Enterprise Password Management - in partnership with Bitwarden
A majority of hacking-related breaches succeed through stolen or weak passwords. Empower employees to generate strong, unique passwords and share them securely whilst keeping all business passwords and other sensitive information in an end-to-end encrypted vault.
Features
- Deploy as a Service, in your Cloud or locally
- Zero knowledge, end-end encryption
- Available across several platforms - including mobile
- Assign role-based access for Organization users
- Use the SCIM protocols to manage and provision
- Enforce security rules for all users
- Reports for Exposed Passwords, Reused Passwords, Weak Passwords, and more
- A robust set of 2FA options
- Biometric authentication available
- Programmatically accessible via API and command line
Benefits
- Enable your team to share passwords securely
- Establish a first line of defence compromised passwords
- Integrate with your existing enterprise environment
- Supports a variety of systems and applications
- Unparalleled SSO Integration and Flexibility
- Reduce cybersecurity risk
Pricing
£2.05 to £3.42 a user a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
7 9 0 8 1 3 7 5 0 6 4 0 3 8 8
Contact
QNETIX LTD
Qnetix - Your Trusted Technology Solutions Partner
Telephone: +443333355673
Email: gcloud@Qnetix.co.uk
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Premium plans, including Teams and Enterprise, receive prioritized support within a categorized ticket-based system.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- The Bitwarden Support team offers global support 24/7/365. Premium plans, including Teams and Enterprise, receive prioritized support within a categorized ticket-based system.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- New customers provide a list of authorized contacts and their permission levels. We engage with those contacts and supply the relevant documentation - including portal access. If extra onboarding support like project management or technical design is required, we may charge a pre-agreed rate.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Users can directly download their data.
- End-of-contract process
- Users are able to download their information. At termination, all information is purged. Information cannot be recovered once your account is cancelled.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Other
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Each user / device can either use the web application or install a platform specific application. Features remain consistent across platforms.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Full administration is available via a secure web interface
- Accessibility standards
- None or don’t know
- Description of accessibility
- NA
- Accessibility testing
- NA
- API
- Yes
- What users can and can't do using the API
- The public API provides organizations a suite of tools for managing members, collections, groups, event logs, and policies.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
- This service offering is for dedicated, customer specific environments.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Event Logs, Exposed Passwords, Reused Passwords, Weak Passwords, Unsecured Websites and Inactive two-step logins.
- Reporting types
-
- API access
- Real-time dashboards
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data can only be decrypted using a key derived from your master password. Bitwarden is a zero knowledge encryption solution, meaning you are the only party with access to your key and the ability to decrypt the vault data. Bitwarden uses AES-CBC 256-bit encryption for your vault data, and PBKDF2 SHA-256 or Argon2 to derive your encryption key. Bitwarden always encrypts and/or hashes your data on your local device before anything is sent to cloud servers for storage. Bitwarden servers are only used for storing encrypted data. Bitwarden is compliant with the following policies: GDPR,CCPA,HIPAA,SOC 2 Type 2,SOC 3
- Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- The service interfaces in the application or web portal allows for information to be downloaded
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- For further information please see: https://bitwarden.com/help/bitwarden-security-white-paper/
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- For further information please see: https://bitwarden.com/help/bitwarden-security-white-paper/
Availability and resilience
- Guaranteed availability
- Bitwarden clients are able to function in offline mode as a copy of the users information is stored locally within that application.
- Approach to resilience
- All components have been built in fully resilience and availability in mind. Availability is dependant on services selected. More information is available on request.
