vpnandprivacy

Alternatives to LastPass

LastPass alternatives, and how to move a vault without losing it

Leaving LastPass is not like changing VPN. The vault holds every account you have, the export is a plaintext file for as long as it exists on your disk, and anything the 2022 breach captured is still out there being attacked offline. This page covers where to go and, just as importantly, the order to do it in.

By The VPN and Privacy team Updated 6 Sept 2026 Facts re-checked 6 Sept 2026

What you are replacing

LastPass scores 50 on this page's weighting, owned by GoTo (LogMeIn). Every pick below beats it on the things this page weighs.

Why people replace LastPass

An attacker took customer vault backups in 2022

Encrypted password fields were still protected by each user's master password, but site URLs were stored unencrypted, so whoever holds those files can see every service each victim used and can keep guessing master passwords offline for as long as they like. Time does not help you here; it helps them.

The architecture has no published independent audit

There is no public independent audit of the current design to point at, in a category where Bitwarden, 1Password and Proton Pass all publish Cure53 reports. For a product that asks you to trust encryption you cannot inspect, that absence is the whole argument.

Ownership changed hands through private equity

LastPass came under GoTo, formerly LogMeIn, which was taken private in 2020 by Francisco Partners and Evergreen Coast Capital for $4.3 billion. It was spun out as a separate company in 2024 but remains under that ownership structure rather than answering to the public markets or to a foundation.

The free tier stopped being useful in 2021

Free accounts are limited to one device type, so a phone and a laptop no longer sync on the same free account. A password manager that does not follow you between devices is not doing the job that makes people use one.

Weights on this page: Privacy & trust 34% · Features 22% · App quality 18% · Price & renewal 14% · Support & refunds 12%. Formula.

The alternatives

1

Bitwarden

Open source, self-hostable, and the only free tier that is not crippled.

73
Owner
Bitwarden, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $0.83/mo
Runs on iOS Android Mac Windows Linux Router Browser TV

The default answer for most people leaving LastPass, and it imports a LastPass CSV export directly. The client and server code are public, Cure53 audits it annually with the reports published, and the free tier syncs unlimited passwords across unlimited devices — the exact restriction that pushed people off LastPass free. Paid is $10 a year and does not rise at renewal.

US company, so Five Eyes jurisdiction, and it took a $100M growth investment in 2022. The apps are plainer than 1Password's.

Privacy & trust
52
Features
100
App quality
75
Price & renewal
98
  • Free tier syncs unlimited passwords across unlimited devices
  • All client and server code is open source
  • Can be self-hosted on your own machine
  • US jurisdiction, inside the Five Eyes
  • Interface is plainer than 1Password or Dashlane
  • Self-hosting is real work, not a checkbox
Lab test pending — scored on public data iOS app score 75/100 from 31,601 ratings Full review Visit Bitwarden
2

1Password

The most polished apps, a second secret key, and no free tier at all.

56
Owner
AgileBits Inc.
Jurisdiction
Canada · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $2.99/mo
Runs on iOS Android Mac Windows Linux Router Browser TV

The pick if the breach is your reason. Its Secret Key means a stolen vault file cannot be attacked with the master password alone — a 128-bit key held only on your devices is required as well, which is precisely the failure mode that made the LastPass vault theft so damaging years after the fact. Travel Mode removes vaults from a device before a border crossing.

Closed source, no free tier, $35.88 a year, Canadian and therefore Five Eyes, and $620M of venture funding implies an eventual exit.

Privacy & trust
42
Features
66
App quality
58
Price & renewal
90
  • The Secret Key means a stolen vault cannot be brute-forced from the password alone
  • Best-designed apps in the category by a distance
  • Travel Mode removes vaults from a device before a border crossing
  • Closed source, so the encryption claims cannot be independently inspected
  • No free tier
  • Canada is a Five Eyes country
Lab test pending — scored on public data iOS app score 58/100 from 36,952 ratings Full review Visit 1Password
3

Proton Pass

Swiss, non-profit-owned, open source, with hide-my-email aliases built in.

73
Owner
Proton Foundation
Jurisdiction
Switzerland · Outside the alliances
No-logs audit
None — apps audited by Cure53, 2024
Price
from $2.99/mo · ~$4.49/mo over 3 yrs after renewal
Runs on iOS Android Mac Windows Linux Router Browser TV

The choice when you want the owner to be structurally different rather than just better behaved: a Swiss non-profit foundation holds control, the code is open, Cure53 has audited it, and email aliasing runs through SimpleLogin, which Proton also owns. If you already pay for Proton VPN or Mail, it is bundled.

