All articles

Passbolt Clears Three Security and Compliance Audits

3 min. read

RB

Remy Bertot

4 March, 2025

Passbolt Cloud Penetration Test (November 2024)

Findings

  • Authentication mechanisms were found to be robust.
  • API security controls were implemented correctly, preventing unauthorized actions.
  • No privilege escalation vulnerabilities were identified in the assumed breach simulation.
  • The recommendations provided were focused on further hardening security mechanisms and maintaining best practices.

Authentication Cryptographic Review (December 2024)

Findings

  • Only one low-risk, informational finding was reported: a minor timing attack issue within an upstream OpenPGP library.
  • No direct vulnerabilities in passbolt’s implementation were found.

SOC 2 Type II Audit (January 2025)

Findings

  • No material weaknesses were found in the design or operational effectiveness of controls. 
  • Testing procedures confirmed that passbolt’s security measures were effectively enforced over the audit period.

Conclusion

Continue reading

Preparing for Passbolt v5: PHP 8.2 Requirement

5 min. read

Preparing for Passbolt v5: PHP 8.2 Requirement

Prepare your passbolt instance for the upcoming v5 release with its new PHP 8.2 requirement. This article explains why we're upgrading, which distributions are affected, and provides straightforward migration strategies to ensure your credentials management system stays secure and up-to-date.

Max Zanardo

Max Zanardo

11 March, 2025

How to Secure Your Passbolt Instance with an SSL Certificate on Windows

6 min. read

How to Secure Your Passbolt Instance with an SSL Certificate on Windows

Learn how to secure your passbolt instance on Windows with an SSL certificate. This step-by-step guide covers generating, configuring, and installing both self-signed certificates for a fully secured setup.

Passbolt team

Passbolt team

24 February, 2025

Flag of European UnionMade in Europe. Privacy by default.