Best European Password Managers

Looking for a secure alternative to LastPass or 1Password? European password managers offer end-to-end encryption, zero-knowledge architecture, and GDPR compliance. Keep your credentials safe with services that prioritize privacy and cannot access your passwords even if they wanted to.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed. Editorial policy

12 European Password Managers

Proton Pass

End-to-end encrypted password manager from Proton

#1 of 12 in this category
Switzerland Free tier available
End-to-end encrypted Email aliases Open source

NordPass

Lithuanian password manager from Nord Security

#2 of 12 in this category
Lithuania Free tier available
XChaCha20 encryption Zero-knowledge Breach scanner

Uniqkey

Danish business password manager

#3 of 12 in this category
Denmark Business focused
100% GDPR compliant Danish data centers Enterprise features

Passbolt

Open source password manager for teams

#4 of 12 in this category
Luxembourg Open source
Team sharing Self-hosted option GPG encryption

Heylogin

Passwordless authentication for teams

#5 of 12 in this category
Germany Free for individuals
Passwordless Smartphone-based Team management

Psono

German open-source password manager for teams, self-hostable with client-side encryption

#6 of 12 in this category
Germany Free and open source / paid hosting and enterprise
Self-hostableClient-side encryptionTeam sharing

KeePass

The German open-source password database that keeps everything in a local encrypted file

#7 of 12 in this category
Germany Free and open source
Local encrypted fileNo cloud at allOpen source

Password Depot

Darmstadt password manager sold as a one-time licence, with a self-hosted server for teams

#8 of 12 in this category
Germany €99.95 one-time (1 user, all own devices) / Family €149.95 one-time for 5 licences / Enter
One-time purchase, no subscriptionSelf-hosted Enterprise ServerISO 27001 certified vendor

F-Secure ID Protection

Finnish password vault with data-breach alerts, from a Helsinki-listed security company

#9 of 12 in this category
Finland €49.99/year (1 device) / €69.99/year (3 devices) / €79.99/year (5 devices), VAT included
Password vault with autofillData-breach monitoringDecrypted only on your device

SecureSafe

Swiss password and file safe for teams, hosted only in Switzerland (server-side encryption, not zero-knowledge)

#10 of 12 in this category
Switzerland Pass from CHF 11.70/month (Starter) / CHF 3.20 per user/month (Professional) / CHF 4.60 pe
Passwords and files in one safeSwiss-only data centresDigital estate / inheritance feature

KeePassXC

Community-built KeePass client for Windows, macOS and Linux, with an ANSSI CSPN visa

#11 of 12 in this category
Germany Free and open source
Offline KDBX vaultAuto-Type and passkeysANSSI CSPN certified build

Steganos Password Manager

German password manager for Windows, iOS and Android that syncs through a cloud you already use, or none at all

#12 of 12 in this category
Germany €29.99/year annual subscription (list price €39.99)
Works without any cloudSync via your own cloud accountWindows, iOS and Android

Key takeaways

  • Proton Pass ranks #1 among the European password managers in this directory, because Proton Pass is the only one that bundles unlimited email aliases with the vault — so the address you give a service is as disposable as the password.
  • heylogin removes the master password entirely: your smartphone is the key, approved with a fingerprint or face, which eliminates the single point of failure every other manager in this category depends on.
  • Passbolt is the only one built for teams from the first day rather than retrofitted, encrypting each shared credential individually to every authorised user's GPG public key, and it can be self-hosted under AGPL v3.
  • NordPass uses XChaCha20 rather than AES-256, which is faster on phones without hardware AES acceleration and uses nonces large enough that reuse attacks are effectively impossible.
  • Eight of the twelve are EU-established, among them NordPass in Lithuania, Uniqkey in Denmark, Passbolt in Luxembourg and heylogin in Germany. Proton Pass and SecureSafe are Swiss under an adequacy decision, and KeePass and KeePassXC are not a service at all: the file stays on your own machine, so there is no jurisdiction to ask about.

A European password manager is an encrypted credential vault operated by a company established in Europe, where the vault is encrypted on your own device before it is stored, so that the provider holds ciphertext it cannot read and can be compelled only through a European court to hand over data that is useless without your key.

European password managers compared

European password managers compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Proton Pass Switzerland Free tier / from about €1.99/month (Pass Plus) Privacy-conscious users who want aliases as well as passwords
#2 NordPass Lithuania Free tier / from about €1.49/month (Premium) Individuals and families wanting a polished European manager
#3 Uniqkey Denmark From about €3/user/month European businesses that need GDPR compliance by architecture
#4 Passbolt Luxembourg Free Community Edition / from about €4/user/month (Pro) Teams and IT departments managing shared infrastructure credentials
#5 heylogin Germany Free tier / from about €2.50/user/month (Business) Users and teams who want to stop having a master password
#6 Psono Germany Free and open source / paid hosting and enterprise plans Teams that want a shared password manager on their own server
#7 KeePass Germany Free and open source People who want their passwords in a file they control, with no service at all
#8 Password Depot Germany €99.95 one-time (1 user, all own devices) / Family €149.95 one-time for 5 licences / Enterprise Server by quote, free for up to 3 users Buyers who want a certified vendor, a one-time price and no vendor cloud
#9 F-Secure ID Protection Finland €49.99/year (1 device) / €69.99/year (3 devices) / €79.99/year (5 devices), VAT included Households that want breach alerts from a listed Finnish security company
#10 SecureSafe Switzerland Pass from CHF 11.70/month (Starter) / CHF 3.20 per user/month (Professional) / CHF 4.60 per user/month (Business); Pass + File bundles from CHF 19.90/month for 5 users Swiss-only storage for passwords and the documents that go with them
#11 KeePassXC Germany Free and open source People who want an offline vault that an outside body has actually examined
#12 Steganos Password Manager Germany €29.99/year annual subscription (list price €39.99) Windows and mobile users who want a local vault and choose their own sync

