—
US-Linked
— Not assessed
— Not assessed
— Not assessed
Luxembourg-incorporated AGPLv3 open-source team password manager (Passbolt SA), SOC 2 Type II, self-hostable, used by LU/FR government.
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
BE
Belgium
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
self-host
EU-Sovereign
SOC 2
Freemium
€5/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Swiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier.
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
Geneva · CH
Switzerland
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Freemium
€2/mo
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
German Apache-2.0 open-source team password manager (esaqa GmbH), self-hostable on EU infrastructure, Cure53-audited 2026, free up to 10 users.
Public DPA: Not assessed
Sub-processors: Yes
Open source: Yes
DE
Germany
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
self-host
EU-Sovereign
ISO/IEC 27001
Freemium
€0/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Swiss zero-knowledge password manager (pCloud International AG), client-side AES-256, free single-device tier, Luxembourg or US data residency.
Public DPA: No
Sub-processors: No
Open source: No
LU
Luxembourg
EU-Based
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
This listing
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Freemium
€30/mo
Minor
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
This listing
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Lithuanian password manager by Nord Security, zero-knowledge XChaCha20, ISO 27001 + SOC 2, but hosted on AWS (US): material CLOUD Act exposure.
Public DPA: Yes
Sub-processors: No
Open source: No
Lithuania
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
SOC 2
Freemium
€2/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
German AGPLv3 open-source password manager (MaKleSoft, Bavaria), audited 3×, self-hostable, but hosted cloud uses Stripe + defunct Privacy Shield ref.
Public DPA: No
Sub-processors: No
Open source: Yes
Germany
EU-Hosted
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
This listing
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
self-host
EU-Sovereign
—
Freemium
€3/mo
Material
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
This listing
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
Spain
EU-Sovereign
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
This listing
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Free
None
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
This listing
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
Germany
EU-Sovereign
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
This listing
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
—
Free
None
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
This listing
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
Danish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused.
Public DPA: Yes
Sub-processors: No
Open source: No
DK
Denmark
EU-Sovereign
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
This listing
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
Paid
None
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
This listing
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.
German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.
Public DPA: Yes
Sub-processors: Yes
Open source: No
Nuremberg · DE
Germany
EU-Sovereign
Sovereignty
A single roll-up of ownership and CLOUD Act exposure.
EU-Sovereign
This listing
EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
EU-Based
EU-operated, with at most minor or transient US exposure.
EU-Hosted
EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
US-Linked
Operated by a US-incorporated entity, directly subject to US jurisdiction.
ISO/IEC 27001
Freemium
€4/mo
None
CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
None
This listing
EU operator, no US parent, no US sub-processors of note.
Minor
A transient US sub-processor (CDN, maps); data at rest stays in the EU.
Material
US parent, or a core sub-processor is a US-owned hyperscaler.
Direct
The operator itself is US-incorporated.