Every European password sharing tool reviewed
Belvaux, Luxembourg
Founded 2017
Community Edition free (AGPLv3, unlimited users) / self-hosted Pro €4.50 per user/month billed annually, minimum 10 users / Cloud Business €5 / Cloud Sovereign €7
Free Community Edition; 7-day trial on Cloud Business
Best for: Teams that want the vault open source and the hosting written down
Passbolt is the only tool in this category that answers both hard questions in public.
The licence is AGPLv3 for the Community Edition and for the Pro Edition, so the code that guards the credentials can be read and the deployment can be taken over; and the hosting is named down to the country and the provider rather than left as "EU".
Cloud Business sits in Belgium and Germany in Google Cloud data centres. Cloud Sovereign, at €7 per user per month billed annually, sits in a private data centre in Luxembourg for buyers who cannot have an American provider anywhere in the chain. Publishing both, with the difference priced, is rarer than it should be.
The product is built for sharing rather than adapted to it: folders with per-member and per-group permissions, OpenPGP end-to-end encryption where the secret key is never sent to the server in cleartext, and a browser extension that does the decryption client-side.
Passbolt SA is registered in Belvaux, Luxembourg, incorporated in 2017 and financially backed since incorporation by the Grand Duchy. The audit record is the strongest here: repeated Cure53 audits, SOC 2 Type II in 2021, a Quarkslab pre-CSPN evaluation in November 2025 and a GDPR audit by Examin in July 2026.
The cost is the minimum. Both the self-hosted Pro Edition at €4.50 per user per month and Cloud Business at €5 require ten users, so a team of four pays for ten or runs the Community Edition, which is free and unlimited but is not the Pro product. The free trial on Cloud Business is seven days, which is short for a tool that has to be rolled out to a whole team before anyone can judge it.
What Passbolt does well
- AGPLv3 in both editions, self-hostable with no user limit
- Hosting named precisely: Belgium and Germany, or a private Luxembourg data centre
- A sovereign option priced in public at €7 per user per month, not "contact sales"
- OpenPGP end-to-end encryption with the private key never leaving the client in cleartext
- Cure53 audits, SOC 2 Type II and a Quarkslab pre-CSPN evaluation
- Luxembourg company, state-backed since incorporation in 2017
Where Passbolt falls short
- Ten-user minimum on Pro and on Cloud Business, which prices out small teams
- Cloud Business runs on Google Cloud, so a US provider sits under a Luxembourg company unless you pay for Sovereign
- Seven-day cloud trial is short for a team rollout
- Self-hosting a PHP and OpenPGP stack needs someone who will keep patching it
Standout feature. Two clouds, both named. Passbolt is the only tool here that tells you which of its data centres has an American company underneath, and sells the alternative at a published price.
Braunschweig, Germany
Private free / Business €3.99 per user/month billed yearly (€4.99 monthly) / Enterprise on request from 50 employees
Free Private plan
Best for: German-hosted teams that want the master password gone entirely
heylogin changes the daily ritual rather than the feature list. There is no master password: logging in means swiping on your phone, and the vault is decrypted using the security chip in the device, unlocked locally by fingerprint, face or PIN.
The cryptography is XSalsa20-Poly1305 and Curve25519, and heylogin GmbH states it has no access to stored data. Removing the master password removes the thing that phishing kits are built to steal, which is a more interesting security argument than another row of compliance badges.
The hosting is stated with a precision that makes it checkable: production on Hetzner servers in Nuremberg, a standby server in Falkenstein for failover, and independent backups at IONOS — German company, German infrastructure, European sub-processors only.
The company is heylogin GmbH at Sophienstr. 40 in Braunschweig, registered as HRB 207299 at the Amtsgericht Braunschweig, founded by Dominik Schürmann and Vincent Breitmoser out of TU Braunschweig, with pre-seed funding from Mozilla Ventures in 2022. It holds ISO/IEC 27001:2022 for its ISMS and published an independent assessment against BSI test criteria in July 2026.
The trade-off is the phone. If the key is a device, then a lost, broken or flat phone is an access problem, and heylogin maintains a whole documentation page about it.
