Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
30 criteria
baselineWhat is the encryption architecture — is it end-to-end/zero-knowledge (vault decryptable only client-side), and has this been validated by a named third-party security audit with a published report?
baselineDescribe the vendor's own security incident history and response — for any past breaches or vault-exposure incidents in this product category, what architectural changes were made, and how would your architecture limit blast radius if your infrastructure were compromised?
baselineWhat SSO/SCIM integration exists for enterprise deployment — automated provisioning/deprovisioning, group-based vault/collection access, and what happens to a departing employee's vault items?
baselineHow does secure sharing work — item/collection-level sharing with granular permissions (view vs. edit vs. share), external/guest sharing, and a full audit trail of who accessed what and when?
baselineDetail passkey support — can the product store and sync passkeys across platforms, act as a passkey provider on iOS/Android/browsers, and what is the migration path as passwords decline?
baselineWhat breach/exposure monitoring is included — checking stored credentials against known breach corpora, weak/reused password reporting, and automated user nudges to rotate?
baselineExplain emergency access and account recovery — what happens when a user loses all devices and their master password, and how does the recovery path avoid becoming the weakest link in the zero-knowledge model?
baselineWhat offline access and platform coverage exists (desktop apps, browsers, mobile, CLI for developers), and does functionality degrade on any platform?
baselineWhat is the pricing model, and does it differ meaningfully between an individual/family tier and the enterprise tier — is a personal/family license bundled with enterprise seats as an employee-retention perk, and at what incremental cost?
baselineDetail admin/IT visibility and reporting — can IT see an org-wide password-hygiene dashboard (weak/reused/breached password counts, MFA adoption) without breaking the product's own zero-knowledge encryption model for individual vault contents?
baselineDoes the platform support privileged/shared-account credential management for business use cases (shared service-account passwords, team-shared credentials) distinct from individual employee password vaults, or is that entirely out of scope requiring a separate PAM product?
baselineWhat is the business-continuity plan if the vendor's own infrastructure has an outage — can employees still access their vaults (e.g., via a cached local copy), or does an outage fully lock out the workforce from all their credentials?
baselineWhat compliance certifications does the platform hold (SOC 2 Type II, ISO 27001) given the extreme sensitivity of what it stores, and can the customer request the actual audit report rather than accepting a compliance-badge claim?
baselineWhat migration tooling exists for moving from a competing password manager (bulk import preserving folder structure/sharing permissions, not just a flat CSV dump), and what is a customer-referenced migration timeline for a large organization?
baselineBeyond passwords, what secure-document/note storage capability exists (e.g., storing sensitive files, software licenses, secure notes), and does this share the same zero-knowledge encryption guarantees as password storage?
baselineDetail rollout/adoption support for a large workforce — self-service enrollment, bulk provisioning via SCIM, and a customer-referenced measured adoption rate (percentage of employees actively using the tool, not just provisioned) after a defined rollout period.
baselineEvaluate password resilience across enterprise authentication systems (e.g., Microsoft AD, cloud identity platforms, critical directories) to identify weak or reused credentials and provide actionable remediation without disrupting operations.
baselineDocument Rules of Engagement for the annual password strength assessment.
baselineProvide an example of a past password strength assessment report (anonymized) showing both executive and technical findings.
baselineProvide a methodology description for the password assessment (tools, hash types, and recovery techniques).
baselineProvide credentials of staff conducting the password assessment work (e.g., CISSP, OSCP).
baselineProvide two or more client references for similar password assessment engagements.
baselineDocument chain of custody: how password data is accessed, transferred, stored, and protected end-to-end.
baselineProvide certified disposal of all password data and recovered credentials, with a written certificate of destruction, immediately after reporting.
baselineProvide an executive and technical report showing percentage of weak/recoverable credentials, estimated recovery times, and risk summary.
baselineProvide remediation recommendations from the password assessment (e.g., password policy changes, MFA enforcement, privileged account hardening).
baselineProvide an option for retest to confirm password remediation fixes are effective.
baselineWhat is the process for handling password resets?
baselineRespond to evaluation criteria categories: Pricing, Workflow and Access, Deployment and Administration, Identity and Entitlements, Fulfillment and Connectors, Dynamic Password Administration and Management, and Vendor Information and Higher Education Experience.
baselineProvide self-service password reset allowing end users to unlock/reset password after proving identity ownership via alternate email, security questions, or pre-registered MFA options.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat is the encryption architecture — is it end-to-end/zero-knowledge (vault decryptable only client-side), and has this been validated by a named third-party security audit with a published report?Answer key — what a strong answer shows
Zero-knowledge architecture with a named, dated, published audit is table stakes — vendors unable to produce the actual report (not just 'we're audited') should be treated cautiously given breach history in this category.
RFPDescribe the vendor's own security incident history and response — for any past breaches or vault-exposure incidents in this product category, what architectural changes were made, and how would your architecture limit blast radius if your infrastructure were compromised?Answer key — what a strong answer shows
This category has had major real breaches; a credible vendor addresses the risk directly with architectural specifics (zero-knowledge limits, KDF iteration hardening) rather than deflecting.
RFIWhat SSO/SCIM integration exists for enterprise deployment — automated provisioning/deprovisioning, group-based vault/collection access, and what happens to a departing employee's vault items?Answer key — what a strong answer shows
Look for SCIM-driven lifecycle including a defined offboarding flow (item transfer/recovery by admins under policy) — orphaned vaults on departure are a real operational failure mode.
RFIHow does secure sharing work — item/collection-level sharing with granular permissions (view vs. edit vs. share), external/guest sharing, and a full audit trail of who accessed what and when?Answer key — what a strong answer shows
Look for cryptographically-enforced sharing (re-encryption per recipient) with real audit events, not vault-password sharing workarounds.
