How can we help you?

Find answers to the most frequently asked questions about the MindYourPass platform.
In hoeverre is MindYourPass digitaal soeverein?
What is the proven MindYourPass approach?
How is my MindYourPass account secured?
What technical security measures does MindYourPass take?
Which laws, regulations, standards, and certifications does MindYourPass comply with?
Where is the data stored?
What data does the MindYourPass Agent collect?
Does MindYourPass store my account passwords?
How does MindYourPass protect my privacy?
What types of passwords does MindYourPass distinguish?
Is my easy-to-remember password sufficient to gain access?
What is the easy-to-remember password?
Why does MindYourPass require user verification?
How do I contact MindYourPass Support?
Where can I find manuals and additional documentation?
I have a question about using MindYourPass. Where can I go for help?
Where can I find the implementation guides and additional documentation?
Can we start small and expand later?
Can MindYourPass be implemented in phases?
How long does an implementation take?
Who carries out the implementation?
What support does MindYourPass offer for a successful implementation and adoption?
Why is focusing on user adoption important?
What does the technical implementation involve?
What does the MindYourPass implementation process look like within an organization?
How does the 14-day free insight trial work?
Can MindYourPass be integrated with Single Sign-On (SSO)?
Which operating systems are supported?
Which browsers are supported?
Does MindYourPass work with all types of applications?
Can I set security policies per application or site?
What is the difference between warning and enforcing?
How does MindYourPass help users comply with security policies?
What makes enforcement with MindYourPass different?
Which policy measures can I set centrally?
What is the difference between the Dashboard and the Control Center?
What is the MindYourPass Portal?
What cryptography does MindYourPass use?
Where does the password calculation take place?
How is the password calculation technically structured?
Where is the data for the password calculation stored?
What data does MindYourPass use to calculate a password?
How does MindYourPass's vaultless technology work?
What is vaultless password technology?
Can I also use MindYourPass for personal purposes?
Which browsers does MindYourPass support?
Does MindYourPass also work on mobile devices?
Does MindYourPass support Multi-Factor Authentication (MFA) and TOTP codes?
Can you also manage notes in the MindYourPass Password Manager?
How does secure account sharing work?
How does autofill work?
Can I use Windows Hello, biometric verification, or a FIDO2 security key to log in to web applications that only support passwords?
Does MindYourPass work with Single Sign-On (SSO)?
Ondersteunt MindYourPass beheer van passkeys?
How does MindYourPass protect against phishing?
Which reports are available?
How does the MindYourPass Assessment work?
What is the MindYourPass Security Score?
How does the MindYourPass Agent measure password security?
Hoe meet de MindYourPass Agent de daadwerkelijke adoptie van bestaande wachtwoordkluizen?
How does MindYourPass map password management?
Which authentication methods does MindYourPass identify?
Which web applications does the MindYourPass Agent detect?
What insights does MindYourPass offer?
How does the MindYourPass Portal work?
How does the MindYourPass Password Manager work?
How does the MindYourPass Agent work?
Which organizations is MindYourPass intended for?
How does MindYourPass help organizations transition to passwordless?
What makes MindYourPass different from other password managers?
Why does a password manager remain important?
Why are SSO, MFA, and passkeys not enough on their own?
Why is MindYourPass more than just a password manager?
What software does MindYourPass consist of?
What problem does MindYourPass solve?
How do you set the policy?
Is enforcement mandatory?
What policies and requirements can you set and enforce?
How strong are the passwords that MindYourPass generates?
What is MindYourPass?
How long does a baseline measurement take?
What preparations do I need to make?
General
What is MindYourPass?
1

MindYourPass is a Dutch platform for secure digital access. It provides organizations with control over the applications they use, authentication methods, password security, and login risks. At the same time, it enables employees to sign in easily and securely while allowing organizations to centrally manage and enforce security policies.

By combining visibility, security, and ease of use for every login, MindYourPass helps organizations bridge today's password-based reality with tomorrow's passwordless future—using phishing-resistant passwords where needed and passkeys wherever possible.

What problem does MindYourPass solve?
2

Organizations often lack sufficient visibility into which applications employees are using, how they log in, and where risks arise from weak, reused, or leaked passwords.

At the same time, secure login practices are fragmented across passwords, MFA, SSO, and passkeys. This makes it difficult to implement centralized policies, ensure compliance, and provide employees with a simple user experience.

MindYourPass brings this environment together. It gives organizations control over every login, helps to specifically reduce risks, and supports the transition from passwords to passwordless.

Why is MindYourPass more than just a password manager?
3

A traditional password manager helps users manage and usually auto-fill passwords. MindYourPass offers this functionality as well, but goes further.

In addition to a powerful password manager, MindYourPass provides organizations with insight into applications, authentication methods, password usage, and login risks. Based on this, organizations can centrally apply and enforce security policies, ensuring secure logins are guaranteed across the entire organization.

Furthermore, MindYourPass distinguishes itself with its patented vaultless technology and supports organizations in the controlled transition from passwords to passwordless.

This is how MindYourPass combines insight, control, security, and ease of use into one platform.

Why are SSO, MFA, and passkeys not enough on their own?
4

Single Sign-On (SSO), Multi-Factor Authentication (MFA), and passkeys are key technologies for making digital access more secure. Yet, many organizations still support hundreds of applications that do not use these features and remain dependent on passwords.

It is precisely within these applications that many cyber risks arise, such as weak or reused passwords and phishing. For this reason, passwords will remain an important part of the application landscape for years to come, and secure password usage remains essential.

SSO, MFA, and passkeys are therefore not a replacement for good password management, but a valuable addition to it.

Why does a password manager remain important?
5

Although an increasing number of applications now support SSO and passkeys, a large portion of the current application landscape still relies on passwords. For these applications, strong, unique passwords remain the foundation for secure digital access.

In practice, it is virtually impossible for users to remember a strong, unique password for every application. A password manager therefore helps users securely generate, store, and automatically fill in passwords. This significantly reduces the risk of weak, reused, or easily guessed passwords and makes secure logging in easier for users.

What makes MindYourPass different from other password managers?
6

Traditional password managers primarily help users manage passwords securely and often fill them in automatically. In doing so, they solve part of the password problem.