Every European password manager reviewed

#1 Proton Pass

Geneva, Switzerland Founded 2023 Free tier / from about €1.99/month (Pass Plus) Free tier

Best for: Privacy-conscious users who want aliases as well as passwords

  • Operating company. Proton AG
  • Jurisdiction. Switzerland (adequacy decision, outside the EEA)
  • Where the data sits. Switzerland, Germany
  • Independent checks. Open source, independently audited
  • Source code. Open source
  • Replaces. LastPass, 1Password, Dashlane

Proton Pass is the only password manager in this category that treats the username as part of the credential.

Alongside the encrypted vault, Proton Pass generates unique email aliases that forward to your real inbox — 10 on the free tier and unlimited with Pass Plus — so the address you hand a service is as disposable as the password.

When an alias starts receiving spam you know exactly which company leaked it, and turning it off costs nothing. Rotating passwords perfectly while giving two hundred services the same address leaves a permanent identifier that survives every breach; this is the gap that closes it.

Proton Pass is built by Proton AG in Geneva with data centres in Switzerland and Germany, is open source, and has been independently audited — which matters because in a zero-knowledge design the client handles your keys and only ciphertext reaches the server.

The vault covers end-to-end encrypted credentials, 2FA codes, secure sharing and integration with Proton Mail, Calendar, Drive and VPN in one account. Free tier available, Pass Plus from about €1.99 per month. As a 2023 entrant it is still filling gaps: enterprise controls are limited, travel mode is absent (emergency access is included in Pass Plus), and browser autofill occasionally struggles on complex sites.

What Proton Pass does well

  • Unlimited email aliases alongside the vault, generated in the same step
  • Open source and independently audited
  • 2FA codes, secure sharing and cross-platform apps included
  • Swiss jurisdiction, data centres in Switzerland and Germany
  • Integrates with Proton Mail, Calendar, Drive and VPN

Where Proton Pass falls short

  • Launched 2023, so fewer features than mature competitors
  • Limited enterprise controls for business deployments
  • No travel mode yet
  • Autofill detection can struggle on complex websites

Standout feature. Aliases inside the vault: Proton Pass is the only manager here where generating a disposable email address happens in the same dialogue as the password, which is why people actually use it.

#2 NordPass

Vilnius, Lithuania Founded 2019 Free tier / from about €1.49/month (Premium) Free tier

Best for: Individuals and families wanting a polished European manager

  • Operating company. Nord Security
  • Jurisdiction. EU (Lithuania)
  • Where the data sits. Europe
  • Independent checks. Independently audited, zero-knowledge
  • Source code. Closed source
  • Replaces. LastPass, 1Password, Dashlane

NordPass is the most refined consumer password manager in this category, and the cheapest paid tier at about €1.49 per month. Where it differs technically is the cipher: NordPass uses XChaCha20 rather than AES-256.

That is a deliberate choice with practical consequences — XChaCha20 is faster on devices without hardware AES acceleration, which covers a great many phones, and its nonces are large enough that reuse attacks are effectively impossible. The algorithm comes from Daniel J. Bernstein and has been extensively analysed.

NordPass is built by Nord Security in Vilnius, the company behind NordVPN, with European data storage and EU establishment giving intra-EEA processing. The zero-knowledge architecture means encryption and decryption happen locally and NordPass never holds the master password or the keys derived from it.

Features cover a password generator, autofill, secure sharing and a data breach scanner. The limitations are honest ones: NordPass is not open source, so the security community cannot verify the implementation independently — mitigated but not replaced by independent audits — and the free plan is limited to a single device.

What NordPass does well

  • Cheapest paid tier here at about €1.49/month
  • XChaCha20 encryption, faster on phones than AES-256
  • Independently audited zero-knowledge architecture
  • Lithuanian company, EU jurisdiction, intra-EEA processing
  • Data breach scanner and polished cross-platform apps

Where NordPass falls short

  • Not open source, so the implementation cannot be independently verified
  • Free plan is limited to a single device
  • Shorter track record than 1Password or LastPass
  • Thinner team and enterprise features than Passbolt or Uniqkey

Standout feature. XChaCha20: NordPass is the only manager in this category that picked a cipher optimised for the phones people actually unlock their vault on.

#3 Uniqkey

Copenhagen, Denmark Founded 2016 From about €3/user/month Demo on request

Best for: European businesses that need GDPR compliance by architecture

  • Operating company. Uniqkey ApS
  • Jurisdiction. EU (Denmark)
  • Where the data sits. Denmark (EU)
  • Independent checks. Zero-knowledge, GDPR by design
  • Source code. Closed source
  • Replaces. LastPass, 1Password, Dashlane

Uniqkey is built for the person who has to answer the compliance question, and the distinction it draws is real.

