providers via SAML/OIDC SSO and SCIM provisioning; LDAP and Active Directory estates; device platforms (OS credential providers, secure enclaves, browser extension frameworks); breach-intelligence corpora and dark-web monitoring sources | Client-side encryption and key management; autofill across browsers, desktops, and mobile; policy, delegation, and approval workflow; credential health and exposure monitoring; secrets and machine-credential delivery; recovery and escrow ceremonies | SIEM platforms consuming audit and health telemetry; CI/CD pipelines, infrastructure-as-code, and Kubernetes workloads drawing secrets; AI agents receiving brokered or scoped credentials; MSP consoles managing tenant estates; compliance reporting and audit evidence |
In the identity stack, EPM is the coverage layer for everything federation does not reach. The identity provider governs the applications it federates; the vault governs the long tail: shared accounts, legacy applications, infrastructure credentials, and the passkeys and secrets accumulating outside SSO. The strongest integrations make the two layers one system: SSO participating in vault key management, directory groups driving vault entitlements, deprovisioning that actually revokes credential access. The boundary with privileged access management is under active pressure, and buyers should decide deliberately whether they are purchasing the workforce layer, the privileged layer, or a platform that claims both.
On lifecycle timing, buy or replace when the identity estate changes shape: an IdP migration, a passwordless initiative, a merger, an AI-automation program that needs governed machine credentials, or an incumbent whose trust model an audit can no longer defend. Switching is more tractable than it appears (importers are broadly documented across the field, and admin-side competitive migration tooling exists), but the vault’s key architecture is the thing you cannot retrofit. Choose the cryptographic model for the decade, and treat everything above it as replaceable.
10. Appendices
Appendix A: Decision Criteria
The evaluation used 23 analyst-authored decision criteria with 0–5 scoring rubrics, grouped by lens:
Green Money (Innovation & Growth)
Developer API ecosystem: Evaluates whether the platform is something third parties can build on—not whether endpoints exist, but whether the API is publicly documented with a published OpenAPI specification, versioned with stated compatibility guarantees, and backed by officially maintained SDKs and worked examples for common workflows.
Identity integration extensibility: Evaluates how far identity integration bends to an enterprise’s own model—not whether SAML and SCIM are supported, but whether attribute mapping and group-to-role rules are administrator-configurable, whether policy is evaluated at unlock time from IdP or device signal, and whether an IdP-unavailable path is documented.
Modular vault architecture: Evaluates whether the vault’s layers are separable in production rather than only on an architecture diagram—whether storage, the cryptographic boundary, and a public API layer are genuinely distinct, whether alternatives actually ship such as a second storage backend or an external KMS integration, and whether components can be replaced in place.
Passwordless and passkey support: Evaluates whether passwordless is a genuine replacement for the master password or a convenience layered over one—whether a passkey or IdP-derived key serves as the vault login credential with documented recovery, whether passkeys are created, synced, shared, and autofilled across desktop browsers and native mobile, and whether passkey-specific admin policy exists.
Secrets management integration: Evaluates whether machine credentials are a first-class object or just human vault entries a script reads—whether a service identity exists distinct from any human account, whether CI/CD, IaC, and container integrations and language SDKs are published, whether a CLI injects secrets into a process environment, and whether rotation is automated.
Tenant isolation and access segregation: Evaluates how real the boundary between business units or client tenants is—not whether vaults and collections partition visibility, but whether delegated administration is documented as unable to reach outside its scope, whether the boundary is cryptographic or instance-level enough to survive a compromised administrator, and whether audit trails are segregated per tenant.
Brown Money (Operations & Efficiency)
Admin automation: Evaluates how much administrative work the platform takes out of human hands—whether policy applies automatically at group or org-unit scope, whether delegated admin roles can be scoped to part of the organization, whether administration is scriptable through a documented API or CLI, and whether access grants pass through approval and recurring certification.
Adoption telemetry: Evaluates whether the admin console reports adoption in a form an administrator can act on—not seat counts and last-login dates, but per-user activation state, event-level records of credential use, trends over time, cohort comparison, and telemetry that triggers onboarding or remediation campaigns.
Availability and failover: Evaluates whether vault access survives infrastructure failure—not uptime asserted in marketing, but a documented redundant topology with automatic failover, published recovery objectives, geographically separated or customer-selectable regions, and offline or cached access for previously authenticated users.
Browser and application coverage: Measures how completely client software reaches the places users actually authenticate—extensions across Chrome, Edge, Firefox and Safari, installed desktop clients on Windows and macOS, iOS and Android registered with the OS-native autofill frameworks, packaged installers for managed rollout, and credential delivery outside the browser.
Credential health monitoring: Evaluates whether credential hygiene is visible organization-wide rather than only in the end-user client—whether an administrator sees weak, reused, breached, and aging credentials against a named breach source with per-user drill-down and export, can act on a flagged credential from that view, and is handed a risk-prioritized queue.
Deployment migration automation: Evaluates how much of an enterprise rollout the vendor actually automates—bulk onboarding through SCIM or directory sync rather than individual invitations, importers for named competing products, packaged installers with silent-install switches across management channels, an org-wide migration path preserving shared-vault folder and permission structure, and a documented upgrade procedure.
Enterprise UX adoption platform: Evaluates whether the product is built to get an organization actually using it—bulk onboarding through SSO and SCIM with a published enroll flow, feature parity across extension, desktop and mobile clients, a vendor-supported CLI or SDK, in-product prompts steering users to the secure action, and activation-funnel rather than seat-count reporting.
