European Alternatives to 1Password, LastPass - Password Sharing (2026) | European Purpose

European Password Sharing Alternatives

Eleven European team password managers, checked against each vendor's own imprint, licence and pricing page. Shared folders, joiners and leavers, audit logs — with the hosting written out, including the two that run on an American hyperscaler.

How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect the order tools appear in. It never buys a listing: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect the order in which tools appear; it never affects whether a tool is listed. Editorial policy

11 European Password Sharing

Passbolt

Luxembourg team vault under AGPLv3: self-host it, or take a cloud whose regions are named

Luxembourg Community Edition free (AGPLv3) / self-hosted Pro €4.50 per user/month billed annually, min 10 users / Cloud Business €5 / Cloud Sovereign €7
AGPLv3, unlimited users self-hostedCloud Business on Google Cloud in Belgium and GermanySovereign cloud in a Luxembourg data centre

heylogin

Braunschweig vault where the phone in your pocket is the key, on Hetzner in Nuremberg

Germany Private free / Business €3.99 per user/month billed yearly (€4.99 monthly) / Enterprise on request from 50 employees
Logins confirmed by swiping on your phoneHetzner Nuremberg, standby in FalkensteinISO/IEC 27001:2022

Uniqkey

Danish access management for a whole company, with joiners and leavers built into the product

Denmark No public price list; quote on request, free trial available
Shared passwords with per-group accessOnboarding, offboarding and SCIMISAE 3402 audited by Grant Thornton

LockSelf

French password, file and transfer suite with an ANSSI CSPN certificate, hosted at Outscale or Scaleway

France No public price list; Starter from 2 licences, Premium from 25, On-Premises from 50, priced per module and per 1- or 3-year term
ANSSI CSPN certified (version 2.2)Hosted at Outscale or Scaleway in FranceOn-premises deployment from 50 licences

Hypervault

Antwerp vault for teams and MSPs at €4 per user a month, with folders you can hand to a client

Belgium Individual free / Individual+ €12 a year / Families €49 a year / Business €4 per user/month (€39 a year) / Enterprise €6 (€59), excl. VAT
€4 per user per month on BusinessUp to 25 client invites, extra clients €2 a monthMicrosoft SSO and Azure AD provisioning on Enterprise

Psono

Apache-2.0 credential manager you run on your own server, free for the first ten users

Germany Free and open source to self-host; all business features free up to 10 users; SaaS and support quoted on request
All business features free up to ten usersApache 2.0, self-hosted behind your firewallThe SaaS runs on AWS and Google Cloud

Passwork

Self-hosted password manager from Barcelona at €3 per user a month, with the licence in your hands

Spain Standard €3 / Advanced €4.50 per user/month billed annually, self-hosted or cloud; one-time lifetime licence offered
Self-hosted licence from €3 per userCloud hosted in GermanyLifetime licence as an alternative to a subscription

Teampass

GPL-3.0 shared vault with no vendor cloud anywhere in the path, maintained by one person since 2009

France Server free (GPL-3.0), no seat limit; Pro browser extension from €49 a year; services quoted per engagement
Free server with no user or feature limitNo vendor cloud and no sub-processor listLDAP/AD, OAuth2 SSO, TOTP and a REST API

SecureSafe

Swiss-only team safes from DSwiss, which states plainly that it is not zero-knowledge

Switzerland Professional CHF 3.20 / Business CHF 4.60 per user/month; Starter bundle CHF 19.90 a month for 5 users; 14-day trial
Unlimited team safes on the Business planData centres exclusively in SwitzerlandServer-side decryption, not zero-knowledge

Padloc

Small German vault that puts shared vaults on the free plan and prices the rest in dollars

Germany Free / Premium $3.49 a month / Family $5.95 / Team $3.49 per user/month ($34.90 a year) / Business $6.99 ($69.90) / Enterprise on request
Shared vaults on the free planUp to 20 shared vaults and 10 groups on TeamAudited three times, most recently by Radically Open Security

Password Depot

Darmstadt password server licensed per named user and run on your own hardware or Azure tenant

Germany Free for up to 3 users; Enterprise Server quoted per named user from 5 users, plus maintenance at 30% of the licence in year one, 27.5% in year two, 25% in year three, plus VAT
Free for up to three usersRuns on your own server or Azure tenantISO/IEC 27001-certified ISMS (TÜV NORD)

Key takeaways

  • Passbolt ranks #1 among the European team password managers in this directory, because it is the only one that is open source under AGPLv3 in both editions, runs self-hosted with no user limit, and names its hosting precisely — Belgium and Germany on Google Cloud for Cloud Business, a private Luxembourg data centre for Cloud Sovereign.
  • Three of the eleven have no vendor cloud at all. Teampass (GPL-3.0), self-hosted Psono (Apache 2.0) and Password Depot's Enterprise Server put the vault on infrastructure you already run, which removes the processor from the GDPR record rather than relocating it.
  • Two European companies run on an American hyperscaler and say so: Passbolt Cloud Business on Google Cloud, and Psono's SaaS on AWS and Google Cloud with no region named at all. Padloc names neither provider nor region and still cites the EU-US Privacy Shield, which was invalidated in 2020.
  • Seven of eleven publish a price. Uniqkey, LockSelf and Password Depot quote only, and Psono publishes nothing beyond "all business features free up to ten users" — which matters more here than in most categories, because a vault is bought per seat and the seat count only ever goes up.
  • LockSelf is the only one holding a state certification rather than a self-declaration: an ANSSI CSPN certificate for version 2.2, with hosting at Outscale or Scaleway under HDS or SecNumCloud qualification.
  • SecureSafe is the only vendor here that states it is not zero-knowledge: server-side encryption with controlled, audited internal decryption, which it says is what makes digital estate management and cross-device features possible.

European team password sharing software is a shared credential vault — folders, groups, per-member permissions and an audit trail — sold by a company established in Europe and hosted on infrastructure the vendor names, so that the one system holding the keys to every other system sits under European jurisdiction rather than under an American parent company.