Most password managers were designed for the US market and later adapted for European regulation; Uniqkey was architected around GDPR from the start, so every decision about data storage and encryption was made against European requirements rather than retrofitted to them. All data is stored exclusively in Danish data centres inside the EU, meaning credential data never leaves European jurisdiction and processing is intra-EEA with no transfer analysis required.

Uniqkey ApS is based in Copenhagen and sells to businesses rather than individuals, from about €3 per user per month with transparent pricing and volume discounts.

The feature set follows: end-to-end encrypted zero-knowledge storage, team management, role-based structure and SSO — which changes what the password manager needs to cover at all, since federated logins remove whole categories of shared credential. Uniqkey is not open source, so the implementation must be trusted rather than inspected, and there is no free tier for evaluation without a sales conversation.

What Uniqkey does well

  • Architected around GDPR rather than adapted to it
  • Data stored exclusively in Danish EU data centres
  • SSO alongside the vault, reducing shared-credential surface
  • Team management and zero-knowledge encryption for business use
  • Transparent per-user pricing with volume discounts

Where Uniqkey falls short

  • Business-only; not aimed at individuals
  • Not open source
  • No free tier — evaluation runs through a demo
  • Smaller ecosystem than the international incumbents

Standout feature. GDPR by architecture: Uniqkey is the only manager here designed against European requirements from the first decision rather than adapted from a US product.

#4 Passbolt

Luxembourg City, Luxembourg Founded 2017 Free Community Edition / from about €4/user/month (Pro) Free Community Edition

Best for: Teams and IT departments managing shared infrastructure credentials

  • Operating company. Passbolt SA
  • Jurisdiction. EU (Luxembourg)
  • Where the data sits. EU cloud, or self-hosted anywhere
  • Independent checks. Open source (AGPL v3), independently audited
  • Source code. Open source
  • Replaces. LastPass Business, 1Password Teams, Dashlane Business

Passbolt is the only password manager in this category built for teams from the first day rather than grown out of a consumer product, and the encryption model shows it.

Passbolt uses OpenPGP: every user holds a GPG key pair, and a shared password is encrypted individually to each authorised user's public key — so neither administrators nor Passbolt itself can decrypt anything. That is genuine zero-knowledge for shared secrets, which is a harder problem than zero-knowledge for personal ones, and it rests on a standard that has been scrutinised for decades rather than a bespoke scheme. The implementation has been independently audited with reports published.

Passbolt SA is based in Luxembourg City and licensed under AGPL v3. Self-hosting runs on Linux with documented manual, Docker and Kubernetes deployment; Passbolt Cloud is the managed alternative in EU data centres with automatic updates, backups and support.

The team features are the point: groups, role-based access control, folders by department or project, comments for context, an activity log for accountability, and an API for automation. The Community Edition is free, Pro from about €4 per user per month. The cost is that GPG has a learning curve, mobile apps trail the web and extension experience, and it is a poor fit for a single individual.

What Passbolt does well

  • Built for teams from day one, not retrofitted from a consumer product
  • OpenPGP encryption per recipient — admins cannot read shared credentials
  • Open source under AGPL v3 with published independent audits
  • Self-host on Linux, Docker or Kubernetes, or use the EU cloud
  • Role-based access, activity log and an API for automation

Where Passbolt falls short

  • Poor fit for individual use
  • GPG-based model has a real learning curve for non-technical users
  • Mobile apps less mature than the web and extension interfaces
  • Self-hosting needs technical expertise and ongoing maintenance

Standout feature. Per-recipient GPG encryption: Passbolt is the only manager here where sharing a credential with a colleague does not require anyone — including the administrator — to be able to read it.

#5 heylogin

Hannover, Germany Founded 2020 Free tier / from about €2.50/user/month (Business) Free tier

Best for: Users and teams who want to stop having a master password

  • Operating company. heylogin GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany
  • Independent checks. End-to-end encrypted
  • Source code. Closed source
  • Replaces. LastPass, 1Password, traditional password managers

heylogin removes the thing every other manager in this category depends on.

There is no master password to memorise: your smartphone is the authentication device, and a login request appears on the phone to be approved with a fingerprint, face recognition or a PIN. The authentication factors become something you have and something you are, rather than something you know — which means there is no secret to forget, and no secret for a phishing page to capture, because it does not exist.

heylogin GmbH is based in Hannover with data hosted in Germany, giving intra-EEA processing under one of Europe's strictest data protection regimes, and the vault is end-to-end encrypted. Team sharing and business features are built in, with a free tier and business plans from about €2.50 per user per month.

For an organisation, the operational argument is that onboarding no longer requires teaching people to construct and remember a strong master password, which is where most credential hygiene programmes fail. The trade-off is honest: the phone becomes more important than it was, so multi-device setup is essential, and heylogin is not open source.

What heylogin does well

  • No master password at all — nothing to forget or be phished for
  • Smartphone plus biometrics as the authentication factors
  • German company, German hosting, intra-EEA processing
  • Team sharing built in, business plans from about €2.50/user/month
  • Onboarding does not depend on users choosing a strong master password

Where heylogin falls short

  • Losing the phone matters more, so multi-device setup is essential
  • Not open source
  • Smaller feature set than mature managers
  • Mobile-first model does not suit everyone's workflow

Standout feature. No master password: heylogin is the only manager in this category that removes the single secret every other one is built around, rather than protecting it better.

