Product Assurance · Verification & Validation

Verification & Validation Plan

A complete, evidence-based plan for confirming the product is built correctly and is the right product for the people who depend on it — across every application, both cloud and self-hosted, and every edition.

Verification — “Did we build the product right?”Confirms the product meets every approved requirement: the right people get in, stored information stays unreadable to others, and it behaves the same across phone, computer and web.
Validation — “Did we build the right product?”Puts the finished product in front of real people — a first-time user, a family organiser, a company administrator — to confirm it genuinely solves their problem.
Bitwarden password manager

What this plan covers

The plan treats verification and validation as related but distinct activities. Verification proves conformance to approved requirements; validation proves real-world fitness with representative users. Depth is driven by risk — the areas where harm would be greatest receive the most checking.

442Verification checks
42Validation exercises
225 / 225Requirements with a check (full coverage)
16Product risks driving priority
14Representative user groups
82Highest-priority (critical) checks
Product areaIncluded?DeploymentsHow it is verifiedHow it is validated
Web applicationYesCloud & self-hostedFull capability + security checksReal users complete real tasks
iPhone/iPad & Android appsYesCloud & self-hostedCapability + unlock + secure-storageReal mobile users incl. offline
Computer apps (Windows/macOS/Linux)YesCloud & self-hostedCapability + unlock checksEveryday-use sessions
Web-browser add-onYesCloud & self-hostedAutofill / save / passkey checksReal browsing tasks
Command-line toolYesCloud & self-hostedAutomation & scripting checksAdministrator workflows
Cloud service & self-hosted serverYesUS/EU cloud; container & orchestrated self-hostService behaviour, separation, install/upgrade/recoveryAdministrator runs it start to finish
Company sign-in & user managementYesEnterprise integrationsPermissions, rules, activity recordsAdministrator rollout scenario
Editions (Free → Enterprise, MSP/provider)YesAllRight features per edition; excluded features stay excludedEach edition delivers its value

Out of scope: anything not part of the released product, and third-party services beyond the listed connection points. Every check produces documented, reviewable evidence supporting a release decision.

Risk-based approach

The plan concentrates effort where a failure would do the most harm. These sixteen risks set the priority of every check.

#What could go wrongWho is affectedPriority
R-01Someone signs in to an account that is not theirsAll usersCritical
R-02One person or company can see another’s informationAll; organizations mostCritical
R-03Stored information is scrambled wrongly or cannot be unlockedAll usersCritical
R-04Information is lost or corruptedAll usersCritical
R-05Changes do not sync correctly across devicesMulti-device usersHigh
R-06A removed employee keeps accessBusinessesCritical
R-07Backup or restore failsSelf-hosted customersHigh
R-08An upgrade breaks the product or its dataAll customersHigh
R-09A tampered software update reaches customersAll customersCritical
R-10The product misleads someone about a security choiceAll usersHigh
R-11A published promise is not actually trueBuyers & the businessHigh
R-12Unusable for people relying on assistive technologyUsers with disabilitiesMedium
R-13Too much personal data collected, or it leaks in logs/errorsAll usersHigh
R-14A connected system (sign-in, directory, email) is mishandledBusinessesHigh
R-15The service is slow or unavailable under loadAll; large orgsHigh
R-16A failure is hard to detect or hard to reverseAll usersHigh
Part 1 — Verification

Did we build the product right?

442 checks across eighteen areas, each with a purpose, plain-language steps, an expected result, a “must-not-happen” result, and an objective pass/fail rule. Every one traces to an approved requirement and a risk.

Verification areaChecksWhat it confirms (and why it matters)
Everyday product capabilities180Twenty everyday actions — create, view, edit, delete, restore, search, organise, share, import, export, attach, generate, autofill, copy, open, sync, work offline, resolve conflicts, lock/unlock, move between personal and company — each tested normally and against invalid input, missing information, interruption, duplicates, permission failure, network loss, very large data, and recovery.
Sign-in & account protection49Registration, sign-in/out, password change, the extra sign-in step (multi-factor), company sign-in (single sign-on), device approval, session expiry/revocation, recovery, deletion, repeated-guess handling, locked accounts, invitations, removal, role changes, automatic add/remove from a directory, multiple devices, and lost devices — including every refusal case.
Installation, setup & upgrade31Fresh install, secure configuration, cloud and self-hosted deployment, certificates, email, company sign-in, storage, backup, high availability, upgrade, failure detection, rollback and uninstall — achievable from the supplied instructions.
Security protections22Identity checks, session protection, permission enforcement, account separation, protection of stored and transmitted information, key protection, safe local storage, add-on permissions, repeated-guess protection, safe input handling, secure recovery/export/backup, records, notifications, dependencies and genuine releases — each with a defined threat and consequence.
Permissions & keeping accounts separate16Every role does only what it should; one user cannot reach another’s information; one company cannot reach another’s; removed users lose access immediately; admin actions are recorded.
Reliability, backup & recovery15Network loss, service/database/external outages, crashes, restarts, interrupted updates/backups/restores, storage failure, disaster recovery and high demand — confirming both that service returns and that information is correct afterwards.
Keeping information correct across devices14Fourteen realistic multi-device situations — offline edits, simultaneous changes, poor network, interrupted sync, delayed/duplicate requests, deleted-item return, offline permission changes — proving information stays correct, complete, current and protected.
Speed & capacity14Sign-in, unlock, search, autofill, sync, import/export and report times; behaviour with very large vaults, very large organizations and many simultaneous users; and recovery after a demand spike.
Accessibility13Keyboard-only use, screen-reader use, meaningful labels, focus order, text enlargement, contrast, error identification, touch-target size, reduced motion and not relying on colour alone.
Keeping information correct & safe12Information stays accurate and correctly protected after shutdowns, interruptions, duplicates, storage limits, bad imports, conflicts, older versions, migration, and backup/restore.
Language & regional support12Each supported language displays correctly; selection works; long text fits; dates/numbers format correctly; right-to-left where supported; a missing translation never blocks a task.
Privacy promises11Only necessary personal information is collected; choices work; nothing leaks in logs or errors; exports and deletion follow the approved rules; connected services receive only approved information.
Works the same everywhere10Ten major capabilities compared across web, mobile, computer, add-on and command line — confirming consistent behaviour, with any difference intended and documented.
Ease of use10People can tell where to begin, complete common tasks, recognise success and failure, correct mistakes, and understand security-sensitive choices.
Business & product promises9Every advertised capability is present and works; edition features are correctly included or excluded; cloud and self-hosted match their descriptions; security and privacy statements reflect real behaviour.
Records & support9Required business and security events are recorded usefully, retrievable by the right people, and free of exposed secrets.
Connections to other systems8Company sign-in, directory sync, provisioning, email, notifications, browser and mobile services and licensing exchange the right information, refuse unauthorised connections, and fail safely.
Trustworthy software supply chain7Open code, enforced quality checks, automated tests, pinned dependencies, signed genuine releases, a component inventory with vulnerability scanning, and published independent assessments — guarding against a tampered update.

