Private Pierce

Password Manager and Authenticator Comparison

This matrix compares the documented custody and authentication paths for four password managers. It does not score, rank, recommend, or independently test any product.

Scope: 4 products

A vault comparison starts with custody paths, not a winner

Account identity, data location, export, recovery, passkeys, TOTP, audits, and source availability are separate documented questions across the four frozen rows: 1Password, Bitwarden, KeePassXC, and Proton Pass.

A password manager authenticator comparison becomes misleading when it compresses every documented attribute into one privacy or security label. The account used to enter a service, the entity operating it, the place data is held, the way a vault can be exported, the route for recovery, and the placement of an authentication factor are different parts of the custody path. This page keeps those parts separate and supplies no score, rank, best label, preferred product, or recommendation.

The roster was frozen before the page was written. Each row has one current persisted cell for each of fifteen preregistered attributes. A displayed value therefore comes from the exact product row and exact attribute shown in the table; it is not borrowed from another product, inferred from marketing language elsewhere, or filled from a superficially similar field. Product, plan, region, platform, claim type, source class, source URL, capture date, and observation version remain attached to each cell.

The matrix compares published evidence rather than product behavior observed through account creation or testing. A vendor architecture statement remains a vendor-stated claim. A public repository remains evidence for the component and scope it names. An assessment record remains evidence of the stated assessor, scope, standard, date, and limitations. None of those evidence types silently becomes a guarantee about the whole service.

Use the privacy-tool comparison methodology and corrections hub for its preregistered roster and attributes, claim labels, capture dates, and correction path. The product cells below carry the product-specific facts. The email alias service comparison covers a neighboring account-identity layer, while the private phone number app comparison applies the same separation to another recovery and identity path.

What identity the product collects and what can trigger later verification

Initial signup identifiers and later verification triggers are different fields, so the matrix does not treat an account-opening requirement as a complete description of every later identity check.

The signup field reports only the identifiers, requiredness, collecting actor, and scope established by the current cell. The later-verification field separately reports a trigger, requested identifier, requesting actor, and scope when the captured document establishes them. A statement in one column does not supply a missing value in the other.

That distinction preserves time and actor boundaries. Initial use, a paid-plan change, account recovery, a risk review, support contact, and another later event are not merged merely because each may involve an identifier. The row stays tied to the product, plan, region, and platform recorded by its source. When a document does not settle one of those qualifiers, the matrix preserves the field-level evidence state instead of inferring it from the rest of the row.

These columns describe documentation, not a completed signup or verification exercise. No account was created and no later event was triggered for this comparison. A requirement stated in a captured document remains scoped to that document and observation. It is not generalized into a claim about every account, plan, platform, region, or future version.

What identity the product collects and what can trigger later verification
JurisdictionSignup identifiersLater verification
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password says account confirmation uses an email and is followed by choosing a strong account password to unlock 1Password.source1Password says it may ask a requester to verify their identity to help it respond securely and efficiently.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden requires a valid email address to complete signup and says other requested information is optional unless the user represents a legal entity or chooses a paid account requiring billing information.sourceBitwarden may request additional information to verify a California privacy-rights requester who has no account or whose account may be compromised, matching it against existing records.source
KeePassXCVerified absencesourceKeePassXC is free and open source, runs on Windows, macOS, and Linux, and stores information in an offline encrypted file.sourceKeePassXC says KeePassXC and KeePassXC-Browser run locally and do not send stored personal data to KeePassXC or a third party.source
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton Pass can be used with a Proton Mail address or an external non-Proton address, which serves as the account identifier.sourceProton may request Proton Captcha, email, or SMS verification for some sensitive operations in addition to account creation and says IP addresses, email addresses, and phone numbers are saved temporarily, or only as a cryptographic hash if saved permanently.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Signup identifiers
Identifiers, requiredness, collecting actor, plan, region, platform, and scope stated for signup or initial use.
Later verification
A later trigger, requested identifier, requesting actor, and scope stated by the current cell.

Where data is operated, retained, and deleted

Operating entity, documented data region, retention, and deletion are separate fields, and an account-deletion mechanism does not establish complete erasure across every record or actor.

