We would like to count page views and clicks with Google Analytics, which sets cookies in your
browser. It is how we learn which pages are worth writing. Nothing loads until you choose, and
declining costs you nothing on this site. What we collect.
A password manager is the one privacy tool almost everybody should use, and the one where the choice matters least in features and most in ownership. Every product here encrypts your vault before it leaves your device. What differs is who the company is, whether anyone outside it can check the encryption claim, and what happens to the price once the first year ends.
Bitwarden73 Open source end to end, self-hostable if you want it, and the only free tier in the category that syncs unlimited passwords across unlimited devices rather than capping you into an upgrade.
Proton Pass73 The pick if the owner matters more to you than the polish.
1Password56 The best-designed apps in the category by a distance, and the only one with a Secret Key, which means a stolen vault cannot be attacked with the master password alone — the exact failure mode that made the LastPass breach so damaging.
Open source, self-hostable, and the only free tier that is not crippled.
73
Owner
Bitwarden, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $0.83/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
Open source end to end, self-hostable if you want it, and the only free tier in the category that syncs unlimited passwords across unlimited devices rather than capping you into an upgrade. Cure53 audits it annually and publishes the reports. At $10 a year the paid tier is a tenth of what some rivals charge, and the price does not jump at renewal.
US jurisdiction, and it took a $100M growth investment in 2022, so there are outside investors even though there is no parent company.
Privacy & trust
52
Features
100
App quality
75
Price & renewal
98
Free tier syncs unlimited passwords across unlimited devices
All client and server code is open source
Can be self-hosted on your own machine
US jurisdiction, inside the Five Eyes
Interface is plainer than 1Password or Dashlane
Self-hosting is real work, not a checkbox
Lab test pending — scored on public dataiOS app score 75/100 from 31,601 ratingsFull reviewVisit Bitwarden
Swiss, non-profit-owned, open source, with hide-my-email aliases built in.
73
Owner
Proton Foundation
Jurisdiction
Switzerland · Outside the alliances
No-logs audit
None — apps audited by Cure53, 2024
Price
from $2.99/mo · ~$4.49/mo over 3 yrs after renewal
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The pick if the owner matters more to you than the polish. Controlled by a Swiss non-profit foundation, open source, audited by Cure53, and it includes real email aliasing through SimpleLogin, which Proton also owns, rather than a bolt-on. If you already pay for Proton VPN or Mail it costs nothing extra.
Launched in 2023, so it is the youngest here, and the two-year price rises at renewal.
Privacy & trust
73
Features
92
App quality
65
Price & renewal
74
Controlled by a Swiss non-profit foundation
Open source and audited by Cure53
Built-in email aliasing via SimpleLogin, not a bolt-on
The most polished apps, a second secret key, and no free tier at all.
56
Owner
AgileBits Inc.
Jurisdiction
Canada · Five Eyes
No-logs audit
None — apps audited by Cure53, 2025
Price
from $2.99/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The best-designed apps in the category by a distance, and the only one with a Secret Key, which means a stolen vault cannot be attacked with the master password alone — the exact failure mode that made the LastPass breach so damaging. Travel Mode removes vaults from a device before a border crossing. Prices do not rise at renewal.
Closed source, no free tier, Canadian and therefore Five Eyes, and $620M of venture funding implies an eventual exit.
Privacy & trust
42
Features
66
App quality
58
Price & renewal
90
The Secret Key means a stolen vault cannot be brute-forced from the password alone
Best-designed apps in the category by a distance
Travel Mode removes vaults from a device before a border crossing
Closed source, so the encryption claims cannot be independently inspected
No free tier
Canada is a Five Eyes country
Lab test pending — scored on public dataiOS app score 58/100 from 36,952 ratingsFull reviewVisit 1Password
4
Keeper
Enterprise-first, heavily certified, and it charges extra for the basics.
61
Owner
Keeper Security, Inc.
Jurisdiction
United States · Five Eyes
No-logs audit
None — other audited by SOC 2 Type II, 2024
Price
from $2.92/mo
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
The choice when someone else is buying: more compliance certifications than anything else here, per-record encryption keys, and admin tooling built for organisations rather than retrofitted. Its App Store rating is the highest in the category across a very large sample.
Breach monitoring and secure file storage are paid add-ons rather than included, which makes the headline price misleading. Closed source.
Privacy & trust
42
Features
60
App quality
77
Price & renewal
94
The most compliance certifications in the category
Zero-knowledge architecture with per-record keys
Excellent App Store rating across a very large sample
Breach monitoring is a paid add-on, not included
Closed source
Free tier is a 30-day trial on one device
Lab test pending — scored on public dataiOS app score 77/100 from 229,924 ratingsVisit Keeper
5
NordPass
Same owner as NordVPN and Surfshark, with the same renewal pricing habit.
58
Owner
Nord Security
Jurisdiction
Netherlands · Nine Eyes
No-logs audit
None — apps audited by Cure53, 2023
Price
from $1.74/mo · ~$3.12/mo over 3 yrs after renewal
Runs oniOSAndroidMacWindowsLinuxRouterBrowserTV
Worth knowing about mainly because of what owns it. NordPass is part of Nord Security alongside NordVPN, Surfshark and Incogni, and it uses XChaCha20 rather than AES, a modern and sensible choice. Cheap on the two-year intro if you already buy from that group.
Closed source, one audit, and the renewal is roughly two and a half times the intro price — the same pattern as NordVPN.
