Password Management
Uniqkey
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Uniqkey A/S · www.uniqkey.eu
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Uniqkey is a business password and access management solution from Uniqkey A/S of Herlev, Denmark, sold as two modules, UniqPass and UniqAccess. The bench scores it strongest on identity integration: Microsoft Entra ID single sign-on connects with just a Tenant ID, pairs with SCIM 2.0 lifecycle sync and automatic deprovisioning, and works with Conditional Access, configurable session lifetimes and passkeys whose private keys never leave the device; the pages state the identity provider never sees vault data. Sharing and access control follows at 5-6, with group sharing, time-limited sharing, restricted visibility of the actual password, location-based access and admin-approved recovery. It is weakest on pricing transparency — no public price figures, only "Start Business Trial" and "Talk To An Expert" — and on security architecture, where scores cluster at 3: AES-256 and SHA-3 are named, but the ISO 27001 mention carries no date, auditor or scope. Sovereignty scores 3-4: the privacy policy names no hosting provider or location and contemplates exceptional transfers to processors outside the EU, and the captured pages give different figures for third-party data transfer.
Speaks for it
- Entra ID single sign-on pairs with SCIM 2.0 provisioning and automatic deprovisioning so no access outlasts employment.
- Sharing covers entire groups in one go, time limits, restricted visibility of the actual password, location-based access and admin-approved SSO recovery.
- The Audit Log records logins, access changes and admin actions with user, action and timestamp, framed for GDPR and NIS2 reporting.
- Passkeys use device-bound private keys with biometrics or device PIN, and more than one passkey can be assigned per login.
- Encrypted passwords are stored locally on each user's device rather than in the cloud, with a one-hour offline mode.
Held against it
- We found no public price figures; the pricing page presents feature lists with "Start Business Trial" and "Talk To An Expert".
- The security copy leans on "six layers of military-grade encryption", the ISO 27001 mention carries no date, auditor or scope, and we found no public information on a security whitepaper or key derivation.
- Hosting is stated as European in marketing copy while the privacy policy names no hosting provider or location, contemplates exceptional transfers to processors outside the EU, and lists subprocessors only by purpose.
- Microsoft Entra ID is the only identity provider named on the captured pages.
- We found no public information on log export or SIEM integration, and "Import and Export" appears as a feature name with no format.
Best for
- You run Microsoft Entra ID and want SSO plus SCIM 2.0 lifecycle sync and automatic deprovisioning tied to your directory.
- Your team shares credentials across groups and needs time-limited sharing with the actual password hidden.
- You need timestamped audit logs framed for GDPR and NIS2 reporting alongside reusable IP, time and geo-location policies.
- You want passwords stored encrypted on each user's device rather than in the cloud, with offline access.
Avoid if
- You need published per-user prices or tier costs to budget before talking to sales.
- Your identity provider is Okta or Google rather than Microsoft Entra ID.
- Your procurement requires subprocessor names and locations rather than purposes such as hosting and email service.
- You need offline access beyond the documented one-hour offline mode.
The scores
Encryption model & independent audits
Show reasoningHide reasoning
How this is scored
What the vendor can prove about its security design: end-to-end encryption with named algorithms and key derivation, which fields are encrypted on the device and which are not, independent audits and penetration tests with published results, a bug bounty, and incident history disclosed.
0 — Security described in adjectives ("bank-grade", "military encryption") with no architecture, no audit and no statement of what the vendor can read.
3 — Encryption algorithms named and "zero knowledge" claimed, but no whitepaper, no statement of which fields stay unencrypted, and audits mentioned without dates, auditors or results.
5 — A published security whitepaper naming algorithms, key derivation and the client-side encryption model, a stated list of what is and is not encrypted (including URLs and metadata), and a named independent audit or certification (ISO 27001, SOC 2) with its date.
8 — Recurring independent penetration tests or code audits with reports or summaries published, a public bug bounty or vulnerability disclosure policy, past security incidents documented with their impact, and open-source clients or cryptography that can be reviewed.
