{
  "cells": {
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says Independent Security Evaluators (ISE) performed a penetration test and code review of the 1Password system during April and June 2020, with full details available in the ISE security assessment report.",
      "fetch_event_id": "3536f3f2-cf57-54ba-a1f1-34f550ab5c92",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Independent Security Evaluators (ISE) was engaged to perform a penetration test and code review of the 1Password system. The assessment was performed during April and June, 2020.\n\nFull details are available in the ISE security assessment report",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "29ac66704fda26a2b46aafa9682999751829fd78ed0c8e7b24634a7c539aabf2",
      "source_url": "https://support.1password.com/security-assessments/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.data_region_choice": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password lets an account be created in the United States, Canada, or European Union region; data stays in the chosen region, and changing regions requires a new account.",
      "fetch_event_id": "60f289cf-26a4-593b-b72b-d1ca1d20deaa",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can create your 1Password account in one of three different regions.\n\n1Password.com 🇺🇸 USD United States\n\n1Password.ca 🇨🇦 CAD Canada\n\n1Password.eu 🇪🇺 EUR European Union\n\nYour data stays in the region you choose. It is never automatically moved from one region to another. To change from one region to another, sign up for a new 1Password account in a different region.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "b807d7769f399be5507d8b9179598a10aa15b8288ea1159a91eefbbf8c35204b",
      "source_url": "https://support.1password.com/regions/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says deleting an account starts deletion of all information from its service, with permanent deletion after 30 days; some individual account holders, family organizers, or team owners may be able to restore it through Support within that period.",
      "fetch_event_id": "93ef184f-144f-5ea2-a1e4-c595dca8b41e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Deleting your account will start the process to delete all your information from the 1Password service.\n\nYou have 30 days before your information is permanently deleted.\n\nIf you have an individual account, or you’re family organizer or team owner in your account, you may be able to restore your account if you contact 1Password Support within 30 days.\n\nSelect Permanently Delete Account at the bottom of the page.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "92e9a35799d399691c224463ae8cad43e74f87573bf5399521a4bd1368f0cccb",
      "source_url": "https://support.1password.com/delete-account/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.emergency_access": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password lets a family organizer, team administrator or owner, or a member of a custom group with Recover Accounts permission restore access for a family or team member who cannot sign in or unlock 1Password.",
      "fetch_event_id": "bc3d7b4f-9d49-50c5-9e10-23f66464e5cd",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can restore access for a family or team member if they can’t sign in to or unlock 1Password.\n\nYou can recover accounts for other people if: You’re a family organizer . You’re a team administrator or owner . You belong to a custom group that has the “Recover Accounts” permission.\n\nThey’ll be able to access all the data they had before.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "3368247f2ba0b01596cd36a98fc56ef7e141559b130cc2f5d5046d56cf8eac9c",
      "source_url": "https://support.1password.com/recovery/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.encrypted_export": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says its exported data files are unencrypted plaintext readable by anyone with access; 1Password 8 exports .1pux or CSV files, and passkeys can currently be exported only on iOS and Android.",
      "fetch_event_id": "d85061c9-4286-566b-99c3-b8cd234d9019",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Exported data files are not encrypted. They are stored in plaintext. Anyone with access to your exported data files will be able to read your passwords.\n\n1Password 8 exports to the 1Password Unencrypted Export (.1pux) format or a comma-separated values (CSV) file.\n\nYou can only export passkeys in 1Password for iOS and Android at this time.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a8a8db64cb0184e58744dd96b3fa727344d73d5ce4ecaf16f0f37527950a126b",
      "source_url": "https://support.1password.com/export/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says it may ask a requester to verify their identity to help it respond securely and efficiently.",
      "fetch_event_id": "84dd8c87-cfcf-5b98-9988-e87885a334e2",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Please note, we may also ask you to verify your identity in order to help us respond to your request securely and efficiently.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c473170202ca8045d0d94c67010e963f447a799b83c1a19e79faccd1c9fd9960",