European password sharing compared

European password sharing tools compared on position, country, entry price and best use
PositionToolEstablishedEntry priceBest for
#1 Passbolt Luxembourg Community Edition free (AGPLv3, unlimited users) / self-hosted Pro €4.50 per user/month billed annually, minimum 10 users / Cloud Business €5 / Cloud Sovereign €7 Teams that want the vault open source and the hosting written down
#2 heylogin Germany Private free / Business €3.99 per user/month billed yearly (€4.99 monthly) / Enterprise on request from 50 employees German-hosted teams that want the master password gone entirely
#3 Uniqkey Denmark No public price list; quote on request Companies whose real problem is who still has access
#4 LockSelf France No public price list: Starter from 2 licences, Premium from 25, On-Premises from 50, priced by module and by a one- or three-year term French organisations that have to show a state certificate
#5 Hypervault Belgium Individual free / Individual+ €12 a year / Families €49 a year / Business €4 per user/month (€39 a year) / Enterprise €6 (€59), excluding VAT Agencies and managed service providers holding other people's credentials
#6 Psono Germany Free and open source to self-host; all business features free up to 10 users; SaaS, professional support and SLAs quoted on request Teams that want the whole thing behind their own firewall for nothing
#7 Passwork Spain Standard €3 / Advanced €4.50 per user/month billed annually, for the self-hosted licence and for the cloud; a one-time lifetime licence is offered Companies that want a licence they own rather than a subscription they rent
#8 Teampass France Server free under GPL-3.0 with no user limit; Pro browser extension from €49 a year; custom development and deployment quoted per engagement Anyone who would rather have no vendor at all
#9 SecureSafe Switzerland Professional CHF 3.20 per user/month (CHF 172.80 a year) / Business CHF 4.60 per user/month (CHF 252.00 a year) / Starter bundle CHF 19.90 a month for 5 users Swiss-jurisdiction teams that want passwords and files in one safe
#10 Padloc Germany Free / Premium $3.49 a month ($34.90 a year) / Family $5.95 ($59.50) / Team $3.49 per user/month ($34.90) / Business $6.99 ($69.90) / Enterprise on request Small teams that want shared vaults without paying for them first
#11 Password Depot Germany Enterprise Server free for up to 3 users; above that, named-user client licences quoted from 5 users, plus software maintenance at 30% of the licence in year one, 27.5% in year two and 25% in year three, plus VAT German organisations that want a server they own and a licence they keep

Every European password sharing tool reviewed

#1 Passbolt

Belvaux, Luxembourg Founded 2017 Community Edition free (AGPLv3, unlimited users) / self-hosted Pro €4.50 per user/month billed annually, minimum 10 users / Cloud Business €5 / Cloud Sovereign €7 Free Community Edition; 7-day trial on Cloud Business

Best for: Teams that want the vault open source and the hosting written down

  • Operating company. Passbolt SA
  • Jurisdiction. EU (Luxembourg)
  • Where the data sits. Self-hosted anywhere; Cloud Business in Belgium and Germany, in Google Cloud data centres; Cloud Sovereign and Enterprise in a private data centre in Luxembourg
  • Independent checks. SOC 2 Type II (2021), repeated Cure53 audits, Quarkslab pre-CSPN evaluation (November 2025), Examin GDPR audit (July 2026)
  • Source code. Open source
  • Replaces. 1Password, LastPass, Bitwarden

Passbolt is the only tool in this category that answers both hard questions in public.

The licence is AGPLv3 for the Community Edition and for the Pro Edition, so the code that guards the credentials can be read and the deployment can be taken over; and the hosting is named down to the country and the provider rather than left as "EU".

Cloud Business sits in Belgium and Germany in Google Cloud data centres. Cloud Sovereign, at €7 per user per month billed annually, sits in a private data centre in Luxembourg for buyers who cannot have an American provider anywhere in the chain. Publishing both, with the difference priced, is rarer than it should be.

The product is built for sharing rather than adapted to it: folders with per-member and per-group permissions, OpenPGP end-to-end encryption where the secret key is never sent to the server in cleartext, and a browser extension that does the decryption client-side.

Passbolt SA is registered in Belvaux, Luxembourg, incorporated in 2017 and financially backed since incorporation by the Grand Duchy. The audit record is the strongest here: repeated Cure53 audits, SOC 2 Type II in 2021, a Quarkslab pre-CSPN evaluation in November 2025 and a GDPR audit by Examin in July 2026.

The cost is the minimum. Both the self-hosted Pro Edition at €4.50 per user per month and Cloud Business at €5 require ten users, so a team of four pays for ten or runs the Community Edition, which is free and unlimited but is not the Pro product. The free trial on Cloud Business is seven days, which is short for a tool that has to be rolled out to a whole team before anyone can judge it.

What Passbolt does well

  • AGPLv3 in both editions, self-hostable with no user limit
  • Hosting named precisely: Belgium and Germany, or a private Luxembourg data centre
  • A sovereign option priced in public at €7 per user per month, not "contact sales"
  • OpenPGP end-to-end encryption with the private key never leaving the client in cleartext
  • Cure53 audits, SOC 2 Type II and a Quarkslab pre-CSPN evaluation
  • Luxembourg company, state-backed since incorporation in 2017

Where Passbolt falls short

  • Ten-user minimum on Pro and on Cloud Business, which prices out small teams
  • Cloud Business runs on Google Cloud, so a US provider sits under a Luxembourg company unless you pay for Sovereign
  • Seven-day cloud trial is short for a team rollout
  • Self-hosting a PHP and OpenPGP stack needs someone who will keep patching it

Standout feature. Two clouds, both named. Passbolt is the only tool here that tells you which of its data centres has an American company underneath, and sells the alternative at a published price.

#2 heylogin

Braunschweig, Germany Private free / Business €3.99 per user/month billed yearly (€4.99 monthly) / Enterprise on request from 50 employees Free Private plan

Best for: German-hosted teams that want the master password gone entirely

  • Operating company. heylogin GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Germany: production on Hetzner servers in Nuremberg with a standby server in Falkenstein, independent backups at IONOS
  • Independent checks. ISO/IEC 27001:2022; independent assessment against BSI test criteria (July 2026)
  • Source code. Closed source
  • Replaces. LastPass, 1Password, Dashlane

heylogin changes the daily ritual rather than the feature list. There is no master password: logging in means swiping on your phone, and the vault is decrypted using the security chip in the device, unlocked locally by fingerprint, face or PIN.

The cryptography is XSalsa20-Poly1305 and Curve25519, and heylogin GmbH states it has no access to stored data. Removing the master password removes the thing that phishing kits are built to steal, which is a more interesting security argument than another row of compliance badges.