10 — The design is verifiable end to end: full source or cryptographic design public, every field encrypted client-side including metadata, audits by named firms repeated yearly with full reports, a threat model that states what a compromise of the vendor's servers would expose, and incident post-mortems published.
The CISO
Marketing copy reads "six layers of military-grade encryption, including AES-256 and SHA-3" — adjectives around named algorithms, not architecture. The ISO 27001 claim carries no date, auditor or certificate, and I found no public information on a security whitepaper, which fields stay unencrypted, a bug bounty, penetration tests or any incident history. 1 11
The Identity Engineer
Algorithms are named (AES-256, SHA-3) together with a zero-knowledge claim that encryption keys never leave devices, but the same page sells "six layers of military-grade encryption" in marketing terms and the ISO 27001 mention comes with no date, certifier or report. We found no public information on a security whitepaper, which fields stay unencrypted, penetration tests, a bug bounty or incident history. 1 3 11
The Compliance Auditor
Encryption is described with named algorithms AES-256 and SHA-3 inside "six layers of military-grade encryption", zero-knowledge is claimed, and an ISO 27001 certification is stated without a date, auditor or results. We found no public information on a security whitepaper, the key-derivation model, which fields stay unencrypted, penetration tests, a bug bounty or incident history. 1 11
The SME Owner
AES-256 and SHA-3 are named, zero-knowledge is claimed with keys stated never to leave devices, and ISO 27001 is mentioned — but without a date, auditor or scope. We found no public information on a security whitepaper, which fields stay unencrypted, penetration tests, or a bug bounty, and the copy leans on "six layers of military-grade encryption", which is exactly the kind of language I cannot hand to a customer questionnaire. 1 3 11
The DevOps Engineer
Algorithms are named — AES-256 and SHA-3 — and zero-knowledge is claimed with keys said never to leave the device, but the pitch wraps it in 'six layers of military-grade encryption'. We found no public information on a security whitepaper, key derivation, which fields remain unencrypted, or an audit carrying a date, auditor or results — the ISO 27001 mention appears as homepage copy with no scope or date, and the security-assessment page turned out to be a consulting offer rather than a report. 1 11 5
The Skeptic
Zero-knowledge and end-to-end encryption are claimed, AES-256 and SHA-3 are named, and one page states encryption keys never leave the devices — but the same page sells "six layers of military-grade encryption" with no whitepaper, no key derivation detail, and no statement of which fields stay unencrypted. The ISO 27001 line carries no certifying body, scope or date, and we found no public information on penetration tests, a bug bounty, or disclosed incident history. Claimed certification with nothing checkable behind it is exactly the pattern I treat as unevidenced. 1 3 11
Sharing, roles & recovery
Show reasoningHide reasoning
How this is scored
How credentials are shared and governed across a company: shared vaults or collections, role-based permissions, view-only and time-limited access, admin account recovery, emergency access, and what happens to shared items when an employee leaves.
0 — Personal vaults only, or sharing by sending a password to another user with no permissions and no record.
3 — Shared folders with all-or-nothing access, no roles, and no stated process for recovering an account or reclaiming credentials from a departing employee.
5 — Shared vaults or collections with read, edit and manage permissions, groups and admin roles, an admin recovery mechanism documented with its key model, and offboarding that transfers a leaver's shared items.
8 — Granular permissions down to hiding the password while allowing autofill, time-limited and one-time sharing with external parties, emergency access with a waiting period, delegated administration per team or location, and approval workflows for sensitive items.
10 — Access is governed and provable: least-privilege defaults, recovery and emergency access designed so the vendor never holds a key and stated so, periodic access reviews supported in the product, and every grant, change and revocation attributable to a person.
