Aller au contenu

KeePassXC

Gestionnaires de mots de passe · Allemagne
Fondé en 2016 · keepassxc.org

GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.

KeePassXC est un service sous contrôle européen hébergé en Allemagne, sans exposition identifiée au CLOUD Act. Référencé dans la catégorie Gestionnaires de mots de passe.

Notes d’évaluation

KeePassXC is a GPLv3 open-source, fully offline desktop password manager maintained by an unfunded international volunteer team (the KeePassXC Team, with core members based in Weimar, Germany; the project began in 2016 as a community fork of KeePassX). There is no cloud, no servers, no account, no telemetry, no data processing of any kind: the encrypted .kdbx database file lives entirely on the user's own devices, which makes CLOUD Act exposure structurally impossible; EU-maintained, open-source, with the strongest data-minimisation posture in the directory alongside Mullvad.

Constats

CLOUD Act
Actionnariat
Sous-traitants
— non divulgué

Signaux vérifiés

Juridiction
  • Hébergement UE / adéquation: Oui
  • Opérateur UE / adéquation: Oui
  • Aucune exposition au CLOUD Act: Oui
Transparence
  • DPA public: Non évalué
  • Sous-traitants divulgués: Non
  • Clients open source: Oui
  • Certification tierce: Non
Aller à

À propos de KeePassXC

KeePassXC is a modern, secure, open-source password manager for Windows, macOS and Linux, maintained by the KeePassXC Team, an unfunded, international volunteer group with core members based in Weimar, Germany. The project began in 2016 as a community-driven fork of KeePassX (itself a cross-platform port of the original Windows-only KeePass), and is licensed under GPLv3 with the full source openly available on GitHub.

KeePassXC is the structurally cleanest listing in the password-manager category, for one simple reason: it is entirely offline. There is no cloud service, no servers, no online account, no subscription, no ads, and no telemetry. Passwords are stored in a locally encrypted .kdbx database file that the user controls completely. KeePassXC explicitly states "no data is stored on remote servers." Because there is no service-side data processing at all, there is no DPA, no sub-processors list, and no hosting country to audit, and CLOUD Act exposure is not merely "none" but structurally impossible. Sync, if the user wants it, is the user's own choice: they can place the .kdbx file on any storage they trust (a EU cloud-storage provider from this directory, a USB key, a self-hosted server), but that is a decision the user makes and controls, not something KeePassXC does.

The trade-off is that KeePassXC is a desktop application, not a service: there is no built-in cross-device sync, no team-sharing infrastructure, and no web client, features that hosted competitors (Proton Pass, NordPass, Uniqkey) provide out of the box. KeePassXC itself ships only desktop builds (Windows, macOS, Linux) and has no official mobile client, but its encrypted .kdbx database uses the open KeePass file format, which compatible third-party mobile apps can open (KeePassDX on Android, Strongbox and KeePassium on iOS), so the offline approach is not confined to the desktop. It does offer a robust feature set within its offline scope: strong AES/ChaCha20 encryption, a password generator, browser integration via the official browser extension, TOTP storage, SSH-agent integration, and Secret Service API support on Linux. The project is funded entirely by donations. Best fit: privacy-maximalist individuals and technically confident users who want absolute local control of their credentials with zero service dependency, and any procurement-grade buyer for whom "there is no vendor and no server" is the strongest possible answer to a sovereignty question.

Carte des sous-traitants · non divulgué

Auto-hébergé : pas de chaîne de sous-traitants éditeur. Ce logiciel n'a pas de service exploité par un éditeur ; en auto-hébergement, les données restent sur l'infrastructure contrôlée par l'opérateur et il n'y a pas de chaîne de sous-traitance éditeur à divulguer.

Référentiels & certifications · aucune répertoriée

Nous avons vérifié le site de l'éditeur et les registres des organismes de certification. Aucune certification active trouvée à la date du dernier audit (2026-08-26).

Matrice de fonctionnalités

Tableau 1Fonctionnalités de KeePassXC

Passkeys Oui
Remplissage auto Oui
Surveillance des fuites Oui
Partage familial Non
Export des données Oui
Appareils Illimité
Plateformes macOS Windows Linux

Intégration & accès

REST API Non
SSO (SAML / OIDC) Non

Conformité & gouvernance

Audit log Non
Self-host / on-prem option Oui

Documents publics

L'accessibilité du DPA n'est pas notée pour cette fiche. Les logiciels auto-hébergés ou locaux, les éditeurs qui ne sont pas sous-traitants, et les produits certifiés SecNumCloud, EUCS ou BSI C5 ne sont pas évalués sur l'accessibilité du DPA : voir Notre méthode.
  • Contrat de sous-traitance (DPA)
    — non évalué
    n/a
  • Liste des sous-traitants
    — sans objet
    n/a

Alternatives dans cette catégorie

  • Allemagne · 4 €/mois
    Souverain UE
    DPA public: Oui Sous-traitants: Oui Open source: Non
  • Allemagne · 3.99 €/mois
    Souverain UE
    DPA public: Non évalué Sous-traitants: Non Open source: Non
  • Lituanie · 2 €/mois
    Hébergé UE
    DPA public: Oui Sous-traitants: Non Open source: Non

Présent dans ces guides