The hosting is stated with a precision that makes it checkable: production on Hetzner servers in Nuremberg, a standby server in Falkenstein for failover, and independent backups at IONOS — German company, German infrastructure, European sub-processors only.

The company is heylogin GmbH at Sophienstr. 40 in Braunschweig, registered as HRB 207299 at the Amtsgericht Braunschweig, founded by Dominik Schürmann and Vincent Breitmoser out of TU Braunschweig, with pre-seed funding from Mozilla Ventures in 2022. It holds ISO/IEC 27001:2022 for its ISMS and published an independent assessment against BSI test criteria in July 2026.

The trade-off is the phone. If the key is a device, then a lost, broken or flat phone is an access problem, and heylogin maintains a whole documentation page about it.

The Business plan at €3.99 per user per month billed yearly covers user and team management; roles with RBAC and the audit log are Enterprise features, quoted on request and aimed at 50 employees and up, which puts governance features out of reach of exactly the small teams that would buy the €3.99 plan.

What heylogin does well

  • No master password: the phone's security chip is the key
  • Hetzner in Nuremberg with a standby in Falkenstein, backups at IONOS — all German
  • ISO/IEC 27001:2022 plus a BSI-criteria assessment published in July 2026
  • European sub-processors only, stated by the vendor
  • €3.99 per user per month billed yearly, and a genuinely free plan for private use

Where heylogin falls short

  • Login depends on a working smartphone; a lost or dead phone is an access event
  • RBAC roles and the audit log are Enterprise-only, aimed at 50+ employees
  • Not open source, and no self-hosting option
  • Enterprise pricing is not published

Standout feature. There is no master password to steal. heylogin is the only tool in this category whose threat model removes the credential that phishing campaigns are actually after.

#3 Uniqkey

Herlev, Denmark Founded 2018 No public price list; quote on request Free trial on request

Best for: Companies whose real problem is who still has access

  • Operating company. Uniqkey A/S
  • Jurisdiction. EU (Denmark)
  • Where the data sits. Europe: the terms say personal data may be processed on equipment and resources located in Europe, without naming a country, data centre or provider
  • Independent checks. ISAE 3402 audit by Grant Thornton
  • Source code. Closed source
  • Replaces. 1Password Business, LastPass Business, Keeper

Uniqkey is sold as access management rather than as a vault, and the feature names give it away: share password with team, control and manage access, onboarding and offboarding, password groups, access restriction, verified domains, SCIM, audit log. For an IT manager whose actual pain is that eleven former employees still have the Instagram password, that framing is the right one — the sharing is assumed, and the product is about who has it and how you take it back.

The company is Uniqkey A/S, CVR 39 00 41 27, at Lyskær 8B in Herlev outside Copenhagen, founded in 2018 by Hakan Yagci, and it raised €5.35m in 2024 to push into European SMEs.

Its terms name an ISAE 3402 audit performed by Grant Thornton, which is an assurance report on controls rather than a product certification. Uniqkey positions itself explicitly on European jurisdiction, and its customer logos lean towards municipalities, healthcare and education — buyers who are asked to prove where the data sits.

Which makes the residency statement the disappointment. The terms say only that personal data may be processed on equipment and resources located in Europe: no country, no data centre, no provider, and the privacy policy adds nothing beyond "service providers and data processors". Prices are not published either — the pricing page is a form. For a product whose pitch is sovereignty and simplicity, both blanks have to be filled in by a sales call.

What Uniqkey does well

  • Built around access control, offboarding and SCIM rather than around a vault
  • Danish company with a public CVR number and a Copenhagen-area address
  • ISAE 3402 assurance report audited by Grant Thornton
  • Audit log, password groups and access restriction in the product rather than as add-ons
  • Used by municipalities, healthcare and education, which is where residency questions get asked hardest

Where Uniqkey falls short

  • No published prices at all: every quote runs through sales
  • Residency is stated only as "located in Europe" — no country, data centre or provider named
  • Not open source, no self-hosting
  • No product-level security certification published, only the ISAE 3402 assurance report

Standout feature. It treats offboarding as the product. Uniqkey is built for the question every audit asks — who still has access — rather than for the question a vault usually answers.

#4 LockSelf

Levallois-Perret, France No public price list: Starter from 2 licences, Premium from 25, On-Premises from 50, priced by module and by a one- or three-year term 14 days, up to 10 colleagues, no card

Best for: French organisations that have to show a state certificate

  • Operating company. LockSelf SAS
  • Jurisdiction. EU (France)
  • Where the data sits. France: hosted at Outscale or Scaleway, with HDS or SecNumCloud certified options, or on your own servers
  • Independent checks. ANSSI CSPN certification (version 2.2)
  • Source code. Closed source
  • Replaces. 1Password, LastPass, Keeper

LockSelf is what a French procurement file looks like when it is turned into a product.

The suite is three modules — LockPass for passwords, LockFiles for document storage, LockTransfer for encrypted sending — and the whole suite carries an ANSSI CSPN certification for version 2.2. That is an evaluation by the French national cybersecurity agency, not a self-declaration or a badge bought from a consultancy, and for a French public body or a regulated supplier it is often the thing that ends the discussion.

LockSelf SAS is at 120 rue Jean Jaurès in Levallois-Perret, and the hosting follows the same logic: sovereign cloud partners Outscale and Scaleway, both French, with HDS or SecNumCloud qualified options for health data and state-adjacent workloads, or an on-premises deployment on your own servers.

LockPass stores credentials with RSA-2048 key pairs, files are AES-256 CBC, and the vault is opened with a login, a password and a six-digit PIN. There is a 14-day trial for up to ten colleagues with no card.

The commercial side is conventionally French, which is to say opaque. Nothing is priced in public: the configurator asks which modules you want, how many licences and whether the term is one or three years, and Starter begins at 2 licences, Premium at 25 and On-Premises at 50. The interface and the documentation assume French, and the product is aimed at French-speaking organisations rather than at a distributed European team.