- Outage reporting
- Bitwarden offers real time status available at https://status.bitwarden.com/
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Bitwarden is audited by reputable third-party security firms as well as independent security researchers. More information is available here: https://bitwarden.com/help/security-faqs/
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
-
- GDPR compliant
- California Consumer Privacy Act
- Complies with EU-U.S. Privacy Shield Frameworks
- HIPAA compliant and annually undergoes a third-party audit
- SOC Type 2 and SOC 3 compliant
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- No
- Security governance approach
-
Bitwarden complies with industry standards, and conducts comprehensive annual audits that are shared transparently. Bitwarden is compliant with the following policies: GDPR,CCPA,
HIPAA,SOC 2 Type 2,SOC 3. More information is available here: https://bitwarden.com/help/security-faqs/#q-how-does-bitwarden-meet-european-compliance-requirements - Information security policies and processes
- Bitwarden is compliant with the following policies: GDPR,CCPA, HIPAA,SOC 2 Type 2,SOC 3. More information is available here: https://bitwarden.com/help/is-bitwarden-audited/
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Bitwarden is compliant with the following policies: GDPR,CCPA, HIPAA,SOC 2 Type 2,SOC 3. More information is available here: https://bitwarden.com/help/is-bitwarden-audited/
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Bitwarden is compliant with the following policies: GDPR,CCPA, HIPAA,SOC 2 Type 2,SOC 3. More information is available here: https://bitwarden.com/help/security-faqs/
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Bitwarden complies with industry standards, and conducts comprehensive annual audits that are shared transparently with our customers. More information is available at: https://bitwarden.com/help/is-bitwarden-audited/
- Incident management type
- Supplier-defined controls
- Incident management approach
- Bitwarden complies with industry standards, and conducts comprehensive annual audits that are shared transparently with our customers. More information is available at: https://bitwarden.com/help/is-bitwarden-audited/
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
While Qnetix is not a manufacturer of hardware or software, we are committed to minimizing any activities that could harm the environment. To achieve this goal, we will: /1/ Assess and seek to reduce the environmental impact of our current and future operations. /2/ Continuously improve our environmental performance and reduce waste by promoting recycling and reuse. /3 / Purchase environmentally responsible goods and services whenever possible. /4/ Train employees on environmental matters and make information available as needed. /5/ Expect similar environmental standards from our suppliers and contractors. /6 / Assist customers in using our products and services in environmentally sensitive ways. /7/ Participate in discussions about environmental issues as necessary. /8/ Comply with all legal and regulatory environmental requirements. /9/ Review this policy annually and update as needed. We share the industry's concern about the environmental impact of obsolete IT equipment that is not recycled. We believe no computer should go to waste. We work with suppliers to enable materials to be reused or recycled, helping conserve natural resources. We have a strong commitment to keeping environmentally sensitive IT materials out of landfills.Covid-19 recovery
Qnetix remain committed to supporting our teams and community in the recovery of the affects of Covid 19. To achieve this goal, we will: /1/ Continue to offer training and education support for those left unemployed by COVID-19. /2 / Support people and communities to manage and recover from the impacts of COVID-19. /3/ Support organisations and businesses to manage and recover from the impacts of COVID-19. /4/ Support the physical and mental health of people affected by COVID-19. /5/ Improve workplace conditions that support the COVID-19 recovery effort including effective social distancing, remote working, and sustainable travel solutions.Tackling economic inequality
Qnetix is committed to addressing economic inequality at its core by creating new businesses and employment opportunities, as well as improving education and training. Our overriding vision is to help reduce the unequal distribution of income and opportunity between different groups in society.Equal opportunity
Qnetix aims to promote equal opportunities and fair management practices beyond legal requirements. Qnetix provides a work environment free from unlawful discrimination, harassment, bullying, or victimization based on sex, marital status, sexuality, disability, age, race, color, ethnicity, nationality, religion, or political beliefs. This principle applies equally to recruitment, training, promotion, dismissal, transfer, benefits, and all terms and conditions of employment. Qnetix does not tolerate breaches of this policy. All such instances will be thoroughly investigated and proven cases subject to disciplinary procedures. Policies for recruitment, selection, training, development, and promotion ensure individuals are treated solely based on relevant aptitudes, skills, and abilities.Wellbeing
At Qnetix, we understand that nurturing employee well-being is critical to developing workplace resilience. We focus on the following key areas: /1/ Physical - We ensure employees have routine in their roles, enough time for exercise, sleep, work-life balance, and nutrition. /2/ Career - We provide learning and development programs for employee growth. /3/ Financial - We offer fair compensation and aim to alleviate financial stress, which has been more prominent during the pandemic. /4/ Social - We host social events, especially now as people emerge from isolation, to build community. /5/ Community - We engage with local schools, colleges, and apprenticeship programs when possible. /6/ Emotional - We support employees through one-on-one meetings and external assistance to aid their mental health. /7/ Purpose - Our regular team meetings set work goals and align individual roles with the company's overall mission.
Pricing
- Price
- £2.05 to £3.42 a user a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Free trials are available. Resource limits and timeframe are agreed on a case basis.