The Business plan at €3.99 per user per month billed yearly covers user and team management; roles with RBAC and the audit log are Enterprise features, quoted on request and aimed at 50 employees and up, which puts governance features out of reach of exactly the small teams that would buy the €3.99 plan.
What heylogin does well
- No master password: the phone's security chip is the key
- Hetzner in Nuremberg with a standby in Falkenstein, backups at IONOS — all German
- ISO/IEC 27001:2022 plus a BSI-criteria assessment published in July 2026
- European sub-processors only, stated by the vendor
- €3.99 per user per month billed yearly, and a genuinely free plan for private use
Where heylogin falls short
- Login depends on a working smartphone; a lost or dead phone is an access event
- RBAC roles and the audit log are Enterprise-only, aimed at 50+ employees
- Not open source, and no self-hosting option
- Enterprise pricing is not published
Standout feature. There is no master password to steal. heylogin is the only tool in this category whose threat model removes the credential that phishing campaigns are actually after.
Herlev, Denmark
Founded 2018
No public price list; quote on request
Free trial on request
Best for: Companies whose real problem is who still has access
Uniqkey is sold as access management rather than as a vault, and the feature names give it away: share password with team, control and manage access, onboarding and offboarding, password groups, access restriction, verified domains, SCIM, audit log. For an IT manager whose actual pain is that eleven former employees still have the Instagram password, that framing is the right one — the sharing is assumed, and the product is about who has it and how you take it back.
The company is Uniqkey A/S, CVR 39 00 41 27, at Lyskær 8B in Herlev outside Copenhagen, founded in 2018 by Hakan Yagci, and it raised €5.35m in 2024 to push into European SMEs.
Its terms name an ISAE 3402 audit performed by Grant Thornton, which is an assurance report on controls rather than a product certification. Uniqkey positions itself explicitly on European jurisdiction, and its customer logos lean towards municipalities, healthcare and education — buyers who are asked to prove where the data sits.
Which makes the residency statement the disappointment. The terms say only that personal data may be processed on equipment and resources located in Europe: no country, no data centre, no provider, and the privacy policy adds nothing beyond "service providers and data processors". Prices are not published either — the pricing page is a form. For a product whose pitch is sovereignty and simplicity, both blanks have to be filled in by a sales call.
What Uniqkey does well
- Built around access control, offboarding and SCIM rather than around a vault
- Danish company with a public CVR number and a Copenhagen-area address
- ISAE 3402 assurance report audited by Grant Thornton
- Audit log, password groups and access restriction in the product rather than as add-ons
- Used by municipalities, healthcare and education, which is where residency questions get asked hardest
Where Uniqkey falls short
- No published prices at all: every quote runs through sales
- Residency is stated only as "located in Europe" — no country, data centre or provider named
- Not open source, no self-hosting
- No product-level security certification published, only the ISAE 3402 assurance report
Standout feature. It treats offboarding as the product. Uniqkey is built for the question every audit asks — who still has access — rather than for the question a vault usually answers.
Levallois-Perret, France
No public price list: Starter from 2 licences, Premium from 25, On-Premises from 50, priced by module and by a one- or three-year term
14 days, up to 10 colleagues, no card
Best for: French organisations that have to show a state certificate
LockSelf is what a French procurement file looks like when it is turned into a product.
The suite is three modules — LockPass for passwords, LockFiles for document storage, LockTransfer for encrypted sending — and the whole suite carries an ANSSI CSPN certification for version 2.2. That is an evaluation by the French national cybersecurity agency, not a self-declaration or a badge bought from a consultancy, and for a French public body or a regulated supplier it is often the thing that ends the discussion.
LockSelf SAS is at 120 rue Jean Jaurès in Levallois-Perret, and the hosting follows the same logic: sovereign cloud partners Outscale and Scaleway, both French, with HDS or SecNumCloud qualified options for health data and state-adjacent workloads, or an on-premises deployment on your own servers.
LockPass stores credentials with RSA-2048 key pairs, files are AES-256 CBC, and the vault is opened with a login, a password and a six-digit PIN. There is a 14-day trial for up to ten colleagues with no card.
