A complete, evidence-based plan for confirming the product is built correctly and is the right product for the people who depend on it — across every application, both cloud and self-hosted, and every edition.

The plan treats verification and validation as related but distinct activities. Verification proves conformance to approved requirements; validation proves real-world fitness with representative users. Depth is driven by risk — the areas where harm would be greatest receive the most checking.
| Product area | Included? | Deployments | How it is verified | How it is validated |
|---|---|---|---|---|
| Web application | Yes | Cloud & self-hosted | Full capability + security checks | Real users complete real tasks |
| iPhone/iPad & Android apps | Yes | Cloud & self-hosted | Capability + unlock + secure-storage | Real mobile users incl. offline |
| Computer apps (Windows/macOS/Linux) | Yes | Cloud & self-hosted | Capability + unlock checks | Everyday-use sessions |
| Web-browser add-on | Yes | Cloud & self-hosted | Autofill / save / passkey checks | Real browsing tasks |
| Command-line tool | Yes | Cloud & self-hosted | Automation & scripting checks | Administrator workflows |
| Cloud service & self-hosted server | Yes | US/EU cloud; container & orchestrated self-host | Service behaviour, separation, install/upgrade/recovery | Administrator runs it start to finish |
| Company sign-in & user management | Yes | Enterprise integrations | Permissions, rules, activity records | Administrator rollout scenario |
| Editions (Free → Enterprise, MSP/provider) | Yes | All | Right features per edition; excluded features stay excluded | Each edition delivers its value |
Out of scope: anything not part of the released product, and third-party services beyond the listed connection points. Every check produces documented, reviewable evidence supporting a release decision.
The plan concentrates effort where a failure would do the most harm. These sixteen risks set the priority of every check.
| # | What could go wrong | Who is affected | Priority |
|---|---|---|---|
| R-01 | Someone signs in to an account that is not theirs | All users | Critical |
| R-02 | One person or company can see another’s information | All; organizations most | Critical |
| R-03 | Stored information is scrambled wrongly or cannot be unlocked | All users | Critical |
| R-04 | Information is lost or corrupted | All users | Critical |
| R-05 | Changes do not sync correctly across devices | Multi-device users | High |
| R-06 | A removed employee keeps access | Businesses | Critical |
| R-07 | Backup or restore fails | Self-hosted customers | High |
| R-08 | An upgrade breaks the product or its data | All customers | High |
| R-09 | A tampered software update reaches customers | All customers | Critical |
| R-10 | The product misleads someone about a security choice | All users | High |
| R-11 | A published promise is not actually true | Buyers & the business | High |
| R-12 | Unusable for people relying on assistive technology | Users with disabilities | Medium |
| R-13 | Too much personal data collected, or it leaks in logs/errors | All users | High |
| R-14 | A connected system (sign-in, directory, email) is mishandled | Businesses | High |
| R-15 | The service is slow or unavailable under load | All; large orgs | High |
| R-16 | A failure is hard to detect or hard to reverse | All users | High |
442 checks across eighteen areas, each with a purpose, plain-language steps, an expected result, a “must-not-happen” result, and an objective pass/fail rule. Every one traces to an approved requirement and a risk.
| Verification area | Checks | What it confirms (and why it matters) |
|---|---|---|
| Everyday product capabilities | 180 | Twenty everyday actions — create, view, edit, delete, restore, search, organise, share, import, export, attach, generate, autofill, copy, open, sync, work offline, resolve conflicts, lock/unlock, move between personal and company — each tested normally and against invalid input, missing information, interruption, duplicates, permission failure, network loss, very large data, and recovery. |
| Sign-in & account protection | 49 | Registration, sign-in/out, password change, the extra sign-in step (multi-factor), company sign-in (single sign-on), device approval, session expiry/revocation, recovery, deletion, repeated-guess handling, locked accounts, invitations, removal, role changes, automatic add/remove from a directory, multiple devices, and lost devices — including every refusal case. |
| Installation, setup & upgrade | 31 | Fresh install, secure configuration, cloud and self-hosted deployment, certificates, email, company sign-in, storage, backup, high availability, upgrade, failure detection, rollback and uninstall — achievable from the supplied instructions. |
| Security protections | 22 | Identity checks, session protection, permission enforcement, account separation, protection of stored and transmitted information, key protection, safe local storage, add-on permissions, repeated-guess protection, safe input handling, secure recovery/export/backup, records, notifications, dependencies and genuine releases — each with a defined threat and consequence. |
| Permissions & keeping accounts separate | 16 | Every role does only what it should; one user cannot reach another’s information; one company cannot reach another’s; removed users lose access immediately; admin actions are recorded. |
| Reliability, backup & recovery | 15 | Network loss, service/database/external outages, crashes, restarts, interrupted updates/backups/restores, storage failure, disaster recovery and high demand — confirming both that service returns and that information is correct afterwards. |