MindYourPass goes further. In addition to a powerful password manager, it provides organizations with continuous insight into applications, authentication methods, password usage, and login risks. Based on this, organizations can centrally apply and enforce security policies, ensuring that secure login is not dependent on the behavior of individual users.

Furthermore, MindYourPass supports both passwords and passkeys from a single platform. Organizations gain insight into their passwordless readiness and can realize the transition to passkeys step-by-step, while applications that still rely on passwords remain securely supported.

MindYourPass also distinguishes itself through its patented vaultless technology, which ensures that passwords are not stored in a traditional password vault.

This is how MindYourPass helps organizations continuously improve digital access: from secure and phishing-resistant password usage today to a controlled transition to passwordless.

How does MindYourPass help organizations transition to passwordless?
8

For most organizations, a fully passwordless environment is not yet a reality. Although an increasing number of applications support passkeys, a large portion of the application landscape still relies on passwords.

MindYourPass helps organizations manage this transition in a controlled manner. The platform provides insight into which applications use passwords, SSO, MFA, and passkeys, allowing organizations to assess their passwordless readiness and prioritize improvements effectively.

At the same time, MindYourPass supports both passwords and passkeys from a single platform. This enables organizations to implement passkeys where possible, while ensuring that applications still dependent on passwords remain supported in a secure and user-friendly way.

In this way, MindYourPass helps organizations make the transition from passwords to passwordless step by step, without compromising on security or ease of use.

Which organizations is MindYourPass intended for?
7

MindYourPass was developed for organizations that want to manage digital access in a secure, controllable, and future-proof way. The platform is suitable for small, medium, and large organizations alike and is used across sectors including government, healthcare, education, housing associations, accounting, and the corporate world.

Whether an organization wants to get started with secure password management, implement passkeys, comply with laws and regulations like NIS2, or gain better insight into applications and login risks: MindYourPass supports every stage of the journey toward secure digital access.

Thanks to its modular design, organizations can start by gaining insight through monitoring and then expand the platform with secure password management, passkeys, and centralized security policies.

Platform
What software does MindYourPass consist of?
1

The MindYourPass platform consists of three components that work together to help organizations make digital access visible, secure, and manageable.

MindYourPass Agent – Continuously provides insight into the applications in use, authentication methods, password usage, and login risks. The Agent can also be deployed as a standalone solution for a baseline assessment, enabling organizations to first gain visibility into their current situation before taking the next steps.

MindYourPass Password Manager – Helps users log in securely using strong passwords, passkeys, and other modern authentication methods.

MindYourPass Portal – Provides dashboards, reporting, and the ability to centrally define, apply, and enforce security policies.

The three components complement each other. Organizations can start by gaining insight with the Agent and then expand the platform with secure password management, passkeys, and centralized security policies. Alternatively, all components can be deployed together from the outset.

How does the MindYourPass Agent work?
2

The MindYourPass Agent is a browser extension that continuously gathers insights into the use of web applications within your organization. The Agent maps out applications, authentication methods, password security, and login risks, enabling organizations to implement targeted improvements.

The gathered insights are displayed in the MindYourPass Portal. This allows organizations to identify risks, prioritize improvements, and track the progress of their security policy.

The Agent can be deployed independently for a baseline measurement or assessment, but it also serves as the foundation for continuous monitoring as part of the full MindYourPass platform.

The Agent was developed with privacy as a core principle. The collected data cannot be traced back to individual users and is used exclusively to provide organizations with insight into risks and opportunities for improvement. More information on this can be found in the Privacy FAQ.

How does the MindYourPass Password Manager work?
3

The MindYourPass Password Manager helps users log in to web applications safely and easily. Users can generate strong, unique passwords and have them filled in automatically. In addition, the password manager supports passkeys, secure credential sharing, and the secure storage of sensitive information, such as Secure Notes and secrets.

The password manager also contributes to phishing-resistant logins by allowing users to authenticate securely without manually entering passwords. Furthermore, users are alerted to leaked passwords and other security risks, enabling timely action.

In combination with the MindYourPass Portal, organizations can centrally manage and enforce security policies. This makes secure logging in not only easier for users, but also more manageable for the organization.

The MindYourPass Password Manager uses patented vaultless technology. As a result, passwords are not stored in a traditional password vault, while users still enjoy the same user-friendly login experience.

How does the MindYourPass Portal work?
4

The MindYourPass Portal is the central management environment for the MindYourPass platform. It provides organizations with real-time insight into applications, authentication methods, password security, and digital access risks.

In addition to dashboards and reports, the Portal offers the ability to centrally manage and enforce security policies. Organizations can prioritize risks, implement improvements, and continuously monitor the progress of their security policies.

By bringing insight, policy, and reporting together in one central environment, the MindYourPass Portal helps organizations make digital access structurally more secure and easier to manage.

Gaining insight
How long does a baseline measurement take?
10

A MindYourPass Assessment typically takes approximately one month to complete.

The process consists of three steps:

  1. Preparation – Installation of the MindYourPass Agent and, if desired, communication with end users.
  2. Measurement – During approximately one month, the Agent analyzes browser login activity to identify web applications, authentication methods and password security.
  3. Reporting – After the measurement period, MindYourPass prepares a report and presents the results, including identified risks, insights and recommendations for improvement.

The exact duration may vary depending on the organization's planning and the speed at which the Agent is deployed.

What preparations do I need to make?
11

Before the measurement starts, you can easily perform the following two actions independently: Install measurement software on employees' business laptops/PCs based on instructions. Communication to staff. MindYourPass is here to help.

What insights does MindYourPass offer?
1

MindYourPass provides organizations with continuous insight into the security of digital access to all web applications. The MindYourPass Agentmaps five key components of digital access:

  • Applications – which web applications are used within the organization, including Shadow IT and Shadow AI.
  • Authentication methods – how users log in, such as with passwords, MFA, SSO, and passkeys.
  • Password management – which password vaults and storage methods are used, such as browser storage, built-in password managers, or enterprise password managers.
  • Password security – the quality of password usage, including weak, reused, and leaked passwords.
  • Digital access risks – the most significant risks, passwordless readiness, and areas for improvement to make digital access more secure.

