Releases, dates, and release notes

The current release is v3.0.3. Every tagged release since 1.7.0 is listed with its date, changes and installer; each component has its own version history.

Server and console

Newest first. Open a row's notes for the full list of changes; the installer link downloads that version's MSI directly.

Server releases from 1.7.0 to 3.0.3
VersionDateWhat changedInstaller
3.0.3

Published

Hotfix for the automatic install and same-version repair of the unsigned MSI.

Notes for 3.0.3
  • Restores the manifest-led automatic install path for the unsigned MSI from the official release.
  • Allows same-version repair only through the signed-manifest update path, so the corrected 3.0.3 package can replace the earlier 3.0.3 package without opening local repair bypasses.
  • Keeps AD action recovery, release metadata alignment, and the existing browser extension, sharing, and DC Agent packages intact.
VaultPilot-3.0.3-x64.msi
3.0.2

Published

Hotfix. Keeps the installed version authoritative when the published release metadata is older, simplifies the Sharing flow, and publishes DC Agent 1.2.22.

Notes for 3.0.2
  • Shows the Legacy label only for release-note versions older than 2.0.0.
  • Keeps the installed VaultPilot version authoritative when the published release metadata is older.
  • Removes the redundant vault-management and shared-vault creation card from Sharing and keeps the Select, Send, and Result flow.
  • Updates the web framework to a security-patched release.
  • Publishes DC Agent 1.2.22 together with the 3.0.2 server package.
  • Keeps the independently versioned Backup Tool and Log Collector at 1.0.3.
VaultPilot-3.0.2-x64.msi
2.2.1

Published

Hotfix. Prevents an unapproved machine-account grant on the managed certificate directory, keeps failed update jobs blocked, and preserves existing data during upgrade.

Notes for 2.2.1
  • Stops the managed certificate folder from gaining an unapproved machine-account permission.
  • Grants access to the certificate and log folders to the account the service actually runs as.
  • Keeps an update marked as failed when the MSI reports an error, even if the new version briefly appears to answer.
  • Restarts the service with the correct installed version after an update.
  • Keeps the useful installer error details in the logs when an installation rolls back.
  • Keeps the existing database, vault data, users, certificates and configuration during upgrade, and moves Backup Tool and Log Collector to 1.0.3 so upgrade and repair install the corrected tools.
VaultPilot-2.2.1-x64.msi
2.2.0

Published

Clearer certificate, Discovery, audit, and settings surfaces; identity-bound directory actions require DC Agent 1.2.20 or newer; Backup Tool and Log Collector gain independent versions.

Notes for 2.2.0
  • Certificate, Discovery, audit, execution, integration, rotation, notification, and server-settings surfaces show details step by step, with the relevant records first.
  • Identity-bound directory actions require DC Agent 1.2.20 or newer; the shipped DC Agent 1.2.21 also keeps custom configuration paths through service recovery, never applies an action result twice, sends unclear results to audited review, and limits diagnostic logging.
  • Backup Tool and Log Collector carry independent 1.0.1 component versions instead of inheriting the console package label; their independent history began at 1.0.0.
  • The signed update manifests record the exact hashes of the MSI, Offline Share Decrypter, and DC Agent files published with this release.
VaultPilot-2.2.0-x64.msi
2.0.0

Major product transition with compatible upgrade and rollback contracts

VaultPilot replaces PassMan as the product identity. Encryption, storage, pairing, manifest verification, and API compatibility stay compatible with existing PassMan installations.

Notes for 2.0.0
  • VaultPilot becomes the primary product identity across the console, first-run and unlock screens, package descriptions, docs, diagnostics copy, and release language.
  • The Overview screen groups security posture, recommendations, breach status, server readiness, operational state, record distribution, quota and update signals, access trend, maintenance, and recent activity into clickable widgets.
  • Sign-in security focuses on master password change, 2FA setup, 2FA binding revoke, and Owner-visible active session review.
  • Server System becomes a settings surface for log rotation and retention, audit retention, safe diagnostics, public host, port, HTTPS certificate state, restart guidance, and non-destructive maintenance boundaries.
  • License language maps capacity, trial or licensed mode, write state, expiry and renewal risk, and unavailable capabilities to real modules such as extension, auto update, RBAC, integrations, and sharing.
  • Extension, Offline Share Decrypter, and DC Agent packages adopt VaultPilot naming while staying compatible with PassMan installs, and repairing the same MSI version keeps the files the service installation needs.
VaultPilot-2.0.0-x64.msi
1.8.21 (PassMan)

Hotfix patch

Reduces database slowdowns while the directory agent checks in and audit events are written, and stops installer logging problems from interrupting the install.

