Passbolt is an open source password manager designed for teams. Built around OpenPGP end-to-end encryption, it lets IT, DevOps and engineering teams securely store, share and manage credentials and secrets on their own infrastructure. Whether you self-host it behind your firewall straight from a Raspberry Pi or a high-availability cluster, you stay in full control of your data.
Key Features
End-to-end encryption — secrets are encrypted on the client side with OpenPGP and can only be decrypted by authorised users, not the server
Granular sharing — share passwords, folders and groups with fine-grained permissions based on roles and the principle of least privilege
Users and groups — organise team access with users, groups and role-based access control (RBAC)
TOTP management — store 2FA codes securely alongside logins
Browser integration — quick-access autofill and auto-suggest via browser extensions for Chrome, Firefox and Edge
Self-hosted — deploy on your own server, docker container, VM or in an air-gapped environment with no internet dependency
Import and export — bring credentials in and out using kdbx and CSV formats
Auditing and reporting — activity logs and password health checks to track who has access to what
Why Use Passbolt?
If your team has outgrown shared KeePass files but you don’t want to hand your secrets to a commercial cloud vault, Passbolt gives you a self-hosted, fully auditable credential platform. The entire codebase is open source — even the paid editions are AGPL v3 — so you can always audit it yourself.
Use Cases
Centralising shared IT, DevOps and database credentials for a team
Enforcing least-privilege access with role-based controls and granular folder sharing
Deploying a sovereign credential platform on-premises or in an air-gapped network
Managing on-call and emergency access to production systems
Platform
Linux · macOS · Windows · Android · iOS · Web (self-hosted server) · Browser extensions (Chrome, Firefox, Edge)
Licence
GNU AGPL v3 (open source, even the commercial editions)
pfSense is the world’s most trusted open-source firewall and router platform, based on FreeBSD and developed by Netgate as the foundation of its security appliance and cloud offerings. It transforms any standard x86 computer into a full-featured enterprise firewall, delivering comprehensive routing, VPN, traffic shaping, and unified threat management capabilities through an easy-to-use web interface. […]
IPFire is a hardened Linux-based firewall distribution designed for security, speed, and ease of use. Developed by the IPFire community since 2004, it provides a complete firewall and router solution suitable for both home users and small-to-medium businesses, with a focus on modularity and a strong security posture. IPFire uses a stateful packet inspection firewall […]
Tor Browser is a free and open-source web browser that protects your privacy by routing your traffic through the Tor network, encrypting it multiple times and bouncing it through three volunteer-operated relays before reaching its destination. Based on Mozilla Firefox ESR, it includes pre-configured privacy hardening: fingerprinting resistance, no retained browsing history, and isolation of […]
Nmap (Network Mapper) is a free and open-source network discovery and security auditing tool that has become the industry standard for port scanning, service detection, OS fingerprinting, and network inventory. Network administrators, security professionals, and system administrators worldwide rely on Nmap to discover hosts, identify running services, detect open ports, and assess network security posture. […]