All insights are available through clear dashboards and reports at the organization, department, and application level. This allows organizations to prioritize security measures based on current data rather than assumptions.

Which web applications does the MindYourPass Agent detect?
2

The MindYourPass Agent automatically maps which web applications are used within the organization. This provides an up-to-date overview of the applications employees are actually using, regardless of whether they have been approved by IT.

In addition to business applications, the MindYourPass Agent also detects unauthorized applications (Shadow IT) and AI tools.

For each application, MindYourPass provides insight into aspects such as organizational usage, authentication methods applied, password management (input method), password security, and key digital access risks. This allows organizations to pinpoint exactly where improvements will have the most impact.

Which authentication methods does MindYourPass identify?
3

MindYourPass identifies which web applications use password authentication. Since the majority of web applications worldwide still rely on passwords, this provides immediate insight into a large portion of your application landscape.

Applications that do not use passwords typically rely on Single Sign-On (SSO) or other modern authentication methods. Consequently, this monitoring serves as an important first step in gaining insight into your organization's current authentication landscape and its passwordless readiness.

Support for detecting additional authentication methods, such as SSO, Multi-Factor Authentication (MFA), and passkeys, will be further expanded in the coming period.

How does MindYourPass map password management?
5

MindYourPass analyzes how passwords are actually used when logging into web applications. This provides insight into how employees manage their passwords.

The platform distinguishes between manual entry, browser autofill, enterprise password manager autofill, and copy-pasting, among other methods. This reveals the extent to which secure password management is being practiced within the organization.

MindYourPass doesn't just show organizations which password managers are being used, but more importantly, to what extent they are actually being utilized during daily logins. Instead of just looking at activated licenses or the number of stored passwords, MindYourPass analyzes all password-based logins and the methods used to enter them. This provides a realistic picture of secure password management adoption and highlights where improvements can still be made.

Hoe meet de MindYourPass Agent de daadwerkelijke adoptie van bestaande wachtwoordkluizen?
6

Veel organisaties meten de adoptie van een wachtwoordmanager aan de hand van het aantal geactiveerde licenties of het aantal opgeslagen wachtwoorden. Deze cijfers geven echter geen betrouwbaar beeld van het daadwerkelijke gebruik.

De MindYourPass Agent analyseert daarom alle wachtwoordgebaseerde logins binnen de organisatie en kijkt hoe wachtwoorden worden ingevoerd. Hierbij wordt onderscheid gemaakt tussen handmatige invoer, automatisch invullen vanuit de browser, automatisch invullen met een enterprise wachtwoordmanager en het gebruik van kopiëren en plakken.

Hierdoor wordt zichtbaar in welke mate een wachtwoordmanager daadwerkelijk wordt gebruikt tijdens het dagelijks inloggen. Dit geeft organisaties een realistisch beeld van de adoptie van veilig wachtwoordbeheer en laat zien waar nog verbeteringen mogelijk zijn.

How does the MindYourPass Agent measure password security?
4

The MindYourPass Agent continuously analyzes the security of passwords used within your organization. The platform checks for issues such as weak passwords, password reuse, and leaked credentials.

It also provides insight into whether the password for your primary organizational account, such as Microsoft Entra ID (Active Directory) or Google Workspace, is being reused for other web applications. This helps organizations identify one of the most common and high-risk forms of password reuse.

The results are combined with information on web applications, password management, and digital access risks. This makes it clear where the greatest risks lie and which improvement measures will have the most impact. By monitoring password security continuously rather than just periodically, organizations always have an up-to-date view of the security of their digital access.

What is the MindYourPass Security Score?
8

The MindYourPass Security Score provides organizations with a single overview of the security of their digital access. The score is displayed as a rating from A to E and is based on a weighted assessment of collected insights regarding web applications, authentication methods, password management, password security, and digital access risks.

When determining the score, not all risks are weighted equally. Critical applications and business-sensitive accounts have a greater impact on the Security Score than less critical applications, ensuring the rating aligns with the actual risk to the organization.

The Security Score highlights the areas with the greatest room for improvement and shows how security evolves over time. This allows organizations to set priorities, track the progress of improvement measures, and monitor the effectiveness of their security policy.

The Security Score is available at the organization, department, and application level, allowing risks to be analyzed and addressed in a targeted manner.

How does the MindYourPass Assessment work?
9

The MindYourPass Assessment is an accessible way to gain insight into the security of digital access within an organization.

Over a period of approximately one month, the MindYourPass Agent collects data on the use of web applications, authentication methods, password management, password security, and digital access risks. Based on this, MindYourPass compiles a report detailing the key findings, risks, and recommendations.

The Assessment shows organizations where the greatest risks lie, which improvement measures will have the most impact, and the extent to which the organization is prepared for the transition to passwordless authentication. It provides an objective basis for prioritizing improvements and measuring progress over time.

Which reports are available?
7

MindYourPass provides clear dashboards and reports that help organizations continuously monitor and improve the security of their digital access.

Reports are available in real-time at the organizational, departmental, and application levels. This allows organizations to analyze risks, track developments over time, and gain insight into the effectiveness of implemented measures.

The reports provide insight into areas including web applications, authentication methods, password management, password security, digital access risks, and the MindYourPass Security Score. This gives organizations up-to-date management information to prioritize security measures and make informed decisions.

How does the 14-day free insight trial work?
12

Get 14 days of free insights and easily discover how your organization uses web applications and what the risks are regarding digital access. Anonymous and privacy-friendly.

The process consists of four steps:

1. Request 14 days of free insights
After your request, you will receive the necessary software and a short installation guide.

2. Install the MindYourPass Agent
The Agent can be centrally deployed on managed devices by your IT department or partner. Installation usually takes just a few minutes.

3. Gain insights via the Dashboard
For 14 days, the Agent automatically and privately maps the use of web applications, authentication methods, and password security. The measurement runs in the background and does not affect user workflows.

4. Receive your results and determine the next steps
After the period ends, you will receive an overview of the key insights and recommendations. You then decide how to proceed: you can end the measurement, continue monitoring, or opt for a comprehensive Assessment with additional analyses, a risk assessment, and a presentation of the results.