The commercial side is conventionally French, which is to say opaque. Nothing is priced in public: the configurator asks which modules you want, how many licences and whether the term is one or three years, and Starter begins at 2 licences, Premium at 25 and On-Premises at 50. The interface and the documentation assume French, and the product is aimed at French-speaking organisations rather than at a distributed European team.
What LockSelf does well
- ANSSI CSPN certification for version 2.2 of the suite
- Hosted at Outscale or Scaleway in France, with HDS and SecNumCloud options
- On-premises deployment available from 50 licences
- Passwords, file storage and encrypted transfer in one contracted suite
- 14-day trial for up to ten colleagues, no card required
Where LockSelf falls short
- No published prices; everything runs through a configurator and a sales call
- Premium starts at 25 licences and on-premises at 50, which excludes small teams
- Strongest in French; a product built for the French market first
- Not open source, and the company publishes no founding date
Standout feature. A CSPN certificate from ANSSI. LockSelf is the only tool here whose security has been evaluated by a national agency rather than attested by its own auditor.
Antwerp, Belgium
Founded 2021
Individual free / Individual+ €12 a year / Families €49 a year / Business €4 per user/month (€39 a year) / Enterprise €6 (€59), excluding VAT
14 days on Business, no card required
Best for: Agencies and managed service providers holding other people's credentials
Hypervault is built for the company that keeps other companies' passwords. Client folders, secure links for people who do not need an account, and up to 25 client invites on the Business plan with extra clients at €2 a month each — that is a pricing model shaped around agencies and managed service providers rather than around headcount.
Structured templates are the other half of it: instead of a notes field, a template with the fields an IMAP host, a domain registrar or a licence key actually has, so records stay comparable across 40 clients.
The company is GTS Data bv in Antwerp, founded in December 2020 by Glenn Van Croonenborch, Thierry Dupont and Sven Böhne and backed by private investors, with Hypervault itself dating from 2021.
Business is €4 per user per month (€39 a year), Enterprise €6 (€59), both excluding VAT, with a 14-day trial and no card — the cheapest published seat in this category. Enterprise adds Microsoft SSO, Azure AD provisioning, 1GB of encrypted storage per user and a branded vault add-on at €29.99 a month.
The residency statement is thinner than the rest of the pitch. Hypervault says repeatedly that it is a Belgian company storing vault data in the European Union, and its privacy policy says the data is in a data centre in the EU — but no provider and no city is named anywhere, which is a gap for a product sold on European sovereignty. There is no security certification published either, and the identity integrations are Microsoft-only.
What Hypervault does well
- The cheapest published seat here: €4 per user per month on Business
- Client invites priced separately at €2 a month instead of as full seats
- Structured templates rather than free-text notes, which keeps multi-client records consistent
- Belgian company with named founders and a board
- 14-day trial with no card, and a free single-user tier
Where Hypervault falls short
- EU data centre named only as "the European Union" — no provider, no city
- No ISO 27001 or equivalent certification published
- SSO and provisioning are Microsoft-only, and Enterprise-only
- Not open source, no self-hosting
Standout feature. Clients are not seats. Hypervault is the only tool here that prices the outsider who needs one credential at €2 a month instead of making you buy them a licence.
Vorra, Germany
Founded 2016
Free and open source to self-host; all business features free up to 10 users; SaaS, professional support and SLAs quoted on request
Free up to 10 users
Best for: Teams that want the whole thing behind their own firewall for nothing
Psono is a credential manager for companies that assumes you will run it yourself.
The server is Apache 2.0, the repository has been public on GitLab since September 2016, and the deployment target is your own network behind your own firewall — which means there is no processor to assess, no sub-processor list to review and no transfer to document. All business features are free up to ten users, which is a real team rather than an evaluation, and vault data is encrypted on the client before it is stored.
It is built by esaqa GmbH at Tiergartenstr. 13 in Vorra, Bavaria, registered as HRB 37978 at the Nuremberg registry court with Sascha Pfeiffer as managing director.
Encrypted team sharing is the core of the product, the admin client is separate from the web client, and there is a public trust centre. For an organisation that already runs its own infrastructure, this is the shortest path from "we share passwords in a spreadsheet" to "we share passwords in a system we control", at no licence cost at all.
