PROXYTEC Software · Self-HostedDeutsch

Passwords don’t belong
in e-mails.

And confidential files even less so.

Password Vault is self-hosted software that lets you hand over credentials and sensitive files to your customers securely – such as Excel sheets with company figures, contracts or ID scans. Encrypted, traceable and automatically deleted after retrieval. Instead of plain-text e-mail or spelling things out on the phone.

PasswordsExcel & company figuresContractsID scansConfiguration files
Free for 30 daysNo credit card requiredUp and running in 15 minutesBy PROXYTEC – IT systems house for 25+ years

From €14.99/month · one licence per company, unlimited customers & employees · self-hosted, GDPR-compliant

Password Vault dashboard: overview with customers, employees and pending shares

The daily problem of handing over credentials

As an IT service provider you constantly pass on passwords and files: new workstations, VPN access, Microsoft 365 accounts, server passwords, configuration files. The usual ways are all problematic – and this is by no means limited to IT.

Plain text by e-mail

Passwords in the body of an e-mail travel unencrypted, end up in several mailboxes and stay there for years – a real GDPR risk.

Spelled out on the phone

Read out character by character: error-prone, time-consuming and completely undocumented. For complex passwords and files it is no option at all.

No proof

Who received which credentials, and when? With e-mail and phone there is no way to prove it afterwards – a problem for enquiries and audits.

Not just IT – many industries hand over business-critical data every day:

IT service providers

Credentials, VPN and server passwords and configuration files for their customers.

Tax advisors & accounting

Payroll statements, accounting-system access and Excel sheets with financial figures for their clients.

HR departments

Salary lists, ID scans and login details for new employees – often bundled in a single Excel file.

Important: Password Vault is not a password manager

The name invites confusion, so let us be clear: this is not about permanently storing your own passwords, but about the one-time, secure transfer to a third party.

A password manager …

… is a vault for permanently storing your own credentials (e.g. KeePass, Bitwarden, 1Password). The passwords stay there so that you can access them at any time. Handing them to third parties is not its purpose.

Password Vault …

… is a secure hand-over channel: you place credentials and files ready for a specific recipient, who retrieves them once – after which they are automatically and irrevocably deleted. Not a permanent store, but a secure transport route with proof.

How Password Vault works – step by step

From inviting the customer to the secure retrieval: the animation shows the complete path of the data between you, your server and your customer’s employee. It runs on its own – click the dots to jump to a step, or pause to study one.

LIVE WORKFLOW
Step 1 · Create & invite
Create the customer and invite the employee

You create the customer and their employee. The employee receives an e-mail with a one-time invitation link that is valid for only 72 hours. This invitation contains no credentials yet – only the way to create the account.

Step 2 · Set up access
The employee sets up their own safe

Via the link the employee defines three things that only they know: their password, their two-factor authentication (authenticator app) and their personal secret name. From now on their personal safe is protected – not by a link, but by a real login.

Step 3 · Share
Share credentials and files

You bundle any number of passwords and files into one share. It is stored AES-256-GCM encrypted on your own server – the key never leaves your premises. The employee only receives a notification that something is waiting.

Step 4 · Retrieve & delete
Retrieve securely, then delete automatically

Only after password, two-factor code and secret name are the data shown decrypted. Afterwards they are automatically and irrevocably deleted. You receive a retrieval confirmation, and every step is recorded in the audit log with a timestamp.

Why not just share a link?

Classic password managers such as 1Password can share passwords too – usually via a share link. And that is exactly where the crucial security difference lies: a link is only as secure as the channel it is sent through.

The scenario: the recipient’s mailbox is already hacked

An attacker is quietly reading your customer’s e-mail. With a share link that is already enough: they open the link before the employee does and have the password. With Password Vault they only find a notification with no content – to retrieve anything they would additionally need the employee’s personal password, their two-factor device and the secret name. The stolen e-mail access alone is not enough. And if the attacker opens the share anyway, the deletion timer starts – and you see the unauthorised retrieval in the audit log.