#6 Psono

Germany Free and open source / paid hosting and enterprise plans Free self-hosted

Best for: Teams that want a shared password manager on their own server

  • Operating company. esaqa GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Self-hosted, or German servers
  • Independent checks. GDPR
  • Source code. Open source
  • Replaces. 1Password Teams, LastPass, Bitwarden

Psono is a team password manager you can host yourself, which is the combination most of this category does not offer. Personal managers self-host badly and team managers are almost always someone else's service — Psono is open source, designed for organisations, and deployable on your own infrastructure.

Encryption happens client-side before anything is transmitted, so a self-hosted Psono server stores material it cannot read, and the same is true of the hosted option on German servers. For team use the sharing model is the part that matters: credentials shared with a group rather than pasted into chat, with access removed when someone leaves rather than remaining in a colleague's notes app.

It is developed in Germany with servers in Germany for the hosted version, using TLS 1.2 with perfect forward secrecy in transit on top of the client-side encryption. Free and open source to self-host, with paid hosting and enterprise plans including the administration features larger deployments need. The costs are the usual ones: self-hosting means you run and update it, the interface is functional rather than polished next to 1Password, and the ecosystem of integrations is smaller.

What Psono does well

  • Open source and self-hostable for team use
  • Client-side encryption — the server stores unreadable data
  • Proper group sharing with revocable access
  • German company, German servers on the hosted option
  • Free to self-host at any team size

Where Psono falls short

  • Self-hosting means you run and update it
  • Interface functional rather than polished
  • Smaller integration ecosystem than commercial rivals
  • Enterprise administration features are paid

Standout feature. A team password manager on your own server — the combination that personal managers and SaaS both miss.

#7 KeePass

Germany Founded 2003 Free and open source Free

Best for: People who want their passwords in a file they control, with no service at all

  • Operating company. Dominik Reichl
  • Jurisdiction. No service — the file is yours
  • Where the data sits. A file on your own device
  • Independent checks. ANSSI CSPN; EU-FOSSA audit; code analysis sponsored by BSI
  • Source code. Open source
  • Replaces. 1Password, LastPass, Dashlane

KeePass is the answer to a question the rest of this category cannot address: what if there is no service? Passwords live in a single encrypted file on your own device. No account, no sync server, no company, no subscription, and no breach of a provider that could ever expose your vault — because there is no provider.

That architecture is why it remains the recommendation for people whose threat model includes the password manager itself. Every cloud-based manager, however well engineered, is a concentrated target holding millions of vaults, and the industry has demonstrated more than once what happens when one is compromised. A local file is not a target of that kind.

It is free and open source under GPL v2 or later, written by Dominik Reichl in Germany and maintained continuously since 2003 — more than two decades, which for security software is the strongest signal available.

A large plugin ecosystem and compatible clients on every platform read the same file format, so the file syncs through whatever storage you already trust. The costs are real: you handle sync and backup yourself, losing the file without a backup loses everything, the interface is dated, and sharing with a team is genuinely awkward — which is what Psono exists for.

What KeePass does well

  • A local encrypted file — no service that can be breached
  • Free and open source under GPL v2 or later
  • Maintained continuously since 2003
  • Compatible clients on every platform read the same file
  • You choose how and whether it syncs

Where KeePass falls short

  • You handle sync and backup yourself
  • Lose the file without a backup and it is gone
  • Dated interface
  • Team sharing is awkward — Psono fits that better

Standout feature. There is no company to breach — the only design in this category where a provider compromise cannot reach you.

#8 Password Depot

Darmstadt, Germany Founded 1998 €99.95 one-time (1 user, all own devices) / Family €149.95 one-time for 5 licences / Enterprise Server by quote, free for up to 3 users Free trial; Enterprise Server free for up to 3 users

Best for: Buyers who want a certified vendor, a one-time price and no vendor cloud

  • Operating company. AceBIT GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. No vendor cloud: a local file, your own Enterprise Server or your own Azure tenant; optional sync via Google Drive, OneDrive, Dropbox or HiDrive
  • Independent checks. ISO/IEC 27001:2022 (TÜV NORD); penetration-tested by SySS
  • Source code. Closed source
  • Replaces. 1Password, LastPass, Keeper

Password Depot is sold the way software used to be sold: €99.95 once for one user across all their own devices, or €149.95 once for a family pack of five licences, with no subscription to cancel.

The Enterprise Server for teams is quoted rather than listed, and is free for up to three users. AceBIT GmbH has been at this since 1998 and runs from Schleiermacherstraße in Darmstadt, registered at Amtsgericht Darmstadt under HRB 33038 — a small German company with a long trading history rather than a funded newcomer.

The part that matters for this directory is that AceBIT operates no cloud of its own. The vault is a local file, or it sits on an Enterprise Server you run, or in your own Azure tenant; nothing is stored on infrastructure AceBIT controls.

AceBIT is also the rare vendor here with an independent certificate rather than a self-description: ISO/IEC 27001:2022 issued by TÜV NORD, with penetration testing by SySS. Among the closed-source options in this category that combination — a named certifier and no vendor-held data — is the strongest evidence on offer.