The CISO
Group sharing, time-limited sharing, restriction of the password's visibility and admin-approved recovery are documented, and offboarding is tied to SCIM so access does not outlast employment. I found no public information on read, edit and manage permission granularity, emergency access with a waiting period, or the key model behind admin-approved recovery. 2 6 8
The Identity Engineer
Group sharing is genuinely granular in the ways that matter — time limits, hiding the actual password, location-based access — and SSO recovery requires admin approval, with onboarding and offboarding listed as product features. We found no public information on a role model of read, edit and manage permissions, emergency access, or what happens to a leaver's shared items, which is exactly what I need documented to run offboarding for two thousand staff. 2 6 8
The Compliance Auditor
Group sharing with time limits, restricted visibility of the actual password and location-based access is documented, alongside onboarding and offboarding, SCIM sync so access does not outlast employment, and an admin-approved SSO recovery. We found no public information on read, edit and manage role granularity, emergency access with a waiting period, approval workflows, or the key model behind recovery. 2 6 8
The SME Owner
This hits my two daily fears directly: sharing with entire groups in one go, time-limited sharing with the password itself hidden, admin-approved recovery when an employee is locked out, and automated offboarding where no access outlasts employment are all on the captured pages. I found no public information on distinct read/edit/manage permission levels or emergency access, and the recovery mechanism's key handling is not documented, so I stop short of the top. 2 6 8
The DevOps Engineer
Sharing rises above folders: logins shared with entire groups in one go, time-limited sharing, restricted visibility of the actual password, and location-based access, alongside an admin-approved SSO recovery flow and SCIM-driven offboarding so access does not outlast employment. We found no public information on read/edit/manage permission tiers, emergency access with a waiting period, or approval workflows for sensitive items. 2 6 8
The Skeptic
Group sharing, time-limited sharing, restricted visibility of the actual password, location-based access and admin-approved SSO recovery are all stated, which is more than all-or-nothing folders. But we found no public information on read, edit and manage permission roles, emergency access, or the key model behind admin-approved recovery, and onboarding and offboarding appear as feature names without a description of what happens to a leaver's shared items. 2 6 8
SSO, directory sync & provisioning
Show reasoningHide reasoning
How this is scored
How the vault fits into the company's identity stack: SSO with Entra ID, Okta or Google, and the key model behind an SSO unlock; SCIM or directory sync for joiners and leavers; MFA options including hardware keys; and passkey support for users and the vault itself.
0 — Each user creates an account by email; no SSO, no directory sync and no MFA beyond an app code.
3 — SSO available only to sign in to the admin console or on the top tier with no description of how the vault is then decrypted, and users provisioned by CSV invite.
5 — SSO with named identity providers (Entra ID, Okta, Google) documented with how the vault key is derived or released, SCIM or directory sync for provisioning and deprovisioning, and MFA including FIDO2 or hardware keys.
8 — SSO unlock designed so the vendor cannot derive the vault key and stated so, group sync driving vault permissions, automated suspension on deprovisioning, conditional access or device policies, and passkeys stored and used across platforms.
10 — Identity is integrated without trust shortcuts: the SSO key model published and independently reviewed, deprovisioning that revokes vault access and shared items immediately with a log entry, passwordless vault unlock with passkeys, and support for the customer's own key-management or trusted-device approval.