Secure & easy sign-in
What types of passwords does MindYourPass distinguish?
15

Depending on the situation, you may encounter three different types of passwords or authentication methods.

Master password or SSO password

Use this to sign in to your MindYourPass account.

  • Private users use a master password.
  • Business users usually sign in via Single Sign-On (SSO), for example using their Microsoft 365, Google, or other organizational account.

Easy-to-remember password

The easy-to-remember password is the standard MindYourPass user authentication method. It is part of the generation process that MindYourPass uses to calculate account passwords.

Instead of an easy-to-remember password, you can also choose biometric authentication or a QR code.

Account passwords

Account passwords are the unique passwords you use to sign in to your web applications.

By default, MindYourPass automatically creates and calculates a unique, strong account password of up to 128 characters for every web application. You do not need to remember or manually enter these passwords.

Would you like to (temporarily) continue using your existing passwords? You can choose traditional passwords. MindYourPass will then use your existing account passwords until you choose to replace them with automatically calculated account passwords.


Please note: the master password (of SSO password) is used exclusively to log in to your MindYourPass account. The easy-to-remember password is used for user authentication before MindYourPass calculates an account password or uses a passkey.

Is my easy-to-remember password sufficient to gain access?
14

No.

The easy-to-remember password is just one of the components MindYourPass uses to calculate the password for one of your accounts.

Each calculation also requires your personal MindYourPass account, the relevant web application, and several cryptographic components of MindYourPass. These components are not known to users and cannot be easily discovered by third parties.

Furthermore, the easy-to-remember password is not used as the password for your web applications and is not stored as such.

As a result, someone who only knows your easy-to-remember password cannot simply calculate or use your passwords.

What is the easy-to-remember password?
13

The easy-to-remember password is the standard user authentication method for MindYourPass. It is part of the generation process used by MindYourPass to calculate passwords.

Before MindYourPass calculates a password or uses a passkey, it first verifies that you are the authorized user. This aligns with the Zero Trust principle: a user is not automatically trusted, but must verify their identity before access is granted.

Unlike the passwords for your web applications, the easy-to-remember password does not need to be unique or complex. In fact, you should choose a password that is easy for you to remember.

Because MindYourPass automatically calculates a unique and strong password for every web application, you no longer need to remember separate passwords for your web applications.

By default, the easy-to-remember password is used for user authentication. You can also choose to use biometric authentication or a QR code.

Why does MindYourPass require user verification?
12

MindYourPass operates according to the Zero Trust principle: a user is not automatically trusted. Before a password is calculated or a passkey is used, MindYourPass therefore requires user verification. This confirms that the authorized user is performing the action.

Depending on your preference, you can verify yourself using:

  • a memorable password (default);
  • biometric verification (FIDO2), such as a fingerprint or facial recognition and FIDO2 keys;
  • a QR code with the MindYourPass app.

The chosen verification method is part of the generation process and is separate from logging into your MindYourPass account.

More information about the memorable password can be found in the relevant FAQ.

Can I also use MindYourPass for personal purposes?
11

Yes. Anyone can use the MindYourPass Password Manager for free to manage personal passwords and other private data.

Users with a MindYourPass business account can easily use a personal environment alongside their business environment. Business and personal data remain logically separated, ensuring both user privacy and organizational control.

The personal environment is fully owned by the user and will always remain free to use, even if the business account ends, for example when leaving a job or switching to a different employer. Personal passwords, passkeys, secure notes, and other private data are retained and remain accessible. A paid personal subscription is not required for this.

This allows users to use the same trusted password manager for both work and personal life, without being dependent on their employer and without the risk of losing personal data when leaving the company.

Which browsers does MindYourPass support?
10

MindYourPass is available as a browser extension for the most popular browsers, including:

  • Google Chrome
  • Microsoft Edge
  • Safari
  • Mozilla Firefox
  • Brave
  • Other Chromium-based browsers

The browser extension supports features such as autofill, password management, passkeys, and secure login for web applications.

Does MindYourPass also work on mobile devices?
9

Yes. The MindYourPass Password Manager is available as a mobile app for iOS and Android.

The app allows users to securely log in to sites and web applications, manage passwords and passkeys, and use strong authentication methods, such as biometric verification. In addition, the app provides access to Secure Notes and allows for the secure management of TOTP codes for Multi-Factor Authentication (MFA).

The mobile app is designed as a secure complement to the browser extension. This allows users to log in easily and securely while on the go, while organizations maintain the same high security standards and user-friendly login experience.

Does MindYourPass support Multi-Factor Authentication (MFA) and TOTP codes?
8

Yes. MindYourPass supports Time-based One-Time Passwords (TOTP), the most widely used form of Multi-Factor Authentication (MFA).

TOTP codes can be securely managed in the MindYourPass Mobile App for iOS and Android. This ensures that users always have their second login factor—the MFA code—available on a separate device, such as their smartphone when working on a computer.

MindYourPass makes this choice deliberately. When both the password and the MFA code are used on the same device, the principle of multiple independent authentication factors is often compromised. By making TOTP codes available on a second device, this separation is maintained and security is strengthened.

In addition to TOTP, MindYourPass also supports other strong authentication methods, such as passkeys and credential generation via Windows Hello, biometric verification, and FIDO2 security keys.

Can you also manage notes in the MindYourPass Password Manager?
7

Yes. With Secure Notes, users can safely store and manage confidential information, such as recovery codes, PINs, or other sensitive data, within MindYourPass.

Just like passwords, Secure Notes are not stored in a central vault. They are protected by the same patented vaultless technology as the MindYourPass Password Manager, ensuring that sensitive information is only accessible to authorized users.

Secure Notes are currently available in the MindYourPass Mobile App for iOS and Android. Support for secure notes in the browser extension will be added in a future release.

How does secure account sharing work?
6

With MindYourPass, users and administrators can securely share login credentials without passwords being visible or needing to be shared manually.

Users who have been granted access to a shared account can log in directly via the MindYourPass Password Manager. The password is filled in automatically, but is generally not visible to the user.