      "source_url": "https://1password.com/legal/privacy/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.open_source_client_server": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "1Password's repository listing describes Go functions for the Secure Remote Password protocol in 1Password Teams and a client library for desktop-app integrations over IPC.",
      "fetch_event_id": "6669207e-f6e0-508c-a887-e532f1ffde6e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "A set of Go functions for Secure Remote Password protocol implementation in 1Password Teams\n\nClient library for communicating with integrations exposed by the 1Password desktop app over IPC\n\n1Password/onepassword-ipc-client\n\nhttps://github.com/1Password/onepassword-ipc-client\n\n1Password/srp\n\nhttps://github.com/1Password/srp\n\nApache-2.0",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "86ca9686b0df4f835b358ead1497658769041d1e4a213c9aec6a22aebd3a34b3",
      "source_url": "https://api.github.com/orgs/1Password/repos?per_page=100&type=public",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
      "fetch_event_id": "84dd8c87-cfcf-5b98-9988-e87885a334e2",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "AgileBits Inc., doing business as 1Password, is committed to processing your information in ways that respect your privacy and keep it safe.\n\n1Password is a Canadian company headquartered in Toronto, Ontario, Canada.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c473170202ca8045d0d94c67010e963f447a799b83c1a19e79faccd1c9fd9960",
      "source_url": "https://1password.com/legal/privacy/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.passkey_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password supports saving passkeys and using them to sign in through a browser; Business administrators can control whether team members may save or use browser passkeys.",
      "fetch_event_id": "7aaed027-52a0-5beb-9f89-619783275fa4",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can use 1Password to save the passkeys you create for your accounts and sign in to websites with passkeys in your browser.\n\nIf you’re an administrator in a 1Password Business account, you can control whether your team members are allowed to save or sign in with passkeys in the browser .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "50cc655368adcdcf37ca7b69defc575a2d9acd10d9a77faea26805707124f7a8",
      "source_url": "https://support.1password.com/save-use-passkeys/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says it checks law-enforcement authority, provides only reasonably required user information, and notifies the customer or user before disclosure unless law, law enforcement, suspected illegal or malicious conduct, or risk of harm prevents notice.",
      "fetch_event_id": "eab1a8b4-756a-5350-8c46-b3cba42f6acd",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "confirm that Law Enforcement has the appropriate authority under applicable law before providing any User Information;\n\nprovide only such User Information as is reasonable and required given the circumstances and the demand from Law Enforcement;\n\nnotify the customer or user of a request for their User Information before disclosing it to Law Enforcement, unless 1Password is prohibited by applicable law or Law Enforcement or where there is a reasonable indication of illegal or malicious conduct or risk of harm.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "7f95f13b99b1908f1509fd4ee2e101a9bc8cd304ad8a7e5bc39a3abf9aec6200",
      "source_url": "https://1password.com/legal/law-enforcement/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says it retains personal information as long as necessary for the stated purposes unless law requires or permits longer retention or the person instructs deletion; updated, modified, or deleted information may remain for a period or as business records.",
      "fetch_event_id": "84dd8c87-cfcf-5b98-9988-e87885a334e2",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We will retain your personal information for as long as necessary to fulfill the purposes set forth in this Privacy Notice, unless a longer retention period is required or permitted by law, or you instruct us to delete your information. We will deidentify, aggregate, or otherwise remove or mask your personal information if we intend to use it for analytical purposes or trend analysis over longer periods of time. Please note that copies of information that you have updated, modified, or deleted may continue to reside in our systems for a period of time, and we may maintain copies of this information as part of our business records.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c473170202ca8045d0d94c67010e963f447a799b83c1a19e79faccd1c9fd9960",
      "source_url": "https://1password.com/legal/privacy/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.separate_app_totp": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password lets users save and access one-time passwords through its browser extension, apps, or 1Password.com for websites using two-step verification.",
      "fetch_event_id": "06357c7a-00d5-53c2-ac06-af37693c8632",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You can save one-time passwords in the 1Password browser extension , in the 1Password apps , or on 1Password.com .\n\nLearn how to use 1Password to store and quickly access your one-time passwords when you turn on two-step verification for a website.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2e9744cf24bf37acd444c61e953b6af6a3df583de4d1f54076e2c5061a4ce56d",