What LockSelf does well

  • ANSSI CSPN certification for version 2.2 of the suite
  • Hosted at Outscale or Scaleway in France, with HDS and SecNumCloud options
  • On-premises deployment available from 50 licences
  • Passwords, file storage and encrypted transfer in one contracted suite
  • 14-day trial for up to ten colleagues, no card required

Where LockSelf falls short

  • No published prices; everything runs through a configurator and a sales call
  • Premium starts at 25 licences and on-premises at 50, which excludes small teams
  • Strongest in French; a product built for the French market first
  • Not open source, and the company publishes no founding date

Standout feature. A CSPN certificate from ANSSI. LockSelf is the only tool here whose security has been evaluated by a national agency rather than attested by its own auditor.

#5 Hypervault

Antwerp, Belgium Founded 2021 Individual free / Individual+ €12 a year / Families €49 a year / Business €4 per user/month (€39 a year) / Enterprise €6 (€59), excluding VAT 14 days on Business, no card required

Best for: Agencies and managed service providers holding other people's credentials

  • Operating company. GTS Data bv
  • Jurisdiction. EU (Belgium)
  • Where the data sits. A data centre in the European Union; the provider is not named
  • Source code. Closed source
  • Replaces. 1Password, LastPass, Keeper

Hypervault is built for the company that keeps other companies' passwords. Client folders, secure links for people who do not need an account, and up to 25 client invites on the Business plan with extra clients at €2 a month each — that is a pricing model shaped around agencies and managed service providers rather than around headcount.

Structured templates are the other half of it: instead of a notes field, a template with the fields an IMAP host, a domain registrar or a licence key actually has, so records stay comparable across 40 clients.

The company is GTS Data bv in Antwerp, founded in December 2020 by Glenn Van Croonenborch, Thierry Dupont and Sven Böhne and backed by private investors, with Hypervault itself dating from 2021.

Business is €4 per user per month (€39 a year), Enterprise €6 (€59), both excluding VAT, with a 14-day trial and no card — the cheapest published seat in this category. Enterprise adds Microsoft SSO, Azure AD provisioning, 1GB of encrypted storage per user and a branded vault add-on at €29.99 a month.

The residency statement is thinner than the rest of the pitch. Hypervault says repeatedly that it is a Belgian company storing vault data in the European Union, and its privacy policy says the data is in a data centre in the EU — but no provider and no city is named anywhere, which is a gap for a product sold on European sovereignty. There is no security certification published either, and the identity integrations are Microsoft-only.

What Hypervault does well

  • The cheapest published seat here: €4 per user per month on Business
  • Client invites priced separately at €2 a month instead of as full seats
  • Structured templates rather than free-text notes, which keeps multi-client records consistent
  • Belgian company with named founders and a board
  • 14-day trial with no card, and a free single-user tier

Where Hypervault falls short

  • EU data centre named only as "the European Union" — no provider, no city
  • No ISO 27001 or equivalent certification published
  • SSO and provisioning are Microsoft-only, and Enterprise-only
  • Not open source, no self-hosting

Standout feature. Clients are not seats. Hypervault is the only tool here that prices the outsider who needs one credential at €2 a month instead of making you buy them a licence.

#6 Psono

Vorra, Germany Founded 2016 Free and open source to self-host; all business features free up to 10 users; SaaS, professional support and SLAs quoted on request Free up to 10 users

Best for: Teams that want the whole thing behind their own firewall for nothing

  • Operating company. esaqa GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. Self-hosted on your own servers; the SaaS runs on Amazon Web Services and Google Cloud, with no region named
  • Independent checks. Open source (Apache 2.0)
  • Source code. Open source
  • Replaces. 1Password, LastPass, Bitwarden

Psono is a credential manager for companies that assumes you will run it yourself.

The server is Apache 2.0, the repository has been public on GitLab since September 2016, and the deployment target is your own network behind your own firewall — which means there is no processor to assess, no sub-processor list to review and no transfer to document. All business features are free up to ten users, which is a real team rather than an evaluation, and vault data is encrypted on the client before it is stored.

It is built by esaqa GmbH at Tiergartenstr. 13 in Vorra, Bavaria, registered as HRB 37978 at the Nuremberg registry court with Sascha Pfeiffer as managing director.

Encrypted team sharing is the core of the product, the admin client is separate from the web client, and there is a public trust centre. For an organisation that already runs its own infrastructure, this is the shortest path from "we share passwords in a spreadsheet" to "we share passwords in a system we control", at no licence cost at all.

Two things to know before choosing it. First, the hosted option undoes the argument: Psono states on its own security page that its SaaS runs on Amazon Web Services and Google Cloud, and names no region, which is the weakest residency statement in this category — take the self-hosted route and the problem disappears.

Second, nothing above the free tier is priced in public: the pricing table on the homepage is loaded by script and professional support, SLAs and the SaaS all end in "contact us for a quote".

What Psono does well

  • Apache 2.0 server, public repository since 2016
  • All business features free for up to ten users
  • Self-hosted behind your own firewall, with no vendor in the processing chain
  • Client-side encryption with encrypted team sharing as the core feature
  • German company with a full commercial-register entry and a public trust centre

Where Psono falls short

  • The SaaS runs on AWS and Google Cloud with no region named — the weakest residency claim here
  • No published prices beyond the free-up-to-ten-users tier
  • Self-hosting means you own the upgrades, the backups and the restore test
  • Interface is functional rather than designed, and the admin client is a separate application

Standout feature. Free for ten users with every business feature. Psono is the only paid-tier product here that gives a whole small team the complete product rather than a trial of it.

#7 Passwork

Barcelona, Spain Standard €3 / Advanced €4.50 per user/month billed annually, for the self-hosted licence and for the cloud; a one-time lifetime licence is offered Free trial, no card required

Best for: Companies that want a licence they own rather than a subscription they rent

  • Operating company. Passwork Europe SL
  • Jurisdiction. EU (Spain)
  • Where the data sits. Self-hosted on your own infrastructure; the Passwork Cloud is hosted in Germany, provider not named
  • Source code. Closed source
  • Replaces. LastPass, 1Password, Keeper

Passwork sells the self-hosted case as the default rather than the fallback.

The licence is €3 per user per month on Standard and €4.50 on Advanced, billed annually, for software that runs on your own infrastructure with double encryption and a zero-knowledge design — and there is a one-time lifetime licence for organisations that would rather buy once than renew forever. That is an unusual offer in a category that has converged on per-seat subscriptions, and it changes the five-year arithmetic considerably.