The CISO
The Entra ID integration is deep — Tenant ID setup, Conditional Access, configurable session lifetime, SCIM 2.0 lifecycle sync and automatic deprovisioning — and passkeys are supported with device-bound keys. But Microsoft Entra ID is the only identity provider named, and I found no public information on how the vault is decrypted when an employee has no Uniqkey password; the zero-knowledge statements are general claims, not a published key-release model. 2 7 8
The Identity Engineer
This is the strongest part of the evidence: connect an Entra ID tenant with just the Tenant ID, SCIM 2.0 keeps user lifecycle in sync so no access outlasts employment, automatic deprovisioning and Conditional Access (MFA, trusted locations, compliant devices, risk-based) are stated, sessions are configurable, and passkeys with device-bound private keys are supported. What holds it back is that the pages assert the identity provider never sees vault data and that no one, not even the vendor, can access credentials, yet there is no documented account of how the vault key is derived or released when employees are set up without a separate Uniqkey password — and Entra ID is the only identity provider named. 2 7 8 11
The Compliance Auditor
SSO with Microsoft Entra ID is documented with Conditional Access policies, configurable session lifetime and SCIM 2.0 lifecycle sync including automatic deprovisioning, and passkeys with a device-bound private key are supported alongside passwordless SSO. One identity provider is named, and beyond the general statement that encryption keys never leave the device we found no public description of how the vault key is derived or released on SSO unlock. 7 8 11
The SME Owner
Entra ID single sign-on with Conditional Access policies, SCIM 2.0 provisioning with automatic deprovisioning, configurable session lifetimes, and passkeys with device-bound keys are all documented, and it is stated that the identity provider never reaches vault data. Entra ID is the only supported provider, and I found no public information on the key model behind an SSO unlock or on hardware security keys. 7 8
The DevOps Engineer
Entra ID SSO is documented with the model stated that the identity provider only verifies access and never sees passwords, secrets or vault data, plus SCIM 2.0 lifecycle automation, Conditional Access with MFA, trusted locations, compliant devices and risk-based rules, configurable session lifetime, MDM and GPO, and passkeys with device-bound private keys. We found no public information on Okta or Google as identity providers, group sync driving vault permissions, or an independently reviewed key model behind the SSO unlock. 2 7 8
The Skeptic
Entra ID SSO with SCIM 2.0, automatic deprovisioning, Conditional Access support, configurable session lifetime and passkeys are documented and concrete. What decides the risk is missing: accounts are created without a separate Uniqkey password and login is passwordless, yet no captured page explains how the vault key is derived or released — the statement that the identity provider cannot see vault data says nothing about whether Uniqkey itself can. We found no public information on Okta or Google as providers, or on group sync driving vault permissions. 2 7 8
Audit logs, policies & reporting
Show reasoningHide reasoning
How this is scored
What an administrator and an auditor can see and enforce: event logs of access and changes, password health and breach reports, enforceable policies (master password, MFA, sharing, export), SIEM integration, and reports an ISO 27001 or NIS2 audit can use.
0 — No audit log and no admin policies; the administrator sees a user list.
3 — A basic activity list and a password-strength score, but no exportable log, no enforceable policies, and no record of who viewed or copied a shared credential.
5 — Event logs covering logins, item access, sharing and admin changes, exportable or available through an API, enforceable policies for master password and MFA, and password health and breach-monitoring reports.
8 — Native SIEM integration with named targets (Splunk, Microsoft Sentinel, Elastic or syslog), policies for sharing, export and browser-extension behaviour, log retention stated, and compliance reports aligned to ISO 27001, NIS2 or BSI IT-Grundschutz.
10 — Auditability is complete: every view, copy, autofill and permission change logged with user and device, logs tamper-evident and retained for a configurable period, alerting on anomalous access, and an auditor role that can read logs without access to secrets.