      "source_url": "https://support.1password.com/one-time-passwords/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says account confirmation uses an email and is followed by choosing a strong account password to unlock 1Password.",
      "fetch_event_id": "9d1f2e4a-7bbd-56c0-a0d4-1e83b2dc414f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You’ll get an email to confirm your account. Then you can choose a strong account password , which you’ll use to unlock 1Password.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "027e28b1221431e35ad7aa72b796042b3910bc7c86fb72e9fbd6180c95b4e244",
      "source_url": "https://support.1password.com/explore/get-started/",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "1Password's srp repository contains Go functions for the Secure Remote Password protocol in 1Password Teams and lists Apache-2.0, master, and a September 2, 2026 timestamp.",
      "fetch_event_id": "6669207e-f6e0-508c-a887-e532f1ffde6e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "A set of Go functions for Secure Remote Password protocol implementation in 1Password Teams\n\n1Password/srp\n\nhttps://github.com/1Password/srp\n\nApache-2.0\n\nmaster\n\n2026-09-02T14:21:18Z",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "86ca9686b0df4f835b358ead1497658769041d1e4a213c9aec6a22aebd3a34b3",
      "source_url": "https://api.github.com/orgs/1Password/repos?per_page=100&type=public",
      "table": "vendor"
    },
    "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "1Password says everything in a 1Password account is always end-to-end encrypted, with the keys held only by the user, making it impossible to learn anything by intercepting the data in transit or obtaining it from AgileBits.",
      "fetch_event_id": "fe6b5a89-7618-581f-b4d4-86200760b184",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "End-to-end encryption leaves the keys in your hands – and nowhere else.\n\nEverything in your 1Password account is always end-to-end encrypted. This makes it impossible for someone to learn anything by intercepting your data while it’s in transit or even obtaining it from AgileBits.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "1ae8f920c3a1e0bf7789f7f08ac216e93850ef43ec9d9a04acf6cce887f94b47",
      "source_url": "https://support.1password.com/1password-security/",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "AuditOne LLP's report examines Bitwarden Inc.'s management assertion that controls within its Password Management System were effective from July 1, 2025, to June 30, 2026, against security and confidentiality trust-services criteria.",
      "fetch_event_id": "5febb7ff-1319-5230-a6ab-0a537342248f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We have examined the Bitwarden Inc. (Bitwarden) accompanying assertion titled \"Assertion of Bitwarden\nInc. Management\" (assertion) that the controls within the Bitwarden Password Management System\n(system) were effective throughout the period July 1, 2025, to June 30, 2026, to provide reasonable\nassurance that Bitwarden service commitments and system requirements were achieved based on the\ntrust services criteria relevant to security and confidentiality\n\nAuditOne LLP | AuditOneLLP.com\n\nCampbell, California\n\nAugust 28, 2026",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "5310565e112e9901f1691966992e1d017dc9d12ed1f247307f9d5e62975b90ab",
      "source_url": "https://bitwarden.com/assets/4nGworevQqsF1ZStDgiyQg/35f7c3e8acf2badb9bd85cb9ddab1d8f/Bitwarden_-_2026_SOC_3_Report.pdf",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.data_region_choice": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden stores cloud data in United States and European Union regions, lets users select a region at login or registration, and says it cannot migrate customer accounts between regions.",
      "fetch_event_id": "3511819e-e335-58d3-b7cd-bf79ea8c971d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Bitwarden cloud is available globally with data storage in both **United States** and **European Union** regions. The practices used by Bitwarden for securing your sensitive data are the same, regardless of which server region you use.\n\nTo choose which Bitwarden server region to create your account or organization on, select the **Server** or **Logging in on:**dropdown on the login or registration screen and select your desired region:\n\nBitwarden server regions are separate, and your account or organization only exists in the region where it was first created.\n\nBitwarden regions are distinct cloud environments. Bitwarden cannot migrate accounts from one region to another for customers. A script is available for organizations to help facilitate migrations.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "d09c9b2280400f81f54a156e1c6ff06d93747db29663e1d1fcc373cc79dd1d8f",
      "source_url": "https://bitwarden.com/help/server-geographies.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden says cancelling an account purges all information from its databases and makes that information unrecoverable, with account deletion available from web-vault settings.",