The qualifications are real. The source is closed, so the client that handles your key has to be trusted rather than read.

The home edition syncs through Google Drive, OneDrive, Dropbox or HiDrive, and three of those four are American services; the self-hosted route via your own Azure tenant still puts the vault on Microsoft infrastructure, even when the tenant is yours. The pricing page does not say whether its figures include VAT, though the server quote is stated as "plus 19% VAT", and the Enterprise Server price only appears after a sales conversation.

What Password Depot does well

  • A one-time licence at €99.95, or €149.95 for five, instead of a subscription
  • ISO/IEC 27001:2022 certified by TÜV NORD, with penetration testing by SySS
  • No vendor cloud at all: a local file, your own server or your own Azure tenant
  • German company in Darmstadt, trading since 1998, registered at HRB 33038
  • Enterprise Server free for up to three users, so a team can test it properly

Where Password Depot falls short

  • Closed source — the client that handles your key cannot be inspected
  • Home sync runs through Google Drive, OneDrive, Dropbox or HiDrive; three of the four are American
  • The self-hosted Azure option still places the vault on Microsoft infrastructure
  • The listed prices do not state whether VAT is included, and the Enterprise Server is quote-only

Standout feature. Bought once, hosted nowhere: Password Depot is the only certified vendor here that never holds your vault, because AceBIT runs no cloud for it to sit in.

#9 F-Secure ID Protection

Helsinki, Finland Founded 1988 €49.99/year (1 device) / €69.99/year (3 devices) / €79.99/year (5 devices), VAT included 30-day free trial

Best for: Households that want breach alerts from a listed Finnish security company

  • Operating company. F-Secure Corporation
  • Jurisdiction. EU (Finland)
  • Where the data sits. Encrypted on your devices and on servers hosted by F-Secure; F-Secure says it keeps sensitive customer data in Finland or the EEA (country and provider not named)
  • Source code. Closed source
  • Replaces. LastPass, Dashlane, Norton Password Manager

F-Secure ID Protection is the consumer end of a Nordic security business: a vault with autofill, plus monitoring that tells you when an address of yours turns up in a breach.

F-Secure Corporation is registered at Tammasaarenkatu 7 in Helsinki and listed on Nasdaq Helsinki, so its accounts and ownership are public in a way almost nothing else in this category is — the present company is the consumer half of the 2022 demerger that sent the business arm on as WithSecure, and it counts its own history back to 1988.

Pricing is straightforward and stated with VAT included: €49.99 a year for one device, €69.99 for three and €79.99 for five, after a 30-day trial. The vault is decrypted on your device, and F-Secure hosts the server side itself.

That is where the detail runs out: the privacy policy for the product says only "servers hosted by F-Secure", and commits to keeping sensitive customer data in Finland or the EEA without naming a country or a provider. For a directory that weighs who supplies the infrastructure, that is a gap, and it is a gap in the vendor's own documentation rather than in the reading of it.

Nothing on the pages checked names an independent certification for the product, and the source is closed, so the vault has neither of the two forms of external assurance the better-placed entries here offer. The price is also high against the field: €49.99 a year for a single device is more than three times NordPass Premium, and the breach monitoring is what you are paying the difference for.

What F-Secure ID Protection does well

  • Listed Finnish company with public accounts: F-Secure Corporation, Helsinki, Nasdaq Helsinki
  • Data-breach monitoring alongside the vault, not as a separate product
  • Prices published with VAT included, from €49.99 a year, with a 30-day trial
  • Decryption happens on your device
  • EU establishment, so processing is intra-EEA

Where F-Secure ID Protection falls short

  • F-Secure hosts the vault servers but names neither the country nor the provider
  • No independent certification stated on the pages checked
  • Closed source
  • €49.99 a year for one device is expensive next to the consumer options above it

Standout feature. A listed vendor you can look up: F-Secure files public accounts on Nasdaq Helsinki, which is more corporate transparency than any private rival here offers — even though it will not say which data centre holds the vault.

#10 SecureSafe

Zurich, Switzerland Pass from CHF 11.70/month (Starter) / CHF 3.20 per user/month (Professional) / CHF 4.60 per user/month (Business); Pass + File bundles from CHF 19.90/month for 5 users 14-day free trial on all plans

Best for: Swiss-only storage for passwords and the documents that go with them

  • Operating company. DSwiss AG
  • Jurisdiction. Switzerland (adequacy decision, outside the EEA)
  • Where the data sits. Switzerland only; data centre operator not named
  • Independent checks. ISO/IEC 27001:2022
  • Source code. Closed source
  • Replaces. 1Password Business, Keeper, Dropbox Passwords

SecureSafe puts credentials and files in the same safe, which is the reason to choose it over a pure password manager: the contract, the scan of the passport and the login for the portal it belongs to end up in one place rather than three.

It is run by DSwiss AG at Flurstrasse 64 in Zurich, registered under UID CHE-112.888.238 with a branch in Roveredo GR and an office in Lisbon, and it is certified to ISO/IEC 27001:2022. Data centres are exclusively in Switzerland, although DSwiss does not name the operator — so you know the country and not the company holding the racks.