The operating-entity column identifies the legal name and jurisdictional details supported by the exact current cell. The data-region column separately reports a documented storage or processing location and whether the captured source describes a user choice. Legal domicile, governing law, customer location, storage location, processing location, and selectable region are not treated as synonyms.

Retention stays at the grain the cell provides: a data category, controller, trigger, duration, and any stated exception. A period attached to one category is not generalized to every record connected with a vault. A relative or non-numeric period remains in the source's terms rather than being converted into an estimated calendar date. If the source does not establish a duration, the matrix does not substitute the deletion flow or a general policy statement.

Deletion reports the documented initiation path, controller, completion statement, timeframe, exceptions, and scope. A way to close an account is not presented as proof that every backup, billing record, support record, legal record, shared item, local file, or separately controlled artifact is erased. The table keeps the actor and stated scope visible so a narrow deletion claim cannot expand into a service-wide promise.

A local-file product and a hosted service are not generalized beyond their own cells. Where the captured evidence leaves a field unsettled, the result remains a typed unknown for that field. Unknown is not rewritten as no collection, no retention, immediate deletion, or proof that a record does not exist.

Where data is operated, retained, and deleted
JurisdictionOperating entityData regionRetentionDeletion
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password lets an account be created in the United States, Canada, or European Union region; data stays in the chosen region, and changing regions requires a new account.source1Password says it retains personal information as long as necessary for the stated purposes unless law requires or permits longer retention or the person instructs deletion; updated, modified, or deleted information may remain for a period or as business records.source1Password says deleting an account starts deletion of all information from its service, with permanent deletion after 30 days; some individual account holders, family organizers, or team owners may be able to restore it through Support within that period.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden stores cloud data in United States and European Union regions, lets users select a region at login or registration, and says it cannot migrate customer accounts between regions.sourceBitwarden says it retains Administrative Data for as long as a person remains a customer and as required by law, then deletes personal information under its retention policies after termination.sourceBitwarden says cancelling an account purges all information from its databases and makes that information unrecoverable, with account deletion available from web-vault settings.source
KeePassXCVerified absencesourceVerified absencesourceKeePassXC says it stores passwords in an offline encrypted file that can be kept in any location, including private or public cloud storage, while no data is stored on remote servers.sourceKeePassXC says its website deletes visitor logs after 90 days and detailed reports after 12 months, retaining only basic trend metrics after that.sourceKeePassXC prompts the user to move a deleted entry to the Recycle Bin when it is enabled; with the Recycle Bin disabled, the entry is permanently removed, and an entry in the Recycle Bin can be permanently deleted with the Delete key.source
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton Pass says data is stored encrypted on servers exclusively in Switzerland, Germany, or Norway, while some hide-my-email functionality is hosted on contracted European cloud servers through SimpleLogin SAS.sourceProton Pass says alias addresses created in Proton Pass are not encrypted so alias forwarding can function and are retained for as long as the user does not delete them.sourceProton says deleting a Proton Account permanently deletes the account and all its data from its systems, including Proton Pass, and prevents the username from being reused.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Operating entity
The legal operating entity and jurisdictional details stated by the current cell.
Data region
Documented storage or processing region, choice mechanism, eligibility, plan, and scope stated by the cell.
Retention
Data category, controller, trigger, duration, exceptions, and scope stated by the captured source.
Deletion
Deletion initiation, controller, completion statement, timeframe, exceptions, and scope stated by the cell.

Exports and emergency access create different recovery paths

An encrypted export or database path concerns portable vault material, while emergency access concerns a documented person- or organization-mediated path into selected account data.

The encrypted-export column records the artifact, format, protection, creation path, restore path, plan, platform, scope, and limitations stated by the current cell. It does not treat every export as equivalent. An encrypted database, an encrypted archive, an export whose protection depends on a selected option, and a general portability statement remain distinct when the source distinguishes them.

The emergency-access column asks a different set of questions: who can be designated, what event starts access, whether a waiting period or approval step is documented, what data or account scope becomes available, and how access can be revoked. Those details describe a delegated process. They do not establish that an export exists, that recovery covers every item, or that the process fits every household or organization.

