A Spanish-based password management company, used by government agencies and universities across Europe, has been discovered to maintain undisclosed technological links to a Russian firm certified by the country’s security services, raising serious cybersecurity concerns.
The company, which markets itself as a European enterprise with origins in Finland and headquarters now in Spain, has built a reputation on its promise of independence from non-European entities. However, an investigation has revealed that its software was originally developed by two Russian co-founders who remain connected to a secretive UAE-based firm that continues to provide software updates to the European operation.
Corporate records show these founders also own a separate Russian company operating under the same brand name and logo. This Russian entity lists clients that include sanctioned missile manufacturers and defense contractors, and holds certifications from Russia’s Federal Service for Technical and Export Control (FSTEC) and the FSB, the country’s primary domestic intelligence agency.
Cybersecurity experts consulted during the investigation warned that the Russian certification process likely required submitting the software’s source code for rigorous state review, potentially creating vulnerabilities that could be exploited. The possibility that weaknesses identified in the Russian version could also exist in the European software represents a significant security risk.
The company’s CEO has denied any current relationship with the Russian counterpart, stating they share only a common codebase origin. He maintained that the Spanish firm operates independently, with separate servers, client data, and administrative systems. However, investigators found evidence suggesting the products continue to evolve in parallel, with near-identical software updates released on matching timelines.
The discovery has startled many European clients who were unaware of these connections. Several government agencies and institutions confirmed they had no knowledge of the Russian ties or the security certifications held by the sister company. One Irish laboratory stated the investigation had “highlighted a new potential risk” that would now be reviewed seriously.
The company’s marketing materials had explicitly stated it had no affiliations with Russian entities, but these claims were removed from the website after reporters began asking questions. The CEO acknowledged receiving rights to the software from the UAE entity in 2024, with full trademark acquisition expected by 2026, but declined to disclose the ownership structure of that intermediary company.
Security analysts emphasize that password management is particularly sensitive, as these systems effectively hold the digital keys to organizations’ entire infrastructure. The update mechanism, where new code is delivered to existing installations, represents one of the most difficult-to-detect potential attack vectors, as demonstrated by the SolarWinds hack attributed to Russian operatives.
While no evidence of malicious code or data breaches has been found, experts stress that transparency in cybersecurity is essential, and the opacity surrounding this company’s structure and relationships should prompt clients to carefully reassess their risk tolerance.