Notes for 1.8.21
  • Reduces database slowdowns when the directory agent checks in often and audit traffic is heavy.
  • Writes less when the directory agent has already checked in recently.
  • Avoids rewriting unchanged Active Directory full-sync data.
  • A local log permission issue no longer interrupts installation or the service restart.
PassMan-1.8.21-x64.msi
1.8.20 (PassMan)

Browser extension channel patch

The browser extension moves to the Chrome Web Store.

Notes for 1.8.20
  • Chrome Web Store becomes the primary browser extension install and update channel.
  • The console no longer offers customers the manual ZIP install.
  • Update Center explains the Web Store channel instead of treating the local ZIP as the standard browser install path.
  • The extension About view shows the installed version and Web Store update checks.
PassMan-1.8.20-x64.msi
1.8.19 (PassMan)

Active Directory agent authorization patch

Fixes directory-agent install and repair being rejected, and stores new agent tokens in a portable form.

Notes for 1.8.19
  • Fixes AD agent install and repair being rejected on some server installations.
  • Stores newly created directory-agent tokens in a portable form while still accepting existing tokens after upgrade.
  • Adds redacted reasons for rejected agent connections to the server log, so operators can tell a missing provider, a revoked token and a wrong token apart without the token ever being logged.
PassMan-1.8.19-x64.msi
1.8.0 (PassMan)

Minor milestone

Update Center progress flow, enterprise console layout, credential bulk operations, and MSI maintenance fixes consolidated into one milestone.

Notes for 1.8.0
  • Update Center shows download, verification, service restart, and console reload as one progress flow.
  • Credential operations include bulk actions, import preview, export, category and tag assignment, and audit reporting.
  • MSI maintenance and legacy installer-helper compatibility are written out in the release notes.
PassMan-1.8.0-x64.msi
1.7.0 (PassMan)

Enterprise console and MSI maintenance release

Keeps the Windows Installer maintenance path on same-version runs, adds an explicit upgrade screen, and introduces credential bulk operations.

Notes for 1.7.0
  • Same-version manual MSI runs keep the Windows Installer maintenance path so Repair and Remove stay available.
  • Newer MSI packages show an explicit upgrade screen when an older PassMan installation is detected.
  • The console gets a clearer page layout, working display-density settings, consistent screen styling, and a simpler Update Center.
  • Credential bulk operations add template download, Excel import preview, selected export, category and tag assignment, archive, revoke or disable, security check, audit report, and guarded deletion.
  • AD-synced credentials expose source, domain, DN or path, account, status, risk, owner, tags, last seen, and last synced metadata while keeping sensitive values masked.
PassMan-1.7.0-x64.msi

The v3.0.3 release notes also describe three earlier PassMan builds that have no download on this page: 1.5.4 (2026-05-28, maintenance hardening and update observability), 1.3.0 (2026-04-18, the secure sharing milestone), and 1.0.3 (2026-02-10, the self-hosted Windows Server foundation). Earlier 1.0.x through 1.4.x builds are summarised there only as older history, and retired builds should not be used for new deployments.

Browser extension

Browser extension versions
VersionServer releaseWhat changed
1.3.33.0.3Installed and updated from the Chrome Web Store.
Not stated2.0.0The package adopts the VaultPilot name and keeps its PassMan compatibility aliases.
Not stated1.8.20Chrome Web Store becomes the install and update channel; the About view shows the installed version and Web Store update checks.

DC Agent Service

DC Agent Service versions
VersionServer releaseWhat changed
1.2.273.0.3Keeps identity binding and hardens configuration-path recovery, result delivery, certificate trust handling, protected-directory validation and diagnostics.
1.2.223.0.2Published together with the 3.0.2 server package.
1.2.212.2.0Preserves custom configuration paths through service recovery, never applies an action result twice, sends unclear deliveries to audited review and limits diagnostic logging.
1.2.20—Minimum for identity-bound actions (unlock, require password change, random password, disable) since 2.2.0; binds each action to the exact target account.
1.2.15–1.2.19—Can still sync the directory; identity-bound actions stay unavailable.
Not stated2.0.0The package adopts the VaultPilot name and keeps its PassMan compatibility aliases.

Offline Share Decrypter

Offline Share Decrypter versions
VersionServer releaseWhat changed
1.2.13.0.3Opens share packages fully in the browser, with no network connection.
Not stated2.0.0The package adopts the VaultPilot name and keeps its PassMan compatibility aliases.

Backup Tool and Log Collector

Backup Tool and Log Collector versions
VersionServer releaseWhat changed
3.0.0 / 3.0.23.0.3Backup Tool 3.0.0 and Log Collector 3.0.2, downloaded from the Server settings screen.
1.0.32.2.1Both tools move to 1.0.3 so Windows Installer replaces the exact hotfix files during upgrade and repair.
1.0.12.2.0Both tools get their own version numbers instead of the console label; their history starts at 1.0.0.

Download and verify the v3.0.3 components