
3 min. read
What we learned from SCIM security audit
Sharing key security lessons from the recent SCIM audit. These codebase patterns can happen to anyone, regardless of language or framework.

Independent reviews are an important part of improving security and governance. To support that effort, Passbolt has completed an independent assessment of its GDPR compliance programme and is appointing Examin SAS as its independent Data Protection Officer (DPO).
Examin reviewed the documentation that supports our GDPR compliance, including privacy policies, data retention rules, data processing agreements, governance processes, and technical safeguards.
We're publishing the audit report alongside this announcement for anyone who would like to review the findings and recommendations in full.
The review concluded that the foundations of our GDPR programme are solid and that the technical and organisational measures in place provide a high level of protection for personal data.
The assessment also highlighted a number of characteristics that have long been part of both the Passbolt product and the way we operate:
GDPR compliance is an ongoing process of reviewing practices, improving governance, and ensuring that technical and organizational measures continue to evolve. One of the reasons we commissioned an independent assessment was to identify opportunities for improvement.
The audit identified a number of them, including expanding our data retention policy to cover additional categories of business data, updating employee privacy documentation, and adding some missing information to the public website.
None of these findings affect the security architecture of Passbolt. They are governance improvements, and we've already started implementing the recommendations.
As part of this work, Examin has been appointed as Passbolt's independent Data Protection Officer (DPO).
Every organisation has competing priorities when it comes to handling data. Product teams need feedback to improve features, support teams need information to investigate issues, marketing teams want to better understand their audience, and sales teams rely on customer insights. These are all legitimate business needs, but they need to be balanced against the rights and expectations of the people whose data is being processed.
An independent DPO brings that balance. Their role is to provide objective advice on data protection, challenge decisions where appropriate, and ensure that privacy remains part of the conversation as the business evolves.
Examin will advise Passbolt on GDPR compliance, monitor our privacy programme, support data protection impact assessments where required, and act as a point of contact for supervisory authorities and individuals exercising their GDPR rights.
Examin is an independent consultancy specialising in data protection and cybersecurity. The company helps organisations assess and improve their GDPR compliance through audits, governance support, technical reviews, and outsourced Data Protection Officer (DPO) services. Its multidisciplinary team combines legal and technical expertise to support organisations as they develop new products, respond to regulatory requirements, and strengthen their privacy programmes.

3 min. read
Sharing key security lessons from the recent SCIM audit. These codebase patterns can happen to anyone, regardless of language or framework.

2 min. read
Passbolt has formally submitted its CSPN application to ANSSI. Following months of preparation with Quarkslab, this marks an important step in our commitment to transparency and independent security validation through one of Europe's most recognised assessment processes.