And confidential files even less so.
Password Vault is self-hosted software that lets you hand over credentials and sensitive files to your customers securely – such as Excel sheets with company figures, contracts or ID scans. Encrypted, traceable and automatically deleted after retrieval. Instead of plain-text e-mail or spelling things out on the phone.
From €14.99/month · one licence per company, unlimited customers & employees · self-hosted, GDPR-compliant
As an IT service provider you constantly pass on passwords and files: new workstations, VPN access, Microsoft 365 accounts, server passwords, configuration files. The usual ways are all problematic – and this is by no means limited to IT.
Passwords in the body of an e-mail travel unencrypted, end up in several mailboxes and stay there for years – a real GDPR risk.
Read out character by character: error-prone, time-consuming and completely undocumented. For complex passwords and files it is no option at all.
Who received which credentials, and when? With e-mail and phone there is no way to prove it afterwards – a problem for enquiries and audits.
Not just IT – many industries hand over business-critical data every day:
Credentials, VPN and server passwords and configuration files for their customers.
Payroll statements, accounting-system access and Excel sheets with financial figures for their clients.
Salary lists, ID scans and login details for new employees – often bundled in a single Excel file.
The name invites confusion, so let us be clear: this is not about permanently storing your own passwords, but about the one-time, secure transfer to a third party.
… is a vault for permanently storing your own credentials (e.g. KeePass, Bitwarden, 1Password). The passwords stay there so that you can access them at any time. Handing them to third parties is not its purpose.
… is a secure hand-over channel: you place credentials and files ready for a specific recipient, who retrieves them once – after which they are automatically and irrevocably deleted. Not a permanent store, but a secure transport route with proof.
From inviting the customer to the secure retrieval: the animation shows the complete path of the data between you, your server and your customer’s employee. It runs on its own – click the dots to jump to a step, or pause to study one.
You create the customer and their employee. The employee receives an e-mail with a one-time invitation link that is valid for only 72 hours. This invitation contains no credentials yet – only the way to create the account.
Via the link the employee defines three things that only they know: their password, their two-factor authentication (authenticator app) and their personal secret name. From now on their personal safe is protected – not by a link, but by a real login.
You bundle any number of passwords and files into one share. It is stored AES-256-GCM encrypted on your own server – the key never leaves your premises. The employee only receives a notification that something is waiting.
Only after password, two-factor code and secret name are the data shown decrypted. Afterwards they are automatically and irrevocably deleted. You receive a retrieval confirmation, and every step is recorded in the audit log with a timestamp.
Classic password managers such as 1Password can share passwords too – usually via a share link. And that is exactly where the crucial security difference lies: a link is only as secure as the channel it is sent through.
An attacker is quietly reading your customer’s e-mail. With a share link that is already enough: they open the link before the employee does and have the password. With Password Vault they only find a notification with no content – to retrieve anything they would additionally need the employee’s personal password, their two-factor device and the secret name. The stolen e-mail access alone is not enough. And if the attacker opens the share anyway, the deletion timer starts – and you see the unauthorised retrieval in the audit log.
There is no known product with exactly this workflow. It is the combination of these points – not any single feature – that defines Password Vault.
The data goes to a specific, logged-in person – not to an anonymous link. Triple protection including a personal secret name, unusual on the market.
Automatic deletion after viewing, plus a retrieval confirmation and a complete audit log – your proof towards the customer.
All data and the key stay on your server. Full data sovereignty and a strong GDPR argument towards your customers.
Your logo and company name in e-mails and login pages. The complete application and all e-mails switch between English and German at the click of a button.
Installation via a script in a quarter of an hour, later updates through the interface – with an automatic backup beforehand.
One price per installation instead of per-user costs – unlimited customers and employees, predictable and cheap to run.
These create anonymous throwaway links: nobody knows who really opened them, there is no customer or employee context, no retrieval confirmation and no branding – and a link can be forwarded. Password Vault hands over to an identified person with retrieval proof for your records.