What makes Password Vault unique

There is no known product with exactly this workflow. It is the combination of these points – not any single feature – that defines Password Vault.

Identified hand-over

The data goes to a specific, logged-in person – not to an anonymous link. Triple protection including a personal secret name, unusual on the market.

Proof included

Automatic deletion after viewing, plus a retrieval confirmation and a complete audit log – your proof towards the customer.

Fully self-hosted

All data and the key stay on your server. Full data sovereignty and a strong GDPR argument towards your customers.

White-label & bilingual

Your logo and company name in e-mails and login pages. The complete application and all e-mails switch between English and German at the click of a button.

15 minutes, updates by click

Installation via a script in a quarter of an hour, later updates through the interface – with an automatic backup beforehand.

Flat licence per company

One price per installation instead of per-user costs – unlimited customers and employees, predictable and cheap to run.

Compared with one-time link tools

Password Pusher, One-Time Secret, Bitwarden Send, etc.

These create anonymous throwaway links: nobody knows who really opened them, there is no customer or employee context, no retrieval confirmation and no branding – and a link can be forwarded. Password Vault hands over to an identified person with retrieval proof for your records.

Compared with MSP password managers

1Password, Bitwarden, Keeper, Passportal (MSP editions)

These manage passwords internally at the provider; to share, your customer would have to use the same manager – with cloud, per-user subscription and onboarding effort. With Password Vault your customer needs no new software and no subscription – only their safe link, their password and their phone.

A look inside the software

A tidy interface, available in English or German – for you as the provider and for your customers’ employees. Click a screenshot to enlarge it.

Dashboard

Everything important at a glance

The overview shows your customers, employees and all shares still awaiting retrieval – including the expiry date. On the right you see the latest activity from the audit log in real time.

Overview page with key figures, pending shares and activity log
Create a share

Bundle credentials and files

Per share you combine several credentials, files and an optional message. Title, username, URL and note are provided; the password is created on demand by the built-in generator.

Form for creating a new share with credentials and password generator
Security on retrieval

The secret name as the third hurdle

Before the employee sees the data, they enter their personal secret name. A clear notice makes it plain: opening it starts the deletion timer – the data are then available only once.

Retrieval page with secret-name field and notice about automatic deletion
Operation & licence

Updates, backups and licence via the interface

Backups run automatically every day and can be downloaded at any time. Updates are applied through the interface – with an automatic backup beforehand. You enter the licence key under Settings.

Settings area for automatic backups and restore

The difference from previous methods

A password manager solves storage – but not the secure hand-over to a customer. The direct comparison shows where Password Vault comes in.

Criterion E-mail / phone Classic password manager Password Vault
PurposeCommunicationPermanently store your own passwordsOne-time secure hand-over to third parties
Encryption of the transferusually nonenot designed for itAES-256-GCM end to end in the system
Automatic deletionno – stays in the mailboxno – stays in the vaultYes, after retrieval or expiry
Recipient needs account / softwarenoyes, the same managerJust a browser
Files transferable toolimited, insecureusually noYes, up to 500 MB per share
Proof / audit lognonoYes, every retrieval documented
Data sovereigntythe providers’ mailboxesoften the vendor cloudSelf-hosted on your server

Triple protection before every first viewing

Before credentials become visible, three independent hurdles must be cleared. Even a compromised mailbox is not enough.

1. Password

A personal account password, hashed server-side with Argon2id – never stored in plain text.

2. Two-factor code

TOTP is mandatory for all accounts via an authenticator app. No access without the time-based code.

3. Secret name

A personal secret word known only to the employee – the final hurdle right before the first viewing.

Feature set

From encryption through customer management to branding – Password Vault is built for everyday use in the IT services business.

