Protect Passwordstate credential data with AES-256 encryption, integrity validation, split encryption keys, signed components and configurable application security controls.
Passwordstate applies multiple layers of protection to stored credentials, application components and communications between users and the Passwordstate server.
These controls include AES-256 encryption, keyed integrity validation, unique initialization vectors, digitally signed software components and deployment restrictions for authorized Passwordstate web servers.
Passwordstate uses 256-bit AES encryption to protect passwords and other sensitive information stored within the Passwordstate database. Encryption is performed using cryptographic functionality provided by the Microsoft .NET Framework.
Unique initialization vectors are used during encryption so that identical plaintext values do not produce identical encrypted output. This helps prevent recognizable patterns from appearing within encrypted data.
Passwordstate uses HMAC-SHA512-based integrity validation to detect unauthorized modification of protected database records.
When protected data is altered outside Passwordstate without the required cryptographic validation, Passwordstate can detect the inconsistency and prevent the affected data from being processed normally.
Passwordstate application components are distributed using digitally signed executables, DLLs and installers. Digital signatures allow customers and operating systems to verify the publisher and identify whether a signed file has been modified after signing.
Passwordstate also uses precompiled ASP.NET pages and code obfuscation techniques to make unauthorized analysis or modification of application code more difficult.
Passwordstate supports TLS-protected HTTPS communications between client devices and the Passwordstate web server. The protocols and cipher suites available will depend on the Windows Server, IIS and operating system configuration used within the customer environment.
Passwordstate can restrict database access to approved Passwordstate web servers. This helps prevent an unauthorized copy of the application from being connected directly to an existing Passwordstate database.
Passwordstate provides controls for protecting, rotating and recovering the encryption material required to access stored credential data.
Passwordstate uses two installation-specific encryption keys that are divided into separate secret components and stored across the Passwordstate web application and database. Access to only one storage location is therefore insufficient to reconstruct the complete encryption keys.
Authorized administrators can rotate Passwordstate encryption keys when required. Protected data is re-encrypted using the replacement keys, and the key rotation activity is recorded within Passwordstate's auditing system.
Encryption key material can be exported in split-secret form to a password-protected archive for secure external retention. This can provide an additional recovery option alongside regular backups of the Passwordstate application files and database.
Passwordstate can be configured to use supported FIPS-compatible cryptographic functionality for organizations whose Windows environments require FIPS-related security policy settings.
Passwordstate includes configurable controls for protecting scripts, configuration data, authentication sessions and credentials during everyday use.
Built-in and custom PowerShell scripts used by Passwordstate are stored encrypted within the database. This helps protect automation used for password resets, account discovery, backups and password validation.
Sensitive configuration values within the Passwordstate web.config file, including database connection information and encryption key components, can be encrypted using supported ASP.NET configuration protection.
Passwordstate supports Integrated Windows Authentication, including Windows passthrough authentication for single sign-on and domain credential authentication combined with supported multi-factor authentication options.
Configurable failed-login controls can detect repeated authentication failures and temporarily restrict further attempts against the Passwordstate web interface and mobile application.
Passwordstate can automatically hide displayed passwords and clear copied password values from the clipboard after a configurable period, helping reduce accidental exposure.
Administrators can define automatic logout periods for inactive sessions, including different timeout settings for users accessing Passwordstate from internal and external locations.
Product security is supported by secure development, vulnerability testing and software signing practices used throughout the Passwordstate development and release process.
Click Studios applies secure development practices informed by OWASP guidance to help identify and mitigate common web application risks, including injection, cross-site scripting and access control weaknesses.
Click Studios performs regular penetration testing covering relevant Passwordstate application and infrastructure components. Customers can also conduct testing within their own licensed environments to assess deployment-specific security requirements.
Download a fully functional 30-day trial and evaluate Passwordstate's encryption, data integrity and application security controls within your own environment.