Privacy & trust
35
Features
76
App quality
69
Price & renewal
78
XChaCha20 encryption rather than AES, a modern choice
Cheap on the two-year intro
Data breach scanner included
Closed source
Renewal is roughly two and a half times the intro price
One audit, in 2023
Lab test pending — scored on public dataiOS app score 69/100 from 12,802 ratingsVisit NordPass
In 2022 an attacker took backups of customer vaults. Encrypted password fields were protected by each user's master password, but site URLs were stored unencrypted, and those vaults are still being attacked offline years later. There is no published independent audit of the current architecture, and the free tier is restricted to one device type.
A good product on a bad free tier: 25 passwords on a single device is a trial, not a tier. Closed source, audit reports are not published, and there has been no standalone desktop app since 2022.
What we weighed for password managers, and the exact weights
Whether the code can be inspected
Every manager claims it cannot read your vault. Only the open-source ones let anyone outside the company check that claim in the software you actually run.
Who owns the company
A vault holds every account you have. Private-equity ownership, heavy venture funding and conglomerate parents all change what a company is eventually for, which is why it is the first thing on every card here.
Whether the free tier is a product or a demo
Some free tiers sync everything across every device. Others cap you at 25 passwords or one device type, which is a trial dressed as a tier.
Price at renewal, not on the banner
The same intro-then-renewal pattern that runs the VPN market has spread here. We score the three-year cost.
Weights on this page: Privacy & trust 34% · Features 22% · App quality 18% · Price & renewal 14% · Support & refunds 12%. Formula.
Why ownership is the top weight here
Every product on this page uses the same basic design: your vault is encrypted on your device with a key derived from your master password, and the company stores a blob it says it cannot read. That claim is either true or it is not, and no feature list tells you which.
Two things make it checkable. Open source, so the software you run can be inspected rather than trusted. And independent audits, published in full, so somebody outside the company has looked. Bitwarden and Proton Pass have both. 1Password has audits but closed code. Dashlane and LastPass have neither in a form you can read.
Behind that sits the question of what the company is for. Bitwarden took growth investment but stayed independent. 1Password raised $620M at a $6.8B valuation, which implies an exit for somebody. LastPass is owned by a private-equity consortium through GoTo. NordPass belongs to the group that owns NordVPN, Surfshark and Incogni. None of that is disqualifying on its own, and all of it changes the incentives over a ten-year horizon — which is roughly how long you will keep a vault.
The LastPass breach, and what it taught the category
In 2022 an attacker got into a LastPass developer account and, months later, took backups of customer vaults. The password fields inside were encrypted with each user’s master password. The site URLs were not encrypted at all, which handed attackers a map of which vaults were worth attacking.
Two lessons stuck. First, an encrypted vault is only as strong as the master password protecting it, which is why 1Password’s Secret Key — a second, high-entropy factor mixed into the key — is a genuinely useful design rather than marketing. Second, a company’s response and its audit record are not decorative. LastPass’s disclosure came in stages over months, and there is still no published independent audit of what it does now.
What the free tiers actually give you
Bitwarden: unlimited passwords, unlimited devices, unlimited passkeys, the same encryption as paid. This is a real product and most people never need to leave it.
Proton Pass: unlimited passwords and devices, ten hide-my-email aliases, one account.
Dashlane: 25 passwords, one device. LastPass: unlimited passwords, but only on one device type — phones or computers, not both. Both of those are trials, and describing them as free tiers is the kind of thing this site exists to point out.
What we have not tested
Nobody’s threat model is served by a reviewer clicking around an app for an afternoon, so what is on this page is documentary: ownership records, audit reports, published pricing, and the App Store review analysis where the sample is large enough to mean something. Our own hands-on testing — import fidelity, autofill reliability across browsers, recovery from a lost device — is on the list, and until it lands each card says so.
In 2022 an attacker took backups of customer vaults, including encrypted passwords, alongside unencrypted site URLs
Frequently asked questions
What is the best password manager in 2026?
Bitwarden, for most people. It is open source, independently audited every year, self-hostable if you want it, and its free tier syncs everything across every device rather than pushing you toward an upgrade. Proton Pass is the pick if non-profit ownership matters more to you, and 1Password if you want the best apps and will pay for them.
Is a password manager actually safe?
Safer than the alternative by a wide margin. The realistic threat to your accounts is password reuse meeting a data breach, which a manager eliminates. The counter-argument is that a manager concentrates risk in one vault, which the LastPass breach demonstrated — but that breach happened to a company that stored site URLs unencrypted and had no published audit, not to the category as a whole.
Should I use my browser's built-in password manager instead?
Apple Passwords, Chrome and Firefox all sync passwords and now support passkeys, and using one is far better than reusing passwords. What they do not do well is share across ecosystems, share securely with other people, store other kinds of secret, or give you an export path that is not painful. If you live entirely inside one ecosystem, the built-in one is a defensible choice.
What happened to LastPass, and does it still matter?
In August 2022 an attacker compromised a developer account, and by December LastPass confirmed backups of customer vaults had been taken. The encrypted password fields were protected by each user's master password, but the site URLs in those vaults were not encrypted at all. Vaults with weak master passwords are still being cracked offline years later, and there is no way to un-steal them. It matters because it is the only case in this category where the worst outcome actually happened.
Is it worth paying, or is the free tier enough?
Bitwarden's free tier is genuinely enough for one person: unlimited passwords, unlimited devices, and the same encryption as the paid tier. Proton Pass's free tier is similar. Paying gets you emergency access, secure file storage, a built-in authenticator and family sharing. Free tiers from Dashlane and LastPass are capped in ways that make them trials rather than products.
Do password managers support passkeys yet?
All of them here do, on all major platforms. Passkeys replace the password with a key pair, so there is nothing phishable to type, and storing them in a manager rather than one vendor's ecosystem is what keeps them portable. This is the strongest current argument for a third-party manager over a platform one.