Security

  • AES-256-GCM for passwords, messages and files; the key stays only on your server
  • Argon2id hashing, mandatory TOTP two-factor for all accounts
  • Personal secret name as a third hurdle
  • Brute-force protection, server-side sessions, HTTPS with Let’s Encrypt
  • Complete audit log with timestamp and IP

Administration

  • Customer and employee management with an invitation workflow (one-time link, 72 h)
  • User roles: administrators and restricted users
  • Groups with view permissions per share
  • Password generator, several credentials and files per share
  • Optional, encrypted message to the recipient

Convenience & operation

  • Your own branding: your logo and company name in e-mails and login pages
  • E-mail delivery via your own SMTP, Microsoft 365 or Google Workspace
  • Updates through the interface with an automatic backup beforehand
  • Daily backups, downloadable at any time; restore with one click
  • Clear settings; the entire application – including customer-facing pages and e-mails – in English or German

Technical requirements

Password Vault runs on any Linux system you like – your own on-site server, a spare PC or mini-PC, or a low-cost VPS. Installation is done via a supplied script in about 15 minutes.

Your own server, PC or VPS

A Linux system (Debian 12/13 or Ubuntu 22.04/24.04), from 1 vCPU and 2 GB RAM (4 GB recommended), 20 GB SSD. This can be your own on-site hardware or a low-cost VPS from about €5/month.

A (sub)domain

One A record pointing to the server – e.g. vault.your-company.com. The HTTPS certificate is set up automatically.

An e-mail mailbox

For sending notifications – via SMTP, Microsoft 365 or Google Workspace.

15-minute setup

One command (sudo bash install.sh) asks only for the domain. Docker, firewall, HTTPS and backups are set up automatically.

What is a VPS – and do I need one?

A VPS (Virtual Private Server) is a rented virtual server at a hosting provider – from about €5/month and exclusively yours. It is handy when you have no hardware of your own. But it is not required: Password Vault runs just as well on-premises on your own server in-house, or even on a spare computer or mini-PC that stays switched on. All you need is a Linux system (Debian/Ubuntu) with the resources listed above – the software and your data sovereignty are identical either way.

Self-hosted = full data sovereignty: all data stay exclusively on your own server. Nothing is transmitted to PROXYTEC or third parties – a strong argument towards your customers and for GDPR.

What you get when you buy

A clear scope of delivery with no hidden add-on modules – and a fair licensing model: one licence per company, not per user and not per customer.

One licence per company – no user or customer limit

You pay once per installation in your company – and with it you serve any number of customers, employees and internal users. No per-account tiers, no billing by customer count. The price stays predictable, no matter how heavily you use Password Vault.

The complete software

The full Password Vault package to install on your own server – self-hosted, full data sovereignty.

Unlimited users & customers

Create as many customers, employees and administrators as you need – with no per-account surcharge.

All features included

Encryption, 2FA, audit log, groups, branding, backups – no add-on fees or locked features.

Updates during the term

Apply new versions conveniently through the interface – with an automatic backup beforehand.

Installation & user guide

Illustrated PDF guides for setup and daily operation, in English and German – available to download immediately.

Your own branding

Your logo and company name appear in all e-mails and on your customers’ login pages.

30-day trial first

Before buying you can test the software for 30 days at full scope – entirely without risk.

Support

Reach us directly with any questions – optionally with paid installation or VPS support.

Full data sovereignty (GDPR)

All data stay on your server. Nothing is sent to PROXYTEC or third parties – a strong GDPR argument.

Pays off from the first month

A single credential handed over insecurely can get expensive. Weigh the risk against the price of a licence – the maths is clear.

The insecure way costs

  • Data breaches can lead to substantial GDPR fines
  • Passwords sit uncontrolled in other people’s mailboxes for years
  • Time lost every day to phone calls, spelling out, follow-ups
  • Loss of customer trust after a security incident
versus

Password Vault costs

  • Encrypted hand-over with automatic deletion and complete proof
  • Unlimited customers and employees – a single licence
  • Minutes instead of hours per hand-over
  • You visibly come across as professional and privacy-conscious
from €14.99/monthone licence per company · less than a coffee per working day

Try, install, license

Download the package and test Password Vault for 30 days at full scope – no registration and no payment details. Then: from €14.99/month, one licence per company with unlimited customers and employees.

