Your most sensitive credentials sit in someone else's cloud black box?
Admin passwords, API keys and maintenance credentials sit with a proprietary cloud provider, and whether its security promises hold cannot be verified. codPass is the open-source password and secrets manager by extocode GmbH: independently operable on-premises, with full data sovereignty. A separate, independent product, open source at github.com/extocode/codpass.
codPass: open-source password and secrets management by extocode GmbH.
Know the feeling?
All credentials in a black box: a cloud manager without insight or data sovereignty
The pain: IT's most sensitive data sits with a proprietary cloud provider. The source code is closed, the infrastructure foreign, and whether the security promises hold cannot be verified. And switching later is painful: the provider has the data, you have the contract.
The consequence: Loss of data sovereignty over the most critical system in IT security, vendor lock-in when prices change, and in an ISO 27001/NIS2 context a hard-to-justify dependency on an unverifiable third party.
How COD solves it: codPass is open source, so the security mechanisms are traceable and verifiable instead of a black box. The service runs entirely in your own operations, with full data control, without dependency on external cloud services and without proprietary lock-in structures. For a secrets manager in particular, this openness is a security feature, not an accessory.
The old self-hosted password manager has itself become the vulnerability
The pain: Many teams have been running a self-hosted password manager for years whose project is barely maintained anymore: outdated PHP foundation, open security advisories, no more updates. Of all things, the system protecting all the credentials is the weakest link.
The consequence: Known, unfixed vulnerabilities in IT's most sensitive system. The outdated platform reappears in every vulnerability scan, and every server update becomes a risk.
How COD solves it: codPass was reworked at the core, not cosmetically: a comprehensive security analysis from code review and architecture assessment, implementation of the identified security fixes and an update to current PHP versions. On top comes a modernized interface, structurally prepared for extensions. It remains open source and independently operable on-premises.
Passwords here, one-time codes there: the second factor in a separate app
The pain: The passwords sit in the password manager, the matching TOTP/HOTP one-time codes in a separate authenticator app on some device. With a shared account, nobody knows for sure where the second factor currently is.
The consequence: Credentials and second factor in two separate places are cumbersome day to day and a findability problem as soon as the person with the app is not at hand.
How COD solves it: codPass manages TOTP and HOTP one-time codes bundled with the passwords in one central place. Credentials and the matching second factor sit together instead of scattered across tools and devices.
Why COD, not just a feature
codPass is deliberately an independent, open-source product by extocode GmbH: operable independently of COD, on-premises, in your hands. The structural advantage lies in the openness itself: for a secrets manager, verifiable source code is the security argument a cloud black box cannot deliver.
Frequently asked questions
See codPass in action
Request a live demo or download the codPass datasheet as a PDF.