Defense in depth
Layered controls span authentication, authorization, encryption, audit logging and tenant isolation. Sensitive operations such as reveal and copy always pass through authenticated, authorized API endpoints.
Trust center
passwhy is designed for teams that must explain who accessed what, when and why—without deploying full privileged access management.
Layered controls span authentication, authorization, encryption, audit logging and tenant isolation. Sensitive operations such as reveal and copy always pass through authenticated, authorized API endpoints.
Organizations can require MFA for vault access. Personal and business workspaces support TOTP-based second factors to reduce account takeover risk.
SSO integration is available on business and enterprise plans, allowing organizations to align vault access with existing identity providers and offboarding workflows.
Every API request is scoped to an organization identifier. Partner and MSP workspaces add customer-level boundaries so technicians only access provisioned client tenants.
Sensitive operations such as secret reveal and vault export can require approver consent. Periodic access review campaigns certify ongoing need for shared credentials and vault access.
Automation uses scoped personal access tokens and organization API keys—not shared passwords. Outbound webhooks sign payloads so receivers can verify event authenticity.
Certificates, PEM/PFX material and VPN configs stored in the secure file vault are encrypted at rest. Every download is authenticated and audited.
Organization owners configure roles, vault permissions, access request policies and retention settings. Platform administrators operate in a separate admin boundary with its own audit trail.
Emergency and break-glass access uses approval workflows, time limits and full audit coverage—so recovery never bypasses governance.
Report security issues to contact@passwhy.com. We acknowledge reports promptly and coordinate disclosure with researchers.
Start a free trial or log in to review vaults, MFA and audit logs with your team.
Contact our security team for compliance mapping, DPAs and architecture reviews.