Your password vault provider isn't your backup plan
Sep 28, 2026
Plenty of people treat their password vault the way they treat email. It lives somewhere else, someone else keeps the lights on, and that's supposed to be enough. Most of the time it is. Until the provider isn't there anymore, and "somewhere else" turns out to be the only copy that ever existed.
The cloud won’t handle it
A vendor backing up its own systems is not the same thing as you having a way to get your data back.
Accounts get suspended over an alleged policy violation, sometimes with no warning and not much room to argue. Vendors get acquired or sunset a product line without much notice. And every so often a service just goes down longer than anyone budgeted for, usually right when someone needed a password to fix something else. This doesn’t require bad faith on the vendor's part. It just means the only copy of your vault was sitting on infrastructure you don't control.
Backups people can restore from
The people who take this seriously keep a local copy that doesn't depend on the vendor's servers being reachable. They encrypt it on their own terms rather than trusting whatever the provider ships by default. At least one copy lives somewhere physically separate, so a stolen laptop or a fire doesn't wipe out every copy at once.
Cloud storage is convenience. Whether you have a backup comes down to one question: can you restore from it without asking anyone's permission.
At company scale
Lose the vault that holds every shared system credential for a company and IT can't get into the infrastructure it's supposed to be fixing. Incident response doesn't start until access gets restored, which means restoring access becomes the emergency, layered on top of whatever emergency was already happening.
Most companies never find out their recovery plan runs on someone else's schedule until the day they need it.
Vault ownership, compared
Vendor-hosted vault | Self-hosted deployment |
|
|---|---|---|
|
Backup cadence |
Set by the vendor |
Set by your own IT policy |
|
Data location |
Wherever the vendor's infrastructure lives |
Your infrastructure, your choice |
|
Recovery path during a vendor outage or dispute |
Depends on the vendor's response |
Independent of any third party |
|
Redundancy and failover |
Whatever tier you're paying for |
Configured to match your own risk tolerance |
|
Compliance evidence |
Requested from the vendor |
Available directly, on demand |
Netwrix Password Secure runs as a self-hosted, scalable server-client system. Your organization sets the backup cadence, chooses where the data lives, and doesn't have to wait on a vendor's response to recover access. Redundancy, load balancing, and high-availability options are part of the architecture, not an upsell, and it deploys on-premises, in the cloud, or across both, depending on how your infrastructure is already set up. Whatever happens with a vendor relationship somewhere else in the business, the credential vault keeping your systems running stays out of it.
Netwrix Password Secure: self-hosted, so backup and recovery stay yours.
Learn moreShare on
Learn More
About the author
Sascha Martens
Chief Technology Officer
Insights from a security professional dedicated to breaking down today’s challenges and guiding teams to protect identities and data.
Learn more on this subject
To self-host or not to self-host your password manager
Static credentials are still AI's easiest way in
AI hacking makes password spraying faster. Here's how to close the gap
Self-hosted password vault: why security teams are taking the keys back
Your browser is not a vault. Please stop giving it the keys.