Locally Hosted Password Management
- Choice of access via many devices and methods:
- KeePass Client (Windows desktop)
- Bruce Schneier's Password Safe Client (Windows desktop)
- MacOS Client
- Linux Client
- Web Browser Client
- Web Browser extension - Auto-Fill Passwords
- Mobile apps (Android, iOS)
- Administrator control over access to single passwords or folders.
- Administrator control over company-defined set of hierarchical user roles (grouping users into roles).
- Centralized policies/configuration (optionally mandate what a group of user's client settings should be).
- Copy role and password access function makes user default allocation simple.
- Credit card information, Social Security and Social Insurance numbers, product keys and passwords, and even files can all be safely stored.
- Import and export capability.
- Backup and restore capability.
Compare Editions
(click a feature to view in-depth details)
| Feature | Enterprise+ | Enterprise | Community |
|
Share Data Securely
Create, Import, and securely Share access to encrypted entries like passwords, data, and other sensitive information. More details... |
|
|
|
|
Quick Installation
Achieve and move on with AES256 Encrypted Database and IIS Express set up automatically. More details.... |
|
|
|
|
Self-Hosted Deployment
Run Password Server on infrastructure you control with a perpetual use license: On-premises, private cloud, hybrid, and air-gapped. More details... |
|
|
|
|
Flexible Deployment Options Host on the built-in web server or IIS, with options for Windows Server Core, silent install, and choice of Stable or Latest releases. |
|
|
|
|
Azure Integration
Password Server can be installed on Microsoft Azure. Additional Azure integration options are possible with Enterprise and SSO editions. More details... |
|
|
|
|
High-Availability Integration
Achieve maximum up-time with load balancing and failover compatibilities. More details... |
|
|
|
| Cross-Platform Apps Apps for Windows, macOS, Linux, iOS and Android (alongside KeePass). Features: biometrics, PIN lock, offline access and multi-server support. |
|
|
|
|
Web Browser Access
Access data easily through the web client with no additional installation required. More details... |
|
|
|
|
KeePass for Pleasant Password Server
Our included KeePass client utilizes the highly secure and user friendly open source interface. More details... |
|
|
|
|
KeePass Auto-Type Enter credentials into application windows using KeePass Auto-Type and configurable keystroke sequences. |
|
|
|
| KeePass on Linux |
|
|
|
|
SSH Key Compatibility (KeeAgent Plugin) Use KeePass compatible KeeAgent functionality to work with SSH keys. |
|
|
|
|
Autofill Browser Plugin
Seamlessly Autofill credentials via browser plugin, securely retrieve and store passwords. More details... |
|
|
|
|
Mobile Access Clients
Android and iPhone mobile clients provide secure access through your preferred device. More details... |
|
|
|
|
Multi-Factor Authentication
Add additional layers of login security with Authenticator apps (TOTP), Biometrics, Yubikey, RADIUS, Email 2FA. More details... |
|
|
|
|
Authenticator Key (TOTP) Generation
Generate and store TOTP values for Two-Factor Authentication (2FA), Authenticator apps. More details... |
|
|
|
|
Manage Users
Manually create/delete/edit/disable users, assign roles, change passwords, etc. More details... |
|
|
|
|
Manage Roles
Create roles, assign permissions and/or select sub-roles. More details... |
|
|
|
|
User Access View
Create and change User/Role Access Levels for password entries. More details... |
|
|
|
|
Inherited User Access Set global access at the root or on any branch of the folder tree. |
|
|
|
|
Delegated Administration Team leads manage their own access, restricting access to specific areas. |
|
|
|
|
Folder Management
Add/Edit/Move/Delete a folder directories for easy organization. More details... |
|
|
|
|
Search and Browse Passwords Easily find the passwords and data you need to access. |
|
|
|
|
Import credentials from KeePass and other Password Managers
Users can import from single user versions of KeePass and in various formats: KDB/KDBX/CSV/XML/TXT. More details... |
|
|
|
|
Supported Languages
Supported Languages: Web app - 6 (English, German, French, Japanese, Spanish, Dutch), Cross-Platform - 16, KeePass - 45+ translations. More details... |
|
|
|
|
Multiple Database Types Supported
Choose from SQLite, PostgreSQL, MSSQL, or Azure SQL. More details... |
|
|
|
|
Password & Passphrase Generator
Generate secure Passwords and Passphrases. More details... |
|
|
|
|
Default Password Profiles
Select a default password templates for all newly created entries. More details... |
|
|
|
|
Private Folders
Users can keep their own data secure and hidden within the database. More details... |
|
|
|
|
File Attachments Files are encrypted along with the password entries. |
|
|
|
|
REST API Access
Automate scripts with custom integrations for user folders, entries, and permissions, through the REST API. More details... |
|
|
|
|
Custom OAuth Clients Register your own OAuth clients for API integrations and scripts. |
|
|
|
|
Web Client Customized Settings
Customize the web client display and global settings. More details... |
|
|
|
|
Scheduled Reports
Configure the recipients, frequency, time, and parameters of audit reports. More details... |
|
|
|
|
Access Reports
All Settings Reports, User Access Report, Role Access Report. More details... |
|
|
|
|
Enhanced Reports
Access Frequency, Password Expiry, Password Age, Password Strength and Load Reports. More details... |
|
|
|
|
Breached Password Detection & Reporting Check passwords against known compromised-password data and review breach-check results. |
|
|
|
|
Offline Mode
Users can access an encrypted local copy of permitted credentials when disconnected, with admin-controlled caching and configurable expiry period (KeePass, Mobile, & Cross-Platform). More details... |
|
|
|
|
Password Safe Client: Legacy Support
Integrates with Bruce Schneier's Password Safe client interface. More details... |
|
|
|
|
Password History
See the full credential history via Web Client. More details... |
|
|
|
|
History Restore
Restore any key History items such as Titles, Usernames, Passwords, URL's, Notes, Custom Fields and more. More details... |
|
|
|
|
Lockout Policies
Set Lockout policies for failed login attempts and alert Administrators. More details... |
|
|
|
|
Timeout Policies
Configure inactivity log out settings for web and application clients. More details... |
|
|
|
|
Offline License Activation
Run your server in a secure air gapped environment, no internet access or external access ports are required. More details... |
|
|
|
|
Direct Linking to Entries Share links to entries with your colleagues, with the data safely secured on your server. |
|
|
|
|
Client Certificate Authentication (mTLS)
Advanced security: requiring trusted client certificates to prove their identity for supported connections, and vice-versa. More details... |
|
|
|
|
Certificate Renewal Automation
Automate certificate renewal and deployment using Let's Encrypt or any ACME certificate authority with a documented ACME-client integration script. More details... |
|
|
|
|
Custom Fields
Add custom data fields to your entry to accommodate various value types. More details... |
|
|
|
|
Audit Events & Compliance
Almost 200 audit event types record user activity and are securely stored and encrypted. More details... |
|
|
![]() |
|
SIEM Integration (Syslog)
Forward Password Server log events to a central syslog. More details... |
|
|
![]() |
|
LDAP and Open LDAP
Supports Lightweight Directory Access Protocol Integration. More details... |
|
|
![]() |
|
Active Directory Integration for Users Access
Get user list from a selected server and select the ones you want to import as users with Windows login access. More details... |
|
|
![]() |
|
Active Directory Integration for Group Access
Get group list from a selected server and select the ones you want to import as roles. More details... |
|
|
![]() |
|
Auto-Import New Active Directory Users
Set up a user directory for new AD users to automatically receive Password Server Accounts. More details... |
|
|
![]() |
|
Active Directory Schedule and Health Check Regularly sync AD account information and check the directory connection status. |
|
|
![]() |
|
Scheduled Backups & Restore
Automatic Scheduled backups of your encrypted server database. Features: Restore databases quickly and easily; Notify on backup failures. More details... |
|
|
![]() |
|
Full Data Export (Script) "Export entries, folders, file attachments, TOTP secrets and custom fields to JSON or CSV with provided script. Optional AES-256 encrypted Zip packaging." |
|
|
![]() |
|
Server-to-Server Content Migration (Script) Transfer supported folders, entries and related data between Password Server installations with provided script. Features: duplicate protection and a verified import report. |
|
|
![]() |
|
Email Notifications
Setup automatic Email Notifications when selected Roles/Users carry out triggering actions. More details... |
|
|
![]() |
|