Two things to know before choosing it. First, the hosted option undoes the argument: Psono states on its own security page that its SaaS runs on Amazon Web Services and Google Cloud, and names no region, which is the weakest residency statement in this category — take the self-hosted route and the problem disappears.
Second, nothing above the free tier is priced in public: the pricing table on the homepage is loaded by script and professional support, SLAs and the SaaS all end in "contact us for a quote".
What Psono does well
- Apache 2.0 server, public repository since 2016
- All business features free for up to ten users
- Self-hosted behind your own firewall, with no vendor in the processing chain
- Client-side encryption with encrypted team sharing as the core feature
- German company with a full commercial-register entry and a public trust centre
Where Psono falls short
- The SaaS runs on AWS and Google Cloud with no region named — the weakest residency claim here
- No published prices beyond the free-up-to-ten-users tier
- Self-hosting means you own the upgrades, the backups and the restore test
- Interface is functional rather than designed, and the admin client is a separate application
Standout feature. Free for ten users with every business feature. Psono is the only paid-tier product here that gives a whole small team the complete product rather than a trial of it.
Barcelona, Spain
Standard €3 / Advanced €4.50 per user/month billed annually, for the self-hosted licence and for the cloud; a one-time lifetime licence is offered
Free trial, no card required
Best for: Companies that want a licence they own rather than a subscription they rent
Passwork sells the self-hosted case as the default rather than the fallback.
The licence is €3 per user per month on Standard and €4.50 on Advanced, billed annually, for software that runs on your own infrastructure with double encryption and a zero-knowledge design — and there is a one-time lifetime licence for organisations that would rather buy once than renew forever. That is an unusual offer in a category that has converged on per-seat subscriptions, and it changes the five-year arithmetic considerably.
The company is Passwork Europe SL at Carrer d'Aragó 208 in Barcelona, VAT ESB19399534. Its own about page says the business started in Finland, later moved its headquarters to Spain, is founder-owned with no outside capital, and runs as a remote-first team across Europe, Latin America and Asia. For buyers who do not want to run a server, the Passwork Cloud is hosted in Germany, which keeps EU jurisdiction without an American provider named in the path.
What is missing is the assurance layer. No security certification is published — no ISO 27001, no CSPN, no SOC 2 — and the privacy policy acknowledges processors located outside the customer's jurisdiction without naming them, relying on standard contractual clauses.
The product is not open source either, so the zero-knowledge claim rests on the vendor's description rather than on published code. For a self-hosted product, where you can at least contain the deployment, that is a smaller problem than it would be in a cloud; it is still a blank where competitors have a certificate.
What Passwork does well
- Self-hosted licence from €3 per user per month, with a one-time lifetime option
- Cloud alternative hosted in Germany for teams that do not want a server
- Spanish company, founder-owned, with the imprint and VAT number published
- Double encryption and a zero-knowledge architecture described in detail
- Free trial with no card required
Where Passwork falls short
- No security certification published at all
- Not open source, so the encryption claims cannot be independently read
- Privacy policy admits unnamed processors outside the EU under standard contractual clauses
- No founding year published, and the company history is only on its own about page
- Cloud provider behind the German hosting is not named
Standout feature. A lifetime licence. Passwork is the only tool here that will sell you the software outright instead of renting it to you per seat forever.
France
Founded 2009
Server free under GPL-3.0 with no user limit; Pro browser extension from €49 a year; custom development and deployment quoted per engagement
30-day extension trial, no card
Best for: Anyone who would rather have no vendor at all
Teampass removes the vendor from the equation. The server is GPL-3.0 and free with no user limit and no feature gate: AES-256-GCM authenticated encryption, PBKDF2 at 600,000 iterations, per-user key wrapping, four-level classification with per-item ownership, LDAP/AD and OAuth2 SSO, TOTP, a REST API with Bash and PowerShell clients, recertification and compliance exports. The paid product is the browser extension, from €49 a year, and that is what funds the project. Nothing interesting was held back for a paid edition.
The residency answer is one line, which is the point: the data stays where you put it. There is no vendor cloud, no sub-processor list and no cross-border transfer to justify, so the GDPR record of processing has nothing to enumerate.
