Aller au contenu

Vaultwarden

Gestionnaires de mots de passe · Espagne

AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.

Vaultwarden est un service sous contrôle européen hébergé en Espagne, sans exposition identifiée au CLOUD Act. Référencé dans la catégorie Gestionnaires de mots de passe.

Notes d’évaluation

Vaultwarden is an AGPLv3 open-source, Rust-written, Bitwarden-compatible server maintained by Daniel García (dani-garcia), a Spanish developer, with a community of contributors, formerly 'bitwarden_rs', renamed to avoid trademark confusion; it is self-host-only with no hosted/cloud product and no company entity, so it has no DPA, no sub-processors, no telemetry and no business model. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: structurally the cleanest possible posture in the password-manager category.

Constats

CLOUD Act
Actionnariat
Sous-traitants
— non divulgué

Signaux vérifiés

Juridiction
  • Hébergement UE / adéquation: Oui
  • Opérateur UE / adéquation: Oui
  • Aucune exposition au CLOUD Act: Oui
Transparence
  • DPA public: Non évalué
  • Sous-traitants divulgués: Non
  • Clients open source: Oui
  • Certification tierce: Non
Aller à

À propos de Vaultwarden

Vaultwarden is an unofficial, open-source server implementation of the Bitwarden client API, written in Rust and maintained by Daniel García (GitHub: dani-garcia), a developer based in Spain, together with a community of contributors. It was formerly known as "bitwarden_rs" and was renamed to Vaultwarden to separate itself from the official Bitwarden server and avoid trademark and branding confusion. It is licensed under the AGPL-3.0 licence, relicensed from GPLv3 specifically to close the loophole that would have allowed commercial SaaS use without contributing back.

The reason Vaultwarden belongs in an EU-sovereignty directory is structural: it is self-host-only. There is no Vaultwarden cloud product, no Vaultwarden company, no commercial entity, no funding, no DPA, no sub-processors, and no telemetry, because there is nothing hosted to process. It is server software that a user or organisation runs themselves, fully compatible with the official Bitwarden desktop, mobile and browser clients, and deliberately lightweight so it can run on a small VPS or Raspberry Pi where the official resource-heavy Bitwarden server would be impractical. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: there is no vendor that could be acquired, change posture, or be served a US warrant.

The trade-offs are the usual self-hosting ones, plus a couple specific to Vaultwarden. There is no enterprise SSO / SCIM support (a deliberate scope decision; that is where official Bitwarden's paid tiers differentiate), the operator is responsible for backups, TLS, and updates, and one of the active maintainers is employed by Bitwarden and contributes on their own time independently (reviewed by other maintainers). Vaultwarden is completely free; funding is via donations. Best fit: technically capable EU individuals, homelab users, and SMBs with IT capacity who want a Bitwarden-compatible vault under their own full control on EU infrastructure, and any procurement-grade buyer for whom "no vendor at all" is the strongest possible sovereignty answer.

Carte des sous-traitants · non divulgué

Auto-hébergé : pas de chaîne de sous-traitants éditeur. Ce logiciel n'a pas de service exploité par un éditeur ; en auto-hébergement, les données restent sur l'infrastructure contrôlée par l'opérateur et il n'y a pas de chaîne de sous-traitance éditeur à divulguer.

Référentiels & certifications · aucune répertoriée

Nous avons vérifié le site de l'éditeur et les registres des organismes de certification. Aucune certification active trouvée à la date du dernier audit (2026-08-26).

Matrice de fonctionnalités

Tableau 1Fonctionnalités de Vaultwarden

Passkeys Oui
Remplissage auto Oui
Surveillance des fuites Non
Partage familial Oui
Export des données Oui
Appareils Illimité
Plateformes iOS macOS Windows Android Linux Web

Intégration & accès

REST API Oui
SSO (SAML / OIDC) Non

Conformité & gouvernance

Audit log Non
Self-host / on-prem option Oui

Documents publics

L'accessibilité du DPA n'est pas notée pour cette fiche. Les logiciels auto-hébergés ou locaux, les éditeurs qui ne sont pas sous-traitants, et les produits certifiés SecNumCloud, EUCS ou BSI C5 ne sont pas évalués sur l'accessibilité du DPA : voir Notre méthode.
  • Contrat de sous-traitance (DPA)
    — non évalué
    n/a
  • Liste des sous-traitants
    — sans objet
    n/a

Alternatives dans cette catégorie

  • Allemagne · 4 €/mois
    Souverain UE
    DPA public: Oui Sous-traitants: Oui Open source: Non
  • Allemagne
    Souverain UE
    DPA public: Non évalué Sous-traitants: Non Open source: Oui
  • Allemagne · 3.99 €/mois
    Souverain UE
    DPA public: Non évalué Sous-traitants: Non Open source: Non

Présent dans ces guides