Skip to content
Independently verified · Quarterly re-audit
EU VETTED

LC-Pass

VERIFIED

German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.

In short

LC-Pass, in the Password managers category, is an EU-owned service with Germany as its hosting location and no identified CLOUD Act exposure.

Assessment notes

LC-Pass is the business password manager in the leitzcloud suite, operated by LC by vBoxx GmbH (Frankfurt am Main, HRB 117087; part of the Dutch vBoxx group). It stores and shares credentials, credit-card data, and other secrets for teams, with collections, group sharing and per-item rights, central management and reporting, and unlimited items, devices, and synchronisation. Data is stored in two georedundant German locations on the operator's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption per the vendor — EU-owned, EU-hosted, no CLOUD Act exposure. It is positioned as a German-hosted alternative to 1Password / LastPass for organisations that want credential management inside EU infrastructure. The vendor supplied an AVV (DPA + sub-processors + data-residency) on request; no public DPA URL is the documentation gap.

CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
JUMP TO
OVERVIEW

About LC-Pass

LC-Pass is the credential-management component of the leitzcloud suite, operated by LC by vBoxx GmbH (Frankfurt am Main; part of the Dutch vBoxx group). It lets organisations securely store, manage, and share passwords, credit-card details, and other sensitive data, organised into collections with group-based sharing and per-item rights, plus central management and reporting for administrators and unlimited items, devices, and synchronisation. The positioning is a German-hosted alternative to 1Password and LastPass for teams that want their secrets held inside EU infrastructure rather than with a US-based provider.

Data is stored across two georedundant German locations on the group's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption stated by the vendor — an EU-owned, EU-hosted, no-CLOUD-Act-exposure posture. The vendor provided an AVV (DPA, sub-processor list, data-residency statement) on request in June 2026; it is not yet published at a public URL, which is the remaining transparency gap. Best fit: DACH SMBs and public-sector-adjacent teams already using or considering leitzcloud who want team credential management under the same German operator and data residency.

SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Capability matrix

Autofill Yes
Family sharing No
Devices Unlimited
Platforms Web
INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €3.99/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

DPA provided on request. The vendor provides its Data Processing Addendum to customers on request — by email or inside the account portal — rather than publishing it at a public URL, so it is not counted as a public DPA (see How we assess).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — on request
    on request
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category

KeePassXC
Germany · Founded 2016
EU-SOVEREIGN

GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016) — no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
NONE
NordPass
Lithuania · Founded 2019
EU-HOSTED

Lithuanian password manager by Nord Security, zero-knowledge XChaCha20, ISO 27001 + SOC 2 — but hosted on AWS (US): material CLOUD Act exposure.

Public DPA Sub-processors Open source
FROM
€2/mo
CLOUD ACT
MATERIAL
Padloc
Germany · Founded 2019
EU-HOSTED

German AGPLv3 open-source password manager (MaKleSoft, Bavaria), audited 3×, self-hostable — but hosted cloud uses Stripe + defunct Privacy Shield ref.

Public DPA Sub-processors Open source
FROM
€3/mo
CLOUD ACT
MATERIAL