The two columns should therefore be read side by side without collapsing them into a resilience score. Portability does not automatically create delegated recovery. Delegated access does not automatically produce a portable protected copy. A restore path does not establish emergency access, and a named emergency feature does not establish the format or protection of exported material.

Each value stays product- and plan-scoped. If a format, protection method, restore step, waiting period, approval condition, scope, or revocation path is absent from the exact cell, the matrix leaves that element in its recorded evidence state. It does not fill the gap from another plan, platform, vendor row, or general expectation about password managers.

Exports and emergency access create different recovery paths
JurisdictionEncrypted exportEmergency access
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password says its exported data files are unencrypted plaintext readable by anyone with access; 1Password 8 exports .1pux or CSV files, and passkeys can currently be exported only on iOS and Android.source1Password lets a family organizer, team administrator or owner, or a member of a custom group with Recover Accounts permission restore access for a family or team member who cannot sign in or unlock 1Password.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden offers account-restricted and password-protected encrypted JSON exports for individuals and organizations, with password-protected files importable to any Bitwarden account.sourceBitwarden lets premium users appoint same-server account holders as trusted emergency contacts with view or takeover access, subject to account-holder approval or expiry of a wait time.source
KeePassXCVerified absencesourceKeePassXC says exports made for transfer, printing, or archiving store passwords and sensitive information in an unencrypted format, while its database file remains fully encrypted and can be backed up.sourceVerified absencesource
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton Pass exports a PGP-encrypted JSON file inside a ZIP from its browser extensions, web app, and Windows app, not its mobile apps, and lets users import that encrypted ZIP directly into Proton Pass.sourceProton lets paid-plan users choose up to five Proton Mail contacts for emergency access, with requests automatically granted after a user-selected wait of 1, 2, 3, 7, 14, or 30 days unless approved or denied earlier.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Encrypted export
Artifact, format, protection, creation and restore paths, plan, platform, scope, and limitations stated by the cell.
Emergency access
Designated actor, trigger, waiting or approval process, access scope, revocation, plan, and limitations stated by the cell.

Passkeys and TOTP depend on where the second factor lives

Passkey support and TOTP placement are separate documented paths, and the matrix reports whether a factor lives inside the vault, in a separate app, or in a named companion context without prescribing one arrangement.

The passkey column records the documented role, storage or synchronization statement, supported platform, plan, scope, and limitations established by the cell. Creating, storing, synchronizing, using, importing, or exporting a passkey are not assumed to be the same capability. A statement about one role does not fill another, and a platform statement does not automatically extend to every client or account type.

The separate-app TOTP column reports the documented placement and relationship of the authenticator path. It keeps an integrated vault feature, a separate application, and a companion product in their stated scopes. The four compared rows do not expand merely because a cell names another app as context. A companion reference helps explain placement; it does not create an extra vendor row or transfer the companion's attributes into the password-manager row.

Location is not a universal verdict. Keeping a password and a time-based one-time password in one product, separating them into different applications, or using another authentication path changes custody and recovery relationships, but the current evidence does not authorize a single arrangement for every threat model. The matrix reports the documented architecture and qualifiers rather than declaring one factor pattern safer.

Plan and platform limits remain load-bearing. When a source describes one device family, subscription, client, or companion path, the table does not broaden it to every platform. When a role or scope is not established, the value remains bounded by the cell rather than being completed from another product's documentation.

