Skip to content
Independently verified · Quarterly re-audit
EU VETTED

pCloud Pass

VERIFIED
Password managers · Switzerland
Founded 2022 · pcloud.com/pass ↗

Swiss zero-knowledge password manager (pCloud AG, Baar), client-side AES-256, free single-device tier, Luxembourg or US data residency.

Why this score?

pCloud Pass is the password-manager product of pCloud AG (Baar, Switzerland, founded 2013 by Tunio Zafer and Anton Titov, ~22M users across the broader pCloud group) — Swiss-incorporated, founder-controlled, with client-side AES-256 zero-knowledge encryption so even pCloud cannot decrypt customer vaults — but pCloud operates two data centres (Luxembourg AND Texas, USA) and customer-data residency depends on the region the user selects at signup, which means a procurement-grade EU buyer must explicitly choose the Luxembourg region — rated 3/5: an otherwise strong Swiss zero-knowledge profile, but pCloud Pass does not publish a standalone DPA (the Business Agreement contains no DPA section and no dedicated data-processing document exists for Pass specifically); under EU Vetted's rubric the absence of a self-serviceable DPA caps the score at 3/5.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About pCloud Pass

pCloud Pass is the standalone password-manager product from **pCloud AG**, a Swiss cloud-storage group headquartered in Baar (canton of Zug) and founded in 2013 by Tunio Zafer (CEO) and Anton Titov. The broader pCloud group reports more than 22 million users worldwide, primarily for its consumer cloud-storage product but increasingly through Pass and the wider Suite bundle. pCloud Pass launched in 2022 as a separate offering with zero-knowledge client-side encryption — passwords are encrypted on the user's device before any data leaves it, so pCloud has no ability to read customer vaults under any circumstance — and bundles features standard for the category: AES-256 encryption, password generation, secure sharing, auto-fill across browsers and mobile, biometric unlock, and recovery flows. For an EU-sovereignty audit the picture is nuanced. The legal entity (pCloud AG) is Swiss-incorporated, founder-controlled, and operates under Swiss law — Switzerland holds an EU adequacy decision so cross-border transfers between EU and CH need no SCCs. But pCloud operates two data centres globally — **Luxembourg (EU)** and **Texas (USA)** — and the customer selects their data-residency region at signup. Buyers who choose EU placement get a clean Swiss-Luxembourg posture; buyers who choose US placement (or default to it without thinking) end up with their encrypted vault on US infrastructure. Per the strict-ownership stance the customer-side choice matters: with explicit EU placement, CLOUD Act exposure is `minor` (Swiss entity, EU at-rest); with US placement, it would be `material`. The score reflects the EU configuration; the Luxembourg-only data-residency point should be a procurement instruction on the actual listing page. Pricing is competitive and lifetime-friendly: the free tier covers one device with basic features; Premium is €29.99/year (annual) or available as a lifetime one-time payment (a distinguishing feature in the password-manager category, where most competitors are subscription-only). Best fit: pCloud Suite customers already on the platform, Swiss / EU SMBs wanting a Swiss-entity password manager without setting up a separate vendor relationship, and consumers who prefer lifetime pricing over subscription. Procurement-grade buyers needing the cleanest possible posture should prefer Proton Pass (CH, Proton Foundation-owned, no US DC option), Passbolt (FR, self-hostable open-source), or Psono (DE, open-source self-host) — all covered elsewhere on this directory.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-11).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

FREEMIUM
from €30/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    www.pcloud.com/terms_of_service.html…
    Open ↗
ALTERNATIVES

Alternatives in this category