Expired Password Notification Email users and roles when a password is about to expire. |
|
|
![]() |
|
Scalable Licensing and Support Stay secure as your organization grows with prorated, upgradable licensing available from 5 to 10,000+ users |
|
|
![]() |
|
Create New Access Levels
Decide what kind of access a user has and what access they can grant to other users. More details... |
|
|
![]() |
|
Custom Client Configuration
Create configurations which enforce policies and assign them to specific users or groups. More details... |
|
|
![]() |
|
Audit Log Quick Filters Create custom quick filters for reviewing common operations or schedule outputs as a report. |
|
|
![]() |
|
Appearance and Branding
Customize the Web Client by adding a company Logo and choosing one of the available background themes. More details... |
|
![]() |
![]() |
|
Bulk Management Operations Update User and Role attributes dynamically with custom filters and operations management. |
|
![]() |
![]() |
|
Advanced Folder Options
Create User Preference, Favorites, and Archives for folders for added functionality. More details... |
|
![]() |
![]() |
| Pleasant Reset Server Integration Additional Active Directory Reset accounts available on separate licenses or as a stand-alone product. |
|
![]() |
![]() |
|
Self-Serve Active Directory Reset
Active Directory / LDAP users can reset their account password from the Windows Log On screen or via web browser. More details... |
|
![]() |
![]() |
|
Custom Reset Challenges
Configure requirements for account password resets using custom text and image based Reset Challenges with optional multi-factor authentication. More details... |
|
![]() |
![]() |
|
Rotate and Sync Privileged AD Credentials Password Auto-Changer allows AD and Unix system passwords to update on a schedule.More details... |
|
![]() |
![]() |
|
Store Privileged AD Credentials
Import your existing Active Directory Credentials as new secure entries. More details... |
|
![]() |
![]() |
|
Local Admin Password Onboarding (Script) Create device-specific local administrator credentials and store them in Password Server during onboarding using a script. |
|
![]() |
![]() |
|
Email Templates
Custom notification templates to alert users to changes from on server. More details... |
|
![]() |
![]() |
|
IP Range Restrictions
Limit access to Password Server and enforce different login criteria based on the IP of incoming requests More details... |
|
![]() |
![]() |
|
Security Zones and Elevation
Allow authorized users to elevate to a increased level of access when required, while using normal permissions for day-to-day tasks More details... |
|
![]() |
![]() |
|
Just-In-Time (JIT) Access with Request & Approval
Request & Approval for Just-in-Time Access: Allow access requests that require approval before granting access to select folders or entries. Features: time-limited access, automatic expiry, and audit trail. More details... |
|
![]() |
![]() |
|
Request & Approval: Four-Eyes Principle Enforce dual-control access policies where a second authorized user must approve before credentials are revealed, supporting four-eyes compliance requirements. |
|
![]() |
![]() |
|
Break-Glass Emergency Access Reach critical credentials in an emergency, with admin alerts and audit trail. |
|
![]() |
![]() |
|
Time Limited Access
Access to entries and folders can be granted with a time limit for temporary access. More details... |
|
![]() |
![]() |
|
Required Comment Field
Administrative setting that requires a user comment for accessing a credential. More details... |
|
![]() |
![]() |
|
Activity Dashboard Review recent entry access, sign-ins, user activity and pending access requests at a glance. |
|
![]() |
![]() |
|
SAML Single Sign On
Log in to Password Server with your preferred SAML Identity Provider More details... |
|
![]() |
![]() |
|
Universal SSO™ Module
Added module for Enterprise, it provides unmatched security by never loading a credential on a user's device. More details... |
|
![]() |
![]() |
|
SSO Proxy for SSH
Highly secured Single Sign On Access to Unix. More details... |
|
![]() |
![]() |
|
SSO Session Recording Record and replay activity in supported SSO SSH proxy sessions, with permission-controlled access to recordings. |
|
![]() |
![]() |
|
Paranoid™ Zero Knowledge Encryption
Enable client-based, device level, End-To-End Encryption (E2EE) keeping secrets from the server, host, and database. More details... |
|
![]() |
![]() |
|
File Integrity Monitoring: Detect Changes
Monitor and detect application file changes More details... |
|
![]() |
![]() |