Passkeys and TOTP depend on where the second factor lives
JurisdictionPasskey supportTOTP placement
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password supports saving passkeys and using them to sign in through a browser; Business administrators can control whether team members may save or use browser passkeys.source1Password lets users save and access one-time passwords through its browser extension, apps, or 1Password.com for websites using two-step verification.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden supports saving and autofilling encrypted passkeys through its browser extension and mobile apps, including iOS 17.0+ and Android 14.0+.sourceBitwarden offers a standalone Authenticator app on iOS and Android as well as a distinct Password Manager authenticator, and says codes can synchronize between the two apps.source
KeePassXCVerified absencesourceKeePassXC supports passkeys through the KeePassXC Browser Extension with a connected database; passkeys can be stored, viewed, imported, and exported, but exported .passkey files are unencrypted.sourceKeePassXC calculates TOTP codes from a secret stored on a database entry and lets users copy, auto-type, or enter those codes through the browser extension; the secret and configuration can also be viewed as a QR code for export to a mobile device.source
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton Pass's passkey page is headed "Store, share and export passkeys" and says passkeys are supported in its browser extension and on Android and iOS devices, that Android supports passkeys only from Android 14, and that users cannot currently log into Proton Pass apps using passkeys.sourceProton Pass generates TOTP codes for saved website login items without requiring a separate authenticator app and documents setup through its browser extension, Android app, and iPhone and iPad app.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Passkey support
Documented passkey role, storage or synchronization statement, platform, plan, scope, and limitations stated by the cell.
TOTP placement
Whether TOTP is documented inside the vault, in a separate app, or in a companion context, with plan and platform scope.

Zero-knowledge, audits, and source availability are different evidence types

A zero-knowledge statement, an assessment record, a public source artifact, and a client-versus-server source statement answer different questions and do not combine into a product-wide assurance.

The zero-knowledge column records the architecture claim, named data or key material, stated limitation, audit relationship, scope, and source type supported by its cell. The matrix preserves the claim as published. It does not independently prove implementation, extend the statement to material the source excludes, or treat the phrase as a universal description of every client, server, recovery process, support workflow, or release.

The assessment column reports the assessor, scope, standard, period or date, report locator, publication status, and stated limitations. An assessment of a bounded component or period remains bounded. Its presence is not a trust badge for every product function, and its absence from the declared source set is not proof that no assessment exists. The claim type printed with the cell controls how the record is read.

Source availability and open-source client or server scope remain separate columns because a repository can establish less than a product-wide source claim. The table records the named component, artifact or repository locator, version or release locator, license, client scope, server scope, and limitations only where the exact cells establish them. A public component does not make an undocumented hosted service, synchronization path, policy layer, or release open source by association.

These four evidence types can inform different questions, but none substitutes for the others. Architecture language is not an assessment. An assessment is not a complete source inventory. A public repository is not an independent test of a hosted deployment. A client-source statement does not settle server scope. Unsupported links between them remain unresolved rather than becoming an overall security conclusion.

Zero-knowledge, audits, and source availability are different evidence types
JurisdictionZero-knowledge claimAssessment recordSource availabilityClient and server source
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password says everything in a 1Password account is always end-to-end encrypted, with the keys held only by the user, making it impossible to learn anything by intercepting the data in transit or obtaining it from AgileBits.source1Password says Independent Security Evaluators (ISE) performed a penetration test and code review of the 1Password system during April and June 2020, with full details available in the ISE security assessment report.source1Password's srp repository contains Go functions for the Secure Remote Password protocol in 1Password Teams and lists Apache-2.0, master, and a September 2, 2026 timestamp.source1Password's repository listing describes Go functions for the Secure Remote Password protocol in 1Password Teams and a client library for desktop-app integrations over IPC.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden says every piece of vault information is encrypted under its zero-knowledge approach and says ETH Zurich's Applied Cryptography Group audited its core cryptography operations under a fully malicious-server assumption.sourceAuditOne LLP's report examines Bitwarden Inc.'s management assertion that controls within its Password Management System were effective from July 1, 2025, to June 30, 2026, against security and confidentiality trust-services criteria.sourceBitwarden's clients repository uses GPL v3.0 by default, while code in its /bitwarden_license directory uses the Bitwarden License v1.0.sourceBitwarden's clients repository houses its non-mobile client applications and links separate repositories for the server, iOS apps, and Android apps.source
KeePassXCVerified absencesourceKeePassXC says passwords remain encrypted at all times, no data is stored on remote servers, and users stay in control of their data.sourceKeePassXC's audit page lists a November 17, 2025 ANSSI Security Visa for KeePassXC 2.7.9 on Windows 10 and links a certification report, certificate, security target, and full technical report.sourceKeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING.sourceKeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING.source
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceProton says Proton Pass performs key generation and data encryption locally, its servers never have access to unencrypted keys, data, or credentials, and all fields receive end-to-end encryption, including usernames, web addresses, and notes.sourceProton Pass says Cure53 audited its code throughout May and June 2023, testing all Proton Pass mobile apps, browser extensions, and its API, and links the audit report.sourceProton says all Proton apps are open source and have been independently audited and verified by third-party experts.sourceProton says all Proton Pass apps are open source and can be independently reviewed by anyone.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