Administrators centrally determine which users have access to shared accounts. Access can be changed or revoked at any time, without the need to share the password again.

This allows organizations to manage shared accounts securely, while users get easy access to the web applications they need.

How does autofill work?
5

The MindYourPass Password Manager automatically detects when a supported web application is opened. Once the user is verified, MindYourPass automatically fills in the correct login credentials, so users don't have to manually enter a username or password.

Autofill only occurs on the correct web application. Because passwords are domain-bound, they cannot be entered on a phishing site or any other domain posing as the original website.

For users, this results in a fast and consistent login experience, while organizations retain control over how and where users can log in.

Is autofill unavailable? Then the user can enter the login credentials using the clipboard flow (copy/paste).

Can I use Windows Hello, biometric verification, or a FIDO2 security key to log in to web applications that only support passwords?
4

Yes. With MindYourPass, users can also log in passwordlessly to web applications that only support usernames and passwords.

Users first authenticate via the MindYourPass Password Manager, for example using Windows Hello, a fingerprint, facial recognition, or a FIDO2 security key. After successful verification, MindYourPass automatically calculates and fills in the correct login credentials for the web application. For the user, this feels like a passwordless login, while the web application continues to work with a password in the background.

This allows organizations to offer users a modern, phishing-resistant login experience, even for existing web applications that do not yet support passkeys or other passwordless authentication methods.

Does MindYourPass work with Single Sign-On (SSO)?
3

Yes. MindYourPass integrates with existing Single Sign-On (SSO) solutions, such as Microsoft Entra ID, Okta, and other Identity Providers that support SAML or OpenID Connect.

Web applications that already support SSO continue to use the existing Identity Provider directly. MindYourPass does not take over this authentication and does not change the existing SSO login flow.

Users sign in to MindYourPass using SSO via the organization's Identity Provider. From there, they can also securely log in to web applications that are not linked to SSO and still require a password. For the user, this feels like the same simple login experience as SSO, for example using Windows Hello, biometric verification, or a FIDO2 security key, without them ever having to enter passwords again.

This creates a single, consistent login experience for all web applications, regardless of whether they use SSO, passkeys, or passwords. MindYourPass calls this Total Sign-On: extending the benefits of Single Sign-On to web applications that do not yet support SSO.

This offers similar benefits for organizations as well. Access to the MindYourPass Password Manager can be managed centrally via the Identity Provider. As a result, existing security measures, such as user provisioning, deprovisioning, and conditional access, can also be applied to access for web applications that still rely on passwords.

Ondersteunt MindYourPass beheer van passkeys?
2

Ja. Naast wachtwoorden ondersteunt MindYourPass ook veilig beheer van passkeys.

Gebruikers kunnen hierdoor veilig en eenvoudig inloggen, ongeacht of een webapplicatie gebruikmaakt van wachtwoorden of passkeys.

In tegenstelling tot veel standaard passkey-oplossingen, waarbij passkeys vaak zijn gekoppeld aan een specifiek apparaat, besturingssysteem of ecosysteem, zijn passkeys via MindYourPass beschikbaar op ieder apparaat waarop de gebruiker met MindYourPass werkt.

Zo combineert MindYourPass het gebruiksgemak van passkeys met de flexibiliteit die organisaties en gebruikers nodig hebben.

How does MindYourPass protect against phishing?
1

MindYourPass helps organizations significantly reduce phishing risks during login.

When users log in with a passkey, authentication is inherently phishing-resistant.

For web applications that still use passwords, MindYourPass provides an additional layer of protection. Its patented vaultless technology generates a unique, domain-bound password for every website. This ensures that passwords cannot be interchanged between sites, meaning a password intended for one website cannot be used on another.

In addition, the MindYourPass Password Manager only auto-fills login credentials on the correct website. This eliminates the need for users to manually enter or copy and paste passwords, further reducing the risk of successful phishing.

In this way, MindYourPass offers a single, secure login experience for both password-based and passwordless applications.

How strong are the passwords that MindYourPass generates?
16

MindYourPass generates a unique and random account password for every web application. The strength of these passwords is determined by three key characteristics:

  • Length – MindYourPass can generate account passwords of up to 128 characters. Passwords of this length are, with current technology, practically impossible to crack using brute-force attacks.
  • Randomness – Every generated account password is completely random. This makes the passwords unpredictable and prevents them from being guessed based on patterns or found in password dictionaries.
  • Uniqueness – A unique account password is generated for every account. As a result, if one password is compromised, it cannot be used to access any of the user's other accounts.

Not all web applications support passwords of up to 128 characters. Therefore, MindYourPass automatically adjusts the password length to the maximum supported by each application. Even shorter randomly generated passwords—for example, 32 characters—provide an exceptionally high level of security.

Setting & enforcing policy
What is the MindYourPass Portal?
1

The MindYourPass Portal is the central management environment for MindYourPass. From the Portal, administrators gain insight into digital access within the organization and can centrally manage security policies.

The Portal includes various features, the two most important of which are:

  • Dashboard – for insights, reporting, and monitoring the security status.
  • Control Center – for configuring, applying, and enforcing security policies.

From the Portal, organizations can, among other things, analyze web applications, prioritize security risks, view reports, and manage policies for passwords and secure access.

What is the difference between the Dashboard and the Control Center?
2

The Portal consists of several components. The two most important are the Dashboard and the Control Center. Both have their own specific function.

Dashboard

The Dashboard provides insight into digital access within the organization. Here you can see, among other things:

  • Web applications and accounts
  • Authentication methods used
  • Use of password managers
  • Adoption of the MindYourPass Password Manager
  • Password security
  • Digital access risks
  • Security Score and trends
  • Reports and recommendations

The Dashboard helps organizations identify risks, prioritize improvements, and monitor progress.

Control Center

The Control Center is the management environment where security policies are configured and managed.

From the Control Center, organizations can set, modify, and apply security policies. The various policy options are explained in further detail in the following FAQs.

In short: the Dashboard provides insight into the current situation, while the Control Center is used to centrally manage security policies.

Which policy measures can I set centrally?
3

The MindYourPass Portal allows organizations to centrally manage security policies. These policies are defined in Protection Levels, which determine the security measures that apply to users and web applications.