The CISO
The audit log is documented as recording every user activity with user, action and timestamp — logins, permission changes and admin promotions — framed for GDPR and NIS2 reporting, alongside enforceable IP, time and geo policies and mandatory 2FA and password requirements. I found no public information on exporting logs to a SIEM, stated log retention, or recording of individual item views and copies. 2 9 10
The Identity Engineer
The Audit Log is described as recording every user activity with user, action and timestamp — logins, access changes, admin actions — positioned for GDPR and NIS2 reporting, and access policies for IP, time and geo plus mandatory 2FA and stronger password rules are enforceable with policy provenance (creator, last update). We found no public information on log export or an API, SIEM targets, log retention, or whether viewing or copying a shared credential is logged — the things my auditors ask for first. 2 9 10
The Compliance Auditor
The Audit Log records logins, access changes and admin actions with user, action and timestamp and is presented as built for GDPR and NIS2 reporting; enforceable policies cover password requirements, mandatory 2FA and reusable IP, time and geo-location rules, with security scores and breach monitoring. We found no public information on export to a SIEM, log access through an API, log retention, tamper-evidence, or whether viewing or copying a shared credential is itself logged. 2 9 10
The SME Owner
Timestamped audit logs of logins, access changes and admin actions, framed for GDPR and NIS2 reporting, plus reusable access policies for IP, time and geography, mandatory 2FA and stronger password rules, plus breach monitoring and security scores, give me real governance. I found no public information on exporting the log, SIEM destinations, or how long logs are retained, which is what an auditor will ask me. 2 9 10
The DevOps Engineer
The audit log records every user activity with user, action and timestamp — logins, access changes, admin actions — tracked in real time with step-by-step incident backtracking and framed for GDPR and NIS2 reporting, while enforceable policies cover stronger password requirements, mandatory 2FA and IP, time and geo restrictions, backed by breach monitoring and risk assessment. We found no public information on exporting logs or an API for them, SIEM integration, stated log retention, or records of who viewed a specific shared credential. 2 9 10
The Skeptic
The audit log page is specific — logins, access changes and admin actions with user, action and timestamp, tracked in real time — and enforceable access policies (IP, time, geo-location, mandatory 2FA, stronger password requirements) plus breach monitoring and security scores are named. We found no public information on exporting logs or an API, SIEM integration, retention periods, or a record of who viewed or copied a shared credential — which is what the GDPR and NIS2 claims would be tested against. 2 9 10
Hosting choice, offline access & export
Show reasoningHide reasoning
How this is scored
Where and how the vault runs and how the data leaves it: cloud region choice, a self-hosted or on-premises option, offline access during a vendor outage, client coverage across operating systems and browsers, and a complete, documented export and import path.
0 — Cloud only in an unstated region, no offline access, and no export or an export that drops attachments and shared items.
3 — Cloud with a region named, apps for common platforms, and an export in CSV only that leaves out attachments, folders, TOTP seeds or custom fields.
5 — An EU region or self-hosted option, offline read access on desktop and mobile, clients for Windows, macOS, Linux, iOS, Android and the major browsers, and an export that covers all item types including attachments.
8 — Both EU cloud and self-hosted or on-premises deployment documented, a status page with incident history, encrypted full-fidelity export and import from named competitors, and vault access continuing during an outage of the vendor's service.
10 — The customer can run and leave the vault on their own terms: self-hosting with documented high availability and backup, an open or documented export format that preserves structure, permissions and history, and a stated procedure for continued access if the vendor ends the service.
The CISO
Offline access exists but is capped at one hour, encrypted storage is stated on each user's device, and "Import and Export" appears only as a feature name with no format or fidelity stated. I found no public information on a self-hosted option, a status page with incident history, or a documented client list across operating systems. 1 2 11
The Identity Engineer
The local-first angle is unusual: encrypted passwords stored on each user's device rather than the cloud, with a one-hour offline mode and multi-browser compatibility. We found no public information on a self-hosted option, a status page, client coverage per operating system, or export fidelity — "Import and Export" appears as a feature name with no format or coverage stated. 2 7 11
The Compliance Auditor
Offline access is documented as a one-hour offline mode with encrypted storage on each user's device, and an import and export feature is listed among the password manager features. We found no public information on a self-hosted or on-premises option, a status page with incident history, per-operating-system client coverage, or what an export covers such as attachments and custom fields. 2 10 11
The SME Owner
European hosting is claimed, offline access exists but is described only as a one-hour offline mode, passwords can be stored encrypted locally on each device, and import and export appear as feature bullets without detail on format or coverage. I found no public information on a self-hosted option, a status page, or a complete list of desktop and mobile clients, so the exit path out of this product is a question, not a plan. 1 2 8 11
The DevOps Engineer
European hosting is claimed across the site and offline access exists — a one-hour offline mode and locally encrypted device storage — but we found no public information on a self-hosted or on-premises deployment, which is what I would need before running the vault on our own hardware. 'Import and Export' appears as a feature name with no documented format, and we found no public information on export fidelity for attachments and item types, a status page with incident history, or client coverage per operating system. 1 2 7 11
The Skeptic
Hosting is stated as Europe in marketing copy while the privacy policy names no hosting provider or location and explicitly contemplates exceptional transfers to processors outside the EU; offline access exists but the documented offline mode lasts one hour; "Import and Export" appears as a feature name with no format, fidelity or attachment coverage stated. We found no public information on a self-hosted option, a status page, or client coverage beyond multi-browser compatibility and mobile authentication. 1 2 3 11
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Who the contracting entity and the parent company are, where vault data and metadata are hosted, and who the subprocessors are. Independently sourced by the sovereignty pipeline; end-to-end encryption narrows what a foreign authority could compel, but metadata, logs and the update channel for the client software remain in the vendor's hands, so the chain still counts.