These manage passwords internally at the provider; to share, your customer would have to use the same manager – with cloud, per-user subscription and onboarding effort. With Password Vault your customer needs no new software and no subscription – only their safe link, their password and their phone.
A tidy interface, available in English or German – for you as the provider and for your customers’ employees. Click a screenshot to enlarge it.
The overview shows your customers, employees and all shares still awaiting retrieval – including the expiry date. On the right you see the latest activity from the audit log in real time.

Per share you combine several credentials, files and an optional message. Title, username, URL and note are provided; the password is created on demand by the built-in generator.

Before the employee sees the data, they enter their personal secret name. A clear notice makes it plain: opening it starts the deletion timer – the data are then available only once.

Backups run automatically every day and can be downloaded at any time. Updates are applied through the interface – with an automatic backup beforehand. You enter the licence key under Settings.

A password manager solves storage – but not the secure hand-over to a customer. The direct comparison shows where Password Vault comes in.
| Criterion | E-mail / phone | Classic password manager | Password Vault |
|---|---|---|---|
| Purpose | Communication | Permanently store your own passwords | One-time secure hand-over to third parties |
| Encryption of the transfer | usually none | not designed for it | AES-256-GCM end to end in the system |
| Automatic deletion | no – stays in the mailbox | no – stays in the vault | Yes, after retrieval or expiry |
| Recipient needs account / software | no | yes, the same manager | Just a browser |
| Files transferable too | limited, insecure | usually no | Yes, up to 500 MB per share |
| Proof / audit log | no | no | Yes, every retrieval documented |
| Data sovereignty | the providers’ mailboxes | often the vendor cloud | Self-hosted on your server |
Before credentials become visible, three independent hurdles must be cleared. Even a compromised mailbox is not enough.
A personal account password, hashed server-side with Argon2id – never stored in plain text.
TOTP is mandatory for all accounts via an authenticator app. No access without the time-based code.
A personal secret word known only to the employee – the final hurdle right before the first viewing.
From encryption through customer management to branding – Password Vault is built for everyday use in the IT services business.
Password Vault runs on any Linux system you like – your own on-site server, a spare PC or mini-PC, or a low-cost VPS. Installation is done via a supplied script in about 15 minutes.
A Linux system (Debian 12/13 or Ubuntu 22.04/24.04), from 1 vCPU and 2 GB RAM (4 GB recommended), 20 GB SSD. This can be your own on-site hardware or a low-cost VPS from about €5/month.
One A record pointing to the server – e.g. vault.your-company.com. The HTTPS certificate is set up automatically.
For sending notifications – via SMTP, Microsoft 365 or Google Workspace.
One command (sudo bash install.sh) asks only for the domain. Docker, firewall, HTTPS and backups are set up automatically.
A VPS (Virtual Private Server) is a rented virtual server at a hosting provider – from about €5/month and exclusively yours. It is handy when you have no hardware of your own. But it is not required: Password Vault runs just as well on-premises on your own server in-house, or even on a spare computer or mini-PC that stays switched on. All you need is a Linux system (Debian/Ubuntu) with the resources listed above – the software and your data sovereignty are identical either way.
Self-hosted = full data sovereignty: all data stay exclusively on your own server. Nothing is transmitted to PROXYTEC or third parties – a strong argument towards your customers and for GDPR.
A clear scope of delivery with no hidden add-on modules – and a fair licensing model: one licence per company, not per user and not per customer.
You pay once per installation in your company – and with it you serve any number of customers, employees and internal users. No per-account tiers, no billing by customer count. The price stays predictable, no matter how heavily you use Password Vault.
The full Password Vault package to install on your own server – self-hosted, full data sovereignty.
Create as many customers, employees and administrators as you need – with no per-account surcharge.
Encryption, 2FA, audit log, groups, branding, backups – no add-on fees or locked features.
Apply new versions conveniently through the interface – with an automatic backup beforehand.