The company is Passwork Europe SL at Carrer d'Aragó 208 in Barcelona, VAT ESB19399534. Its own about page says the business started in Finland, later moved its headquarters to Spain, is founder-owned with no outside capital, and runs as a remote-first team across Europe, Latin America and Asia. For buyers who do not want to run a server, the Passwork Cloud is hosted in Germany, which keeps EU jurisdiction without an American provider named in the path.

What is missing is the assurance layer. No security certification is published — no ISO 27001, no CSPN, no SOC 2 — and the privacy policy acknowledges processors located outside the customer's jurisdiction without naming them, relying on standard contractual clauses.

The product is not open source either, so the zero-knowledge claim rests on the vendor's description rather than on published code. For a self-hosted product, where you can at least contain the deployment, that is a smaller problem than it would be in a cloud; it is still a blank where competitors have a certificate.

What Passwork does well

  • Self-hosted licence from €3 per user per month, with a one-time lifetime option
  • Cloud alternative hosted in Germany for teams that do not want a server
  • Spanish company, founder-owned, with the imprint and VAT number published
  • Double encryption and a zero-knowledge architecture described in detail
  • Free trial with no card required

Where Passwork falls short

  • No security certification published at all
  • Not open source, so the encryption claims cannot be independently read
  • Privacy policy admits unnamed processors outside the EU under standard contractual clauses
  • No founding year published, and the company history is only on its own about page
  • Cloud provider behind the German hosting is not named

Standout feature. A lifetime licence. Passwork is the only tool here that will sell you the software outright instead of renting it to you per seat forever.

#8 Teampass

France Founded 2009 Server free under GPL-3.0 with no user limit; Pro browser extension from €49 a year; custom development and deployment quoted per engagement 30-day extension trial, no card

Best for: Anyone who would rather have no vendor at all

  • Operating company. No company: built and maintained by Nils Laumaillé since 2009
  • Jurisdiction. No vendor — you host it
  • Where the data sits. Your own server. There is no vendor cloud, no sub-processor list and no transfer to justify
  • Independent checks. Open source (GPL-3.0)
  • Source code. Open source
  • Replaces. 1Password Teams, LastPass Teams, Bitwarden

Teampass removes the vendor from the equation. The server is GPL-3.0 and free with no user limit and no feature gate: AES-256-GCM authenticated encryption, PBKDF2 at 600,000 iterations, per-user key wrapping, four-level classification with per-item ownership, LDAP/AD and OAuth2 SSO, TOTP, a REST API with Bash and PowerShell clients, recertification and compliance exports. The paid product is the browser extension, from €49 a year, and that is what funds the project. Nothing interesting was held back for a paid edition.

The residency answer is one line, which is the point: the data stays where you put it. There is no vendor cloud, no sub-processor list and no cross-border transfer to justify, so the GDPR record of processing has nothing to enumerate.

Teampass also does something no other tool here does — agentless rotation of Linux account passwords over SSH — and its compliance page is unusually honest about limits, stating plainly that no tool makes an organisation compliant with ISO 27001, NIS2 or GDPR, and that what it produces is the access evidence an auditor expects.

The risk is concentrated in one person. Nils Laumaillé has built and maintained Teampass since 2009, writes most of the code, answers most of the discussions and handles the security reports; there is no company, no legal entity to contract with and no support desk.

Nine security advisories were published with release 3.2.1.1 alone — publishing them is to the project's credit, and needing them is the counterpoint. A procurement department that requires a vendor, an SLA or a signed DPA cannot buy this, and should not pretend otherwise.

What Teampass does well

  • GPL-3.0 server, free at any team size with no feature held back
  • No vendor cloud at all, so there is no processor to assess
  • LDAP/AD, OAuth2 SSO, TOTP, REST API and compliance exports included
  • Agentless rotation of Linux account passwords over SSH, which nothing else here does
  • Sixteen years of continuous releases and a public security advisory history

Where Teampass falls short

  • One maintainer, no company, no legal entity and no support contract
  • Security advisories arrive in batches; you own the patching schedule
  • Interface and setup expect someone comfortable with PHP, MySQL and Docker
  • Only the browser extension is commercially supported

Standout feature. There is no processor to assess. Teampass is the only option here where the GDPR question about your password vault has a one-sentence answer.

#9 SecureSafe

Zurich, Switzerland Professional CHF 3.20 per user/month (CHF 172.80 a year) / Business CHF 4.60 per user/month (CHF 252.00 a year) / Starter bundle CHF 19.90 a month for 5 users 14-day free trial on all plans

Best for: Swiss-jurisdiction teams that want passwords and files in one safe

  • Operating company. DSwiss AG
  • Jurisdiction. Switzerland (adequacy decision, outside the EEA)
  • Where the data sits. Switzerland only, in certified data centres; the operator is not named
  • Independent checks. ISO/IEC 27001:2022, PCI DSS v4.0, Swiss Made Software
  • Source code. Closed source
  • Replaces. 1Password Business, LastPass Business, Dropbox Passwords

SecureSafe is the Swiss answer, and unusually it tells you exactly what it has traded away. DSwiss AG in Zurich stores everything in certified data centres exclusively in Switzerland, with triple-redundant storage, ISO/IEC 27001:2022 and PCI DSS v4.0 — and its security page states that the architecture is server-side encryption with controlled, audited internal decryption rather than zero-knowledge, because that is what makes digital estate management, enterprise functions and cross-device features work. Most vendors would have left that sentence out.

For teams, the Business plan at CHF 4.60 per user per month (CHF 252.00 a year) gives an unlimited number of team safes with central permission management; Professional at CHF 3.20 is individual safes only, which is worth checking before buying the cheaper tier for a team.

A Starter bundle covers five users at CHF 19.90 a month with one shared safe. All plans include a 14-day trial, and passwords and encrypted files sit in the same product — the digital estate feature, which hands access to a nominated person after death, is the one thing here that no competitor offers.

Two caveats. Switzerland is outside the EEA: it has an adequacy decision, so transfers are straightforward, but Swiss law is not EU law and this is not an intra-EEA processing arrangement. And the encryption model means the provider can technically decrypt, under audited internal process — for most business buyers that is an acceptable trade for the features it enables, and for anyone whose requirement is that the provider cannot read the vault, it is disqualifying.

