Passbolt
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Luxembourg-incorporated AGPLv3 open-source team password manager (Passbolt SA), SOC 2 Type II, self-hostable, used by LU/FR government.
Passbolt offers EU hosting in Belgium, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Password managers.
Assessment notes
Passbolt SA (9 Avenue du Blues, L-4368 Belvaux, Luxembourg; incorporated 2017, concept since 2011) is a fully AGPLv3 open-source team password manager (even the paid Business tier is open source) built around OpenPGP end-to-end encryption, self-hostable by default with Cloud as a managed alternative, and audited by independent third parties several times a year with all reports public; SOC 2 Type II attested. Customer base includes the Luxembourg government IT body and France's Ministry of the Interior. Founder team active; investors are Luxembourg / EU (Luxinnovation, Scalefund, Yeast, Expon Capital, Airbridge Equity Partners); €11M raised across 2020 (€3M) and the €8M Series A announced January 2025; 30+ remote-first team. The August 2026 re-verify downgrades the hosting posture: the DPA (updated 14 July 2026) and the privacy policy (updated 11 August 2026) now disclose that Passbolt Cloud data is hosted on Google Cloud Platform in Belgium and Germany and fronted by Cloudflare, against a 14-name sub-processor list of which 9 are US-resident (GCP, Cloudflare, AWS SES, Chargebee, HubSpot, New Relic, Slack, Stripe, Zoho), so the default hosted offering carries material CLOUD Act exposure. The Cloud Sovereign and Cloud Enterprise tiers are hosted instead in a sovereign private Luxembourg data centre, and the AGPLv3 self-host route on EU infrastructure remains EU-owned, EU-hosted, with no CLOUD Act exposure.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 14 · 9 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: Yes
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Passbolt
Passbolt is one of the most transparent open-source password-manager listings in this directory. The legal entity is Passbolt SA at 9 Avenue du Blues, L-4368 Belvaux, Luxembourg, incorporated as a formal company in 2017 after the concept originated within a Luxembourg digital agency in 2011. The product was conceived as a collaborative successor to KeePass, with a focus on team credentials sharing, RBAC, audit logging, and OpenPGP-based end-to-end encryption (1:1 keys per credential). Customer references include the Luxembourg government IT body and the French Ministry of the Interior. These are strong public-sector procurement signals that, combined with the open-source licensing, make Passbolt a natural fit for EU sovereign-procurement workflows.
Licensing and audit transparency are the strongest part of this listing. Both the Community (free) edition AND the paid Business + Enterprise editions are released under the GNU Affero General Public License v3 (AGPLv3). Buyers can fork the codebase, run audits internally, and never face vendor lock-in. The company commissions independent third-party audits multiple times per year with all reports public, including SOC 2 Type II attestation. Encryption is OpenPGP with 1:1 per-credential keys; no server operator (including Passbolt's own Cloud team) can decrypt customer vaults. Self-host deployment supports Docker, Kubernetes (Helm), and native installation on Ubuntu, Rocky Linux, and openSUSE. That gives full flexibility to run on Hetzner, OVHcloud, Scaleway, IONOS, STACKIT, or any other EU GPU / VPS infrastructure. The hosted Cloud has to be read separately, because the default tier is not Luxembourg-hosted. The DPA (updated 14 July 2026) and the privacy policy (updated 11 August 2026) state that Cloud Site data sits on Google Cloud Platform in Belgium and Germany behind Cloudflare for WAF and CDN, against a 14-name sub-processor list of which 9 are US-resident, which is why CLOUD Act exposure for the hosted product is recorded as Material. The Cloud Sovereign and Cloud Enterprise tiers are hosted instead in a sovereign private data centre in Luxembourg, and the AGPLv3 self-host route on EU infrastructure removes the vendor counterparty altogether.
Pricing is open-source-friendly and procurement-grade. Community Edition is free under AGPLv3 with unlimited users, core feature set, browser extensions, API, role-based access, with community support only. The paid ladder then splits by deployment. Self-hosted Pro Edition is €4.50 per user per month billed annually (10-user minimum, volume discounts above 100 users) and adds tags, LDAP provisioning, SSO (Microsoft, Google, OpenID), account recovery, audit logs, and a packaged VM appliance with next-business-day email support. On the hosted side, Cloud Business is €5 per user per month billed monthly, same 10-user minimum, on Google Cloud in Belgium and Germany; Cloud Sovereign is €7 per user per month billed annually in a sovereign private data centre in Luxembourg that the vendor describes as an ISO 27001 certified hosting environment; Cloud Enterprise is custom on that same Luxembourg data centre, with 4-hour SLA, white-glove migration, custom development, and disaster-recovery consulting. Non-profits qualify for special pricing. Best fit: EU public-sector buyers, regulated industries (finance, defence, healthcare), teams that need SAML / LDAP SSO with audit-log compliance, and any procurement-grade buyer who wants AGPLv3 source-availability plus SOC 2 Type II attestation on a Luxembourg-incorporated open-source vendor.
Sub-processor map · 14
-
Amazon Web Services USUnited States
Transactional email delivery (SES)
-
Chargebee USUnited States
Subscription and invoice management
-
Cloudflare USUnited States
Web application firewall and content delivery network
-
Google Cloud Platform USUnited States
Website and cloud data hosting; Passbolt Cloud databases located in Belgium and Germany
-
HubSpot USUnited States
CRM and customer support
-
New Relic USUnited States
Performance and security monitoring
-
Slack USUnited States
Support and alerting
-
Stripe USUnited States
Payment processing
-
Zoho USUnited States
Accounting
-
Aikido EUBelgium
Web application firewall
-
Chartmogul EUGermany
Subscription and invoice management
-
n8n EUGermany
Integration platform
-
Odoo EUBelgium
Accounting
-
Thales Cyber Solutions EULuxembourg
Security Operations Center
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services | United States | Transactional email delivery (SES) | US |
| Chargebee | United States | Subscription and invoice management | US |
| Cloudflare | United States | Web application firewall and content delivery network | US |
| Google Cloud Platform | United States | Website and cloud data hosting; Passbolt Cloud databases located in Belgium and Germany | US |
| HubSpot | United States | CRM and customer support | US |
| New Relic | United States | Performance and security monitoring | US |
| Slack | United States | Support and alerting | US |
| Stripe | United States | Payment processing | US |
| Zoho | United States | Accounting | US |
| Aikido | Belgium | Web application firewall | EU |
| Chartmogul | Germany | Subscription and invoice management | EU |
| n8n | Germany | Integration platform | EU |
| Odoo | Belgium | Accounting | EU |
| Thales Cyber Solutions | Luxembourg | Security Operations Center | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Passbolt
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Germany · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
GermanyEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: Yes -
-
Germany · €3.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: Yes
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: No
|
€3.99/mo |