With a Protection Level, you can define:

  • Whether the use of the MindYourPass Password Manager is mandatory.
  • The requirements that passwords must meet.
  • Whether users receive a warning or are required to take action when they do not comply with the policy.

Protection Levels can be applied to the entire organization, per department, or per individual web application. This allows organizations to implement security policies in a controlled, phased manner at a pace that suits them.

What makes enforcement with MindYourPass different?
4

Traditional password managers are often optional in practice. Users can frequently still log in manually or use a different password manager. As a result, compliance with security policies remains dependent on user behavior.

With Protection Levels MindYourPass can enforce security policies through software. When a Protection Level requires it, MindYourPass becomes the only permitted way to log in to the relevant web application. This ensures that security policy compliance is technically enforced.

The following FAQ explains what users experience when a Protection Level is enforced.

How does MindYourPass help users comply with security policies?
5

When a user logs in to a web application that requires a Protection Level, MindYourPass automatically checks whether the set security policy is being met.

If not, MindYourPass guides the user step-by-step to ensure compliance with the policy. Depending on the configured Protection Level, the user can, for example:

  • register the account in the MindYourPass Password Manager;
  • set a strong, unique, or MindYourPass-generated password;
  • replace a password that has been leaked, reused, or linked to the wrong identity.

Once the security policy requirements are met, the user can log in to the web application immediately.

What is the difference between warning and enforcing?
6

With a Protection Level, you not only determine the security requirements users must meet, but also how MindYourPass responds to them.

There are two options:

Warn

When a user does not meet the set security policy, they receive a warning. For example, if a password is reused or has been leaked. The user can choose to continue logging in without taking immediate action. This setting is suitable when an organization wants to first inform users or help them get used to a new security policy.

Enforce

When a user does not meet the set security policy, the required action must be completed before they can log in. MindYourPass guides the user through this step by step. This setting is suitable when an organization wants to enforce compliance with the security policy.

Can I set security policies per application or site?
7

Yes. Protection Levels can be applied to individual web applications, groups of web applications, departments, or the entire organization. This allows security policies to be tailored to the risk and importance of the applications.

To keep management simple, MindYourPass uses default Protection Levels for managed and unmanaged web applications. New web applications automatically adopt the corresponding default policy. You only need to set an exception if a different policy is required for a specific web application or group of web applications.

This approach minimizes management, prevents unnecessary maintenance, and ensures that newly discovered web applications are automatically covered by the correct security policy.

Vaultless technology
How does MindYourPass's vaultless technology work?
2

MindYourPass's patented vaultless technology calculates a password every time it is needed. As a result, passwords never need to be stored in a central or local password vault.

For every site or web application, the exact same password is calculated based on a set of unique data. Because the same input always leads to the same result, the password can be regenerated on any authorized device without ever needing to be stored.

Furthermore, the calculation is domain-specific. This ensures that a unique password is automatically used for every web application, preventing a password from being used on another website or phishing domain.

For the user, this works just like a traditional password manager: after verification, the correct login credentials are automatically filled in. Behind the scenes, however, passwords are calculated rather than stored.

What is vaultless password technology?
1

Traditional password managers store passwords in a central or local vault. The MindYourPass Password Manager works in a fundamentally different way.

Instead of storing passwords, MindYourPass calculates them the moment they are needed using patented vaultless technology. As a result, passwords never need to be stored, synchronized, or shared between devices.

This reduces the attack vector and prevents a central password vault containing all your passwords from becoming a target for cyberattacks. At the same time, users enjoy the same simple login experience as they would with a traditional password manager.

The same vaultless technology is also applied to other sensitive data that users manage in MindYourPass.

What data does MindYourPass use to calculate a password?
3

To calculate a password, MindYourPass uses a combination of unique data. Together, these ensure that the same password is always calculated for every user and every web application, without the need for it to be stored.

The calculation is based on three components:

  • The user's identity, such as an organizational identity or a personal identity.
  • The web application, ensuring that a unique, domain-specific password is calculated for every website or application.
  • User authentication, which verifies that the user is authorized to have the password calculated.

This combination creates a unique password for every user and every web application. If any of these components change, the result of the calculation changes as well.

The actual security architecture goes even further. The necessary data is stored in a distributed manner, and the final password calculation takes place on the user's device. As a result, no single party possesses all the information required to reconstruct a password.

Where is the data for the password calculation stored?
7

The data required to calculate a password is not stored in a single central location. Instead, MindYourPass's patented vaultless technology uses multiple, separate security data points sourced from different locations.

Some of the data comes from the user, some from the organization, and some is managed by MindYourPass. Furthermore, the security data is stored in separate, logically isolated environments.

This architecture ensures that no single user, administrator, server, or database independently possesses all the information needed to calculate a password. Only after an authorized user has successfully authenticated can the necessary data be securely brought together for the password calculation.

Because of this distributed storage, there is no central location containing all passwords or all necessary data. This reduces the impact of a potential security incident and contributes to the resilience of the solution.

How is the password calculation technically structured?
4

MindYourPass password calculation is based on multiple independent security data points. For every user and every web application, these data points are combined to calculate a unique password.

The calculation uses six security data points (codes and salts) related to the identity, web application, and user.

These security data points are distributed across different sources. Some are linked to the user, some to the organization, and some are managed by MindYourPass. As a result, no single user, administrator, server, or database independently possesses all the information required to calculate a password.

Only after a user has successfully authenticated are the necessary security data points brought together to calculate the password locally on the user's device.

This layered architecture ensures that a single compromised component is not enough to reconstruct passwords.

Where does the password calculation take place?
5

The final password calculation takes place locally on the user's device. To do this, the browser extension combines the necessary security data from various sources. The final password is calculated locally, used exclusively for authentication, and then immediately cleared from the system memory.

As a result, the password is not stored, not sent over the internet, and is not visible to MindYourPass itself.

What cryptography does MindYourPass use?
6

MindYourPass's vaultless technology uses modern cryptographic techniques to calculate passwords securely and reproducibly.

Password calculation is based on a cryptographic hash function (SHA-512). This function converts the necessary security data into a unique, irreversible result. Because the same input always produces the same output, a password can be recalculated every time without needing to be stored.