0 — Non-EU vendor and contracting entity, hosting unstated, and subprocessors unnamed.
3 — An EU data region offered while the contracting entity and parent are non-EU without a stated safeguard, or the subprocessor list is absent.
5 — EU hosting as standard or selectable and an EU contracting entity, but the parent company or parts of the chain (support, analytics, email, client distribution) are non-EU.
8 — EU hosting on named infrastructure, EU contracting entity, subprocessor list published with locations, a DPA covering vault metadata and logs, and a self-hosted option that removes the vendor from the data path.
10 — Sovereign end to end and evidenced: European ownership, entity, hosting and every subprocessor, certifications published (ISO 27001, BSI C5 or equivalent), and source code or builds verifiable so the client update channel is not a blind trust in the vendor.
The CISO
Uniqkey A/S is named as the contracting party alongside a data processing agreement and a European region is claimed on the homepage, but the privacy policy names no hosting location and explicitly contemplates exceptional transfers to processors outside the EU — and the captured pages give different figures for third-party data transfer. No subprocessor is named with a location and ownership is unevidenced, so the chain from client updates to support email remains unverifiable. 1 3 4
The Identity Engineer
European positioning is consistent across the pages ("based in Europe", "operated within European infrastructure") and the contracting entity is Uniqkey A/S, but the hosting claim rests on homepage copy while the privacy policy names no hosting location or provider and explicitly contemplates exceptional transfers to processors outside the EU. The privacy policy names subprocessor purposes only (hosting, system maintenance, email); we found no published list of subprocessor names or locations. 1 3 4 7
The Compliance Auditor
Hosting is stated only in marketing terms as European infrastructure while the privacy policy names no hosting provider or location and explicitly contemplates exceptional transfers to processors outside the EU; the terms name Uniqkey A/S and its affiliates but we found no public confirmation of jurisdiction, parent company or ownership. We found no public subprocessor list with names or locations, only purposes such as hosting, system maintenance and email service. 1 3 4 7
The SME Owner
The company presents itself as European with everything "protected in Europe", but the privacy policy names no hosting location or provider, lists subprocessors only as categories such as hosting and email service, and itself contemplates exceptional transfers of personal data outside the EU. I found no public information on ownership or on certification details beyond a homepage ISO 27001 mention, so the chain remains mostly assertion. 1 3 7 8
The DevOps Engineer
European positioning runs through the site — 'Everything stays protected in Europe' — and the terms are with Uniqkey A/S, but the privacy policy names no hosting provider or location and expressly contemplates exceptional transfers to processors outside the EU. Subprocessors appear only as purposes — hosting, system maintenance, email — and we found no public information on their names or locations, on ownership, or on a self-hosted option that would remove the vendor from the data path. The captured pages also give different signals on third-party transfer, with the homepage stating none and the policy describing processors. 1 3 4 7 8
The Skeptic
European hosting and European alignment appear as marketing statements, while the terms name Uniqkey A/S and its affiliates without confirming jurisdiction or ownership on the captured pages, and the privacy policy names no hosting location and allows exceptional outside-EU transfers to processors. Processors are listed by purpose only — hosting, system maintenance, email — with no names or locations, and the homepage's "no third-party data transfer" sits beside a privacy policy that describes acting processors; the captured pages give different accounts of third-party processing. We found no public information on a published subprocessor list or DPA contents, so very little of the chain is verifiable. 1 3 4 7 8
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone: price per user and tier, which features (SSO, SCIM, SIEM, self-hosting) sit in which tier, minimum seats, add-ons, and the minimum term.
