Metaluxo
← Insights

Startups & SMEs

Password Managers for Teams: Which One Passes a Security Audit?

That every audited password manager must demonstrate.

The auditor asks for your password policy. You hand over a document that says “use strong passwords.” Then they ask: “Which password manager does your team use?” You pause. Half the team uses 1Password, a quarter uses Bitwarden, and the rest use Chrome autofill.

This is where most SME security audits fail. Not because the passwords are weak, but because there is no central control, no audit trail, and no way to prove that anyone is following the policy.

At Metaluxo we review IT security for SMEs across the EU. The password manager question appears in every audit. This post covers what auditors actually check and which products meet the standard.


What a security audit checks

An auditor does not care which brand you use. They care about three things:

1. Zero-knowledge encryption

The provider must not be able to access your passwords. This is usually proven by:

  • Client-side encryption (your master password never leaves your device)
  • AES-256 or equivalent encryption
  • A security whitepaper or third-party audit report confirming the architecture

Auditors will ask for the audit report. If the provider does not have one, you fail this control.

2. Multi-factor authentication

The password manager must support and enforce MFA. SMS-based MFA is increasingly rejected by auditors. Acceptable methods include:

  • TOTP (authenticator apps like Google Authenticator or Authy)
  • Hardware keys (YubiKey, FIDO2)
  • Biometric authentication on mobile devices

The auditor will check whether MFA is mandatory for all users or optional. Optional MFA fails.

3. Admin audit log

You must be able to prove who accessed which password, when, and from where. The audit log should include:

  • User login events
  • Password creation, modification, and sharing
  • Failed login attempts
  • Administrative changes (user additions, removals, policy changes)

The auditor will ask for a sample of log entries. If you cannot produce them, you fail.


Products that typically pass

ProductZero-knowledgeMFA enforceableAudit logNotes
1Password BusinessYesYesYesSOC 2 Type 2 certified, widely accepted
Bitwarden EnterpriseYesYesYesOpen source, self-hostable
Dashlane BusinessYesYesYesSOC 2 Type 2 certified
Keeper BusinessYesYesYesFedRAMP authorized
LastPass EnterpriseYesYesYesSecurity incidents in 2022; some auditors now question it

Products that typically fail:

  • Browser password managers (Chrome, Safari, Edge) — no admin controls, no audit log
  • Free consumer tiers — no MFA enforcement, no sharing policies
  • Spreadsheets or documents — no encryption, no access control, no audit trail

Implementation checklist

  1. Choose a business tier. The consumer version of any password manager lacks the admin controls an audit requires.

  2. Enforce MFA. Make it mandatory for all users, including admins. Disable SMS where possible.

  3. Define sharing policies. Who can share passwords? With whom? For how long? Document it.

  4. Onboard and offboard properly. When someone joins, provision their vault. When they leave, revoke access and transfer shared items within 24 hours.

  5. Export the audit log quarterly. Store it in a separate system. If the password manager is compromised, you lose the log with it.

  6. Train staff. A password manager is only as secure as the people using it. Train them on master password hygiene, MFA setup, and phishing awareness.


At Metaluxo we review password management as part of our ISO 27001 and vCISO engagements. If you are preparing for an audit and are unsure whether your current setup will pass, book a free 30-minute consultation and we will assess it against the controls your auditor will check.

Common questions

Are browser password managers secure for business use?

No. Browser password managers lack admin controls, audit logs, and sharing policies. They are designed for consumers, not for teams that need accountability and compliance evidence.

What is zero-knowledge encryption in a password manager?

It means the provider cannot access your passwords — only you hold the decryption key. If the provider is breached, your passwords remain encrypted and unusable to the attacker.

Should we force employees to use the company password manager?

Yes. A policy that allows personal password managers creates shadow IT and eliminates your ability to enforce security standards or respond to breaches.

Related reading

Send us a message
Message us Book now