Thanks to this approach, passwords cannot be derived from the security data used, and they never need to be stored centrally or locally.

Compatibility & integrations
Does MindYourPass work with all types of applications?
1

Yes.

The MindYourPass Password Manager works with virtually all web applications where users log in via a browser using a username and password or passkeys. Because MindYourPass operates within the browser, no connections or integrations with individual web applications are required. This allows the solution to be used for both modern cloud applications and legacy web applications.

In addition, MindYourPass also supports applications that are not accessed via the web, such as on-premise or desktop applications, using the clipboard flow (copy-paste).

Which browsers are supported?
2

The MindYourPass browser extension is available for the most popular browsers:

  • Google Chrome
  • Microsoft Edge
  • Mozilla Firefox
  • Safari
  • Brave
  • Other Chromium-based browsers

Browser extensions are centrally managed and automatically updated via the official extension stores of the respective browsers.

Which operating systems are supported?
3

MindYourPass supports the most common operating systems:

  • Windows
  • macOS
  • iOS
  • Android

The browser extension is available for Windows and macOS. In addition, mobile apps are available for iOS and Android, allowing users to log in securely on smartphones and tablets as well.

Can MindYourPass be integrated with Single Sign-On (SSO)?
4

Yes. MindYourPass supports Single Sign-On (SSO) via OpenID Connect (OIDC) for logging into the MindYourPass Password Manager.

This allows users to log in with their existing corporate account, without needing to remember a separate master password for MindYourPass.

Privacy & security
How does MindYourPass protect my privacy?
1

MindYourPass has been developed according to the Privacy by Design principle. This means we only process the data necessary to ensure the solution functions safely and effectively.

Your passwords and other data are not stored and are not accessible to MindYourPass.

Does your organization use MindYourPass Monitoring or an Assessment? In that case, we only collect the data required to provide insight into application usage, authentication methods, and password security. The results are not traceable to individual employees, allowing organizations to gain insight into risks without unnecessarily compromising user privacy.

MindYourPass processes personal data in accordance with applicable privacy legislation. You can find more information about this in the MindYourPass privacy policy.

In hoeverre is MindYourPass digitaal soeverein?
5

MindYourPass is een Nederlandse oplossing: ons (hoofd)kantoor, systemen en data bevinden zich in Nederland. Voor onze infrastructuur maken we momenteel gebruik van Google Cloud in Eemshaven. Daarmee zijn we vooralsnog afhankelijk van een Amerikaanse cloudprovider.

Voor de vertrouwelijkheid is die afhankelijkheid beperkt. Wachtwoorden worden niet in een database opgeslagen en de verwerking van persoonsgegevens is tot het uiterste minimum beperkt. De belangrijkste afhankelijkheid van Google Cloud zit daarom in de beschikbaarheid en continuïteit van de dienstverlening.

Tegelijkertijd werken we aan de overstap naar een Europese cloudprovider. We verwachten deze overstap binnen enkele maanden af te ronden. Daarmee verminderen we onze afhankelijkheid van niet-Europese infrastructuur en vergroten we de digitale soevereiniteit van MindYourPass.

Does MindYourPass store my account passwords?
2

No. MindYourPass does not store your account passwords in a password vault or database.

Instead, MindYourPass calculates your account passwords the moment you log in to a web application. This means account passwords do not need to be stored centrally and cannot be retrieved from a vault at a later time.

This vaultless technology reduces the risks associated with centralized password storage and is a key component of the MindYourPass security architecture.

You can find more information about our vaultless technology in the Vaultless password technologysection.

What data does the MindYourPass Agent collect?
3

The MindYourPass Agent exclusively analyzes browser activities relevant to secure digital access. The Agent is not a general monitoring tool and does not collect data that is not necessary for this purpose.

Depending on the MindYourPass solution used, the Agent collects information including:

  • the web applications and websites visited;
  • password quality (strength, reuse, leaks)
  • the use of password managers.

The MindYourPass Agent does not collect account passwords and does not monitor the content of web pages, documents, emails, or other personal data.

With MindYourPass Monitoring and the Assessment, the results are also not traceable to individual employees. This provides organizations with insight into risks, trends, and areas for improvement without violating user privacy.

Where is the data stored?
4

MindYourPass processes and stores data within the European Economic Area (EEA). Appropriate technical and organizational security measures are applied to ensure the confidentiality, integrity, and availability of data.

MindYourPass distinguishes between different types of data. For instance, account information and configuration data are stored to ensure the service functions correctly, while account passwords are not stored, but are calculated exclusively at the moment you log in to a web application.

Would you like to know more about how data is processed and stored? Please consult the MindYourPass privacy policy or contact MindYourPass Support.

Which laws, regulations, standards, and certifications does MindYourPass comply with?
5

MindYourPass develops and delivers its services in accordance with recognized, statutory EU standards and guidelines for information security and privacy.

In addition, MindYourPass is:

  • ISO/IEC 27001 certified for information security;
  • Data Pro Certified, which demonstrates that our services meet the requirements of the General Data Protection Regulation (GDPR).

Furthermore, MindYourPass supports organizations in strengthening secure digital access and complying with relevant laws and regulations, such as the Network and Information Security Directive (NIS2).

More information about our certifications, security measures, and privacy policy is available upon request.

What technical security measures does MindYourPass take?
6

MindYourPass implements various technical and organizational security measures to ensure the confidentiality, integrity, and availability of data and services.

The services are secured by, among other things:

  • encrypted communication between users, systems, and the MindYourPass service (TLS);
  • encrypted data storage where applicable;
  • strong authentication and authorization for access to management environments;
  • logging and monitoring of services;
  • periodic security updates and patch management;
  • secure software development and periodic security testing.

In addition, account passwords and other sensitive (personal) data are not stored, but are calculated exclusively at the moment they are needed to log in to a web application.

By combining these security measures with MindYourPass's vaultless technology, the risk of misuse of centrally stored account passwords is minimized.

How is my MindYourPass account secured?
7

MindYourPass applies multiple layers of security to protect your account and access to your account passwords.