Teampass also does something no other tool here does — agentless rotation of Linux account passwords over SSH — and its compliance page is unusually honest about limits, stating plainly that no tool makes an organisation compliant with ISO 27001, NIS2 or GDPR, and that what it produces is the access evidence an auditor expects.
The risk is concentrated in one person. Nils Laumaillé has built and maintained Teampass since 2009, writes most of the code, answers most of the discussions and handles the security reports; there is no company, no legal entity to contract with and no support desk.
Nine security advisories were published with release 3.2.1.1 alone — publishing them is to the project's credit, and needing them is the counterpoint. A procurement department that requires a vendor, an SLA or a signed DPA cannot buy this, and should not pretend otherwise.
What Teampass does well
- GPL-3.0 server, free at any team size with no feature held back
- No vendor cloud at all, so there is no processor to assess
- LDAP/AD, OAuth2 SSO, TOTP, REST API and compliance exports included
- Agentless rotation of Linux account passwords over SSH, which nothing else here does
- Sixteen years of continuous releases and a public security advisory history
Where Teampass falls short
- One maintainer, no company, no legal entity and no support contract
- Security advisories arrive in batches; you own the patching schedule
- Interface and setup expect someone comfortable with PHP, MySQL and Docker
- Only the browser extension is commercially supported
Standout feature. There is no processor to assess. Teampass is the only option here where the GDPR question about your password vault has a one-sentence answer.
Zurich, Switzerland
Professional CHF 3.20 per user/month (CHF 172.80 a year) / Business CHF 4.60 per user/month (CHF 252.00 a year) / Starter bundle CHF 19.90 a month for 5 users
14-day free trial on all plans
Best for: Swiss-jurisdiction teams that want passwords and files in one safe
SecureSafe is the Swiss answer, and unusually it tells you exactly what it has traded away. DSwiss AG in Zurich stores everything in certified data centres exclusively in Switzerland, with triple-redundant storage, ISO/IEC 27001:2022 and PCI DSS v4.0 — and its security page states that the architecture is server-side encryption with controlled, audited internal decryption rather than zero-knowledge, because that is what makes digital estate management, enterprise functions and cross-device features work. Most vendors would have left that sentence out.
For teams, the Business plan at CHF 4.60 per user per month (CHF 252.00 a year) gives an unlimited number of team safes with central permission management; Professional at CHF 3.20 is individual safes only, which is worth checking before buying the cheaper tier for a team.
A Starter bundle covers five users at CHF 19.90 a month with one shared safe. All plans include a 14-day trial, and passwords and encrypted files sit in the same product — the digital estate feature, which hands access to a nominated person after death, is the one thing here that no competitor offers.
Two caveats. Switzerland is outside the EEA: it has an adequacy decision, so transfers are straightforward, but Swiss law is not EU law and this is not an intra-EEA processing arrangement. And the encryption model means the provider can technically decrypt, under audited internal process — for most business buyers that is an acceptable trade for the features it enables, and for anyone whose requirement is that the provider cannot read the vault, it is disqualifying.
What SecureSafe does well
- Data centres exclusively in Switzerland, with triple-redundant storage
- ISO/IEC 27001:2022 and PCI DSS v4.0
- Unlimited team safes on Business at CHF 4.60 per user per month
- Passwords and encrypted files in one product, with a digital-estate handover feature
- States its own encryption trade-off in public instead of claiming zero-knowledge
Where SecureSafe falls short
- Not zero-knowledge: the provider can decrypt under an audited internal process
- Switzerland is outside the EEA, so this is not intra-EEA processing
- Team safes only on Business; Professional at CHF 3.20 is individual safes
- The data centre operator is not named, and no founding year is published
- Prices are in Swiss francs, so the cost moves with the exchange rate
Standout feature. It says it is not zero-knowledge. SecureSafe is the only vendor in this category that publishes the trade-off its feature set depends on instead of hiding behind the phrase.
Ansbach, Germany
Free / Premium $3.49 a month ($34.90 a year) / Family $5.95 ($59.50) / Team $3.49 per user/month ($34.90) / Business $6.99 ($69.90) / Enterprise on request
30 days on the paid plans
Best for: Small teams that want shared vaults without paying for them first
Padloc is the small one, and it is generous where the others are not: shared vaults are in the free plan, alongside unlimited items, unlimited devices, multi-factor authentication, a built-in authenticator and markdown notes.