| Geo-Distributed Segmentation (Contact us) Ensure data sovereignty and reduce latency. Define geo-fenced regions for selective data distribution, synchronize nodes while respecting cross-border restrictions, and selectively restrict IP access to specific database caches. Contact us. |
|
![]() |
![]() |
High Security
| Threat Type It Protects Against | ||
| Security Measure. | External | Internal |
| Central encrypted storage. Credentials are stored on the server. Optional: offline copies are encrypted and expire on an admin-set date. | ![]() |
![]() |
| Encryption in transit. TLS-encrypted connections using the strongest available protocols. | ![]() |
![]() |
| Encryption at rest. AES-256 database encryption; FIPS 140-2 compliant encryption algorithm. | ![]() |
![]() |
| SHA-512 Hashing Algorithm. | ![]() |
![]() |
| In-memory protection. Passwords stay encrypted in memory while KeePass runs. | ![]() |
![]() |
| Zero Knowledge Encryption option: No one can gain access to your passwords. Only you can view & share. Enable device level End-To-End Encryption (E2EE) options to keep secrets from the server, host, and database. Uses RSA-2048, AES-256-GCM and salted PBKDF2-HMAC-SHA256. | ![]() |
![]() |
| Strong sign-in. MFA, lockout policies, and IP restrictions defend against brute-force and credential-stuffing attacks. | ![]() |
![]() |
| Least privilege. Roles, JIT access, and approvals limit what each account can reach. | ![]() |
![]() |
| Full audit trail. Almost 200 event types, which you can send to your SIEM. | ![]() |
![]() |
| File Integrity Monitoring. Detects unexpected changes to application files. | ![]() |
![]() |
| Clipboard Clearing. The clipboard clears a few seconds after use. | ![]() |
not applicable |
| Private network or air-gapped. Run with no access from outside your network. | ![]() |
not applicable |
Read more about FIPS Compliance.
Client-Side Password Access
- Web Client allows for user access outside the office and with any operating system.
- Cross-Platform Desktop/Mobile Apps (MacOS, Linux, Android, iOS)
- Easy to use and familiar interface used by millions.
- Only one Master Password is required to be remembered by the user.
- Most features of KeePass are supported: continue to use your favorite plug-ins.
- Over 45+ language translations available.
- Strong security, including automatic clipboard erase.
- Strong random password & passphrase generator.
- Import / export from existing database.
- Searching and sorting.
- Auto-type, Global Auto-Type Hot Key and Drag & Drop.
- Time fields and entry attachments.
- View password history in web client.
Time Saving
- Eliminate lost time on retrieval of forgotten passwords.
- Active Directory / LDAP function allows for quick user import through the “Auto Import Enabled” setting and auto account creation for users on first user login.
- Setting access levels for roles rather than individual users and then assign roles to users.
- Client Configuration allows configuration settings to be easily set and enforced.
- No extensive training required.
Cost Saving
- Reduce password retrieval or reset costs managed by a help desk by 40% or more.
- Improved productivity and downtime throughout the organization.
- Reduce administrative costs with much greater access and controls.
- Quick capabilities for new user setup or lapsed user disconnection.
- Sharing of Passwords across teams is quick and simple.
Policy Enforcement
- Establish Password policies that can be enforced.
- Ensure accountability of every access point to sensitive data with logging tool.
- Implement defined configurations that ensure policy adherence.
- Access Levels definition enables variable settings that can easily be assigned to Roles or Users.
Widely Accessible
- Web Client enables access through the internet (Any internet connected device can access Pleasant Password Server including smart phones, tablets, and home computers).
- Native Windows clients (Keepass and Password Safe)
- Native Desktop clients (MacOS, Linux)
- Native Mobile apps (Android, iOS)
Well Supported
- Free Upgrades and Support for one year.
- Video tutorials explain key features and setup, so you’re up and running fast.
- Customized implementation and maintenance is available through local partners. Contact us for more information.
Incredible Value
- Best price in the market, with only a one-time fee.
- No-risk, 90-Day Money-Back Guarantee.
Server's System Requirements
- Windows 11/10 or Windows Server 2025/2022/2019/2016
- Earlier versions also supported (Windows 8/7/Vista, Server 2012/2008)
- .NET 4.8
- Detailed Requirements