You sign in with a master password (personal users) or via Single Sign-On (SSO) (business users). When signing in on a new device for the first time, you will be asked to register this device as a trusted device . This verifies that the device is safe to use for accessing your MindYourPass account.

In addition, MindYourPass requires user authentication before account passwords are calculated or passkeys are used.

Account passwords are not stored; they are only calculated when needed to sign in to a web application. Combined with technical security measures and MindYourPass's vaultless technology, the risk of unauthorized access is significantly minimized.

More information about user authentication and trusted devices can be found in the chapter Secure and easy login.

Implementation
What does the MindYourPass implementation process look like within an organization?
1

The implementation of MindYourPass always begins with a technical setup.

For a MindYourPass Assessment or Monitoring, the implementation consists of the technical installation of the MindYourPass Agent.

Implementing the MindYourPass Password Manager involves both a technical software setup and an organizational rollout. In addition to the technical configuration, this includes a focus on user deployment, communication, onboarding, training, and user adoption.

Separate implementation guides are available for each solution, describing the implementation steps in detail.

What does the technical implementation involve?
2

The technical implementation depends on the chosen MindYourPass solution and consists of the installation, configuration, and any SSO integrations required to start using the solution.

Depending on the chosen solution, the technical implementation may include:

  • installation of the MindYourPass Agent (browser extension);
  • installation of the MindYourPass Password Manager (browser extension) and optionally the mobile app;
  • centralized deployment via Microsoft Intune or another MDM solution;
  • configuration of Single Sign-On (SSO) and automatic user provisioning via an Identity Provider;
  • access to the MindYourPass Portal, if applicable.

Not every implementation includes all components. The implementation guide for your chosen solution describes which steps apply.

Why is focusing on user adoption important?
3

When implementing a password manager, the focus is often on the technical setup. In practice, the organizational side frequently receives less attention, even though it is the key factor in determining the success of the implementation.

When users are not properly guided, adoption rates lag, and insecure login habits—such as continuing to use existing password managers, browser storage, or manually entered passwords—often persist.

That is why a successful password manager implementation consists of both a technical and an organizational rollout. For the MindYourPass Password Manager, user adoption is a standard part of our recommended implementation approach. By properly preparing, guiding, and supporting users, the transition becomes smoother, and secure login practices quickly become part of their daily routine.

What support does MindYourPass offer for a successful implementation and adoption?
4

MindYourPass provides support during both the technical and organizational implementation of the MindYourPass Password Manager.

Implementation guides with step-by-step instructions for administrators and IT are available for every solution. In addition, the online Help Center offers user manuals, Quick Starts, videos, tutorials, and FAQs for both end users and administrators.

Best practices for communication, onboarding, and user adoption are also available for the implementation of the MindYourPass Password Manager. If desired, organizations can make use of online training, on-site training, and implementation guidance provided by MindYourPass or an implementation partner.

Who carries out the implementation?
5

The technical implementation is typically carried out by the organization's IT department or the (external) workplace administrator. This involves deploying the necessary software and configuration based on instructions and support provided by MindYourPass where needed.

The organizational implementation of the MindYourPass Password Manager can be carried out by the organization itself with support from an implementation partner or MindYourPass. The focus here is on communication, onboarding, training, and user adoption.

MindYourPass Customer Support is happy to advise organizations on the most appropriate implementation approach and the available support.

How long does an implementation take?
6

The lead time for an implementation depends on the chosen solution and the size of the organization.

The technical implementation can usually be completed within a few hours. When implementing the MindYourPass Password Manager, additional time is required for organizational implementation, such as communication, user adoption, and any necessary training.

The implementation guide for each solution describes the implementation steps and the expected lead time.

Can MindYourPass be implemented in phases?
7

Yes. Organizations can choose to implement MindYourPass in phases. For example, by starting with an Assessment or Monitoring, or by rolling out the MindYourPass Password Manager incrementally across the organization.

When implementing the MindYourPass Password Manager, organizational rollout and user adoption can be phased, for instance by department, team, or location. This allows users to be guided step-by-step and enables the organization to gain experience before the solution is rolled out company-wide.

The implementation approach is tailored to the chosen solution, the size of the organization, and the desired phasing.

Can we start small and expand later?
8

Yes. MindYourPass is built on a modular structure. Organizations can start with one or more solutions and expand them at a later stage.

Many organizations start with an Assessment (1 month) or Monitoring (continuous) to gain insight into the web applications used, authentication methods, password security, and digital access risks. Based on these insights, they can determine which improvement measures will add the most value after just a few weeks.

Depending on the results, organizations may choose, for example, to roll out the MindYourPass Password Manager in phases, implement additional security measures, or introduce a centralized security policy.

Where can I find the implementation guides and additional documentation?
9

Separate implementation guides are available for every MindYourPass solution. These provide a step-by-step description of the technical implementation, configuration, and any necessary organizational deployment.

Comprehensive implementation documentation for administrators, IT departments, and implementation partners is available at mindyourpass.io/enterprise. Here you will find implementation guides, administrator manuals, technical documentation, and best practices for a successful rollout.

For end users, a Help Center is available at mindyourpass.io/help containing user manuals, quick-start guides, instructional videos, and answers to frequently asked questions.

Support
I have a question about using MindYourPass. Where can I go for help?
1

Are you using MindYourPass within an organization? Please contact your internal administrator, service desk, ambassador/key-user first. They can answer most questions regarding the use of MindYourPass.

Still need help? Consult the available documentation or contact MindYourPass Support.

Where can I find manuals and additional documentation?
2

Depending on your role, different documentation is available:

  • mindyourpass.io/help – for end users and private users. Here you will find user manuals, quick starts, instructional videos, and answers to frequently asked questions.
  • mindyourpass.io/enterprise – for organizations, administrators, and implementation partners. Here you will find implementation guides, administrator documentation, technical information, and best practices.
How do I contact MindYourPass Support?
3

Still having trouble after checking the documentation? Please contact MindYourPass Support at support@mindyourpass.com.

To help us resolve your query as quickly as possible, please provide a clear description of the issue and, if applicable, include relevant information such as screenshots or screen recordings, error messages, the relevant URL(s), your browser, and your operating system.