Psono
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Cette fiche Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
German Apache-2.0 open-source team password manager (esaqa GmbH), self-hostable on EU infrastructure, Cure53-audited 2026, free up to 10 users.
Psono propose un hébergement européen en Allemagne, mais une maison mère ou un sous-traitant américain laisse une exposition matérielle au CLOUD Act. Référencé dans la catégorie Gestionnaires de mots de passe.
Notes d’évaluation
Psono is an Apache-2.0 open-source team password manager developed by esaqa GmbH (Tiergartenstr. 13, 91247 Vorra, Germany; CEO Sascha Pfeiffer): fully self-hostable on the customer's own infrastructure, multi-level encryption (client-side + SSL + storage), SAML / LDAP / audit-log / compliance-policy features, free for up to 10 users on the business feature set, ISO 27001 certified (trust centre at trust.esaqa.com) with a public sub-processor register, and audited by Cure53 in 2026; for self-hosting buyers on EU infrastructure (Hetzner / OVHcloud / Scaleway) EU-owned, self-hosted, with no CLOUD Act exposure and structurally minimal vendor-counterparty risk. The hosted SaaS, however, runs on Google Cloud (Ireland) fronted by Cloudflare with US payment/support sub-processors (Stripe, Paddle, Sentry, Freshworks), so the directory rates default CLOUD Act exposure as material and reserves the clean posture for the self-hosted route.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Cette fiche Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
Autre Une juridiction hors UE. La propriété suisse/EEE compte ici comme européenne ; le Royaume-Uni et d'autres non.
-
- Sous-traitants
- 9 · 7 US
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Non
-
DPA public: Non évalué
-
Sous-traitants divulgués: Oui
-
Clients open source: Oui
-
Certification tierce: Oui
L'exposition dépend de votre mode d'exploitation.
Exploité par l'éditeur : les sous-traitants ci-dessous s'appliquent.
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
Déployez sur votre propre infrastructure UE et vous contrôlez l'hébergement et chaque sous-traitant.
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
Aller à
À propos de Psono
Psono is a German open-source team password manager built and operated by esaqa GmbH (Tiergartenstr. 13, 91247 Vorra, Germany; CEO Sascha Pfeiffer). The entire product, spanning server, web client, browser extensions, and mobile apps (Flutter), is published under the permissive Apache 2.0 licence and lives on GitHub. The product reports more than 2 million downloads and is engineered for the enterprise team-credentials use-case: SAML and LDAP single-sign-on, granular role-based access controls, audit logging, compliance policies (mandatory password complexity / rotation / 2FA), shared groups, recovery codes, and a YubiKey / FIDO2 / TOTP second-factor stack. Encryption is multi-layered: client-side encryption-at-rest, TLS in transit, and additional server-side storage encryption, so server operators (including Psono's own SaaS team) cannot read customer vaults.
For procurement-grade EU buyers Psono is one of the cleanest listings in this directory. The legal entity is a German GmbH with full HRB transparency, founder-controlled, no PE / VC / parent on record. Apache 2.0 licensing means there is no vendor lock-in (a customer can fork the codebase if Psono ever changes posture), and the 2026 Cure53 audit plus ISO 27001 certification (trust centre at trust.esaqa.com, with a publicly maintained sub-processor register) provide independent third-party validation of the security and compliance architecture, matching the standard set by Proton / Mullvad / IVPN in the VPN category. Self-hosting on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) gives an EU-owned, self-hosted posture with no CLOUD Act exposure and zero vendor-counterparty risk.
Pricing is freemium with an unusually generous free tier: all business features are free for up to 10 users, including SAML, LDAP, audit logs, and compliance policies, a tier that competitive open-source competitors (Bitwarden, Vaultwarden) gate behind paid plans. Paid tiers scale by user count and offer managed SaaS hosting for buyers who prefer not to self-host, though that hosted path runs on Google Cloud (Ireland) behind Cloudflare with US payment and support sub-processors, which is why the directory rates the default offering at material CLOUD Act exposure and treats self-hosting as the procurement-grade route. Apps for macOS, Windows, Linux, iOS, Android, plus Chrome / Firefox / Safari extensions, plus a Docker Hub-published server image for self-host. Best fit: German and EU SMBs and enterprises that need SAML/LDAP team-credentials management, regulated buyers needing audit-log compliance, and any procurement-grade buyer who wants the structural cleanliness of self-host plus Apache-2.0 open source.
Carte des sous-traitants · 9
-
Apple USÉtats-Unis
Push notifications for iPhones and iPads
-
Cloudflare USÉtats-Unis
DDoS protection, CDN and DNS
-
Freshworks Inc. USÉtats-Unis
Ticketing to handle customer support requests
-
Google Cloud EMEA Limited USIrlande
Hosting (servers, databases, network) for the managed SaaS; US-owned hyperscaler
-
Sentry Inc. USÉtats-Unis
Error reporting
-
Stripe Inc. USÉtats-Unis
Credit cards and payments
-
Brevo (Sendinblue) EUFrance
Transactional email (registration, share, invoice) and email marketing
-
Paddle.com Inc. USÉtats-Unis
Credit cards and payments (US-resident billing entity)
-
Scaleway, S.A.S EUFrance
Hosting (servers, databases, network) for the managed SaaS
| Prestataire | Pays | Finalité | Propriétaire |
|---|---|---|---|
| Apple | États-Unis | Push notifications for iPhones and iPads | US |
| Cloudflare | États-Unis | DDoS protection, CDN and DNS | US |
| Freshworks Inc. | États-Unis | Ticketing to handle customer support requests | US |
| Google Cloud EMEA Limited | Irlande | Hosting (servers, databases, network) for the managed SaaS; US-owned hyperscaler | US |
| Sentry Inc. | États-Unis | Error reporting | US |
| Stripe Inc. | États-Unis | Credit cards and payments | US |
| Brevo (Sendinblue) | France | Transactional email (registration, share, invoice) and email marketing | EU |
| Paddle.com Inc. | États-Unis | Credit cards and payments (US-resident billing entity) | US |
| Scaleway, S.A.S | France | Hosting (servers, databases, network) for the managed SaaS | EU |
Source : liste publiée des sous-traitants de l’éditeur, lue le 26 août 2026.
Référentiels & certifications
Matrice de fonctionnalités
Tableau 2Fonctionnalités de Psono
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Allemagne · 4 €/moisSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
AllemagneSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Non évalué Sous-traitants: Non Open source: Oui -
-
Allemagne · 3.99 €/moisSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Non évalué Sous-traitants: Non Open source: Non -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
4 €/mois |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non évalué
Sous-traitants: Non
Open source: Oui
|
— |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non évalué
Sous-traitants: Non
Open source: Non
|
3.99 €/mois |