Skip to content
Compliance

Governance, audit and compliance evidence

Access recertification, rotation tracking and exportable evidence. Teampass will not make you compliant — no software does — but it produces the artefacts your auditor asks for.

A note on the word "compliant". No tool makes an organisation compliant with ISO 27001, NIS2, GDPR or SOC 2 — those apply to how you operate, and are assessed by an auditor, not by a vendor. What Teampass does is generate the access-control evidence those frameworks expect you to be able to produce. Every mapping on this page is phrased as "supports", and it means exactly that.

Access recertification

The review, and the proof that it happened

A recertification campaign takes the current access model, routes each grant to the person accountable for it, and records an approve-or-revoke decision against it. Those decisions are immutable: once recorded they cannot be edited, which is the property that makes them evidence rather than notes.

The output answers the three questions that usually go unanswered — who has access, who confirmed they should, and when. Not reconstructed from memory the week before an audit, but captured as the review happened.

Scope the campaign

Pick the folders, roles or users under review.

Route to owners

Each access goes to the person who can actually judge it.

Record decisions

Approve or revoke, timestamped and immutable.

Export the evidence

CSV, ready to attach to an audit file.

The Teampass administration options, showing the Governance and compliance settings category
Where it is configured Governance and compliance is a settings category of its own, next to integrations, logging and authentication — not a bolt-on.
Evidence

What you can hand over

Access matrices

Who can reach which folders and items, derived from the live model rather than a maintained-by-hand document.

Rotation evidence

When each credential was last changed, measured against the rotation policy for its folder, with an overdue report.

Classification & ownership

Four classification levels and a named owner per item, so sensitivity and accountability are recorded rather than assumed.

Leaver risk report

The credentials a departing account could reach — the exact scope of the rotation you owe after an exit.

Per-item history

Views, edits and shares recorded against each item, for the incident where "who saw this" stops being hypothetical.

Posture reporting

Weak, reused, breached and overdue credentials, scored continuously and attributable per user.

Framework mapping

Where these features land in the frameworks

Indicative, not a certification and not legal advice. Confirm the mapping with your own auditor — control numbering changes between revisions.

Expectation Typical reference Teampass supports it with
Access is granted on a defined basis ISO 27001 A.5.15 · SOC 2 CC6.1 Folder tree, roles, per-user overrides, rights matrix
Access rights are reviewed periodically ISO 27001 A.5.18 · SOC 2 CC6.2 Recertification campaigns with immutable decisions
Privileged access is restricted and tracked ISO 27001 A.5.15 · NIS2 art. 21(2)(i) Role scoping, admin lockout controls, per-item history
Authentication information is managed securely ISO 27001 A.5.17 Encrypted storage, TOTP/SSO, password policy and generator
Access is removed on termination ISO 27001 A.5.11 · SOC 2 CC6.3 Account disablement plus the leaver risk report
Information is classified and owned ISO 27001 A.5.12 · A.5.9 Four-level classification and per-item ownership
Appropriate technical protection of personal data GDPR art. 32 AES-256-GCM at rest, self-hosting, access logging
Cryptography is used appropriately ISO 27001 A.8.24 Authenticated encryption, PBKDF2 600k, per-user key wrapping
Logging and monitoring of access ISO 27001 A.8.15 · NIS2 art. 21(2)(b) Item history, user logs, operational statistics

Indicative mapping only. Teampass is not certified against any of these frameworks, and certification would not transfer to your deployment if it were.

Data residency

There is no processor to assess

Teampass runs on infrastructure you choose. There is no vendor cloud in the path, no sub-processor list, no cross-border transfer to justify. For a GDPR record of processing, the entry is short: the data stays where you put it.

The browser extension does not change this. Credentials travel between the extension and your own Teampass instance — they do not transit our servers. See the extension privacy policy.

Run a recertification campaign before you commit.

Install it, point it at a copy of your access model, and see what the evidence export actually looks like.