      "fetch_event_id": "8ea8808a-e0ae-565f-87e6-edd2bae44001",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All information is purged from our databases when you cancel your account. Information cannot be recovered once your account is cancelled.\n\nIt is your responsibility to properly cancel your account with Bitwarden. You can [delete your account at any time](https://bitwarden.com/help/delete-your-account/) by going into your web vault Settings. The Settings screen provides a simple, no questions asked delete option.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9cf821db85a8bcc0d14597ad150ed73cc4ea1d1f722f28efe91adb2b333e7cb2",
      "source_url": "https://bitwarden.com/terms.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.emergency_access": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden lets premium users appoint same-server account holders as trusted emergency contacts with view or takeover access, subject to account-holder approval or expiry of a wait time.",
      "fetch_event_id": "44d3b433-a7a4-539f-b460-a55688a3ea34",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Emergency access lets you prepare for the unexpected by appointing trusted emergency contacts who can request access to your Bitwarden vault if needed. Trusted emergency contacts can be granted either view or takeover access, giving you control over what they can do if they ever need to step in:\n\n3. The [request is approved ](https://bitwarden.com/help/request-and-grant-emergency-access/#2-the-trusted-contacts-request-is-approved-or-denied/)by the account holder or after the wait time expires.\n\n[Adding a trusted contact](https://bitwarden.com/help/add-and-manage-trusted-emergency-contacts/) for emergency access is available to premium users, including members of paid organizations (Families, Teams, and Enterprise). If your organization turned on the [Automatic confirmation policy](https://bitwarden.com/help/policies/#automatic-user-confirmation/), emergency access is **not** available for your account.\n\nAnyone with a free or premium Bitwarden account on the same [Bitwarden server](https://bitwarden.com/help/server-geographies/) can be designated as a trusted emergency contact.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a65e748add6840f0302a4cacadf4405428cf939602da6594e4e4a31ac9e4217a",
      "source_url": "https://bitwarden.com/help/emergency-access.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.encrypted_export": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden offers account-restricted and password-protected encrypted JSON exports for individuals and organizations, with password-protected files importable to any Bitwarden account.",
      "fetch_event_id": "23c4cfc2-1294-5a42-a9be-b36e276de19a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Vault data can be exported in an encrypted `.json` file [for individuals](https://bitwarden.com/help/export-your-data/) and [for organizations](https://bitwarden.com/help/export-organization-items/). Two encrypted export types are available:\n\n- **Account restricted:** Export an encrypted file that can only be re-imported to the Bitwarden account or organization that generated the encrypted export file. This process utilizes the relative [account](https://bitwarden.com/help/account-encryption-key/) or organization encryption key specific to the restricted export.\n\n- **Password protected:** Export an encrypted file protected with a password of your choosing. This file can be decrypted with the password and can be imported to any Bitwarden account. The specified password is salted, used to derive an encryption key using [your configured KDF settings](https://bitwarden.com/help/kdf-algorithms/#changing-kdf-algorithms/), and finally stretched with HDKF into a new encryption key, which encrypts your data, and message authentication code (MAC).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c76373205543bb2e72327551eac24ecf981ad1c757b61df2da7f4d6ee46d88da",
      "source_url": "https://bitwarden.com/help/encrypted-export.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden may request additional information to verify a California privacy-rights requester who has no account or whose account may be compromised, matching it against existing records.",
      "fetch_event_id": "d1fd9f03-7b46-5073-9ecb-1793031d638a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "For security purposes, we may request additional information from you to verify your identity when you request to exercise your California privacy rights. If you do not have an account with us, or if we have reason to suspect that the security of your account is compromised, we will request additional information from you to match with our existing records to verify your identity, depending on the nature of the request and the sensitivity of the information sought.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "364b9890421f0d653c5dd5702e3813ca159d2f4d614fed4f01552206424ee89f",
      "source_url": "https://bitwarden.com/privacy.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.open_source_client_server": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "Bitwarden's clients repository houses its non-mobile client applications and links separate repositories for the server, iOS apps, and Android apps.",