Read the security page before buying, because SecureSafe is not zero-knowledge and does not claim to be. It describes server-side encryption with controlled, audited internal decryption, which means DSwiss can, under its own controls, decrypt what it stores.

Every other manager in this directory is built so the provider mathematically cannot. That is a design decision rather than an oversight — it is what makes server-side features and the digital-inheritance function work — but it changes what a Swiss jurisdiction buys you: with zero knowledge the law barely matters, and here it is the whole protection.

Pricing is published, which is more than several rivals manage: the Pass module starts at CHF 11.70 a month for Starter, CHF 3.20 per user per month for Professional and CHF 4.60 per user per month for Business, with Pass + File bundles from CHF 19.90 a month for five users.

All plans have a 14-day trial. The pages do not say whether those figures include VAT, EUR and USD can be selected on the pricing page, and Switzerland sits outside the EEA under an adequacy decision, so an EU buyer is relying on that decision holding.

What SecureSafe does well

  • Passwords and files in one safe, so credentials and documents stay together
  • ISO/IEC 27001:2022 certified
  • Data centres exclusively in Switzerland
  • Published per-user pricing from CHF 3.20 and a 14-day trial on every plan
  • Swiss company with a register entry: DSwiss AG, UID CHE-112.888.238, Zurich

Where SecureSafe falls short

  • Not zero-knowledge: server-side encryption with controlled, audited internal decryption
  • The Swiss data centre operator is not named
  • Switzerland is outside the EEA, so transfers rest on the adequacy decision
  • Closed source, and the prices do not state whether VAT is included

Standout feature. Swiss soil, but not zero knowledge: SecureSafe is the one safe here that its own operator can open, which is exactly why where it stands matters so much.

#11 KeePassXC

Weimar, Germany Founded 2016 Free and open source Free

Best for: People who want an offline vault that an outside body has actually examined

  • Operating company. KeePassXC Team (legal contact: Janek Bevendorff)
  • Jurisdiction. No service — the file is yours
  • Where the data sits. An encrypted KDBX file on your own device; no KeePassXC cloud
  • Independent checks. ANSSI CSPN security visa (version 2.7.9, 2025)
  • Source code. Open source
  • Replaces. 1Password, LastPass, Bitwarden

KeePassXC answers the same question as KeePass — passwords in an encrypted KDBX file on your own device, no account, no sync server, no company holding anything — and, like KeePass, has been examined from outside.

The French cybersecurity agency ANSSI granted KeePassXC a CSPN security visa for version 2.7.9 on Windows 10, valid from 17 November 2025 to 17 November 2028.

A CSPN visa is a state-run evaluation with a defined scope and a published result, which is a different kind of assurance from "the source is on GitHub, look for yourself". For a vault with no provider to audit, the client is the whole security story. KeePass, for its part, lists an ANSSI CSPN certification of its own and code audits sponsored by Germany's BSI and the European Commission, so outside examination is something both offline vaults can show.

It is a community project rather than a company. The legal contact given on keepassxc.org/team is Janek Bevendorff in Weimar, Germany, the same arrangement as KeePass with Dominik Reichl, and the copyright line dates the team to 2016. The licence is GPL-2 or GPL-3, the project publishes native builds for Windows, macOS and Linux, and the feature set covers Auto-Type and passkeys alongside the vault. It is free, with nothing to upgrade to.

What you give up is everything a vendor provides. There is no support contract, no service level and no one to escalate to; there is no KeePassXC cloud, so sync and backup are your own arrangements through whatever storage you already trust.

Team sharing is as awkward here as in KeePass — Psono and Passbolt exist for that. And read the certificate for what it says: the visa covers version 2.7.9 on Windows 10, not every later build on every platform.

What KeePassXC does well

  • ANSSI CSPN security visa for version 2.7.9, running 17 November 2025 to 17 November 2028
  • An encrypted KDBX file on your own device — no KeePassXC cloud to breach
  • Open source under GPL-2 or GPL-3, free with no paid tier
  • Native builds for Windows, macOS and Linux from the project itself
  • Auto-Type and passkeys in an offline vault

Where KeePassXC falls short

  • No company behind it: no support contract and no service level
  • You arrange sync and backup yourself, and a lost file without a backup is gone
  • The CSPN visa covers one version on Windows 10, not every build on every platform
  • Team sharing is awkward — Psono or Passbolt fit that better

Standout feature. A state-certified offline vault on three desktop systems: KeePassXC holds ANSSI visa ANSSI-CSPN-2025/16 and is built and tested by the project itself on Windows, macOS and Linux.

#12 Steganos Password Manager

Karlsruhe, Germany Founded 1997 €29.99/year annual subscription (list price €39.99) 30-day free trial; 30-day money-back guarantee

Best for: Windows and mobile users who want a local vault and choose their own sync

  • Operating company. Steganos Software GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. A local encrypted file; optional sync through your own Dropbox, Microsoft OneDrive, Google Drive or MagentaCLOUD account (encrypted on your devices)
  • Source code. Closed source
  • Replaces. LastPass, Dashlane, Norton Password Manager

Steganos Password Manager keeps the vault as an encrypted file on your machine and leaves the syncing to you: it works with no cloud at all, or through your own Dropbox, Microsoft OneDrive, Google Drive or MagentaCLOUD account, with the data encrypted on your devices before it leaves them.

