NewGoverned credential, secrets and access management—multi-tenant platform for businesses and MSPs.

Start Free

Trust center

Security architecture for governed credential access

passwhy is designed for teams that must explain who accessed what, when and why—without deploying full privileged access management.

Defense in depth

Layered controls span authentication, authorization, encryption, audit logging and tenant isolation. Sensitive operations such as reveal and copy always pass through authenticated, authorized API endpoints.

Multi-factor authentication

Organizations can require MFA for vault access. Personal and business workspaces support TOTP-based second factors to reduce account takeover risk.

Single sign-on

SSO integration is available on business and enterprise plans, allowing organizations to align vault access with existing identity providers and offboarding workflows.

Tenant isolation

Every API request is scoped to an organization identifier. Partner and MSP workspaces add customer-level boundaries so technicians only access provisioned client tenants.

Approvals and access reviews

Sensitive operations such as secret reveal and vault export can require approver consent. Periodic access review campaigns certify ongoing need for shared credentials and vault access.

API scopes and webhook signing

Automation uses scoped personal access tokens and organization API keys—not shared passwords. Outbound webhooks sign payloads so receivers can verify event authenticity.

Encrypted secure files

Certificates, PEM/PFX material and VPN configs stored in the secure file vault are encrypted at rest. Every download is authenticated and audited.

Admin controls

Organization owners configure roles, vault permissions, access request policies and retention settings. Platform administrators operate in a separate admin boundary with its own audit trail.

Recovery access controls

Emergency and break-glass access uses approval workflows, time limits and full audit coverage—so recovery never bypasses governance.

Responsible disclosure

Report security issues to contact@passwhy.com. We acknowledge reports promptly and coordinate disclosure with researchers.

Evaluate passwhy in your own workspace

Start a free trial or log in to review vaults, MFA and audit logs with your team.

Security questionnaire or DPA?

Contact our security team for compliance mapping, DPAs and architecture reviews.