Priority mix: 82 critical   202 high   158 medium. Critical checks are release-blocking. Security-critical areas already carry existing evidence from independent expert assessments, and every issue those assessments raised becomes a repeated check.

Part 2 — Validation

Did we build the right product?

42 exercises with real, representative people doing complete, realistic tasks — because passing technical checks does not prove a product is useful.

The questions validation answers

  • Does it solve the problem the customer came for?
  • Can ordinary people complete the important tasks on their own?
  • Does it fit how families, businesses and IT teams actually work?
  • Do people understand the security choices they are asked to make?
  • Can people recover from common mistakes?
  • Does it stay useful on a poor connection?
  • Do the editions deliver their intended value?
  • Are the published claims credible, with limits stated plainly?

Who we test with — 14 representative groups

New and experienced individuals, family organisers and members, employees, business and security administrators, IT/self-hosted administrators, help-desk staff, multi-device users, users of assistive technology, users with limited technical confidence, users migrating from another product, and users on unreliable networks. Participant numbers are proposed for product-owner approval.

The real-world exercises

ExerciseRun byWhat it proves
A new person starts using the productNew individual userSet up, protect the account, save and use information, autofill, work offline, recover from a mistake
A family sets up sharingFamily organiser + memberShare some items, keep others private, change and remove access everywhere
A business rolls the product outBusiness administratorCompany sign-in, staff, permissions, rules, activity review, remove a leaver, audit records
A company runs it on its own serversIT / self-hosted administratorInstall, secure, back up, upgrade, restore, and work through a realistic failure
One person, many devicesMulti-device userOffline and conflicting changes end up correct with nothing lost or exposed
Someone using assistive technologyAssistive-technology userComplete every key task, including a security-sensitive action
Someone switches from another productMigrating userMove data in accurately and trust the result
Someone works on a poor connectionUnreliable-network userKeep working and stay correct when connectivity drops
How success is measured

In plain terms: task finished (with/without help), time taken, errors made, points of confusion, help requested, unsafe security decisions, confidence, understanding, and ability to recover. Satisfaction alone is never treated as proof.

Beyond scenarios

Validation also proves 12 published promises (including “only you can unlock your information”, “ready for business”, “you can run it yourself”, “your data is yours”), that operations staff can run the whole life-cycle, and that real users can follow the documentation unaided.

Decisions needed, and the release test

Targets to be set (not invented here). A few checks cannot be judged until a product owner sets the bar: acceptable speed targets; an availability / recovery-time target; a chosen accessibility level; participant numbers and pass rates; the confirmed supported-versions list; and the current, in-date compliance report. Each is proposed and flagged for approval.
The product is acceptable when…
  • Every critical check has passed.
  • Every kind of user completed the important real-world tasks.
  • No unresolved unsafe security misunderstanding remains.
  • All devices and both cloud and self-hosted are covered.
  • Any remaining limitation is documented and formally accepted.
A release should be stopped if…
  • Anyone can reach information that isn’t theirs.
  • Information can be lost, damaged, or left unreadable.
  • A removed user keeps access.
  • A backup cannot be restored, or an upgrade loses information.
  • A published promise cannot be backed by evidence.

The detailed plans

This report is the overview. The complete, working detail — every check with its full record, the risk assessment, cross-platform and compatibility matrices, environments, roles, schedule, traceability and gaps — is in two workbooks.

Acknowledging the community

This product exists because of an open, global community. Founded in 2016 and built on a transparent, open-source approach, it is shaped by contributors and users around the world who share the mission of helping people manage sensitive information safely. Its stated values — responsibility, inclusion, and transparency — are reflected directly in this plan’s emphasis on evidence, honest limitations, and coverage for every kind of user.

We gratefully acknowledge:

  • Open-source contributors who make the code publicly reviewable, so anyone can verify how it protects information.
  • The community forum and the wider user community, whose real-world needs inform what “the right product” means here.
  • Volunteer translators whose work makes the product usable in 50+ languages — the basis of this plan’s language and regional checks.
  • Security researchers participating through the bug-bounty program, and the independent assessment firms whose published reviews form existing verification evidence.

Serving a community of more than 15 million users and 80,000+ organizations across 180+ countries — the scale that makes this rigor necessary.