      "fetch_event_id": "d8bb0484-957d-57a9-b678-4d8338f57c90",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "This repository houses all Bitwarden client applications except the mobile applications ([iOS](https://github.com/bitwarden/ios) | [android](https://github.com/bitwarden/android)).\n\n- [bitwarden/server](https://github.com/bitwarden/server): The core infrastructure backend (API, database, Docker, etc).\n\n- [bitwarden/ios](https://github.com/bitwarden/ios): Bitwarden iOS Password Manager & Authenticator apps.\n\n- [bitwarden/android](https://github.com/bitwarden/android): Bitwarden Android Password Manager & Authenticator apps.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "c5ea2d6804adf6756a7960464af86cfcbcbf4e0218377a86797dcd9cf1fa6db8",
      "source_url": "https://raw.githubusercontent.com/bitwarden/clients/main/README.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
      "fetch_event_id": "8ea8808a-e0ae-565f-87e6-edd2bae44001",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Except to the extent applicable law provides otherwise, this Agreement between you and Bitwarden and any access to or use of the Website or the Service are governed by the federal laws of the United States of America and the laws of the State of California, without regard to conflict of law provisions. You and Bitwarden agree to submit to the exclusive jurisdiction and venue of the courts located in the State of California.\n\nBitwarden Inc. is incorporated in the State of Delaware in the United States of America. 8bit Solutions LLC is wholly owned by Bitwarden Inc.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9cf821db85a8bcc0d14597ad150ed73cc4ea1d1f722f28efe91adb2b333e7cb2",
      "source_url": "https://bitwarden.com/terms.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.passkey_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden supports saving and autofilling encrypted passkeys through its browser extension and mobile apps, including iOS 17.0+ and Android 14.0+.",
      "fetch_event_id": "32acab3a-2b68-53b4-a247-eef4c11100b9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Save passkeys in your Bitwarden vault and use the browser extension or mobile apps to autofill them across the apps and websites you use every day. Stored passkeys are protected with Bitwarden's trusted end-to-end encryption.\n\n- Use [passkeys to log in and unlock](https://bitwarden.com/help/login-with-passkeys/) your Bitwarden account.*\n\n[Passkeys](https://bitwarden.com/resources/passkeys-faq/) are a replacement for passwords that provide fast, easy, and secure sign-ins to websites and apps. Passkeys are a discoverable FIDO credential that can be synced to allow secure passwordless sign-ins across devices or dedicated to a single piece of hardware as a device-bound passkey.\n\nWhen creating a new passkey on a website or app, the browser extension will prompt you to store the passkey:\n\nOnly one passkey can be saved per login item. If a passkey already exists for a service, overwrite the existing passkey or select the + **Add icon** to create a new login item to store an additional passkey:\n\nYou can save and use passkeys from Bitwarden with iOS version 17.0+.\n\nYou can save and use passkeys from Bitwarden with Android version 14.0+.\n\n> [!NOTE] Android passkeys, no passkey-based 2FA\n> In Android, Bitwarden-stored passkeys can only be used as a primary login credential. Android does not allow third-party passkey providers like Bitwarden to support passkey-based 2FA, also known as \"non-discoverable credentials.\"\n\nPasskeys are included in [JSON exports](https://bitwarden.com/help/export-your-data/) generated by Bitwarden and, once exported, can be [imported to a Bitwarden account](https://bitwarden.com/help/import-data/).\n\nOn mobile, passkeys can also be [imported](https://bitwarden.com/help/import-data/#tab-mobile-5ALQx9afSqWXX9jfXsY5sb/) and [exported](https://bitwarden.com/help/export-your-data/#tab-mobile-1QlXqfleMlF6jWT87Dbn2u/) directly using the FIDO Credential Exchange Protocol (CXP), on iOS 26+ and Android 14+. Both applications must support CXP.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "d28cbae1540aa7aebd11be21037f184b18a06d1d412bb533de44a4c5a22e21c8",
      "source_url": "https://bitwarden.com/help/storing-passkeys.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden says it may disclose information when reasonably necessary to comply with law, legal process, or lawful government requests, including national-security or law-enforcement requirements.",
      "fetch_event_id": "d1fd9f03-7b46-5073-9ecb-1793031d638a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "We believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process, or lawful government request, including in connection with national security or law enforcement requirements.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "364b9890421f0d653c5dd5702e3813ca159d2f4d614fed4f01552206424ee89f",
      "source_url": "https://bitwarden.com/privacy.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden says it retains Administrative Data for as long as a person remains a customer and as required by law, then deletes personal information under its retention policies after termination.",