The youngest product here, launched in 2023, and the two-year price rises at renewal from $71.76 to $143.76.

Privacy & trust
73
Features
92
App quality
65
Price & renewal
74
  • Controlled by a Swiss non-profit foundation
  • Open source and audited by Cure53
  • Built-in email aliasing via SimpleLogin, not a bolt-on
  • Youngest of the majors, launched 2023
  • Not self-hostable
  • Renewal is higher than the intro price
Lab test pending — scored on public data iOS app score 65/100 from 7,869 ratings Full review Visit Proton Pass
4

Keeper

Enterprise-first, heavily certified, and it charges extra for the basics.

61
Owner
Keeper Security, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — other audited by SOC 2 Type II, 2024
Price
from $2.92/mo
Runs on iOS Android Mac Windows Linux Router Browser TV

The one to look at when the vault is not only yours: per-record encryption keys, the most compliance certifications in the category, and admin tooling designed for organisations rather than bolted on afterwards. Its App Store rating is the highest here across a very large sample.

Breach monitoring and secure file storage are paid add-ons, so the headline price understates it. Closed source, US-based, and the free tier is a 30-day trial on one device.

Privacy & trust
42
Features
60
App quality
77
Price & renewal
94
  • The most compliance certifications in the category
  • Zero-knowledge architecture with per-record keys
  • Excellent App Store rating across a very large sample
  • Breach monitoring is a paid add-on, not included
  • Closed source
  • Free tier is a 30-day trial on one device
Lab test pending — scored on public data iOS app score 77/100 from 229,924 ratings Visit Keeper
When to stay with LastPass There is no version of this page that recommends staying. If you were a LastPass customer before the 2022 incident, the safe assumption is that a copy of your vault as it existed then is in someone else's hands, and every password inside it should be treated as compromised regardless of which manager you move to. The one legitimate reason to keep the account open a little longer is a staged migration: keep it until every credential has been rotated in the new manager, then delete it. Migrating is not the fix on its own — rotating the passwords is.

This migration is different

Most switching guides are about money. This one is about a file.

In 2022, an attacker obtained backups of LastPass customer vaults. The password fields inside were encrypted with each user’s master password — but the site URLs were not, so anyone holding those backups can see exactly which services each victim used, and can run offline guesses against the master password with no rate limit and no lockout. That work continues years later, and it gets cheaper every year.

So the question is not only “which password manager is better”. It is “what is the correct order of operations to get out safely”, and the order matters more than the destination.

Do these three things in this order

Change the master password and enable two-factor authentication on the LastPass account. Everything else runs through this account, and it should not still be protected by a password you chose in 2021.

Export, import, delete. The CSV export is plaintext. It should exist for minutes, not days, and it should never touch a synced folder, an email or a cloud drive.

Rotate. Email first, then banking, then anything with a card stored, then everything you have reused. Moving your vault to a new product does not undo a password that was stolen — only changing the password does.

Choosing where to go

Bitwarden is the right default. It is open source, audited annually by Cure53 with the reports published, it imports LastPass exports cleanly, and its free tier does the thing LastPass free stopped doing in 2021: sync across all your devices. Paid is $10 a year, which is a tenth of what some rivals charge.

1Password is the right answer if the breach itself is what frightened you. Its Secret Key is a second 128-bit secret stored only on your devices, so a stolen server-side vault cannot be brute-forced with a master password alone. That is a direct architectural answer to how the LastPass theft played out.

Proton Pass is the right answer if you want the ownership to be different in kind. A Swiss non-profit foundation holds the controlling stake, the code is open, and email aliasing through SimpleLogin is built in rather than bolted on. It is also the youngest product here.

Keeper is the right answer when the vault is shared with colleagues rather than family: per-record keys, deep admin controls and the compliance paperwork enterprises ask for.

Our full password manager ranking scores all of them on the same formula, and explains why LastPass sits on the avoid list rather than the chart.

What “zero knowledge” is worth without an audit

Every product in this category says it cannot read your vault. That claim is either checkable or it is not.

Bitwarden, 1Password and Proton Pass publish independent audit reports. There is no comparable published independent audit of LastPass’s current architecture. After an incident in which vault backups left the building, an unverifiable claim is not a reassurance — it is the same promise, repeated.

