Padloc
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
German AGPLv3 open-source password manager (MaKleSoft, Bavaria), audited 3×, self-hostable, but hosted cloud uses Stripe + defunct Privacy Shield ref.
Padloc offers EU hosting in Germany, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Password managers.
Assessment notes
Padloc is an AGPLv3 open-source password manager developed by MaKleSoft (a German micro-company at Meisenstr. 5, Ansbach, Bavaria; contact Martin Kleinschrodt), end-to-end encrypted and audited by three independent security groups, self-hostable for free for personal/non-profit use, but the hosted cloud version has material gaps: the public privacy policy still references the long-defunct 'U.S.-E.U. Privacy Shield Framework' (invalidated by Schrems II in July 2020), names Stripe (US) as payment processor, and does not disclose the cloud hosting location or a sub-processor list, so the hosted product carries material CLOUD Act exposure and an out-of-date privacy posture; self-hosted on EU infrastructure it is EU-owned, self-hosted, with no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: No
-
Sub-processors disclosed: No
-
Open-source clients: Yes
-
Third-party certification: No
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Padloc
Padloc is an open-source, end-to-end encrypted password manager developed by MaKleSoft, a German micro-company based at Meisenstr. 5 in Ansbach, Bavaria, with Martin Kleinschrodt as the contact person. It is the successor to the earlier "Padlock" project (which dates to around 2015) and was rebranded to Padloc around 2019. The product is published under the GNU Affero General Public License (AGPLv3), with a commercial licence available for commercial use; self-hosting is free for personal use and non-profit organisations. Padloc states its data is end-to-end encrypted so neither MaKleSoft nor anyone else can read it, and the project advertises that it has been audited by three independent groups of security experts.
For an EU-sovereignty audit, Padloc splits sharply into two products. The self-hosted path is excellent: AGPLv3 source on GitHub, a published security whitepaper, a German developer bound by GDPR, and full control of where the data lives. Run on Hetzner, OVHcloud or Scaleway and it is EU-owned, self-hosted, with no CLOUD Act exposure. The hosted cloud path is where the concerns sit. Padloc's public privacy policy still states that its third-party data processors "conform to the U.S.-E.U. Privacy Shield Framework", a framework that the Court of Justice of the EU invalidated in the Schrems II ruling in July 2020. A privacy policy that has not been updated to reflect five-year-old case law is itself a red flag. The policy also names Stripe (US) as the payment processor and does not disclose the cloud hosting location or a full sub-processors list. On that basis the hosted product carries material CLOUD Act exposure and an unresolved DPA / sub-processor gap.
Pricing is freemium: a Free $0 tier; Premium at $3.49/month ($34.90/year); Family at $5.95/month; Team at $3.49/user/month; Business at $6.99/user/month; Enterprise custom. Best fit: privacy-conscious individuals and teams who will self-host Padloc on EU infrastructure. That is the configuration that earns the listing. Buyers considering the hosted cloud version should weigh the outdated privacy policy and prefer Proton Pass, Passbolt or Psono until MaKleSoft updates its sub-processor and hosting disclosures.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Padloc
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
-
OpenTerms of Servicepadloc.app/tos…
Alternatives in this category
-
Germany · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
GermanyEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: Yes -
-
Germany · €3.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: No
|
€3.99/mo |