IdP reconciliation: Evaluates whether the directory and the vault stay in agreement across a user’s lifecycle—not whether SCIM provisioning exists, but whether nested groups and entitlements map to vault roles and collections, whether reconciliation is event-driven or runs on a documented interval, and whether offboarding revokes vault decryption access rather than only login.
GRCS (Governance, Risk, Compliance & Security)
Audit trail and forensic logging: Evaluates whether activity logging can carry an investigation—not whether an activity view exists, but whether per-item read events are captured, records resist alteration or selective deletion by tenant administrators, retention is stated, events reach a named SIEM in near real time, and integrity is independently verifiable.
Compliance certifications: Evaluates both the vendor’s third-party attestations and the compliance capability inside the product—not a badge wall, but whether attestations are current and publicly verifiable, whether credential policy is enforced tenant-wide and per group, whether audit evidence exports in a form an auditor can use, and whether control mappings are published.
Data residency retention and deletion: Evaluates whether the customer controls where vault data lives and can prove it was destroyed—not a residency statement in a policy document, but selectable location covering backups and logs, retention an administrator cannot silently bypass, documented legal hold, and deletion that yields a retainable artifact.
FIDO attestation audit: Evaluates whether authenticator provenance is captured for audit rather than discarded at registration—whether attestation is verified against a trust anchor, whether each enrolled credential’s AAGUID or model is visible to administrators and can be filtered or exported, whether policy restricts which authenticators enroll, and whether provenance reaches external systems.
Scoped recovery and escrow: Evaluates whether the organization itself can restore a locked-out user’s vault access, and under what controls—whether recovery is admin-initiated rather than vendor-performed, gated by an approval step and a step-up challenge on the recovering administrator, recorded in a queryable audit log, and backed by customer-controlled key escrow.
Vault cryptography architecture: Evaluates whether the encryption design is documented precisely enough to be checked rather than asserted—whether the cipher and mode, the key-derivation function and its parameters are named, whether the key-custody model is stated explicitly, whether every vault-unlock path says whether the vendor can obtain plaintext, and whether independent audit confirms it.
Emerging Technology
Agentic non-human identity credential governance: Evaluates whether AI agents, service accounts, and automation runtimes are governed as distinct vault principals—not whether a script can call an API using a human’s account, but whether each non-human identity carries assigned human ownership, scoped grants, expiry or rotation, revocation, and audit attribution of its own.
AI-assisted credential intelligence: Evaluates whether credential risk analysis goes beyond deterministic hygiene flags—whether a weighted, multi-factor score ranks where to remediate first, whether unusual access is judged against per-user behavioral baselines rather than fixed thresholds, whether recommended remediations execute from the console, and whether posture can be queried in natural language.
Credential exposure breach: Evaluates what happens once a stored credential turns up exposed—not whether the product checks a breach corpus, but whether findings roll into an organization-wide administrator view, carry per-finding severity, drive containment the platform executes itself such as rotation or session revocation, and stream into incident-response tooling.
Appendix B: Vendor Participation in Fact Check
As part of the GigaOm research process, every vendor evaluated in this report was given the opportunity to review the material concerning them before publication. Each of the vendors on the final roster received a fact-check package consisting of the vendor's capsule narrative and its full set of criteria scores, and was invited to respond by the stated deadline with factual corrections and supporting evidence. All vendor responses—whether capsule comments, contested scores, or supplementary documentation—were reviewed and adjudicated by the analyst team against the published rubric; scores were revised only where submitted evidence demonstrably satisfied the rubric's requirements, and the research team retained final editorial and scoring authority throughout. Vendors that did not respond by the deadline were evaluated on the basis of publicly available information and previously gathered research.
11. About Paul Stringfellow
Paul Stringfellow has more than 25 years of experience in the IT industry helping organizations of all kinds and sizes use technology to deliver strong business outcomes. Today, that work focuses mainly on helping enterprises understand how to manage their data to ensure it is protected, secure, compliant, and available. He is still very much a “hands-on” practitioner and continues to be involved in a diverse range of data projects. Paul has been recognized across the industry and has spoken at many industry, vendor, and community events. He writes for a number of industry publications to share his enthusiasm for technology and to help others realize its value.
Paul hosts his own enterprise technology webcast and writes regularly on his blog.
12. About GigaOm
GigaOm provides technical, operational, and business advice for IT’s strategic digital enterprise and business initiatives. Enterprise business leaders, CIOs, and technology organizations partner with GigaOm for practical, actionable, strategic, and visionary advice for modernizing and transforming their business. GigaOm’s advice empowers enterprises to successfully compete in an increasingly complicated business atmosphere that requires a solid understanding of constantly changing customer demands.
GigaOm works directly with enterprises both inside and outside of the IT organization to apply proven research and methodologies designed to avoid pitfalls and roadblocks while balancing risk and innovation. Research methodologies include but are not limited to adoption and benchmarking surveys, use cases, interviews, ROI/TCO, market landscapes, strategic trends, and technical benchmarks. Our analysts possess 20+ years of experience advising a spectrum of clients from early adopters to mainstream enterprises.
GigaOm’s perspective is that of the unbiased enterprise practitioner. Through this perspective, GigaOm connects with engaged and loyal subscribers on a deep and meaningful level.
13. Copyright
© Knowingly, Inc. 2026 "GigaOm Radar: Enterprise Password Management" is a trademark of Knowingly, Inc. For permission to reproduce this report, please contact sales@gigaom.com.