Skip to content

Vaultwarden

Password managers · Spain

AGPLv3 Rust Bitwarden-compatible server by Daniel García (Spain), self-host-only, no company, no telemetry; EU-maintained, no CLOUD Act exposure when run on EU infrastructure.

Vaultwarden is an EU-owned service hosted in Spain, with no identified CLOUD Act exposure. It is listed under Password managers.

Assessment notes

Vaultwarden is an AGPLv3 open-source, Rust-written, Bitwarden-compatible server maintained by Daniel García (dani-garcia), a Spanish developer, with a community of contributors, formerly 'bitwarden_rs', renamed to avoid trademark confusion; it is self-host-only with no hosted/cloud product and no company entity, so it has no DPA, no sub-processors, no telemetry and no business model. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: structurally the cleanest possible posture in the password-manager category.

Findings

CLOUD Act
Ownership
Sub-processors
— not disclosed

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: Yes
Transparency
  • Public DPA: Not assessed
  • Sub-processors disclosed: No
  • Open-source clients: Yes
  • Third-party certification: No
Jump to

About Vaultwarden

Vaultwarden is an unofficial, open-source server implementation of the Bitwarden client API, written in Rust and maintained by Daniel García (GitHub: dani-garcia), a developer based in Spain, together with a community of contributors. It was formerly known as "bitwarden_rs" and was renamed to Vaultwarden to separate itself from the official Bitwarden server and avoid trademark and branding confusion. It is licensed under the AGPL-3.0 licence, relicensed from GPLv3 specifically to close the loophole that would have allowed commercial SaaS use without contributing back.

The reason Vaultwarden belongs in an EU-sovereignty directory is structural: it is self-host-only. There is no Vaultwarden cloud product, no Vaultwarden company, no commercial entity, no funding, no DPA, no sub-processors, and no telemetry, because there is nothing hosted to process. It is server software that a user or organisation runs themselves, fully compatible with the official Bitwarden desktop, mobile and browser clients, and deliberately lightweight so it can run on a small VPS or Raspberry Pi where the official resource-heavy Bitwarden server would be impractical. Run on EU infrastructure (Hetzner, OVHcloud, Scaleway, IONOS, STACKIT) it is EU-maintained, self-hosted, with no CLOUD Act exposure and zero vendor-counterparty risk: there is no vendor that could be acquired, change posture, or be served a US warrant.

The trade-offs are the usual self-hosting ones, plus a couple specific to Vaultwarden. There is no enterprise SSO / SCIM support (a deliberate scope decision; that is where official Bitwarden's paid tiers differentiate), the operator is responsible for backups, TLS, and updates, and one of the active maintainers is employed by Bitwarden and contributes on their own time independently (reviewed by other maintainers). Vaultwarden is completely free; funding is via donations. Best fit: technically capable EU individuals, homelab users, and SMBs with IT capacity who want a Bitwarden-compatible vault under their own full control on EU infrastructure, and any procurement-grade buyer for whom "no vendor at all" is the strongest possible sovereignty answer.

Sub-processor map · not disclosed

Self-hosted: no vendor sub-processor chain. This software has no vendor-operated service; when self-hosted, data stays on infrastructure the operator controls and there is no vendor processing chain to disclose.

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-08-26).

Capability matrix

Table 1Capabilities of Vaultwarden

Passkeys Yes
Autofill Yes
Breach monitoring No
Family sharing Yes
Data export Yes
Devices Unlimited
Platforms iOS macOS Windows Android Linux Web

Integration & access

REST API Yes
SSO (SAML / OIDC) No

Compliance & governance

Audit log No
Self-host / on-prem option Yes

Public documents

DPA accessibility is not scored for this listing. Self-hosted or local software, vendors that are not data processors, and products carrying a SecNumCloud, EUCS or BSI C5 certification are not assessed on DPA accessibility. See How we assess.
  • Data Processing Addendum (DPA)
    — not assessed
    n/a
  • Sub-processors list
    — not applicable
    n/a

Alternatives in this category

  • Germany · €4/mo
    EU-Sovereign
    Public DPA: Yes Sub-processors: Yes Open source: No
  • Germany
    EU-Sovereign
    Public DPA: Not assessed Sub-processors: No Open source: Yes
  • Germany · €3.99/mo
    EU-Sovereign
    Public DPA: Not assessed Sub-processors: No Open source: No

Featured in these guides