Password managers: why we chose Proton Pass

At Elefen, every sensitive credential — client sites, hosting accounts, admin accounts — goes through a password manager. Our choice: Proton Pass. An independent security audit, conducted by the firm Recurity Labs and published in May 2026, confirms the soundness of that decision. Here’s why this practice is essential for a web agency, and what it concretely changes for you.

A password manager: basic hygiene, not a luxury

A web agency holds the keys to dozens of sites: WordPress admin access, hosting accounts, domain names, payment gateways. Reusing passwords or storing them in a text file would be irresponsible — a single leak could compromise several clients at once. A password manager solves the problem at the source:

  • every service gets a unique, long, randomly generated password;
  • credentials are encrypted and shared in a controlled way within the team;
  • access can be revoked quickly, for example when an employee leaves.

Why we chose Proton Pass

Several password managers are excellent. We chose Proton Pass for verifiable reasons, not for the marketing:

  • Open code and public audits. Proton Pass’s code is open source and regularly submitted to independent audits whose results are published.
  • End-to-end encryption. Credentials are encrypted on the device before anything is sent to the servers: no one, not even Proton, can read them.
  • A protective jurisdiction. Proton is a Swiss company, subject to one of the world’s strictest legal frameworks for privacy.

What the 2026 independent audit says

Between January and April 2026, Recurity Labs — an ISO 27001-certified IT security firm active for nearly twenty years — examined every component of Proton Pass: browser extensions, mobile and desktop apps, command-line interface. The audit was fully independent, with no financial ties to Proton. Two conclusions stand out from the report, published on May 12, 2026:

  • no remotely exploitable vulnerability was identified — visiting a malicious site or clicking a bad link is not enough to compromise a user;
  • no way around the encryption was found — no backdoor, no weak key, no shortcut.

The overall security posture was rated “well above average,” and the few observations raised by the auditors were all fixed by Proton by the time of the verification test. The full report is available on the Proton blog.

What this changes for our clients

When you entrust us with your site’s hosting or maintenance, you’re also entrusting us with credentials. The password manager is part of a broader approach: unique passwords for every service, systematic two-factor authentication on sensitive accounts and regular access reviews. It’s also a business requirement: Law 25 requires Quebec businesses to put reasonable security measures in place to protect personal information — and that applies to us just as much as to the vendors you work with.

What about your business?

If your team still shares passwords by email or keeps them in a document, this is the most cost-effective security fix you can make this year. Adopt a reputable manager — Proton Pass is our documented choice, but the important thing is to use one —, turn on two-factor authentication and clean out dormant access. Want to take stock of your site’s security and your credentials? Write to us: we’ll tell you where to start.