You’ve probably noticed the massive push for “digital sovereignty.” European governments and universities are desperate to keep their data out of the hands of Big Tech and foreign adversaries. So, they buy software from local vendors. They buy “Spain-based” tools. They feel safe.
They shouldn’t.
Take Passwork, a password manager used by European government agencies and universities. It’s registered in Spain. It looks European. It feels European. But it shares its core technology, its origins, and its update mechanisms with a state-certified Russian firm.
Digital sovereignty isn’t about where a company files its taxes; it’s about who writes the code at 2 AM when a zero-day vulnerability drops.
A password manager is the ultimate honeypot. It’s the vault for state secrets, institutional data, and the master keys to critical infrastructure. When you centralize your security architecture in a tool that is umbilically tied to an adversarial nation, you aren’t protecting your data. You’re gift-wrapping it.
This is the illusion of digital sovereignty. A corporate registration in Madrid means absolutely nothing if your supply chain runs through Moscow. We’ve been so obsessed with data residency—where the servers are physically located—that we completely ignored the software supply chain. Who owns the intellectual property? Who pushes the updates? Who has the keys to the update servers?
A security tool built on an opaque supply chain isn’t a shield; it’s a funnel.
The chilling realization is that the very software trusted to lock away our most sensitive secrets might be holding the keys out the back window. When you trust a vendor, you aren’t just trusting their marketing page. You are trusting every developer who has ever touched the codebase, and every entity that controls the update pipeline.
It’s time to stop trusting logos and start auditing supply chains. Because in the age of geopolitical cyber warfare, a “local” vendor with a foreign backdoor is the most dangerous Trojan horse of all.
FAQ
Q: Doesn't the Spanish registration mean they follow GDPR?
A: GDPR protects how your data is processed and stored, not who writes the underlying code. If the update mechanism is compromised by a foreign entity, GDPR compliance won't stop them from walking out the back door with your master keys.
Q: What's the practical implication?
A: Institutional buyers must demand supply chain transparency, code audits, and clear documentation of who controls update pipelines before deploying any security tool. You can't just buy based on a corporate address.
Q: Maybe password managers are inherently flawed?
A: Centralizing all your secrets in one digital vault, controlled by a third-party vendor, is a massive single point of failure. The convenience is brilliant, but the architecture is a sitting duck if the vendor's loyalties are opaque.