Password managers without US sub-processors
European password managers verified to run with no US sub-processors, compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.
In short The password managers listed here operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator with no US parent and no US-incorporated processor, or software you run entirely yourself. Uniqkey (Denmark, Copenhagen, Danish-hosted business access management) is the strongest managed team option; Passbolt (Luxembourg, open-source, SOC 2 Type II) and Psono (Germany) clear the bar on their self-hosted editions rather than on their own clouds, and KeePassXC (offline desktop) plus Vaultwarden (self-hosted, Bitwarden-compatible) remove the cloud operator entirely. Passbolt Cloud runs on Google Cloud in Belgium and Germany behind Cloudflare, with nine of its fourteen sub-processors US-owned. Vault contents are end-to-end encrypted in all of them; the jurisdictional bar on this page concerns the account, metadata and service layer that encryption does not cover.
Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.
About this collection
About Password managers without US sub-processors
Password managers without US sub-processors, as listed on this page, means one of two things: a managed service whose operating company is incorporated in the EU, EEA or Switzerland, holds no US parent, and routes no customer data through a US-incorporated processor, or software that runs entirely under your own control, offline or self-hosted, so that no third-party operator exists in the first place. Both routes clear the same bar; they get there differently, and the listing marks which is which.
This category rewards strictness unusually well. Credentials are the keys to everything else an organisation runs, and the password manager's own service layer (accounts, metadata, sharing structures, the update channel) concentrates trust even when vault contents are end-to-end encrypted. The European field here is genuinely strong: open-source team products from Luxembourg and Germany, a Danish business access platform, and mature offline and self-hosted options. Each listing is matched against the vendor's own published documentation and rechecked on a quarterly cadence.
Why it matters
Why it matters
Password managers split cleanly into two zones with very different exposure. The vault blob (the encrypted contents themselves) is genuinely opaque to the operator: unreadable without the user's master password, whoever holds the ciphertext, so jurisdiction over the storage layer matters less there than in almost any other SaaS category. Everything around the blob is the opposite case: account identities, billing records, vault metadata (entry counts, access timestamps, sharing structures), and, easy to overlook, the telemetry and crash-reporting SDKs many clients embed, which routinely phone usage data and stack traces to a third-party analytics vendor that may sit outside the operator's own jurisdiction entirely.
That second zone is why jurisdiction still matters after encryption. A US-incorporated operator can be compelled to produce what it holds (metadata, account data), and a US-incorporated telemetry or crash-reporting vendor is a separate, often-overlooked link in the same chain. The client-update channel adds a third angle: whoever controls it can technically ship whatever it wants to the software that handles plaintext locally. The tools on this page either place the operator (and its telemetry vendor) in an EU/EEA/Swiss jurisdiction with no US parent, or remove the operator entirely by putting the server, or the encrypted file itself, in your hands. Each listing records ownership, hosting and the sub-processor chain, telemetry included, as separate, evidenced signals.
Showing all 6 alternatives in this category
-
heylogin
EU-SOVEREIGNGerman passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.
DE Public DPA Sub-processors Open source 0 sub-procs €4 /mo -
KeePassXC
EU-SOVEREIGNGPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.
Public DPA Sub-processors Open source 0 sub-procs -
LC-Pass
EU-SOVEREIGNGerman-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.
DE Public DPA Sub-processors Open source 0 sub-procs €3.99 /mo -
Proton Pass
EU-SOVEREIGNSwiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier.
CH Public DPA Sub-processors Open source 8 sub-procs · 5 US €2 /mo -
Uniqkey
EU-SOVEREIGNDanish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused.
DK Public DPA Sub-processors Open source 0 sub-procs -
Vaultwarden
EU-SOVEREIGNAGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.
Public DPA Sub-processors Open source 0 sub-procs
| Compare | Sovereignty | Cert. | Pricing | Signals | Open | ||
|---|---|---|---|---|---|---|---|
|
German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.
|
NUREMBERG · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Freemium
€4 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.
|
—
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Free |
Public DPA
Sub-processors
Open source
|
→ | |
|
German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.
|
FRANKFURT · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid
€3.99 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Swiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier.
|
GENEVA · CH
Switzerland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€2 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Danish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused.
|
DK
Denmark
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid |
Public DPA
Sub-processors
Open source
|
→ | |
|
AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.
|
—
Spain
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Free |
Public DPA
Sub-processors
Open source
|
→ |
At a glance
Key facts per option, checked against each vendor's own documents.
-
hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €4/mo.
Best for: Password manager for German and EU teams that want a passwordless, ISO 27001-certified vault with a 100% German sub-processor stack and no US CLOUD Act exposure.
-
hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.
Best for: Password manager for privacy-focused individuals who want fully offline, local control of their credentials with no cloud or service dependency.
-
hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €3.99/mo.
Best for: Password manager for DACH teams that want German-hosted credential management and sharing inside the leitzcloud suite.
-
hosted in Switzerland, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €2/mo.
Best for: Password manager for privacy-focused individuals and families who want a Swiss zero-knowledge vault with hide-my-email aliases on a generous free tier.
-
hosted in Denmark, zero-knowledge end-to-end encryption, no CLOUD Act exposure.
Best for: Password manager for Nordic and EU businesses that want Danish-hosted credential and access management with a NIS2-compliance focus.
-
hosted in Spain, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.
Best for: Password manager for homelab users and EU SMBs with IT capacity who want a Bitwarden-compatible vault self-hosted under their own control.
Start with the operating model your team can sustain. Managed European services (Uniqkey) suit teams that want SSO, provisioning and support with no operations burden. Compare on audit posture (certifications, pentest publication), browser-extension quality and per-seat price. Passbolt's own cloud is the counter-example on this page: it is EU-hosted, but on Google Cloud in Belgium and Germany behind Cloudflare, with nine of its fourteen sub-processors US-owned, so only its self-hosted edition clears the bar here. Self-hosted servers (Psono, Passbolt CE, Vaultwarden) suit teams with existing EU infrastructure and the discipline to patch and back up; they reduce the jurisdictional question to your own hosting choice. Offline managers (KeePassXC) fit individuals and small technical teams that can live without built-in sync, or that sync the encrypted database through storage they already trust.
For regulated buyers, treat the password manager's operator, and any telemetry or crash-reporting vendor it embeds, like any other processor: any US incorporation in the chain is typically a veto, and the self-hosted and offline routes are often the shortest path through procurement. For SMBs, onboarding friction and recovery flows tend to matter more day to day than the jurisdictional question. Check how each product handles a forgotten master password and offboarding before committing. The filters above narrow the list by hosting country, open-source licence or pricing.
Switching from US password managers?
Side-by-side European alternatives (same hosting, ownership and CLOUD Act checks) for the US tools most often replaced in this category.
Frequently asked questions
Password vaults are end-to-end encrypted, so why does US jurisdiction still matter?
What counts as 'no US sub-processors' on this page?
Do offline and self-hosted password managers have sub-processors at all?
How do these relate to Bitwarden, 1Password or LastPass?
Can I import my existing vault?
How we verified every listing here.
For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.