What SecureSafe does well

  • Data centres exclusively in Switzerland, with triple-redundant storage
  • ISO/IEC 27001:2022 and PCI DSS v4.0
  • Unlimited team safes on Business at CHF 4.60 per user per month
  • Passwords and encrypted files in one product, with a digital-estate handover feature
  • States its own encryption trade-off in public instead of claiming zero-knowledge

Where SecureSafe falls short

  • Not zero-knowledge: the provider can decrypt under an audited internal process
  • Switzerland is outside the EEA, so this is not intra-EEA processing
  • Team safes only on Business; Professional at CHF 3.20 is individual safes
  • The data centre operator is not named, and no founding year is published
  • Prices are in Swiss francs, so the cost moves with the exchange rate

Standout feature. It says it is not zero-knowledge. SecureSafe is the only vendor in this category that publishes the trade-off its feature set depends on instead of hiding behind the phrase.

#10 Padloc

Ansbach, Germany Free / Premium $3.49 a month ($34.90 a year) / Family $5.95 ($59.50) / Team $3.49 per user/month ($34.90) / Business $6.99 ($69.90) / Enterprise on request 30 days on the paid plans

Best for: Small teams that want shared vaults without paying for them first

  • Operating company. MaKleSoft UG
  • Jurisdiction. EU (Germany)
  • Where the data sits. Not stated: the privacy policy names neither the hosting provider nor a region, only "third party data processors"
  • Independent checks. Open source; audited by three independent groups, most recently Radically Open Security
  • Source code. Open source
  • Replaces. 1Password, LastPass, Bitwarden

Padloc is the small one, and it is generous where the others are not: shared vaults are in the free plan, alongside unlimited items, unlimited devices, multi-factor authentication, a built-in authenticator and markdown notes.

Team at $3.49 per user per month raises that to 20 shared vaults, 10 groups and directory sync with automatic provisioning; Business at $6.99 gives 50 vaults, 20 groups and 20GB of encrypted storage. For a five-person company that wants to stop emailing passwords this week, the free tier is a working starting point rather than a demo.

The publisher is MaKleSoft UG at Meisenstr. 5 in Ansbach, Bavaria, with a postal address in Munich, and the app is open source and end-to-end encrypted. Padloc has been audited three times by independent groups, most recently by Radically Open Security, and publishes a security whitepaper alongside the source. Clients cover Windows, macOS, Linux, iOS, Android and the major browsers, and there is a 30-day trial on the paid plans.

The paperwork has not kept up with the product. The privacy policy names no hosting provider and no region — only "third party data processors" — and still states that they conform to the EU-US Privacy Shield framework, which the Court of Justice invalidated in July 2020.

The footer copyright reads 2022. Prices are in US dollars from a German UG. None of that changes the encryption, and all of it matters if the reason you are shopping in Europe is that you have to answer a question about where the data sits.

What Padloc does well

  • Shared vaults included in the free plan
  • Open source and audited three times, most recently by Radically Open Security
  • Team at $3.49 per user per month with directory sync and automatic provisioning
  • German publisher with a full imprint, clients on every major platform
  • 30-day trial on the paid plans

Where Padloc falls short

  • Privacy policy names no hosting provider and no region
  • Still cites the EU-US Privacy Shield, invalidated in July 2020
  • Prices quoted in US dollars despite the German entity
  • A small UG with a copyright line last updated in 2022 — a continuity question worth asking
  • No certification and no self-hosted commercial edition

Standout feature. Shared vaults on the free plan. Padloc is the only tool here that lets a team share properly before it has paid anything.

#11 Password Depot

Darmstadt, Germany Founded 1998 Enterprise Server free for up to 3 users; above that, named-user client licences quoted from 5 users, plus software maintenance at 30% of the licence in year one, 27.5% in year two and 25% in year three, plus VAT Free for up to 3 users

Best for: German organisations that want a server they own and a licence they keep

  • Operating company. AceBIT GmbH
  • Jurisdiction. EU (Germany)
  • Where the data sits. No vendor cloud: your own Enterprise Server or your own Azure tenant
  • Independent checks. ISO/IEC 27001-certified ISMS (TÜV NORD); penetration-tested by SySS GmbH (December 2025)
  • Source code. Closed source
  • Replaces. 1Password, LastPass, Keeper

Password Depot is the oldest approach here and, for some buyers, still the right one. AceBIT GmbH has been selling it from Darmstadt since 1998, and the Enterprise Server is software you install — on your own hardware or inside your own Azure tenant — with clients for Windows, macOS, Linux, iOS, Android and the browser. There is no AceBIT cloud in the path at all, which makes the data residency question a question about your own data centre.

Licensing is per named user, meaning one person across as many devices as they use, and the server is free for up to three users.

Above that, a quote covers the client licences from five users upwards plus software maintenance at 30% of the licence value in the first year, 27.5% in the second and 25% in the third, plus VAT — an old-fashioned structure that is more predictable over five years than a per-seat subscription, and considerably harder to compare against one. AceBIT's ISMS is ISO/IEC 27001-certified by TÜV NORD, and the software was penetration-tested by SySS in December 2025.

What you are not buying is a modern collaboration product. There is no published price list, the ordering flow is quote-then-contract, and the sharing model is built around a central server with named users rather than around folders shared with an outside client at short notice. For a German Mittelstand company with its own infrastructure and an auditor to satisfy, that is a feature. For a distributed team that wants to invite a freelancer this afternoon, it is not.

What Password Depot does well

  • No vendor cloud: your own server or your own Azure tenant
  • Free for up to three users, with the server licence included
  • ISO/IEC 27001-certified ISMS audited by TÜV NORD, and a SySS penetration test from December 2025
  • Named-user licences covering all of that person's devices
  • German company since 1998, with a full commercial-register entry in Darmstadt

Where Password Depot falls short

  • No published prices: quote first, then contract
  • Maintenance at 30% of the licence value in year one on top of the licence itself
  • Built for a central server and named users, not for ad-hoc external sharing
  • Not open source, and the client licences start at five users
  • Product and support are oriented to German-speaking customers

Standout feature. You buy it, you keep it. Password Depot is the only tool here sold as a licence for software that runs on your own hardware, with the vendor outside the data path entirely.

What actually breaks when a team shares passwords?