RFPDetail passkey support — can the product store and sync passkeys across platforms, act as a passkey provider on iOS/Android/browsers, and what is the migration path as passwords decline?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Passkey provider capability (not just storage) across all major platforms is the forward-looking requirement; a password-only product is buying into a shrinking category.
RFIWhat breach/exposure monitoring is included — checking stored credentials against known breach corpora, weak/reused password reporting, and automated user nudges to rotate?Answer key — what a strong answer shows
Look for continuous monitoring with per-user actionable reporting and admin-visible security scores, not a one-time import check.
RFPExplain emergency access and account recovery — what happens when a user loses all devices and their master password, and how does the recovery path avoid becoming the weakest link in the zero-knowledge model?Answer key — what a strong answer shows
Recovery must be explicit about tradeoffs (recovery keys, admin-held escrow under policy, or genuinely unrecoverable) — a too-easy recovery path silently breaks the zero-knowledge promise.
RFIWhat offline access and platform coverage exists (desktop apps, browsers, mobile, CLI for developers), and does functionality degrade on any platform?Answer key — what a strong answer shows
Look for full offline vault access and per-platform feature parity — CLI/API access matters for developer adoption, offline for travel/incident scenarios.
RFIWhat is the pricing model, and does it differ meaningfully between an individual/family tier and the enterprise tier — is a personal/family license bundled with enterprise seats as an employee-retention perk, and at what incremental cost?Answer key — what a strong answer shows
A bundled personal/family tier is a common, real differentiator for enterprise password-manager deals — ask explicitly whether it's included and at what cost.
RFPDetail admin/IT visibility and reporting — can IT see an org-wide password-hygiene dashboard (weak/reused/breached password counts, MFA adoption) without breaking the product's own zero-knowledge encryption model for individual vault contents?Answer key — what a strong answer shows
Look for a real answer on how aggregate hygiene reporting is reconciled with a genuine zero-knowledge architecture — these two goals are in real tension and a vendor should explain the actual mechanism, not just claim both.
RFIDoes the platform support privileged/shared-account credential management for business use cases (shared service-account passwords, team-shared credentials) distinct from individual employee password vaults, or is that entirely out of scope requiring a separate PAM product?Answer key — what a strong answer shows
Shared/privileged credential management is a distinct use case from individual password vaults — a vendor should clarify this scope boundary explicitly.
RFPWhat is the business-continuity plan if the vendor's own infrastructure has an outage — can employees still access their vaults (e.g., via a cached local copy), or does an outage fully lock out the workforce from all their credentials?Answer key — what a strong answer shows
A password manager outage that fully locks users out of every credential is an unusually severe availability failure mode — ask for a specific offline/cached-access fallback, not just an uptime SLA number.
RFIWhat compliance certifications does the platform hold (SOC 2 Type II, ISO 27001) given the extreme sensitivity of what it stores, and can the customer request the actual audit report rather than accepting a compliance-badge claim?Answer key — what a strong answer shows
Given this product stores the literal keys to every other system, insist on the real audit report — a compliance-badge claim without the underlying report is insufficient evidence for a product this sensitive.
RFIWhat migration tooling exists for moving from a competing password manager (bulk import preserving folder structure/sharing permissions, not just a flat CSV dump), and what is a customer-referenced migration timeline for a large organization?Answer key — what a strong answer shows
A flat CSV import that loses folder structure and sharing permissions creates real migration friction — ask for a concrete example of a structure-preserving migration and a real customer timeline.
RFPBeyond passwords, what secure-document/note storage capability exists (e.g., storing sensitive files, software licenses, secure notes), and does this share the same zero-knowledge encryption guarantees as password storage?Answer key — what a strong answer shows
Secure document storage is a common adjacent use case — confirm it carries the same encryption guarantees as core password storage, not a weaker tier.
RFIDetail rollout/adoption support for a large workforce — self-service enrollment, bulk provisioning via SCIM, and a customer-referenced measured adoption rate (percentage of employees actively using the tool, not just provisioned) after a defined rollout period.Answer key — what a strong answer shows
Provisioning a license doesn't guarantee real adoption — ask for an actual usage/adoption figure from a customer reference, not just a provisioning count, since unused licenses provide zero security benefit.
RFPEvaluate password resilience across enterprise authentication systems (e.g., Microsoft AD, cloud identity platforms, critical directories) to identify weak or reused credentials and provide actionable remediation without disrupting operations.
RFPDocument Rules of Engagement for the annual password strength assessment.
RFPProvide an example of a past password strength assessment report (anonymized) showing both executive and technical findings.
RFPProvide a methodology description for the password assessment (tools, hash types, and recovery techniques).
RFPProvide credentials of staff conducting the password assessment work (e.g., CISSP, OSCP).
RFPProvide two or more client references for similar password assessment engagements.
RFPDocument chain of custody: how password data is accessed, transferred, stored, and protected end-to-end.
RFPProvide certified disposal of all password data and recovered credentials, with a written certificate of destruction, immediately after reporting.
RFPProvide an executive and technical report showing percentage of weak/recoverable credentials, estimated recovery times, and risk summary.
RFPProvide remediation recommendations from the password assessment (e.g., password policy changes, MFA enforcement, privileged account hardening).
RFPProvide an option for retest to confirm password remediation fixes are effective.
RFPWhat is the process for handling password resets?
RFPRespond to evaluation criteria categories: Pricing, Workflow and Access, Deployment and Administration, Identity and Entitlements, Fulfillment and Connectors, Dynamic Password Administration and Management, and Vendor Information and Higher Education Experience.
RFPProvide self-service password reset allowing end users to unlock/reset password after proving identity ownership via alternate email, security questions, or pre-registered MFA options.