Multi level encryption starting with a client side encryption layer, allowing true end to end encryption for password sharing, followed by SSL and storage encryption.
Transparent public audit possibilities of the complete code. Security comes from proper encryption and not from hiding security flaws.
A self hosted credential manager allows you to host the server on your own and grants you even greater access control capabilities. It also elimates the need to rely on public services for your data.
before the data leaves your device
of the server's key
with TLS 1.2 and Salsa20
of all login forms
of all sensitive information
gets handled automatically
across all devices
securely between users
with support for Yubikey, Duo, TOTP, e.g.Google Authenticator and Fido's webauthn / passkey
for websites and applications
for random passwords similar, to our online password generator
to audit your passwords, age, complexity and length
to store other information
as a cherry on top
adds old passwords on the fly
for all stored secrets
allows usage for normal applications too
for Chrome passwords and other password manager
of users and shares for RBAC
Possibility to limit rights on shares.
allowing to encrypt and decrypt PGP messages.
allows to encrypt and decrypt gmail, outlook.com and yahoo mails
access your passwords even offline
allow the integration of passwords in build pipelines or startup scripts.
fire callbacks to specific urls whenever a secret changes in order to trigger automated actions e.g. restart XYZ
solve the digital legacy problem in case of emergencies or decease.
Old versions of secrets (e.g. passwords) are stored and are accessible in the history
Psono has been translated in a lot of different languages.
With client side file encryption
All components allow to be setuped for HA
Scriptable integration of secrets into your infrastructure
IP based routing allow site affine storage access, remote office setups or cloud hybrid setup
Share secrets and files via link with others, even if they don't have an account
Supporting local storage, GCP, AWS, Azure... for client side encrypted files
Detects if a password has been part of a known breach
Authenticate against your company's LDAP Server, SAML or OIDC IDP. Change passwords, manage email addresses and deactivate users in a central place.
Compliancy and auditing capabilities are one of the security pillars of your company? Then you will love this feature, allowing you to trace every single REST call.
Enforce rules on your users to e.g. ensure two factor authentication or disable features like for example export, emergency- or recovery-codes.