| Keeping information correct across devices | 14 | Fourteen realistic multi-device situations — offline edits, simultaneous changes, poor network, interrupted sync, delayed/duplicate requests, deleted-item return, offline permission changes — proving information stays correct, complete, current and protected. |
| Speed & capacity | 14 | Sign-in, unlock, search, autofill, sync, import/export and report times; behaviour with very large vaults, very large organizations and many simultaneous users; and recovery after a demand spike. |
| Accessibility | 13 | Keyboard-only use, screen-reader use, meaningful labels, focus order, text enlargement, contrast, error identification, touch-target size, reduced motion and not relying on colour alone. |
| Keeping information correct & safe | 12 | Information stays accurate and correctly protected after shutdowns, interruptions, duplicates, storage limits, bad imports, conflicts, older versions, migration, and backup/restore. |
| Language & regional support | 12 | Each supported language displays correctly; selection works; long text fits; dates/numbers format correctly; right-to-left where supported; a missing translation never blocks a task. |
| Privacy promises | 11 | Only necessary personal information is collected; choices work; nothing leaks in logs or errors; exports and deletion follow the approved rules; connected services receive only approved information. |
| Works the same everywhere | 10 | Ten major capabilities compared across web, mobile, computer, add-on and command line — confirming consistent behaviour, with any difference intended and documented. |
| Ease of use | 10 | People can tell where to begin, complete common tasks, recognise success and failure, correct mistakes, and understand security-sensitive choices. |
| Business & product promises | 9 | Every advertised capability is present and works; edition features are correctly included or excluded; cloud and self-hosted match their descriptions; security and privacy statements reflect real behaviour. |
| Records & support | 9 | Required business and security events are recorded usefully, retrievable by the right people, and free of exposed secrets. |
| Connections to other systems | 8 | Company sign-in, directory sync, provisioning, email, notifications, browser and mobile services and licensing exchange the right information, refuse unauthorised connections, and fail safely. |
| Trustworthy software supply chain | 7 | Open code, enforced quality checks, automated tests, pinned dependencies, signed genuine releases, a component inventory with vulnerability scanning, and published independent assessments — guarding against a tampered update. |
Priority mix: 82 critical 202 high 158 medium. Critical checks are release-blocking. Security-critical areas already carry existing evidence from independent expert assessments, and every issue those assessments raised becomes a repeated check.
42 exercises with real, representative people doing complete, realistic tasks — because passing technical checks does not prove a product is useful.
New and experienced individuals, family organisers and members, employees, business and security administrators, IT/self-hosted administrators, help-desk staff, multi-device users, users of assistive technology, users with limited technical confidence, users migrating from another product, and users on unreliable networks. Participant numbers are proposed for product-owner approval.
| Exercise | Run by | What it proves |
|---|---|---|
| A new person starts using the product | New individual user | Set up, protect the account, save and use information, autofill, work offline, recover from a mistake |
| A family sets up sharing | Family organiser + member | Share some items, keep others private, change and remove access everywhere |
| A business rolls the product out | Business administrator | Company sign-in, staff, permissions, rules, activity review, remove a leaver, audit records |
| A company runs it on its own servers | IT / self-hosted administrator | Install, secure, back up, upgrade, restore, and work through a realistic failure |
| One person, many devices | Multi-device user | Offline and conflicting changes end up correct with nothing lost or exposed |
| Someone using assistive technology | Assistive-technology user | Complete every key task, including a security-sensitive action |
| Someone switches from another product | Migrating user | Move data in accurately and trust the result |
| Someone works on a poor connection | Unreliable-network user | Keep working and stay correct when connectivity drops |
In plain terms: task finished (with/without help), time taken, errors made, points of confusion, help requested, unsafe security decisions, confidence, understanding, and ability to recover. Satisfaction alone is never treated as proof.
Validation also proves 12 published promises (including “only you can unlock your information”, “ready for business”, “you can run it yourself”, “your data is yours”), that operations staff can run the whole life-cycle, and that real users can follow the documentation unaided.
This report is the overview. The complete, working detail — every check with its full record, the risk assessment, cross-platform and compatibility matrices, environments, roles, schedule, traceability and gaps — is in two workbooks.
This product exists because of an open, global community. Founded in 2016 and built on a transparent, open-source approach, it is shaped by contributors and users around the world who share the mission of helping people manage sensitive information safely. Its stated values — responsibility, inclusion, and transparency — are reflected directly in this plan’s emphasis on evidence, honest limitations, and coverage for every kind of user.
We gratefully acknowledge:
Serving a community of more than 15 million users and 80,000+ organizations across 180+ countries — the scale that makes this rigor necessary.