Password managers without US sub-processors
European password managers verified to run with no US sub-processors, compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.
The password managers listed here operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator with no US parent and no US-incorporated processor, or software you run entirely yourself. Passbolt (Luxembourg, open-source, SOC 2 Type II, EU-hosted) and Uniqkey (Denmark, Copenhagen, Danish-hosted business access management) are the strongest managed team options; Psono (Germany) is the self-hostable open-source alternative, and KeePassXC (offline desktop) plus Vaultwarden (self-hosted, Bitwarden-compatible) remove the cloud operator entirely. Vault contents are end-to-end encrypted in all of them; the jurisdictional bar on this page concerns the account, metadata and service layer that encryption does not cover.
Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.
Password managers without US sub-processors, as listed on this page, means one of two things: a managed service whose operating company is incorporated in the EU, EEA or Switzerland, holds no US parent, and routes no customer data through a US-incorporated processor, or software that runs entirely under your own control, offline or self-hosted, so that no third-party operator exists in the first place. Both routes clear the same bar; they get there differently, and the listing marks which is which.
This category rewards strictness unusually well. Credentials are the keys to everything else an organisation runs, and the password manager's own service layer (accounts, metadata, sharing structures, the update channel) concentrates trust even when vault contents are end-to-end encrypted. The European field here is genuinely strong: open-source team products from Luxembourg and Germany, a Danish business access platform, and mature offline and self-hosted options. Each listing is matched against the vendor's own published documentation and rechecked on a quarterly cadence.
Password managers split cleanly into two zones with very different exposure. The vault blob (the encrypted contents themselves) is genuinely opaque to the operator: unreadable without the user's master password, whoever holds the ciphertext, so jurisdiction over the storage layer matters less there than in almost any other SaaS category. Everything around the blob is the opposite case: account identities, billing records, vault metadata (entry counts, access timestamps, sharing structures), and, easy to overlook, the telemetry and crash-reporting SDKs many clients embed, which routinely phone usage data and stack traces to a third-party analytics vendor that may sit outside the operator's own jurisdiction entirely.
That second zone is why jurisdiction still matters after encryption. A US-incorporated operator can be compelled to produce what it holds (metadata, account data), and a US-incorporated telemetry or crash-reporting vendor is a separate, often-overlooked link in the same chain. The client-update channel adds a third angle: whoever controls it can technically ship whatever it wants to the software that handles plaintext locally. The tools on this page either place the operator (and its telemetry vendor) in an EU/EEA/Swiss jurisdiction with no US parent, or remove the operator entirely by putting the server, or the encrypted file itself, in your hands. Each listing records ownership, hosting and the sub-processor chain, telemetry included, as separate, evidenced signals.
At a glance
Key facts per option, checked against each vendor's own documents.
-
hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €4/mo.
Best for: Password manager for German and EU teams that want a passwordless, ISO 27001-certified vault with a 100% German sub-processor stack and no US CLOUD Act exposure.
-
hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.
Best for: Password manager for privacy-focused individuals who want fully offline, local control of their credentials with no cloud or service dependency.
-
hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €3.99/mo.
Best for: Password manager for DACH teams that want German-hosted credential management and sharing inside the leitzcloud suite.
-
hosted in Luxembourg, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €5/mo.
Best for: Password manager for EU public-sector and regulated teams that need AGPLv3 open-source credential sharing with SAML/LDAP SSO and audit logs.
-
hosted in Switzerland, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €2/mo.
Best for: Password manager for privacy-focused individuals and families who want a Swiss zero-knowledge vault with hide-my-email aliases on a generous free tier.
-
hosted in Denmark, zero-knowledge end-to-end encryption, no CLOUD Act exposure.
Best for: Password manager for Nordic and EU businesses that want Danish-hosted credential and access management with a NIS2-compliance focus.
-
hosted in Spain, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.
Best for: Password manager for homelab users and EU SMBs with IT capacity who want a Bitwarden-compatible vault self-hosted under their own control.
