Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • English (US) Français Deutsch Español Türkçe
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)TACACS+Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPStrongholdAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • English (US) Français Deutsch Español Türkçe
  • Sign in
  • Contact Us

Your secrets stay on your device

Stronghold, the vault module of the Central Operations Dashboard (COD, the central operations and management platform for your IT), is the end-to-end-encrypted vault for passwords and secrets: the server only ever stores ciphertext, master password and private keys stay on the device.

Passwords, credentials and secrets are scattered across notes, spreadsheets and chats in many teams, hard to share and even harder to secure. Stronghold is the end-to-end-encrypted vault right inside COD: master password and private keys stay solely on the device, the server only stores ciphertext. New in COD 3.6 and shipped in production, multi-tenant, fully on-premises and KRITIS-ready.

Request a live demoDownload datasheet

Your secrets stay on your device

Zero-knowledge, the server sees only ciphertext

Stronghold is a zero-knowledge vault: encryption happens in the browser, not on the server. So the plaintext stays solely on the device that created it.

  • Argon2id derives the key from your master password, X25519 sealed box wraps the keys, AES-GCM secures the entries
  • Even an entry's link to an asset lives inside the encrypted blob, the server never learns what an entry points to
  • Master password and private keys never leave the device, the server stores ciphertext only

Browser extension for Chrome and Firefox

Prebuilt extensions for Chrome and Firefox ship in the release bundle and are handed out to end users by the operator, credentials end up where they are needed.

  • Every device is securely coupled via device pairing, if the administrator revokes a device it is wiped cleanly
  • In-page autofill fills credentials field-accurately into the real login form, via overlay or keyboard shortcut
  • Searchable vault list in the popup with copy for username, password and URL

Team vaults and targeted shares

Alongside personal vaults there are shared team vaults, so a team uses the same credentials without passing passwords around by chat.

  • Team vaults with the roles OWNER and MEMBER, the last owner is protected
  • You share individual entries across users, with read or write permission and an expiry date, public-key encrypted
  • When an access is revoked, a rekey follows automatically for the remaining members, vaults stay tenant-separated

Switch over without data loss, import from common managers

You do not have to start from scratch. You bring existing password collections into Stronghold client-side, without the server seeing plaintext.

  • Import from KeePass, Bitwarden (including encrypted exports), 1Password and generic CSV
  • The import is decrypted in the browser, even during the move the server sees no plaintext
  • An import creates a personal vault by default, from which you move entries into the team on purpose

Part of the COD platform

Stronghold is not a siloed tool but a module of the Central Operations Dashboard, run behind the COD backend proxy with its permission logic.

  • Reachable only behind the backend proxy with COD permission logic, the frontend never talks to the service directly
  • Tamper-proof audit log (HMAC chain) and rate limiting
  • Multi-tenant and fully deployable on-premises, KRITIS-ready, full control of your data

Frequently asked questions

Can someone with server access read my passwords?

No. Stronghold is a zero-knowledge vault. Encryption happens in the browser with Argon2id, X25519 sealed box and AES-GCM. The server stores ciphertext only, master password and private keys stay on the device. Even an entry's link to an asset is stored encrypted.

Is Stronghold new or do I still have to wait for it?

Stronghold is released and shipped in production with COD 3.6. It is the core new feature of this release, runs with its own database behind the backend proxy and is part of the release bundle including the prebuilt browser extensions.

Can I bring over my existing passwords?

Yes. Stronghold imports from KeePass, Bitwarden, 1Password and generic CSV. The import is decrypted client-side in the browser and lands in a personal vault by default, from which you move entries into team vaults on purpose.

See all questions in the FAQ →

See Stronghold live

Request a live demo and see Stronghold hands-on in your own COD environment, or download the datasheet with all features compactly on one page.

Request a live demoDownload datasheet

Folgen Sie uns
​
  • COD Overview
  • Features
  • Pricing
  • Integrations
  • NIS2
  • codPass
  • References
  • Downloads
  • FAQ
  • Contact

Kotzinger Straße 21 • 83278 Traunstein • Deutschland

  • ​+49 (861) 88 00 32 00
  • ​info@extoco.de
Datenschutz Impressum ​
Copyright © extocode GmbH
English (US) Français Deutsch Español Türkçe

We use cookies to provide you a better user experience on this website. Privacy Policy

Decline Accept