Team at $3.49 per user per month raises that to 20 shared vaults, 10 groups and directory sync with automatic provisioning; Business at $6.99 gives 50 vaults, 20 groups and 20GB of encrypted storage. For a five-person company that wants to stop emailing passwords this week, the free tier is a working starting point rather than a demo.
The publisher is MaKleSoft UG at Meisenstr. 5 in Ansbach, Bavaria, with a postal address in Munich, and the app is open source and end-to-end encrypted. Padloc has been audited three times by independent groups, most recently by Radically Open Security, and publishes a security whitepaper alongside the source. Clients cover Windows, macOS, Linux, iOS, Android and the major browsers, and there is a 30-day trial on the paid plans.
The paperwork has not kept up with the product. The privacy policy names no hosting provider and no region — only "third party data processors" — and still states that they conform to the EU-US Privacy Shield framework, which the Court of Justice invalidated in July 2020.
The footer copyright reads 2022. Prices are in US dollars from a German UG. None of that changes the encryption, and all of it matters if the reason you are shopping in Europe is that you have to answer a question about where the data sits.
What Padloc does well
- Shared vaults included in the free plan
- Open source and audited three times, most recently by Radically Open Security
- Team at $3.49 per user per month with directory sync and automatic provisioning
- German publisher with a full imprint, clients on every major platform
- 30-day trial on the paid plans
Where Padloc falls short
- Privacy policy names no hosting provider and no region
- Still cites the EU-US Privacy Shield, invalidated in July 2020
- Prices quoted in US dollars despite the German entity
- A small UG with a copyright line last updated in 2022 — a continuity question worth asking
- No certification and no self-hosted commercial edition
Standout feature. Shared vaults on the free plan. Padloc is the only tool here that lets a team share properly before it has paid anything.
Darmstadt, Germany
Founded 1998
Enterprise Server free for up to 3 users; above that, named-user client licences quoted from 5 users, plus software maintenance at 30% of the licence in year one, 27.5% in year two and 25% in year three, plus VAT
Free for up to 3 users
Best for: German organisations that want a server they own and a licence they keep
Password Depot is the oldest approach here and, for some buyers, still the right one. AceBIT GmbH has been selling it from Darmstadt since 1998, and the Enterprise Server is software you install — on your own hardware or inside your own Azure tenant — with clients for Windows, macOS, Linux, iOS, Android and the browser. There is no AceBIT cloud in the path at all, which makes the data residency question a question about your own data centre.
Licensing is per named user, meaning one person across as many devices as they use, and the server is free for up to three users.
Above that, a quote covers the client licences from five users upwards plus software maintenance at 30% of the licence value in the first year, 27.5% in the second and 25% in the third, plus VAT — an old-fashioned structure that is more predictable over five years than a per-seat subscription, and considerably harder to compare against one. AceBIT's ISMS is ISO/IEC 27001-certified by TÜV NORD, and the software was penetration-tested by SySS in December 2025.
What you are not buying is a modern collaboration product. There is no published price list, the ordering flow is quote-then-contract, and the sharing model is built around a central server with named users rather than around folders shared with an outside client at short notice. For a German Mittelstand company with its own infrastructure and an auditor to satisfy, that is a feature. For a distributed team that wants to invite a freelancer this afternoon, it is not.
What Password Depot does well
- No vendor cloud: your own server or your own Azure tenant
- Free for up to three users, with the server licence included
- ISO/IEC 27001-certified ISMS audited by TÜV NORD, and a SySS penetration test from December 2025
- Named-user licences covering all of that person's devices
- German company since 1998, with a full commercial-register entry in Darmstadt
Where Password Depot falls short
- No published prices: quote first, then contract
- Maintenance at 30% of the licence value in year one on top of the licence itself
- Built for a central server and named users, not for ad-hoc external sharing
- Not open source, and the client licences start at five users
- Product and support are oriented to German-speaking customers
Standout feature. You buy it, you keep it. Password Depot is the only tool here sold as a licence for software that runs on your own hardware, with the vendor outside the data path entirely.