If a password falls into the hands of someone who shouldn’t have access to it, that ultimately comes down to the responsibility of the IT person or whoever is managing the systems not necessarily the security product itself. If someone leaks sensitive information or intentionally exposes it, that is a user or process error rather than a flaw in the product. I understand why they may have concerns or doubts about handling it a specific way, but security isn’t the only consideration. Product usability is just as important. A security solution can be extremely secure, but if it’s overly complicated or difficult for people to use correctly, that can create its own security risks.