Field definitions

Zero-knowledge claim
Architecture claim, named data or key material, limitations, audit relationship, scope, and source type stated by the cell.
Assessment record
Assessor, scope, standard, period or date, report locator, publication status, and limitations stated by the cell.
Source availability
Named component, repository or artifact locator, version or release locator, license, scope, and limitations stated by the cell.
Client and server source
Documented client scope, server scope, repository or artifact, license, release context, and limitations stated by the cell.

Request reporting and the limits of this comparison

Each request-reporting cell records only the published period, jurisdiction, unit, scope, and counts its source supplies; the page does not independently test, score, or rank the four products.

Request reports require their units to remain visible. Requests, orders, accounts, identifiers, disclosures, and challenged matters are not interchangeable counts. A process statement is not a count, and a count does not fully describe a process. When the captured evidence does not disclose a field under the declared method, the comparison preserves that evidence state instead of printing zero.

Read every value as a dated, scoped record. The capture date says when the source was collected; it does not promise that a policy, interface, repository, plan, platform, or product remains unchanged. Inclusion and alphabetical row order do not express an endorsement. The page has no score, rank, highlight, affiliate parameter, best label, or preferred-product conclusion.

The matrix also makes no independent performance claim. Vendor-stated architecture, zero-knowledge, encryption, recovery, and deletion language describes the captured documents. A source artifact applies to the component and version it names. An assessment record applies to its stated scope and period. Separate-app TOTP placement describes documented custody, not the correct design for every threat model.

A typed unknown is field-specific. It does not inherit an answer from another column or vendor, and it does not mean the underlying feature, record, process, or capability cannot exist. The frozen roster is limited to the four compared rows. Context named inside a cell does not create another row or import that context's attributes.

The privacy-tool comparison methodology and corrections hub explains that a capture date records when a source was read, not that the source has stayed the same since; it also provides the correction path. This page remains bounded to the four-row, sixty-cell evidence set it transcludes.

Request reporting and the limits of this comparison
JurisdictionRequest reporting
1Password1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.source1Password says it checks law-enforcement authority, provides only reasonably required user information, and notifies the customer or user before disclosure unless law, law enforcement, suspected illegal or malicious conduct, or risk of harm prevents notice.source
BitwardenBitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.sourceBitwarden says it may disclose information when reasonably necessary to comply with law, legal process, or lawful government requests, including national-security or law-enforcement requirements.source
KeePassXCVerified absencesourceVerified absencesource
Proton PassProton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.sourceNot disclosed in the captured primary source.source

Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.

How to read Unknown

Unknown: Verified absence
The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
Unknown: Not yet verified
The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.

Frequently asked questions

Does zero knowledge mean every part of a password manager is independently verified?

No. This matrix preserves the architecture claim, named scope, source type, limitations, and any assessment relationship stated by the exact cells; it does not convert the phrase into product-wide independent verification.

Is an encrypted export the same as emergency access?

No. An encrypted export concerns a documented portable artifact and restore path, while emergency access concerns a documented person- or organization-mediated access process.

Do password managers store and use passkeys the same way?

The matrix does not assume they do. It reports the role, storage or synchronization statement, platform, plan, scope, and limitations supplied by each current passkey cell.

Should TOTP live inside a password manager or in a separate app?

This page does not prescribe one arrangement. It reports documented TOTP placement and keeps each plan, platform, scope, and companion context attached to its cell.

Does a public repository mean the whole hosted service is open source?

No. A public repository supports only the named component, artifact, release, license, and scope established by the current cells.