UK Cyber Essentials certified · EU hosted · NCSC aligned

Cyber Essentials
Certified Password Manager

SealedKeys holds UK Cyber Essentials certification. Use a password manager that already meets the standard you're being assessed against — with zero-knowledge encryption, full audit logs and EU data residency.

How SealedKeys addresses the five Cyber Essentials controls

Cyber Essentials covers five technical controls. Here's how SealedKeys directly supports each one.

Access Control

Only authorised users can access your systems and data

Role-based access control with team vaults, granular permissions, SSO integration, and instant revocation. Every access is logged.

Secure Configuration

Devices and software are configured to reduce vulnerabilities

Default-secure: zero-knowledge by design, TLS 1.3 in transit, AES-256-GCM at rest, no default passwords, no shared admin credentials in the vault.

Malware Protection

Protect against malware and other attacks

Client-side encryption means stolen database data is useless. Breach detection via HIBP k-anonymity in the Security dashboard. TOTP seed storage for MFA on all accounts.

Patch Management

Software is up to date and vulnerabilities are addressed promptly

SaaS model — SealedKeys manages infrastructure patching. No software to deploy or maintain on your end.

Boundary Firewalls and Internet Gateways

Protect against external threats

Hetzner EU infrastructure with network-level protection, TLS 1.3 termination at Nginx, and no inbound access other than HTTPS.

Features that support your assessment

Evidence-ready from day one.

Cyber Essentials certified

UK Government Cyber Essentials certification — the NCSC baseline security standard. Evidence of this certification is available for your assessment paperwork.

EU data residency

Data stored on Hetzner infrastructure in Germany. Never transferred to the US or third countries. Evidenced hosting location available on request.

Full audit log

Every secret access, copy, edit and deletion logged with timestamp, user and IP. Produce an access history for any secret during an assessment or incident review.

Zero-knowledge encryption

Encryption key derived client-side — the server never holds a key that can decrypt your secrets. A breach of SealedKeys cannot expose your credentials.

SAML 2.0 SSO

Centralise identity and access management via Okta, Entra ID or Google Workspace. Deprovisioning in your IdP immediately revokes SealedKeys access.

Open-source encryption

The encryption implementation is published on GitHub. Your IT assessor can verify the zero-knowledge claim independently — no vendor trust required.

Frequently asked questions

What is Cyber Essentials and why does it matter for password managers?+

Cyber Essentials is a UK government-backed certification scheme that defines baseline security controls for organisations. It is mandatory for suppliers bidding for many UK government contracts involving handling personal data or providing certain technical services. A Cyber Essentials certified password manager helps you demonstrate that your access control and credential management practices meet the standard.

Is SealedKeys Cyber Essentials or Cyber Essentials Plus certified?+

SealedKeys holds Cyber Essentials certification. Cyber Essentials Plus involves an independent technical audit — details of current certification status are available on request by emailing hello@sealedkeys.com.

How does SealedKeys help with the Access Control requirement?+

SealedKeys provides role-based access control, team vaults with granular permissions, SAML 2.0 SSO for centralised identity, immediate access revocation, and a full audit log of every access event. These directly address the Cyber Essentials access control control.

Can I use SealedKeys as evidence in a Cyber Essentials assessment?+

Yes. SealedKeys' Cyber Essentials certificate can be cited as evidence that your password management tool meets the standard. The audit log provides access history evidence. The zero-knowledge architecture and EU hosting can support answers to questions about data storage and encryption.

Does SealedKeys support multi-factor authentication?+

Yes. SealedKeys supports TOTP-based MFA for all accounts. You can also store TOTP seeds for other accounts within the vault. SAML SSO delegates authentication to your identity provider, which may enforce its own MFA policies.

Which other UK compliance frameworks does SealedKeys align with?+

SealedKeys aligns with UK GDPR (EU data residency, zero-knowledge processing model, DPA available), NCSC guidance on password management (unique strong passwords, breach detection), and ISO 27001 controls around access management and cryptography. It is designed with the requirements of UK government suppliers in mind.

Related

Cyber Essentials certified from day one

25 items free. Pro at £3.49/user/month. No credit card required.