Zum Inhalt springen

Padloc

Passwort-Manager · Deutschland
Gegründet 2019 · padloc.app

German AGPLv3 open-source password manager (MaKleSoft, Bavaria), audited 3×, self-hostable, but hosted cloud uses Stripe + defunct Privacy Shield ref.

Padloc bietet EU-Hosting in Deutschland, doch ein US-Mutterkonzern oder Unterauftragsverarbeiter hinterlässt ein materielles CLOUD-Act-Risiko. Gelistet unter Passwort-Manager.

Bewertungsnotizen

Padloc is an AGPLv3 open-source password manager developed by MaKleSoft (a German micro-company at Meisenstr. 5, Ansbach, Bavaria; contact Martin Kleinschrodt), end-to-end encrypted and audited by three independent security groups, self-hostable for free for personal/non-profit use, but the hosted cloud version has material gaps: the public privacy policy still references the long-defunct 'U.S.-E.U. Privacy Shield Framework' (invalidated by Schrems II in July 2020), names Stripe (US) as payment processor, and does not disclose the cloud hosting location or a sub-processor list, so the hosted product carries material CLOUD Act exposure and an out-of-date privacy posture; self-hosted on EU infrastructure it is EU-owned, self-hosted, with no CLOUD Act exposure.

Befund

CLOUD Act
Eigentümer
Unterauftragsverarbeiter
— nicht offengelegt

Geprüfte Signale

Jurisdiktion
  • EU-/Angemessenheits-Hosting: Ja
  • EU-/Angemessenheits-Betreiber: Ja
  • Keine US-CLOUD-Act-Exposition: Nein
Transparenz
  • Öffentlicher AVV: Nein
  • Unterauftragsverarbeiter offengelegt: Nein
  • Open-Source-Clients: Ja
  • Zertifizierung durch Dritte: Nein
CLOUD Act je nach Betrieb

Die Exposition hängt davon ab, wie Sie dieses Produkt betreiben.

Gehostetes SaaS (Standard)

Anbieterbetrieben: die unten genannten Unterauftragsverarbeiter gelten.

Selbst gehostet (Open Source)

Auf eigener EU-Infrastruktur betreiben: Sie kontrollieren Hosting und jeden Unterauftragsverarbeiter.

Springen zu

Über Padloc

Padloc is an open-source, end-to-end encrypted password manager developed by MaKleSoft, a German micro-company based at Meisenstr. 5 in Ansbach, Bavaria, with Martin Kleinschrodt as the contact person. It is the successor to the earlier "Padlock" project (which dates to around 2015) and was rebranded to Padloc around 2019. The product is published under the GNU Affero General Public License (AGPLv3), with a commercial licence available for commercial use; self-hosting is free for personal use and non-profit organisations. Padloc states its data is end-to-end encrypted so neither MaKleSoft nor anyone else can read it, and the project advertises that it has been audited by three independent groups of security experts.

For an EU-sovereignty audit, Padloc splits sharply into two products. The self-hosted path is excellent: AGPLv3 source on GitHub, a published security whitepaper, a German developer bound by GDPR, and full control of where the data lives. Run on Hetzner, OVHcloud or Scaleway and it is EU-owned, self-hosted, with no CLOUD Act exposure. The hosted cloud path is where the concerns sit. Padloc's public privacy policy still states that its third-party data processors "conform to the U.S.-E.U. Privacy Shield Framework", a framework that the Court of Justice of the EU invalidated in the Schrems II ruling in July 2020. A privacy policy that has not been updated to reflect five-year-old case law is itself a red flag. The policy also names Stripe (US) as the payment processor and does not disclose the cloud hosting location or a full sub-processors list. On that basis the hosted product carries material CLOUD Act exposure and an unresolved DPA / sub-processor gap.

Pricing is freemium: a Free $0 tier; Premium at $3.49/month ($34.90/year); Family at $5.95/month; Team at $3.49/user/month; Business at $6.99/user/month; Enterprise custom. Best fit: privacy-conscious individuals and teams who will self-host Padloc on EU infrastructure. That is the configuration that earns the listing. Buyers considering the hosted cloud version should weigh the outdated privacy policy and prefer Proton Pass, Passbolt or Psono until MaKleSoft updates its sub-processor and hosting disclosures.

Unterauftragsverarbeiter-Karte · nicht offengelegt

Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.

Rahmenwerke & Zertifizierungen · keine gelistet

Wir haben die Website des Anbieters und die Register der Zertifizierungsstellen geprüft. Keine aktiven Zertifizierungen gefunden zum Zeitpunkt der letzten Prüfung (2026-08-26).

Funktionsmatrix

Tabelle 1Funktionen von Padloc

Leak-Überwachung Ja
Familienfreigabe Ja
Datenexport Ja
Geräte Unbegrenzt
Plattformen iOS macOS Windows Android Linux Web

Integration & Zugriff

REST API Nein
SSO (SAML / OIDC) Nein

Compliance & Governance

Audit log Nein
Self-host / on-prem option Ja

Preise & Tarife

ab 3 €/Monat
Freemium
Preisseite ansehen

Öffentliche Dokumente

Anbieter veröffentlicht keinen öffentlichen AVV. Ohne öffentlich zugänglichen Auftragsverarbeitungsvertrag können kleine EU-Kunden den Verarbeitervertrag nicht selbst abschließen. Dies wird als fehlender öffentlicher AVV vermerkt (siehe So prüfen wir).
Anbieter veröffentlicht keine Liste der Unterauftragsverarbeiter. Schrems-II-Konformität und CLOUD-Act-Risiko lassen sich ohne sie nicht unabhängig prüfen.
  • Auftragsverarbeitungsvertrag (AVV)
    — fehlt
    fehlt
  • Liste der Unterauftragsverarbeiter
    — fehlt
    fehlt
  • Nutzungsbedingungen
    padloc.app/tos…
    Öffnen

Alternativen in dieser Kategorie

  • Deutschland · 4 €/Mt.
    EU-souverän
    Öffentl. AVV: Ja Subprozessoren: Ja Open Source: Nein
  • Deutschland
    EU-souverän
    Öffentl. AVV: Nicht bewertet Subprozessoren: Nein Open Source: Ja
  • Deutschland · 3.99 €/Mt.
    EU-souverän
    Öffentl. AVV: Nicht bewertet Subprozessoren: Nein Open Source: Nein

In diesen Übersichten gelistet