0 — No public prices at all; every tier is a sales conversation.
3 — A starting price exists, but which business features (SSO, SCIM, audit logs) sit in which tier is unclear — the invoice is unknowable.
5 — Per-user tier prices public with the main features per tier, but at least one commonly needed piece (SSO, SIEM integration, self-hosting, minimum seats) is unpriced or "on request".
8 — Every tier priced publicly with its feature set and seat minimum, add-on prices listed, self-hosted licensing stated, minimum term and VAT treatment given.
10 — Complete price computability: annual invoice derivable for a given number of users, with every add-on, self-hosting licence, support level and renewal condition published.
The CISO
The only pricing facts public are a free business trial and a note that personal use is not sold separately; every per-user price, tier boundary, seat minimum and term sits behind "Talk To An Expert". I cannot compute an annual invoice from these pages. 2 4
The Identity Engineer
We found no price figures on any captured page — no per-user cost, no tier prices, no seat minimums, no add-on prices — with "Start Business Trial" and "Talk To An Expert" as the calls to action. The pricing page does show which features belong to the password manager and access modules, but the annual invoice for a given headcount is not computable from public information. 2 4
The Compliance Auditor
The pricing page presents feature lists and calls to action — "Start Business Trial", "Talk To An Expert" — and we found no public prices for any tier, no per-user rate, seat minimum, add-on price or contract term. As captured, the annual invoice is not computable from public pages. 2 11
The SME Owner
I cannot price forty seats from anything captured: the pricing page shows feature lists per product, a "Start Business Trial" button and "Talk To An Expert", and personal use is stated as "only available to individuals who currently have a Uniqkey license... through their workplace". We found no public information on per-user prices, tier prices, seat minimums, add-ons or terms, so the invoice is a sales conversation. 2 4 8
The DevOps Engineer
The captured pricing page names the modules and offers a business trial, but we found no public price figures of any kind, and the call to action is 'Start Business Trial Talk To An Expert'. With no per-user price, tier costs, seat minimums, term or VAT treatment found in the public captures, a buyer cannot compute an annual invoice; the only pricing-related statement we found is that personal use is not sold separately. 2 4 10
The Skeptic
A pricing page exists, but every confirmed statement on it is a feature list or a "Start Business Trial" and "Talk To An Expert" prompt — we found no public information on per-user prices, which tier carries which business feature, seat minimums, term length, or VAT treatment. With no price figure published on any captured page, a buyer cannot compute any part of the annual invoice without a sales conversation; only a business trial is evidenced. 1 2 10
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 1 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 1 Oct 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The region is stated only as homepage marketing copy; the privacy policy names no hosting location or provider, and its section 7.4 explicitly contemplates exceptional transfers to processors outside the EU.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 71 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
Sources (11)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.uniqkey.eu Checked 1 Oct 2026 Details →
- 2 Pricing page www.uniqkey.eu Checked 1 Oct 2026 Details →
- 3 Privacy policy www.uniqkey.eu Checked 1 Oct 2026 Details →
- 4 Terms of service www.uniqkey.eu Checked 1 Oct 2026 Details →
- 5 Encryption model & independent audits — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 6 Sharing, roles & recovery — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 7 SSO, directory sync & provisioning — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 8 SSO, directory sync & provisioning — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 9 Audit logs, policies & reporting — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 10 Audit logs, policies & reporting — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →
- 11 Hosting choice, offline access & export — found from sitemap www.uniqkey.eu Checked 1 Oct 2026 Details →