Click Studios

Click Studios (SA) Pty Ltd is an Agile software development company specialising in the development of a secure Enterprise Password Management solution called Passwordstate.

Contact Info

Level 2, 70 Hindmarsh Square, Adelaide, SA 5000, Australia
sales@clickstudios.com.au

Follow Us

Data Security and Application Protection

Protect Passwordstate credential data with AES-256 encryption, integrity validation, split encryption keys, signed components and configurable application security controls.

Protect Sensitive Credential Data

Passwordstate applies multiple layers of protection to stored credentials, application components and communications between users and the Passwordstate server.

These controls include AES-256 encryption, keyed integrity validation, unique initialization vectors, digitally signed software components and deployment restrictions for authorized Passwordstate web servers.

AES-256 Encryption

Passwordstate uses 256-bit AES encryption to protect passwords and other sensitive information stored within the Passwordstate database. Encryption is performed using cryptographic functionality provided by the Microsoft .NET Framework.

Unique Initialization Vectors

Unique initialization vectors are used during encryption so that identical plaintext values do not produce identical encrypted output. This helps prevent recognizable patterns from appearing within encrypted data.

Data Integrity Validation

Passwordstate uses HMAC-SHA512-based integrity validation to detect unauthorized modification of protected database records.

When protected data is altered outside Passwordstate without the required cryptographic validation, Passwordstate can detect the inconsistency and prevent the affected data from being processed normally.

Encryption and integrity: Encryption protects the confidentiality of stored information, while keyed integrity validation helps detect unauthorized modification of protected records.

Signed and Protected Application Components

Passwordstate application components are distributed using digitally signed executables, DLLs and installers. Digital signatures allow customers and operating systems to verify the publisher and identify whether a signed file has been modified after signing.

Passwordstate also uses precompiled ASP.NET pages and code obfuscation techniques to make unauthorized analysis or modification of application code more difficult.

TLS-Protected Communications

Passwordstate supports TLS-protected HTTPS communications between client devices and the Passwordstate web server. The protocols and cipher suites available will depend on the Windows Server, IIS and operating system configuration used within the customer environment.

Authorized Web Server Controls

Passwordstate can restrict database access to approved Passwordstate web servers. This helps prevent an unauthorized copy of the application from being connected directly to an existing Passwordstate database.

Data Protection Controls

  • AES-256 encryption
  • Unique initialization vectors
  • HMAC-SHA512 integrity validation
  • Split encryption key storage
  • Encryption key rotation
  • Protected key recovery exports

Application Protection

  • Digitally signed components
  • Precompiled ASP.NET pages
  • Code obfuscation
  • TLS-protected communications
  • Authorized web server controls
  • Configurable session protection

Encryption Key Protection and Recovery

Passwordstate provides controls for protecting, rotating and recovering the encryption material required to access stored credential data.

Split Encryption Key Storage

Passwordstate uses two installation-specific encryption keys that are divided into separate secret components and stored across the Passwordstate web application and database. Access to only one storage location is therefore insufficient to reconstruct the complete encryption keys.

Encryption Key Rotation

Authorized administrators can rotate Passwordstate encryption keys when required. Protected data is re-encrypted using the replacement keys, and the key rotation activity is recorded within Passwordstate's auditing system.

Encryption Key Recovery

Encryption key material can be exported in split-secret form to a password-protected archive for secure external retention. This can provide an additional recovery option alongside regular backups of the Passwordstate application files and database.

FIPS-Compatible Encryption

Passwordstate can be configured to use supported FIPS-compatible cryptographic functionality for organizations whose Windows environments require FIPS-related security policy settings.


Operational Security Controls

Passwordstate includes configurable controls for protecting scripts, configuration data, authentication sessions and credentials during everyday use.

Protected PowerShell Scripts

Built-in and custom PowerShell scripts used by Passwordstate are stored encrypted within the database. This helps protect automation used for password resets, account discovery, backups and password validation.

Protected Configuration Values

Sensitive configuration values within the Passwordstate web.config file, including database connection information and encryption key components, can be encrypted using supported ASP.NET configuration protection.

Integrated Windows Authentication

Passwordstate supports Integrated Windows Authentication, including Windows passthrough authentication for single sign-on and domain credential authentication combined with supported multi-factor authentication options.

Failed Login Protection

Configurable failed-login controls can detect repeated authentication failures and temporarily restrict further attempts against the Passwordstate web interface and mobile application.

Password Display and Clipboard Controls

Passwordstate can automatically hide displayed passwords and clear copied password values from the clipboard after a configurable period, helping reduce accidental exposure.

Configurable Session Timeouts

Administrators can define automatic logout periods for inactive sessions, including different timeout settings for users accessing Passwordstate from internal and external locations.


Click Studios Security Practices

Product security is supported by secure development, vulnerability testing and software signing practices used throughout the Passwordstate development and release process.

Secure Development Practices

Click Studios applies secure development practices informed by OWASP guidance to help identify and mitigate common web application risks, including injection, cross-site scripting and access control weaknesses.

Penetration Testing

Click Studios performs regular penetration testing covering relevant Passwordstate application and infrastructure components. Customers can also conduct testing within their own licensed environments to assess deployment-specific security requirements.

Evaluate Passwordstate

Download a fully functional 30-day trial and evaluate Passwordstate's encryption, data integrity and application security controls within your own environment.