      "fetch_event_id": "d1fd9f03-7b46-5073-9ecb-1793031d638a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Bitwarden obtains Personal Information in connection with your account creation, usage of the Bitwarden Service and support, and payments for the Bitwarden Service such as names, emails address, phone and other contact information for users of the Bitwarden Service and the number of items in your Bitwarden Service account (\"Administrative Data\"). Bitwarden uses Administrative Data to provide the Bitwarden Service to you. We retain Administrative Data for as long as you are a customer of Bitwarden and as required by law. If you terminate your relationship with Bitwarden, we will delete your Personal Information in accordance with our data retention policies.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "364b9890421f0d653c5dd5702e3813ca159d2f4d614fed4f01552206424ee89f",
      "source_url": "https://bitwarden.com/privacy.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.separate_app_totp": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden offers a standalone Authenticator app on iOS and Android as well as a distinct Password Manager authenticator, and says codes can synchronize between the two apps.",
      "fetch_event_id": "6c6ed716-4d1a-54fc-bc11-ea0263a1599b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Bitwarden Authenticator is a standalone app that generates time-based one-time passwords (TOTPs) for logins that support authenticator app two-factor authentication (2FA). It generates 5-10 digit codes, by default using SHA-1 and rotating them every 30 seconds.\n\nBitwarden offers [two authenticators](https://bitwarden.com/help/bitwarden-authenticator/#whats-the-difference-between-bitwarden-authenticator-and-password-managers/): the Bitwarden Authenticator app and Password Manager [integrated authenticator](https://bitwarden.com/help/integrated-authenticator/). Bitwarden Authenticator is available for everyone, with or without a Bitwarden Password Manager account. If you use both apps, you can [synchronize codes](https://bitwarden.com/help/totp-sync/) between Authenticator and your Bitwarden vault.\n\nBitwarden Authenticator is available on iOS and Android devices.\n\n- iOS: [App Store](https://apps.apple.com/us/app/bitwarden-authenticator/id6497335175) (iOS 15+)\n\n- Android: [Google Play](https://play.google.com/store/apps/details?id=com.bitwarden.authenticator&pli=1) (Android 9+)",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "cd23ce0c53b6feeaedbb2aa7469e6d70433934e4eb6f29895c6376134faa504d",
      "source_url": "https://bitwarden.com/help/bitwarden-authenticator.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden requires a valid email address to complete signup and says other requested information is optional unless the user represents a legal entity or chooses a paid account requiring billing information.",
      "fetch_event_id": "8ea8808a-e0ae-565f-87e6-edd2bae44001",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You must provide a valid email address in order to complete the signup process. Any other information requested, such as your real name, is optional, unless you are accepting these terms on behalf of a legal entity (in which case we need more information about the legal entity) or if you opt for a [paid account](https://bitwarden.com/terms/#payment/), in which case additional information will be necessary for billing purposes.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "9cf821db85a8bcc0d14597ad150ed73cc4ea1d1f722f28efe91adb2b333e7cb2",
      "source_url": "https://bitwarden.com/terms.md",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "Bitwarden's clients repository uses GPL v3.0 by default, while code in its /bitwarden_license directory uses the Bitwarden License v1.0.",
      "fetch_event_id": "3f8c1aec-b545-5aea-97e6-7fcde40b9986",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Source code in this repository is covered by one of two licenses: (i) the\nGNU General Public License (GPL) v3.0 (ii) the Bitwarden License v1.0. The\ndefault license throughout the repository is GPL v3.0 unless the header\nspecifies another license. Bitwarden Licensed code is found only in the\n/bitwarden_license directory.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "01fe7fd5a624e6a81557ff4b76c4a7b9a3d89c6a1b58083b74aff7bce843bb41",
      "source_url": "https://raw.githubusercontent.com/bitwarden/clients/main/LICENSE.txt",
      "table": "vendor"
    },
    "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Bitwarden says every piece of vault information is encrypted under its zero-knowledge approach and says ETH Zurich's Applied Cryptography Group audited its core cryptography operations under a fully malicious-server assumption.",
      "fetch_event_id": "f9926710-505c-599c-a02e-0bf0130e9dd1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Bitwarden takes a zero knowledge encryption approach to password management, meaning every piece of information in your vault is encrypted. For more information on this approach, please see the blog post [How End-to-End Encryption Paves the Way for Zero Knowledge](https://bitwarden.com/blog/end-to-end-encryption-and-zero-knowledge/).\n\n### 2025 Bitwarden Cryptography Report\n\nBitwarden completed an audit of Bitwarden core cryptography operations by the Applied Cryptography Group at ETH Zurich under the assumption of a fully malicious server.\n\n[Read the report](https://bitwarden.com/assets/Kki4W785JIPOdFj6EeWB5/dbf51066c1041aa90dc503ca0c911194/2025_Bitwarden_Cryptography_Report.pdf)",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "51385f8b9c0b81c4c46bffbba7f74e7f12425a66be1def93cf2b190f4fc0188e",
