Skip to content
Independently verified · Quarterly re-audit
EU VETTED
Curated collection

Password managers without US sub-processors

European password managers verified to run with no US sub-processors, compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.

In short

The password managers listed here operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator with no US parent and no US-incorporated processor, or software you run entirely yourself. Passbolt (Luxembourg, open-source, SOC 2 Type II, EU-hosted) and Uniqkey (Denmark, Copenhagen, Danish-hosted business access management) are the strongest managed team options; Psono (Germany) is the self-hostable open-source alternative, and KeePassXC (offline desktop) plus Vaultwarden (self-hosted, Bitwarden-compatible) remove the cloud operator entirely. Vault contents are end-to-end encrypted in all of them; the jurisdictional bar on this page concerns the account, metadata and service layer that encryption does not cover.

EU Vetted Editorial
Verified June 2026 How we verify

Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Why it matters

At a glance

Key facts per option, checked against each vendor's own documents.

  • heylogin

    hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €4/mo.

    Best for: Password manager for German and EU teams that want a passwordless, ISO 27001-certified vault with a 100% German sub-processor stack and no US CLOUD Act exposure.

  • KeePassXC

    hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.

    Best for: Password manager for privacy-focused individuals who want fully offline, local control of their credentials with no cloud or service dependency.

  • LC-Pass

    hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €3.99/mo.

    Best for: Password manager for DACH teams that want German-hosted credential management and sharing inside the leitzcloud suite.

  • Passbolt

    hosted in Luxembourg, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €5/mo.

    Best for: Password manager for EU public-sector and regulated teams that need AGPLv3 open-source credential sharing with SAML/LDAP SSO and audit logs.

  • Proton Pass

    hosted in Switzerland, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €2/mo.

    Best for: Password manager for privacy-focused individuals and families who want a Swiss zero-knowledge vault with hide-my-email aliases on a generous free tier.

  • Uniqkey

    hosted in Denmark, zero-knowledge end-to-end encryption, no CLOUD Act exposure.

    Best for: Password manager for Nordic and EU businesses that want Danish-hosted credential and access management with a NIS2-compliance focus.

  • Vaultwarden

    hosted in Spain, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.

    Best for: Password manager for homelab users and EU SMBs with IT capacity who want a Bitwarden-compatible vault self-hosted under their own control.

How to choose
SWITCHING GUIDES

Switching from US password managers?

Side-by-side European alternatives (same hosting, ownership and CLOUD Act checks) for the US tools most often replaced in this category.

FAQ

Frequently asked questions

Password vaults are end-to-end encrypted, so why does US jurisdiction still matter?
Encryption protects vault contents, not the service around them. The operator still holds account and billing data, vault metadata such as entry counts and access timestamps, sharing structures in team products, and the client-update channel. Those remain reachable by legal process against the operator, and the update channel is a supply-chain dependency on whoever controls it, which is why the operator's jurisdiction is recorded independently of the encryption model.
What counts as 'no US sub-processors' on this page?
Either the operating company is EU/EEA/Swiss with no US parent and no US-incorporated sub-processor in the data path (the directory's 'CLOUD Act exposure: none' bar), or the product runs entirely under your control (offline or self-hosted), so no third-party operator exists at all.
Do offline and self-hosted password managers have sub-processors at all?
Effectively no; that is their structural advantage. An offline manager like KeePassXC stores an encrypted file you control, with no vendor cloud; a self-hosted server like Vaultwarden or Psono makes you the operator, so the chain collapses to your own hosting choice. The trade-off is that updates, backups and availability become your responsibility.
How do these relate to Bitwarden, 1Password or LastPass?
Those three are operated by US-incorporated companies, which places them outside this page's bar regardless of where data is hosted. Vaultwarden is an independent open-source server implementation compatible with Bitwarden's clients. Hosted by you on European infrastructure, it keeps the client ecosystem while replacing the US-operated service layer. Each profile records the operator and ownership separately so the distinction stays visible.
Can I import my existing vault?
Generally yes. CSV import from the major US incumbents is standard across the tools here, and Vaultwarden accepts Bitwarden exports natively. What needs manual re-creation is typically shared collections, attachments and TOTP seeds, depending on the source. Each profile notes the documented import paths.
Methodology

How we verified every listing here.

For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →