Scope the campaign
Pick the folders, roles or users under review.
Access recertification, rotation tracking and exportable evidence. Teampass will not make you compliant — no software does — but it produces the artefacts your auditor asks for.
A note on the word "compliant". No tool makes an organisation compliant with ISO 27001, NIS2, GDPR or SOC 2 — those apply to how you operate, and are assessed by an auditor, not by a vendor. What Teampass does is generate the access-control evidence those frameworks expect you to be able to produce. Every mapping on this page is phrased as "supports", and it means exactly that.
A recertification campaign takes the current access model, routes each grant to the person accountable for it, and records an approve-or-revoke decision against it. Those decisions are immutable: once recorded they cannot be edited, which is the property that makes them evidence rather than notes.
The output answers the three questions that usually go unanswered — who has access, who confirmed they should, and when. Not reconstructed from memory the week before an audit, but captured as the review happened.
Pick the folders, roles or users under review.
Each access goes to the person who can actually judge it.
Approve or revoke, timestamped and immutable.
CSV, ready to attach to an audit file.
Who can reach which folders and items, derived from the live model rather than a maintained-by-hand document.
When each credential was last changed, measured against the rotation policy for its folder, with an overdue report.
Four classification levels and a named owner per item, so sensitivity and accountability are recorded rather than assumed.
The credentials a departing account could reach — the exact scope of the rotation you owe after an exit.
Views, edits and shares recorded against each item, for the incident where "who saw this" stops being hypothetical.
Weak, reused, breached and overdue credentials, scored continuously and attributable per user.
Indicative, not a certification and not legal advice. Confirm the mapping with your own auditor — control numbering changes between revisions.
| Expectation | Typical reference | Teampass supports it with |
|---|---|---|
| Access is granted on a defined basis | ISO 27001 A.5.15 · SOC 2 CC6.1 | Folder tree, roles, per-user overrides, rights matrix |
| Access rights are reviewed periodically | ISO 27001 A.5.18 · SOC 2 CC6.2 | Recertification campaigns with immutable decisions |
| Privileged access is restricted and tracked | ISO 27001 A.5.15 · NIS2 art. 21(2)(i) | Role scoping, admin lockout controls, per-item history |
| Authentication information is managed securely | ISO 27001 A.5.17 | Encrypted storage, TOTP/SSO, password policy and generator |
| Access is removed on termination | ISO 27001 A.5.11 · SOC 2 CC6.3 | Account disablement plus the leaver risk report |
| Information is classified and owned | ISO 27001 A.5.12 · A.5.9 | Four-level classification and per-item ownership |
| Appropriate technical protection of personal data | GDPR art. 32 | AES-256-GCM at rest, self-hosting, access logging |
| Cryptography is used appropriately | ISO 27001 A.8.24 | Authenticated encryption, PBKDF2 600k, per-user key wrapping |
| Logging and monitoring of access | ISO 27001 A.8.15 · NIS2 art. 21(2)(b) | Item history, user logs, operational statistics |
Indicative mapping only. Teampass is not certified against any of these frameworks, and certification would not transfer to your deployment if it were.
Teampass runs on infrastructure you choose. There is no vendor cloud in the path, no sub-processor list, no cross-border transfer to justify. For a GDPR record of processing, the entry is short: the data stays where you put it.
The browser extension does not change this. Credentials travel between the extension and your own Teampass instance — they do not transit our servers. See the extension privacy policy.
Install it, point it at a copy of your access model, and see what the evidence export actually looks like.