      "source_url": "https://bitwarden.com/help/is-bitwarden-audited.md",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC's audit page lists a November 17, 2025 ANSSI Security Visa for KeePassXC 2.7.9 on Windows 10 and links a certification report, certificate, security target, and full technical report.",
      "fetch_event_id": "c27f565f-0828-512c-b4f6-44a90d370d78",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "ANSSI Security Visa (ANSSI-CSPN-2025/16)\n\n<dt>Date:</dt> <dd>November 17, 2025</dd> <dt>Valid Until:</dt> <dd>November 17, 2028</dd> <dt>Auditor:</dt> <dd>French National Cybersecurity Agency (ANSSI)</dd> <dt>KeePassXC Version:</dt> <dd><a href=\"https://github.com/keepassxreboot/keepassxc/releases/tag/2.7.9\">2.7.9 (Windows 10)</a></dd>\n\n<dt>Documents:</dt> <dd> <ul class=\"uk-list uk-list-collapse uk-list-disc\"> <li><a href=\"https://keepassxc.org/blog/2025-11-23-2.7.11-released/\">Blog Post</a></li> <li><a href=\"https://cyber.gouv.fr/offre-de-service/solutions-certifiees-et-qualifiees/services-de-securite-evalue/decouvrir-les-solutions-certifiees-qualifiees/\">ANSSI Certified Products Catalogue</a></li> <li><a href=\"https://messervices.cyber.gouv.fr/visas/ANSSI-CSPN-2025-16-rapport.pdf\">Certification Report (PDF, FR)</a></li> <li><a href=\"https://messervices.cyber.gouv.fr/visas/ANSSI-CSPN-2025-16-certificat.pdf\">Certificate (PDF, FR)</a></li> <li><a href=\"https://messervices.cyber.gouv.fr/visas/ANSSI-CSPN-2025-16-cible.pdf\">Security Target (PDF, EN)</a></li> <!-- <li><a href=\"https://keepassxc.org/assets/pdf/Cible-ANSSI-CSPN-2025-16en.pdf\">Security Target (PDF, EN)</a></li>--> <li><a href=\"https://keepassxc.org/assets/pdf/Synacktiv-ANSSI-CSPN-KeePassXC-RTE-v1.3.pdf\">Full Technical Report (PDF, EN)</a></li> </ul> </dd>",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "f078048d24f72caf22d3c759c73b60d8144aca6df58595a21dff0a7883014c91",
      "source_url": "https://keepassxc.org/audits/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.data_region_choice": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC says it stores passwords in an offline encrypted file that can be kept in any location, including private or public cloud storage, while no data is stored on remote servers.",
      "fetch_event_id": "be3703bd-3dbc-5000-beb5-c0f69248643a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your passwords remain encrypted at all times and no data is stored on remote servers, so you stay in full control of your data. No cloud, no ads, no subscriptions.\n\nWe do the heavy lifting in a no-nonsense, ad-free, tracker-free, and cloud-free manner. Free and open source.\n\nYou can run KeePassXC on Windows, macOS, and Linux systems. KeePassXC is for people with extremely high demands of secure personal data management. It saves many types of information, such as usernames, passwords, URLs, attachments, and notes in an offline, encrypted file that can be stored in any location, including private and public cloud solutions.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8622d73c6e63b60348fe7b9fcbad6f883f5dd7e4e052e075f24b2f1b5103a3f7",
      "source_url": "https://keepassxc.org/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC prompts the user to move a deleted entry to the Recycle Bin when it is enabled; with the Recycle Bin disabled, the entry is permanently removed, and an entry in the Recycle Bin can be permanently deleted with the Delete key.",
      "fetch_event_id": "ab989ebe-5cf8-5e63-897a-77a2e442c722",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Select the entry you want to delete and press the <kbd>Del</kbd> button on your keyboard.\n\nYou will be prompted to move the entry to the Recycle Bin (if enabled).\n\nIf the recycle bin is disabled then deleted entries will be permanently removed from the database.\n\nTo permanently delete the entry, navigate to the Recycle Bin, select the entry you want to delete and press the <kbd>Del</kbd> button on your keyboard.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "71b1fff44e55a91d7400e415c7f8bfb45ccd42ae646bdf851323379a36c554cf",
      "source_url": "https://keepassxc.org/docs/KeePassXC_GettingStarted",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.emergency_access": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Verified absence",
      "fetch_event_id": "be3703bd-3dbc-5000-beb5-c0f69248643a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your passwords remain encrypted at all times and no data is stored on remote servers, so you stay in full control of your data. No cloud, no ads, no subscriptions.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8622d73c6e63b60348fe7b9fcbad6f883f5dd7e4e052e075f24b2f1b5103a3f7",
      "source_url": "https://keepassxc.org/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.encrypted_export": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC says exports made for transfer, printing, or archiving store passwords and sensitive information in an unencrypted format, while its database file remains fully encrypted and can be backed up.",