That is the KeePass arrangement with a commercial product around it, at €29.99 a year against a €39.99 list price, with a 30-day trial and a 30-day money-back guarantee. The platforms named are Windows, iOS and Android.

Steganos Software GmbH sits at Rüppurrer Straße 1a in Karlsruhe, registered at Amtsgericht Mannheim under HRB 758 458 with Patrick Heise as managing director, and dates itself to 1997 in Frankfurt am Main.

The ownership takes a second look: that address and that managing director are also Nero AG's, whose imprint gives HRB 362519 Mannheim and the same CEO, and the Steganos shop sells Nero products alongside its own.

Neither site states the group relationship, and Nero AG — a German company with offices in Glendale, California and Hangzhou — does not publish its ultimate shareholders. For a directory whose first question is who owns the vendor, that is unresolved rather than damning.

The rest of the qualifications follow the price. No independent certification is stated on the pages checked, and the source is closed, so there is no external assurance of either kind. Three of the four supported sync services are American, and a European buyer who takes that route has moved the ciphertext onto US infrastructure by choice — MagentaCLOUD, from Deutsche Telekom, is the one option that does not. The pricing page does not say whether €29.99 includes VAT.

What Steganos Password Manager does well

  • Works with no cloud at all: the vault is a local encrypted file
  • Sync runs through an account you already have, encrypted on your devices first
  • MagentaCLOUD from Deutsche Telekom is available as a German sync option
  • €29.99 a year against a €39.99 list price, with a 30-day trial and a 30-day money-back guarantee
  • German company in Karlsruhe, registered at HRB 758 458, trading since 1997

Where Steganos Password Manager falls short

  • The ownership is unclear: the address, managing director and shop are shared with Nero AG, the relationship is stated nowhere and Nero AG's ultimate shareholders are not published
  • Three of the four sync services offered are American
  • No independent certification stated on the pages checked, and the source is closed
  • The named platforms are Windows, iOS and Android
  • The price does not state whether VAT is included

Standout feature. You pick the cloud, or none: Steganos is the only paid product here that never asks you to store the vault anywhere the vendor chose — and the only one whose corporate parentage you cannot establish from its own pages.

Are you buying for yourself or for a team? They are different products.

A personal password manager optimises for one person's convenience: autofill that works everywhere, sync across devices, a generator, breach alerts. Proton Pass and NordPass are built this way, and both have free tiers you can live on.

A team password manager optimises for something else entirely — who has access to what, who granted it, who revoked it, and what happens when someone leaves. Passbolt was designed for that from day one, with groups, role-based access control, folders organised by department or project, comments for context and an activity log for accountability. Uniqkey is built for the same buyer with SSO and team management, priced per user.

Retrofitting either direction goes badly. A consumer manager with a "family plan" bolted on does not give an IT team the audit trail it needs. Passbolt, conversely, says plainly that its team focus makes it less suitable for individual use.

heylogin sits across both: a free tier for individuals and a business tier from about €2.50 per user per month, with team sharing built in.

What happens when the master password is the single point of failure?

Everything in a conventional password manager depends on one secret. Forget it and the vault is gone; have it stolen and the vault is open. That is the design of Proton Pass, NordPass, Uniqkey and Passbolt, and it is why every one of them warns about recovery configuration.

heylogin removes the secret. Instead of memorising a master password, your smartphone is the authentication device: a login request appears on the phone and you approve it with a fingerprint, face or PIN. The factors become something you have and something you are, rather than something you know and can forget.

The trade is that you have moved the single point of failure rather than eliminated it. Losing the phone matters more than it did, so multi-device setup is not optional. What you gain is that a phishing page cannot capture a master password that does not exist, and no amount of social engineering extracts a memory nobody holds.

For a team, the operational argument is stronger still: onboarding does not require teaching people to construct and remember a strong master password, which is the step where most credential hygiene programmes quietly fail.

Does open source matter more here than elsewhere?

Yes, because the client is what handles your keys. In a zero-knowledge design the server only ever sees ciphertext, so the entire security claim rests on code running on your own device — and closed-source code means taking the vendor's word for what it does with the master key.

Proton Pass and Passbolt both publish their source. Passbolt goes further and builds on OpenPGP, a cryptographic standard that has been examined for decades rather than a bespoke scheme, with independently published audit reports.

NordPass, Uniqkey and heylogin are not open source. NordPass mitigates this with independent security audits, which is a real but weaker assurance: an audit examines a snapshot, while published source can be examined by anyone at any time.

This is not a reason to dismiss the closed-source options — Nord Security has a clean record and Uniqkey is built for a compliance buyer who cares about certification more than source access. But if two products are otherwise equal, published source is the tiebreaker in this category more than in any other.

Why do email aliases belong in a password manager?

Because half of a credential is the username, and for most services the username is your email address. Rotating passwords perfectly while handing the same address to two hundred services leaves a permanent identifier that ties those accounts together and follows you through every breach.

Proton Pass is the only manager in this category that closes that gap. When signing up for a service you generate a unique alias that forwards to your real inbox; the free tier includes 10 aliases and Pass Plus makes them unlimited. If an alias starts receiving spam you know exactly which service leaked it, and disabling it costs nothing.

