Your vault is encrypted before it reaches us
Everything stored in your vault is end-to-end encrypted on your device before it is synchronised. The keys are derived from your master password, and your master password is never transmitted to or stored by BusinessOps. We host the encrypted result; only your team can unlock it.
What BusinessOps cannot see or recover
- Passwords, logins and secure notes in any vault
- Stored authenticator (TOTP) seeds and generated codes
- Attachments and the contents of secure Sends
- Anyone's master password
- A way to decrypt your data if every recovery option is lost
What BusinessOps can see, to run the service
- Account email addresses and invitation status
- Your organisation's name and user count
- Sign-in timestamps, device types and connection logs
- Event logs (who did what, when), where enabled for your vault
- Billing details, handled by Stripe
- Instance health: storage used, versions, uptime
Administrative reality, disclosed: our operators can suspend an instance, and can disable a user's two-step login or start the account recovery process where your organisation has enabled those features. Actions like these happen only on a verified request from your named administrator, and they are logged. We cannot read vault contents in any of these flows.
Your own instance, not an account in a shared app
Every customer gets a dedicated vault instance: your own application and database, isolated from every other customer, on hardened infrastructure we manage. Tenants are isolated containers on shared, hardened hosts. That means no other customer's users, groups or permissions exist inside your deployment at all, which structurally removes the cross-organisation class of problem that shared platforms have to police.
Where your data lives
- Primary hosting: Australia
- Encrypted backups: replicated to a second Australian server we manage, plus an offline copy
- Billing: processed by Stripe; card details never touch our servers
- Transactional email (invites, receipts): sent from our mail host
Our rule for this page: we only publish location statements we have verified, we re-verify them whenever a provider changes, and if we cannot verify a claim we do not make it. Last verified 26 July 2026.
Built on open source, kept current
BusinessOps Passwords runs the actively maintained open-source Vaultwarden server and is used through the official Bitwarden apps (browser extensions, mobile and desktop). We run unmodified upstream releases and track them closely: the apps update on their own schedule, and an out-of-date server eventually stops working with them, so applying server updates promptly is part of the service, not an extra.
- Security updates: applied promptly after upstream release, ahead of standard updates
- The official client apps are audited annually by their vendor
- The server software has undergone a code analysis by Germany's BSI (2024) and an independent penetration test (2024). It has not had a comprehensive formal audit, and we will not describe it as "audited"
BusinessOps is not affiliated with, endorsed by or sponsored by Bitwarden, Inc. Bitwarden is a trademark of Bitwarden, Inc., referenced only to describe client compatibility.
Backups: our part and yours
We take routine encrypted platform backups of every tenant so we can recover our infrastructure from hardware failure or operator error. Those backups are encrypted at rest and replicated off the primary server.
They are not a substitute for your own copies. Because your vault is end-to-end encrypted, no backup we hold can be read, partially restored, or reconstructed into your data by anyone but your team. Your administrator must export the organisation vault regularly, verify the export opens, and store it somewhere safe. The Terms of Service make this split of responsibility binding: platform recovery is ours, your usable copy of your own data is yours.
Master passwords and lockouts
The encryption that keeps us out keeps everyone out. If a master password is lost and no recovery path exists, that user's data is permanently unrecoverable, and no support ticket can change the mathematics. Set up the escape hatches on day one: enable admin-led account recovery for your organisation, have each member enrol, and configure emergency access for the business owner. On the Set Up For You plan we configure and test these with you at onboarding.
When something goes wrong
- We notify affected customers without undue delay, with a target of 72 hours from confirming an incident, and tell you plainly what was and was not exposed
- Encrypted vault contents remain protected by your keys even if infrastructure is compromised
- We comply with applicable Australian breach notification law
- Suspect a problem on your side (a phished master password, a stolen laptop)? Tell us immediately and we will help disable sessions and rotate access
Security reports: hello@businessops.com.au. We appreciate responsible disclosure and will respond.
What we do not claim
We are a small Australian provider, and we would rather prove things than assert them. So, for the record: we do not hold ISO 27001, SOC 2 or IRAP certifications and will not imply otherwise. No system, including this one, is "unhackable" or "100% secure", and a password manager does not by itself make any business compliant with the AML/CTF Act, the Privacy Act or anything else. What you get instead: the exact claims on this page, each one checkable, and a named human accountable for them during AEST business hours.