Not the encryption. What breaks is the boundary between "everyone can see it" and "one person owns it". Teams start with a single shared vault because it is simple, and within a year the intern can read the payment provider credentials. The fix is folders or vaults with per-member permissions, which every tool here has, and the discipline to use more than one of them, which no tool can supply.

The second failure is the leaver. Removing someone from the workspace takes away their access, but it does not change the secret they already read.

Uniqkey builds joiner and leaver flows in with SCIM provisioning, Teampass ships a leaver risk report and recertification exports, Hypervault and Padloc do directory sync from Azure AD, and Passbolt groups let you withdraw a set of folders in one move. None of them rotates the credential for you, so budget the rotation work rather than assuming the tool did it.

The third is the credential nobody owns: the shared mailbox, the registrar account, the bank portal with one login and four people using it. These are exactly the items that end up in a spreadsheet, because they belong to a function rather than a person. Hypervault sells structured templates for this, Teampass has four-level classification with per-item ownership, and Password Depot licenses per named user precisely so that a shared login still has an accountable owner.

The fourth is the external party. A client, a contractor or an agency needs one credential, not a seat. Hypervault includes up to 25 client invites and charges €2 a month for each one beyond that; Passbolt and Psono handle it with a folder shared to a limited account. Sending it by email "just this once" is the behaviour the tool was bought to stop, and it survives longer than anyone expects.

Self-host it, or buy the cloud?

Self-hosting removes the processor entirely. Teampass puts it plainly: the data stays where you put it, so a GDPR record of processing has nothing to list, no sub-processor to assess and no transfer to justify. Psono under Apache 2.0, Passbolt's Community Edition under AGPLv3 and Password Depot's Enterprise Server reach the same position from different licences.

The cost is that you now run the most security-critical server in the company. Upgrades, backups, TLS certificates, restore testing and someone who answers when authentication breaks on a Friday — for a team of fifteen, that person's time costs considerably more than €4 a seat. A self-hosted vault that is two versions behind is worse than a hosted one that is patched.

The middle path is a vendor cloud with the open licence as insurance. Passbolt Cloud Business at €5 per user per month runs on Google Cloud in Belgium and Germany; if that is not acceptable, Cloud Sovereign at €7 moves the same product into a private data centre in Luxembourg. That is a rare thing to find published: most vendors offer one answer and expect you to take it.

One thing to check before committing either way: whether the features you are buying exist in the edition you are deploying. Passbolt's Community Edition is free with unlimited users but is not the Pro Edition, and Psono gives all business features free only up to ten users. The licence is not the same question as the feature list.

"EU-hosted" is at least three different claims

The strongest version names the country, the provider and the building. heylogin states production on Hetzner in Nuremberg with a standby in Falkenstein and backups at IONOS. LockSelf names Outscale and Scaleway, both French, with HDS or SecNumCloud qualified options. SecureSafe states Swiss data centres only. Passwork states that its cloud is in Germany. These are checkable claims.

The middle version is a European region on an American platform. Passbolt Cloud Business is in Belgium and Germany, in Google Cloud data centres — European ownership, European region, American provider. That is a defensible position for most buyers and a disqualifying one for a few, which is exactly why Passbolt also sells the Luxembourg sovereign option. The distinction matters because the provider, not the region, is what determines whose law can reach the infrastructure.

The weakest version is a continent. Uniqkey's terms say personal data may be processed on equipment and resources located in Europe, and name nothing further. Hypervault says a data centre in the European Union without naming the provider. Psono says AWS and Google Cloud with no region at all, which is the least specific statement in this category. Padloc names nothing and still references the EU-US Privacy Shield, a framework the Court of Justice struck down in July 2020.

Where you land on this should follow from your own obligations, not from a general preference. If your procurement rules reach the sub-processor — public sector, health, defence supply chain — the middle version fails the check and you are down to heylogin, LockSelf, SecureSafe, Passwork's German cloud, or self-hosting.

How per-seat pricing distorts a password vault

Every tool here except Teampass and Password Depot's free tier charges per seat, and the predictable response is to not give someone a seat. The contractor on a six-week job, the bookkeeper who needs one login, the client who should own their own credentials — each becomes a reason to paste a password into chat, which is the precise failure the vault was bought to prevent.

The published prices cluster tightly: Passwork €3, heylogin €3.99, Hypervault €4, Passbolt €4.50 to €7, Padloc $3.49 to $6.99, SecureSafe CHF 3.20 to CHF 4.60. At a team of twenty the spread between the cheapest and dearest is roughly €70 a month, which is less than an hour of the administrator's time. Choosing on price alone in this category is optimising the smallest variable.

Minimums do more damage than rates. Passbolt requires ten users on Pro and on Cloud Business, so a team of four pays for ten. LockSelf Premium starts at 25 licences and On-Premises at 50. Password Depot quotes from five. For a small team, the minimum is the price.

The escapes are real but narrow. Teampass has no seat limit at all and charges only for the browser extension, from €49 a year. Self-hosted Psono is free to ten users, Passbolt's Community Edition to any number, and Password Depot's server to three. Hypervault is the only one that priced external parties separately rather than as seats, at €2 a month per extra client.

What a team password manager will not do

It is not a secrets manager. Credentials that a deployment pipeline, a container or a scheduled job needs at runtime should not live behind a vault that expects a human to unlock it with a fingerprint. If the consumer is a machine, the answer is a secrets store with short-lived tokens, and none of the eleven tools here is that.

It is not privileged access management. No product in this category brokers an SSH session, records what an administrator did, or enforces check-out and check-in of a domain admin account. The nearest thing is Teampass, which rotates Linux account passwords over SSH agentlessly — useful, and still not PAM.

It is not single sign-on. A vault fills in passwords for the long tail of applications your identity provider cannot federate, which means it works next to Entra ID or Okta rather than replacing them. Hypervault Enterprise and Padloc Team do directory sync and SSO for the vault itself; Uniqkey adds SCIM. That is provisioning into the vault, not the retirement of passwords.

And it is not a compliance certificate. Teampass says this more honestly than most vendors: no tool makes an organisation compliant with ISO 27001, NIS2 or GDPR, because those describe how you operate and are assessed by an auditor. What a vault produces is the access evidence an auditor asks for. Buying one and changing nothing about how the team works produces a tidier spreadsheet, in a nicer interface.