Illustrated PDF guides for setup and daily operation, in English and German – available to download immediately.
Your logo and company name appear in all e-mails and on your customers’ login pages.
Before buying you can test the software for 30 days at full scope – entirely without risk.
Reach us directly with any questions – optionally with paid installation or VPS support.
All data stay on your server. Nothing is sent to PROXYTEC or third parties – a strong GDPR argument.
A single credential handed over insecurely can get expensive. Weigh the risk against the price of a licence – the maths is clear.
Download the package and test Password Vault for 30 days at full scope – no registration and no payment details. Then: from €14.99/month, one licence per company with unlimited customers and employees.
The complete version, no feature limits. After 30 days the software switches to a locked mode – no data are lost.
No risk. 30 days at full scope, no payment details, no automatic subscription. After the trial you decide at your own pace – no data is lost.
A licence is valid per company and installation – with unlimited users, employees and customers. Choose a 12 or 24-month term. After purchase you receive the key by e-mail and enter it under Settings → Licence.
One-time payment per term – no subscription debit. The software reminds you 30 days before expiry; renewal is a new licence purchase. All prices plus VAT.
The online shop will open shortly; until then you can order the licence directly from us.
You would rather not deal with installation and servers yourself? For an additional fee we handle the installation and setup on your server – and, if you wish, help you choose and set up a suitable VPS. Get in touch at support@proxytec.de – we will make you an offer.
No. A password manager stores your own passwords permanently so you can access them. Password Vault is for the one-time, secure transfer of credentials and files to a recipient – with automatic deletion after retrieval. The two complement each other but do not replace one another.
Exclusively on your own server. Password Vault is self-hosted – the encryption key is held only by you, and no data is transmitted to PROXYTEC or third parties. That is a central GDPR argument towards your customers.
No. Your customer’s employee only needs a browser and an authenticator app for the two-factor code. On first access they set up their password, secret name and 2FA themselves via an invitation link.
After installation the software runs for 30 days at full scope – without registration or payment details. It then switches to a locked mode: no data is lost and admin read access remains. Enter a licence key to unlock it again.
No problem. For an additional fee we handle the installation and setup on your server, or help you choose and set up a suitable VPS. Get in touch – we will make you an offer.
Passwords, messages and files are encrypted with AES-256-GCM; the key stays only on your server. Accounts are protected by Argon2id hashing, mandatory TOTP two-factor and the personal secret name. Every access is logged in the audit log with a timestamp and IP.
The licence is per company and installation – not per user and not per customer served. You can create any number of customers, employees and internal users without the price changing. You only choose the term (12 or 24 months).
A VPS is only a convenient option, not a must. Password Vault runs just as well on-premises on your own in-house server, or on a spare computer or mini-PC that stays switched on. All you need is a Linux system (Debian/Ubuntu) with the minimum resources listed and a reachable (sub)domain. Whether on your own hardware or a VPS – the software and your data sovereignty stay the same.
Password Vault is a software solution developed by PROXYTEC, provided for installation and operation on infrastructure supplied or managed by the customer (their own server or VPS). As the customer operates the software on their own or self-managed server or VPS, they are responsible for securing it – in particular operating-system and security updates, firewall and access protection, the use of strong credentials, as well as setup, secure operation, applying software updates and regular backups.
The software is provided in the version supplied. No fitness for a purpose beyond the service description, no uninterrupted availability and no absolute security against unauthorised access are warranted.
PROXYTEC’s liability – on any legal ground – is excluded to the extent permitted by law. This does not affect liability for intent and gross negligence, for damage arising from injury to life, body or health, under the German Product Liability Act, or for the breach of essential contractual obligations. Our General Terms and Conditions (in particular sections 3 and 9, German) and the legal notice apply in addition. The German version of these terms is legally binding.
Test Password Vault free for 30 days – no payment details, no risk. Or let us handle the entire setup. You are up and running in 15 minutes.