Try free for 30 days

The complete version, no feature limits. After 30 days the software switches to a locked mode – no data are lost.

  • Complete feature set
  • No registration, no payment details
  • Installed in about 15 minutes

No risk. 30 days at full scope, no payment details, no automatic subscription. After the trial you decide at your own pace – no data is lost.

Download (version 1.1.0)
LICENCE

Buy a licence

A licence is valid per company and installation – with unlimited users, employees and customers. Choose a 12 or 24-month term. After purchase you receive the key by e-mail and enter it under Settings → Licence.

  • Per company – not per user or customer
  • Unlimited users, employees and customers
  • Term of 12 or 24 months
  • Licence key by e-mail
12 months
€239net
= €19.99/month
Save 25%
24 months
€359net
= €14.99/month

One-time payment per term – no subscription debit. The software reminds you 30 days before expiry; renewal is a new licence purchase. All prices plus VAT.

The online shop will open shortly; until then you can order the licence directly from us.

No time or no server? We set it up.

You would rather not deal with installation and servers yourself? For an additional fee we handle the installation and setup on your server – and, if you wish, help you choose and set up a suitable VPS. Get in touch at support@proxytec.de – we will make you an offer.

Frequently asked questions

No. A password manager stores your own passwords permanently so you can access them. Password Vault is for the one-time, secure transfer of credentials and files to a recipient – with automatic deletion after retrieval. The two complement each other but do not replace one another.

Exclusively on your own server. Password Vault is self-hosted – the encryption key is held only by you, and no data is transmitted to PROXYTEC or third parties. That is a central GDPR argument towards your customers.

No. Your customer’s employee only needs a browser and an authenticator app for the two-factor code. On first access they set up their password, secret name and 2FA themselves via an invitation link.

After installation the software runs for 30 days at full scope – without registration or payment details. It then switches to a locked mode: no data is lost and admin read access remains. Enter a licence key to unlock it again.

No problem. For an additional fee we handle the installation and setup on your server, or help you choose and set up a suitable VPS. Get in touch – we will make you an offer.

Passwords, messages and files are encrypted with AES-256-GCM; the key stays only on your server. Accounts are protected by Argon2id hashing, mandatory TOTP two-factor and the personal secret name. Every access is logged in the audit log with a timestamp and IP.

The licence is per company and installation – not per user and not per customer served. You can create any number of customers, employees and internal users without the price changing. You only choose the term (12 or 24 months).

A VPS is only a convenient option, not a must. Password Vault runs just as well on-premises on your own in-house server, or on a spare computer or mini-PC that stays switched on. All you need is a Linux system (Debian/Ubuntu) with the minimum resources listed and a reachable (sub)domain. Whether on your own hardware or a VPS – the software and your data sovereignty stay the same.

Disclaimer

Password Vault is a software solution developed by PROXYTEC, provided for installation and operation on infrastructure supplied or managed by the customer (their own server or VPS). As the customer operates the software on their own or self-managed server or VPS, they are responsible for securing it – in particular operating-system and security updates, firewall and access protection, the use of strong credentials, as well as setup, secure operation, applying software updates and regular backups.

The software is provided in the version supplied. No fitness for a purpose beyond the service description, no uninterrupted availability and no absolute security against unauthorised access are warranted.

PROXYTEC’s liability – on any legal ground – is excluded to the extent permitted by law. This does not affect liability for intent and gross negligence, for damage arising from injury to life, body or health, under the German Product Liability Act, or for the breach of essential contractual obligations. Our General Terms and Conditions (in particular sections 3 and 9, German) and the legal notice apply in addition. The German version of these terms is legally binding.

Hand over passwords securely – starting today

Test Password Vault free for 30 days – no payment details, no risk. Or let us handle the entire setup. You are up and running in 15 minutes.

Password Vault – from €14.99/monthOne licence per company, unlimited customers & employees · free 30-day trial