Skip to content
Independently verified · Quarterly re-audit
EU VETTED

LC-Pass

VERIFIED

German-hosted business password manager from LC by vBoxx GmbH; collections, group sharing, central management, unlimited devices; an EU-hosted 1Password / LastPass alternative.

In short

LC-Pass, in the Password managers category, is an EU-owned service with Germany as its hosting location and no identified CLOUD Act exposure.

Assessment notes

LC-Pass is the business password manager in the leitzcloud suite, operated by LC by vBoxx GmbH (Frankfurt am Main, HRB 117087; part of the Dutch vBoxx group). It stores and shares credentials, credit-card data, and other secrets for teams, with collections, group sharing and per-item rights, central management and reporting, and unlimited items, devices, and synchronisation. Data is stored in two georedundant German locations on the operator's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption per the vendor, EU-owned, EU-hosted, no CLOUD Act exposure. It is positioned as a German-hosted alternative to 1Password / LastPass for organisations that want credential management inside EU infrastructure. The vendor supplied an AVV (DPA + sub-processors + data-residency) on request; no public DPA URL is the documentation gap.

CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
JUMP TO
OVERVIEW

About LC-Pass

LC-Pass is the credential-management component of the leitzcloud suite, operated by LC by vBoxx GmbH (Frankfurt am Main; part of the Dutch vBoxx group). It lets organisations securely store, manage, and share passwords, credit-card details, and other sensitive data, organised into collections with group-based sharing and per-item rights, plus central management and reporting for administrators and unlimited items, devices, and synchronisation. The positioning is a German-hosted alternative to 1Password and LastPass for teams that want their secrets held inside EU infrastructure rather than with a US-based provider.

Data is stored across two georedundant German locations on the group's own infrastructure, ISO/TÜV-certified and DSGVO-oriented, with zero-knowledge encryption stated by the vendor, an EU-owned, EU-hosted, no-CLOUD-Act-exposure posture. The vendor provided an AVV (DPA, sub-processor list, data-residency statement) on request in June 2026; it is not yet published at a public URL, which is the remaining transparency gap. Best fit: DACH SMBs and public-sector-adjacent teams already using or considering leitzcloud who want team credential management under the same German operator and data residency.

SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications

ISO/IEC 27001
ACTIVE
FEATURES

Capability matrix

Autofill Yes
Family sharing No
Devices Unlimited
Platforms Web
INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
from €3.99/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

DPA provided on request. The vendor provides its Data Processing Addendum to customers on request (by email or inside the account portal) rather than publishing it at a public URL, so it is not counted as a public DPA (see How we assess).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — on request
    on request
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category

heylogin
Germany · Founded 2021
EU-SOVEREIGN

German passwordless zero-knowledge password manager (heylogin GmbH, Braunschweig), all-German sub-processor stack, ISO 27001:2022, no CLOUD Act exposure.

Public DPA Sub-processors Open source
FROM
€4/mo
CLOUD ACT
NONE
KeePassXC
Germany · Founded 2016
EU-SOVEREIGN

GPLv3 fully-offline desktop password manager (KeePassXC Team, Weimar DE, est. 2016): no cloud, no servers, no telemetry; structurally zero CLOUD Act exposure.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
NONE
NordPass
Lithuania · Founded 2019
EU-HOSTED

Lithuanian password manager by Nord Security, zero-knowledge XChaCha20, ISO 27001 + SOC 2, but hosted on AWS (US): material CLOUD Act exposure.

Public DPA Sub-processors Open source
FROM
€2/mo
CLOUD ACT
MATERIAL