The practical effect is compartmentalisation that actually gets used. Alias systems that live in a separate product get abandoned within a month because generating one is an extra step at exactly the wrong moment; inside the password manager, it happens in the same dialogue as the generated password.

It works with any email address rather than requiring Proton Mail, though the integration is tighter if you use both.

What should a European team actually check before rolling one out?

Where the vault is stored, and under which law. Uniqkey stores exclusively in Danish data centres and was designed around GDPR from the architecture up rather than adapted to it — which is the distinction a European compliance officer is actually asking about. Passbolt offers an EU cloud or self-hosting on Linux with documented Docker and Kubernetes deployment. heylogin hosts in Germany. Proton Pass is Swiss, covered by an adequacy decision rather than intra-EEA processing.

Then check the leaving process, because it is where credential management fails. When an employee departs, someone has to revoke every shared credential they could see and rotate the ones that matter. Passbolt's role-based access control and activity log make that a defined procedure; a consumer manager with shared folders makes it a memory exercise.

Then check the integrations you depend on. Uniqkey includes SSO, which changes what the password manager even needs to cover. Passbolt exposes an API for automation, which matters if credentials feed deployment pipelines.

And check autofill against your own critical applications before committing. Proton Pass and Passbolt both acknowledge browser-extension autofill issues on complex sites, and a manager that fails on the one internal application everybody uses daily will be worked around within a week.

How we selected and ranked these 12 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Proton Pass holds #1 among the European password managers in this directory, because Proton Pass pairs an open-source, independently audited vault with unlimited email aliases, so both halves of a credential become disposable. The right answer depends on the buyer: NordPass for the cheapest polished consumer option, Passbolt for teams needing GPG-based sharing and self-hosting, Uniqkey for European businesses that need GDPR-by-design and SSO, and heylogin for anyone who wants to stop having a master password at all.

NordPass Premium is the cheapest paid option at about €1.49 per month, with Proton Pass Plus at about €1.99.

Both offer free tiers — NordPass's free plan is limited to a single device, while Proton Pass's free tier includes 10 email aliases. heylogin has a free tier with business plans from about €2.50 per user per month. Passbolt's Community Edition is free and self-hosted, with Pro from about €4 per user per month. Uniqkey starts at about €3 per user per month and is business-only.

Proton Pass and Passbolt both publish their source code. Passbolt is AGPL v3 and builds on OpenPGP, a standard examined by cryptographers for decades, with independently published audit reports. This matters more in this category than in most, because in a zero-knowledge design the client handles your keys and the server only sees ciphertext — so the entire security claim rests on code running on your device. NordPass, Uniqkey and heylogin are closed source, though NordPass has been independently audited.

heylogin is built exactly for that. Instead of memorising a master password, your smartphone is the authentication device: a login request appears on your phone and you approve it with a fingerprint, face recognition or PIN. The authentication factors become something you have and something you are, rather than something you know and can forget or have phished. The trade-off is that losing the phone matters more, so multi-device setup is essential rather than optional.

Passbolt, which was designed for collaboration from day one rather than retrofitted from a consumer product. Each shared credential is encrypted individually to every authorised user's GPG public key, groups and role-based access control manage permissions, folders organise by department or project, comments add context and an activity log tracks every change. Uniqkey is the alternative for European businesses that want a managed product with SSO and Danish data residency at about €3 per user per month.

Passbolt. Self-hosting is supported on Linux with documentation covering manual installation, Docker and Kubernetes, and the Community Edition is free with no user limit. That gives complete control over the password data, the infrastructure and the update schedule. Passbolt Cloud is the managed alternative, hosted in EU data centres with automatic updates, backups and professional support. Self-hosting requires technical expertise and ongoing maintenance, so organisations without IT resources should use the cloud version.

XChaCha20 is a modern stream cipher developed by Daniel J. Bernstein, used by NordPass instead of the more common AES-256. It is faster on devices without hardware AES acceleration — which includes many phones — and uses nonces large enough that nonce reuse attacks are effectively impossible. It has been extensively analysed by cryptographers. Combined with NordPass's zero-knowledge architecture, encryption and decryption happen locally and only ciphertext reaches NordPass servers.

Proton Pass is the only one in this category with aliases built in. When signing up for a service you generate a unique address that forwards to your real inbox: 10 aliases on the free tier, unlimited with Pass Plus. If an alias starts receiving spam you know precisely which service leaked it, and disabling it does not affect your main address. It works with any email provider, though the integration is tighter with Proton Mail.

For a business, usually not. Proton Pass is Swiss, which sits outside the EU with an adequacy decision covering transfers and outside the Five, Nine and Fourteen Eyes arrangements.

NordPass in Lithuania, Uniqkey in Denmark, Passbolt in Luxembourg and heylogin in Germany are EU-established, so processing is intra-EEA with no transfer analysis at all. Uniqkey goes furthest, storing exclusively in Danish data centres and building GDPR compliance into the architecture rather than adapting a US product to it — which is what a European compliance officer is actually asking about.

Not on this list?

If you build a European password managers tool that belongs here, tell us about it. Every suggestion is checked against the same criteria as the tools above: European ownership and hosting, a real product, and pricing we can verify. A listing is editorial, and we say so on this page where placement is paid.

Suggest your tool