How we selected and ranked these 11 tools

Every tool on this page is in the European Purpose directory, which means the operating company is established in Europe and we have verified that from the company register or the vendor's own legal notice rather than from a marketing page. Tools headquartered outside Europe are not eligible, however good they are.

  1. Feature verification (weight: 40%). We check each capability against the vendor's own documentation and product pages, and record what the tool does rather than what the category is assumed to include.
  2. Ease of adoption (weight: 30%). Integrations, published API access, trial availability and how much configuration stands between signing and a usable result.
  3. Value and transparency (weight: 30%). Published pricing counts in a vendor's favour; quote-only pricing is recorded as quote-only rather than estimated. We weigh what a buyer gets for the entry price, not the headline feature count.
  4. Editorial review. Three people touch every page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's documentation. The three weights above decide the order; a position is a ranking against the other European tools in this category, not an absolute score.

Vendor-reported outcomes — ROI figures, margin uplift, time saved — are labelled as vendor claims wherever they appear on this page. We have not audited them, and neither has anyone else who quotes them. Read our full editorial process for how pages are re-verified.

Frequently asked questions

Passbolt holds #1 among the European team password managers in this directory.

It is open source under AGPLv3 in both the Community and Pro editions, self-hostable with no user limit, and unusually precise about hosting: Cloud Business in Belgium and Germany on Google Cloud, Cloud Sovereign in a private Luxembourg data centre at €7 per user per month.

The right answer still depends on the constraint: heylogin for a German-hosted product with ISO/IEC 27001:2022 and nothing American underneath, LockSelf for an ANSSI CSPN certificate, Uniqkey when joiners and leavers are the actual problem, and Teampass when there must be no vendor at all.

Teampass is the only one that is free at any team size: the GPL-3.0 server has no seat limit and no feature gate, with encryption, access control, recertification, SSO and the API all included; only the browser extension is paid, from €49 a year.

Psono gives all business features free up to ten users. Passbolt's Community Edition is free under AGPLv3 for unlimited users. Password Depot's Enterprise Server is free for up to three users. Hypervault and Padloc have free plans, but Hypervault's is single-person; Padloc's free tier does include shared vaults.

Five. Teampass and Psono are self-hosted first and need no vendor cloud at all. Passbolt ships a free AGPLv3 Community Edition and a self-hosted Pro Edition at €4.50 per user per month billed annually with a ten-user minimum.

Passwork sells a self-hosted licence from €3 per user per month, with a one-time lifetime option. Password Depot's Enterprise Server runs on your own hardware or inside your own Azure tenant. LockSelf offers on-premises deployment from 50 licences. heylogin, Uniqkey, Hypervault, SecureSafe and Padloc are cloud only.

Passbolt Cloud Business runs in Belgium and Germany on Google Cloud, which Passbolt states on its own pricing page — and is why it also sells Cloud Sovereign in a Luxembourg private data centre.

Psono states on its security page that the SaaS runs on Amazon Web Services and Google Cloud, without naming a region, which is the least specific residency claim here. Padloc names no provider and no region, and its privacy policy still refers to the EU-US Privacy Shield, invalidated in 2020. heylogin (Hetzner, IONOS), LockSelf (Outscale, Scaleway), SecureSafe (Switzerland only) and Passwork's German cloud keep US providers out of the path.

LockSelf holds an ANSSI CSPN certificate for version 2.2 of its suite, a French state evaluation. heylogin holds ISO/IEC 27001:2022 and published an independent assessment against BSI test criteria in July 2026. SecureSafe holds ISO/IEC 27001:2022 and PCI DSS v4.0.

AceBIT, behind Password Depot, has an ISO/IEC 27001-certified ISMS audited by TÜV NORD and a SySS penetration test from December 2025. Passbolt has SOC 2 Type II from 2021, repeated Cure53 audits and a Quarkslab pre-CSPN evaluation from November 2025. Uniqkey names an ISAE 3402 audit by Grant Thornton. Hypervault and Passwork name no certification on their own pages.

Several, and they split by what you value. Passbolt is the open-source answer: AGPLv3, groups, folder-level permissions and OpenPGP encryption, self-hosted or in a named EU region.

Hypervault is the cheapest published seat at €4 per user per month, with templates and client folders aimed at agencies and managed service providers. Uniqkey is the closest to 1Password's enterprise pitch — access management, SCIM, offboarding, audit log — but publishes no prices. heylogin is the one that changes the daily routine: your phone is the key, and there is no master password to phish.

For five to twenty people with published pricing, the shortlist is Passwork at €3 per user per month, heylogin at €3.99 billed yearly, Hypervault at €4 excluding VAT and Padloc Team at $3.49.

Watch the minimums rather than the rates: Passbolt asks for ten users on Pro and Cloud Business, LockSelf Premium for 25 licences, Password Depot quotes from five. Below ten people, the free tiers do real work — Psono up to ten users, Password Depot up to three, Teampass without limit.

Both descriptions are true and the site says so itself. Teampass has been built and maintained by Nils Laumaillé since 2009, is GPL-3.0, and includes AES-256-GCM encryption, four-level classification, per-item ownership, LDAP/AD and OAuth2 SSO, TOTP, a REST API and compliance exports in the free server — no feature held back for a paid edition.

There is no company behind it, no support desk and no legal entity to contract with, which is a real procurement problem. Nine security advisories were published with release 3.2.1.1 alone; publishing them is a point in its favour, and needing them is the counterpoint.

Ownership and revocation. A personal manager assumes one vault with one owner, and sharing is an afterthought bolted on with a link.

A team manager assumes the credential belongs to a role, and everything follows from that: folders and groups, permissions per member, an audit log of who opened what, provisioning from the directory when someone joins, and removal when they leave. Proton Pass and NordPass are covered in the password managers category on this site; the eleven here are built around the shared case.

No. Bitwarden's terms name 8bit Solutions LLC, wholly owned by Bitwarden Inc., both incorporated in Delaware.

Dashlane contracts with Dashlane SAS in Paris for EU users, but its own privacy policy describes affiliates as under common control with Dashlane, Inc. in New York and names AWS as the hosting provider without a region. Keeper is based in Chicago. Netwrix Password Secure, formerly the German product MATESO Password Safe, has been owned since September 2022 by Netwrix, whose headquarters is in Frisco, Texas.