-
heyloginEU-SOVEREIGN
German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.
DE Public DPA Sub-processors Open source 0 sub-procs €4 /mo -
KeePassXCEU-SOVEREIGN
GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.
Public DPA Sub-processors Open source 0 sub-procs -
LC-PassEU-SOVEREIGN
German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.
DE Public DPA Sub-processors Open source 0 sub-procs €3.99 /mo -
PassboltEU-SOVEREIGN
Luxembourg-incorporated AGPLv3 open-source team password manager (Passbolt SA), SOC 2 Type II, self-hostable, used by LU/FR government.
LU Public DPA Sub-processors Open source 0 sub-procs €5 /mo -
Proton PassEU-SOVEREIGN
Swiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier.
CH Public DPA Sub-processors Open source 7 sub-procs · 4 US €2 /mo -
UniqkeyEU-SOVEREIGN
Danish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused.
DK Public DPA Sub-processors Open source 0 sub-procs -
VaultwardenEU-SOVEREIGN
AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.
Public DPA Sub-processors Open source 0 sub-procs
| Compare | Sovereignty | Cert. | Pricing | Signals | Open | ||
|---|---|---|---|---|---|---|---|
|
German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.
|
NUREMBERG · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Freemium
€4 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.
|
—
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Free |
Public DPA
Sub-processors
Open source
|
→ | |
|
German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.
|
FRANKFURT · DE
Germany
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid
€3.99 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Luxembourg-incorporated AGPLv3 open-source team password manager (Passbolt SA), SOC 2 Type II, self-hostable, used by LU/FR government.
|
BELVAUX · LU
Luxembourg
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
SOC 2
|
Freemium
€5 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Swiss zero-knowledge password manager (Proton AG / Proton Foundation), open-source apps + extensions, Cure53-audited, free unlimited tier.
|
GENEVA · CH
Switzerland
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— |
Freemium
€2 /mo
|
Public DPA
Sub-processors
Open source
|
→ | |
|
Danish business password & access manager (Uniqkey A/S, Copenhagen), Danish-hosted, zero-knowledge E2E, ISO 27001, EIFO-backed, NIS2-focused.
|
DK
Denmark
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
ISO/IEC 27001
|
Paid |
Public DPA
Sub-processors
Open source
|
→ | |
|
AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.
|
—
Spain
|
SOVEREIGNTY
A single roll-up of ownership and CLOUD Act exposure.
|
— | Free |
Public DPA
Sub-processors
Open source
|
→ |
Start with the operating model your team can sustain. Managed European services (Passbolt cloud, Uniqkey) suit teams that want SSO, provisioning and support with no operations burden. Compare them on audit posture (SOC 2, pentest publication), browser-extension quality and per-seat price. Self-hosted servers (Psono, Passbolt CE, Vaultwarden) suit teams with existing EU infrastructure and the discipline to patch and back up; they reduce the jurisdictional question to your own hosting choice. Offline managers (KeePassXC) fit individuals and small technical teams that can live without built-in sync, or that sync the encrypted database through storage they already trust.
For regulated buyers, treat the password manager's operator, and any telemetry or crash-reporting vendor it embeds, like any other processor: any US incorporation in the chain is typically a veto, and the self-hosted and offline routes are often the shortest path through procurement. For SMBs, onboarding friction and recovery flows tend to matter more day to day than the jurisdictional question. Check how each product handles a forgotten master password and offboarding before committing. The filters above narrow the list by hosting country, open-source licence or pricing.
Switching from US password managers?
Side-by-side European alternatives (same hosting, ownership and CLOUD Act checks) for the US tools most often replaced in this category.
Frequently asked questions
Password vaults are end-to-end encrypted, so why does US jurisdiction still matter?
What counts as 'no US sub-processors' on this page?
Do offline and self-hosted password managers have sub-processors at all?
How do these relate to Bitwarden, 1Password or LastPass?
Can I import my existing vault?
How we verified every listing here.
For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.