Skip to content
All posts

August 24, 2026

How you swap the note under the keyboard for your own password vault

Till password on paper, tax adviser login in an Excel list, WiFi over messenger. What a self-hosted password vault with Vaultwarden changes about that, what it costs day to day, and when renting is the better call.

A robot at a workbench lifts a keyboard and places a blank note into a small metal cash box that a person holds open, with more blank notes and a lamp lying next to it.

There is a note taped under the keyboard at the till. The login for the tax adviser's portal sits in an Excel list in the accounting folder, the WiFi password went out over messenger to a temp two years ago who left long since, and three people share the same combination of company name and founding year, because that one you can remember.

This is not sloppiness. This is what happens when a business collects sixty logins over the years and there is no place where they belong. The note is the obvious solution to a real problem. It is just a bad one.

Everyone gets their own vault, and more fits in it than passwords

The first step is unspectacular. Every person in the business gets an account with their own encrypted area. Remember one password instead of sixty, the app fetches the rest.

What goes in there is not only logins. Bitwarden, whose data format Vaultwarden speaks, supports secure notes, cards, identities and SSH keys as their own item types alongside logins. And files can be attached to any item, up to 500 MB per file and 5 GB per account. On your own server you set those limits yourself.

That turns the password store into a place for everything that otherwise lives in the owner's mailbox. The recovery code for the banking portal. The photo of the key number for the spare key. The PDF contract with the customer number sheet, sitting right on the provider's entry instead of in a folder only one person can find.

Company logins belong to the business, not to the person

Now the part that concerns the business. Company logins have no place in an employee's private vault. They belong in an organisation with collections, split by department or project. Accounting sees the accounting collection, the north site sees its own, the supplier portal login sits in one place once instead of five times on paper. Who gets to see which collection is decided by a person during setup, not by a default.

The difference shows on the day someone leaves. With an organisation you revoke that person's access, the items stay with the business, done. Without one you face the choice of changing thirty passwords or changing none. In practice it will be none, and the note under the keyboard stays valid.

It must not be annoying day to day

A password vault gets opened twenty times a day. If it stutters while doing that, the note wins back.

That is why Bitwarden compatibility is not a technical detail but the reason the thing holds up in daily use. The official apps and browser extensions talk to your own server as soon as the address is entered there. Windows, Mac, Linux, iPhone, Android, the usual browsers. The colleague in the warehouse notices no difference from the rented version, and that is exactly the point.

Two things belong with that. Vaultwarden is an unofficial server, and the feature set can differ depending on the Bitwarden version. And the project went through a code review by the BSI in 2024 and fixed the findings within weeks, before the report made the press.

In community discussions you read both sides. In the Kuketz forum users weigh Bitwarden against Vaultwarden and arrive at different conclusions depending on how willing they are to maintain a server. In the simon42 community, users report on their running setups, and in the Bitwarden subreddit the same sticking points keep coming up. Reachability while travelling, updates, and the question of what happens when nobody is left who looks after it. A recurring piece of advice from those threads is that anyone without an appetite for server maintenance is better off with a subscription. The advice is right, and it is incomplete.

Why in your own house

The argument is not the price. The price is a side effect.

The argument is who owns the data and how easily you can leave again. Sovereignty comes in levels here, and you pick the depth. A rented service is a legitimate choice. Your own server in Germany goes one level deeper, and your encrypted data then sits on a machine whose access you control. In both cases the provider stays replaceable, because the data format is open and an export fits the other route. That replaceability is the actual gain. It is the reason we run our own password vault ourselves, like the rest of the infrastructure this site runs on.

Three routes, and two decisions before that

There are not two options, there are three.

  • Do it yourself. Your own server, your own updates, your own backups. Cheap in money, expensive in attention.
  • Rent. An account with the provider, a price per head, maintenance is not your problem. The fastest route away from the note.
  • Have it run for you. The same software on a server that belongs to you, maintained by someone you pay for it. The data stays with you, the phone rings elsewhere at night.

Before you pick one of the three, settle two things.

First, who gets woken up when the service goes down on a Friday evening. A name, not a role. If nobody can think of that name, doing it yourself is the wrong answer.

Second, how you get to the passwords if that very server is out for a week. The apps keep an encrypted copy locally and keep working offline, but you do not build an emergency plan on that alone. It takes a regular encrypted export in a second location and a handful of logins that are reachable without the vault, so the way back does not run through the service that is down.

Anyone who wants neither to give those two answers themselves nor to hand them to somebody else is better off renting. That is not a defeat, it is a clean decision.

And it is still the smaller question. The comparison that counts is not your own server against a subscription. The comparison is vault against the note under the keyboard, and that one is not close.

Was this helpful?