After you have moved

Keep the LastPass account alive, empty and locked for a couple of weeks in case something was missed in the import. Then delete it properly through the account-deletion flow rather than just removing the browser extension, which leaves the account and its stored data intact.

Then, once a year, check whether your addresses have appeared in anything new with the email breach checker. Migration is a day’s work. Rotation is what actually closes the hole.

LastPass against the picks

FeatureLastPassBitwarden1PasswordProton Pass
Ultimate ownerGoTo (LogMeIn)Bitwarden, Inc.AgileBits Inc.Proton Foundation
JurisdictionUnited States (Five Eyes)United States (Five Eyes)Canada (Five Eyes)Switzerland (Outside the alliances)
No-logs auditNone foundNone — apps audited by Cure53, 2025None — apps audited by Cure53, 2025None — apps audited by Cure53, 2024
Cheapest monthly$3.00$0.83$2.99$2.99
True cost / mo, 3 yrs$3.00$0.83$2.99$4.49
Money-back30 days30 days14 days30 days
PlatformsiOS, Android, Mac, Windows, Linux, Browser · not Router, TViOS, Android, Mac, Windows, Linux, Browser · not Router, TViOS, Android, Mac, Windows, Linux, Browser · not Router, TViOS, Android, Mac, Windows, Linux, Browser · not Router, TV
DevicesUnlimitedUnlimitedUnlimitedUnlimited
Countries
WireGuard????
Kill switch????
Obfuscation????
RAM-only servers????
Open-source apps????
Split tunnelling????
Multi-hop????
Port forwarding????
Ad blocker????
P2P allowed????
Free tier????
NetflixUnknownUnknownUnknownUnknown
BBC iPlayerUnknownUnknownUnknownUnknown
Works in ChinaUnknownUnknownUnknownUnknown
Works in UAEUnknownUnknownUnknownUnknown
Cash / cryptoNocryptoNocrypto
Live chat????
iOS app score58/100 (4.4★)75/100 (4.8★)58/100 (4.7★)65/100 (4.8★)
Our lab testPendingPendingPendingPending

How to switch without paying twice

  1. Change the master password and turn on two-factor firstDo this before exporting anything. Everything that follows passes through the LastPass account, and if that account is still protected by a password from 2021 you are exporting into an open room.
  2. Export to CSV, import, then destroy the fileThe export is plaintext: every password in one readable file. Import it into the new manager immediately, then delete it and empty the trash. Never leave it in Downloads, never email it to yourself, and never keep it on a synced folder.
  3. Rotate the accounts that matter, in orderEmail first, because it resets everything else. Then banking, then anything holding a card, then everything reused anywhere. A migration copies old passwords into a new vault; it does not make passwords stolen in 2022 safe again.
  4. Move your two-factor codes deliberatelyIf LastPass Authenticator held your TOTP codes, re-enrol each account in the new app one at a time and keep the recovery codes somewhere offline until every one is confirmed working. This is where people lock themselves out.
  5. Delete the LastPass account, not just the appRemoving the extension leaves the account and its stored vault in place. Delete the account through LastPass's own account-deletion flow once the new manager has been running for a couple of weeks and you are certain nothing was missed.

Frequently asked questions

Is my LastPass vault still at risk after the 2022 breach?

If you were a customer at the time, assume the encrypted copy taken then can be attacked offline for as long as an attacker cares to try. Strong, unique master passwords with high iteration counts make that expensive rather than impossible, and the unencrypted site URLs in the stolen data tell the attacker which accounts are worth the effort. Rotate the passwords; do not rely on the encryption holding forever.

What is the easiest password manager to switch to from LastPass?

Bitwarden. It accepts a LastPass CSV export directly, the import maps folders and secure notes without manual cleanup, and the free tier syncs across every device so you can move first and decide about paying later.

Is Bitwarden's free tier really enough?

For one person, yes. Unlimited passwords across unlimited devices, sync included, and passkey support. The $10-a-year upgrade adds file attachments, emergency access and integrated TOTP — worth it, but not required to leave LastPass today.

Should I use my browser's built-in password manager instead?

It is better than reusing passwords, and it is worse than any pick here: it ties you to one browser vendor, it rarely offers a real independent audit of the sync layer, and sharing or emergency access is limited. If you are already making a move, make it to a dedicated manager.

How do I move my two-factor codes off LastPass Authenticator?

One account at a time, and never in a hurry. Open each service's security settings, disable and re-enable two-factor with the new app, confirm a code works, and store the fresh recovery codes offline. Do not delete the old authenticator until every account has been re-enrolled and tested.