      "fetch_event_id": "f6ff0b3d-31bf-5d98-881e-b3234043b30e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "KeePassXC supports multiple ways to export your database for transfer to another program or to print out and archive.\n\nThese exports do not contain all the information in your database due to various limitations in the export format. For example, the CSV export does not support attachments, advanced attributes, Auto-Type settings, or custom icons. The XML export does not support attachments. The HTML export is mainly for printing and does not support attachments and some custom data fields.\n\nExporting your database will result in all of your passwords and sensitive information being stored in an unencrypted format. We do not recommend saving your exported database for long periods of time as that can cause a compromise of sensitive information.\n\nThe HTML export file is intended to be human-readable (viewed/printed in a web browser) rather than machine-readable (re-imported into another database file). The intention of HTML export is to provide a \"paper backup\" functionality for those who want to ensure access to their passwords in case of catastrophic failure of IT infrastructure. To create a paper backup, export the database to an HTML file, print the file with your web browser, then delete the file.\n\nIn addition to these save options, KeePassXC can create a backup of your existing database file just prior to saving.\n\nAlternatively, backups can be created on-demand using the <em>Database</em> &#8594; <em>Save Database Backup&#8230;&#8203;</em> menu feature.\n\nClick Done. You will be prompted to select a location to save your database file. The database file is saved on to your computer with the default <code>.kdbx</code> extension. You can store your database wherever you wish, it is fully encrypted at all times preventing unauthorized access.\n\nYou can safely store your database file in the cloud (OneDrive, Dropbox, Google Drive, Nextcloud, Syncthing, etc.). The database file is always fully encrypted; unencrypted data is never written to disk and is never accessible to your cloud storage provider. We recommend using a storage service that keeps automatic backups (version history) of your database file in the event of corruption or accidental deletion.\n\nNavigate to the location of the database on your computer and open the database file. The database unlock screen will appear:",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dea7cb713f0dd255b6c4a3994eb956ddd22ba5cf0e4bed83ad2bab79fa0db068",
      "source_url": "https://keepassxc.org/docs/KeePassXC_UserGuide",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC says KeePassXC and KeePassXC-Browser run locally and do not send stored personal data to KeePassXC or a third party.",
      "fetch_event_id": "e7d29188-0894-58b2-b425-17d1df2ffd11",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "KeePassXC and KeePassXC-Browser are run locally on your computer. At no time will any of your stored personal data be sent to us or a third party. That's how it works. Period.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "f73b7eda63063b9f01e0b4180054e2c643fe469f702d2d103a0c7c485ff447d0",
      "source_url": "https://keepassxc.org/privacy/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.open_source_client_server": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "KeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING.",
      "fetch_event_id": "f9dd042d-046e-52ec-8f61-e814343ab106",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "## License\n\nKeePassXC code is licensed under GPL-2 or GPL-3. Additional licensing for third-party files is detailed in [COPYING](./COPYING).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "b2cc8a8c80f2fcd8f82d659ff7e063c7b33f84f4da460720a88f97a7a7d655c6",
      "source_url": "https://raw.githubusercontent.com/keepassxreboot/keepassxc/9e0f57a4a4c6c629fa6d0a593acb7d089b1d95cd/README.md",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Verified absence",
      "fetch_event_id": "d443be45-c5f8-53e4-9973-0e9110f08e56",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Legal Info / Impressum",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "c9300e495898e39e53025878fefbc52a6abc9de02ed7d0aeb9fc3bc8638ba842",
      "source_url": "https://keepassxc.org/team/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.passkey_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC supports passkeys through the KeePassXC Browser Extension with a connected database; passkeys can be stored, viewed, imported, and exported, but exported .passkey files are unencrypted.",
      "fetch_event_id": "f6ff0b3d-31bf-5d98-881e-b3234043b30e",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Passkeys are only supported with the use of the KeePassXC Browser Extension and a properly connected database.\n\nAfter the passkey has been registered, a new entry is created to the database under <em>KeePassXC-Browser Passwords</em> with <em>(passkey)</em> added to the entry title. The entry holds additional attributes that are used for authenticating the passkey.\n\nAll passkeys in a database can be viewed and accessed from the <em>Database</em> &#8594; <em>Passkeys&#8230;&#8203;</em> menu item. The page shows both <em>Import</em> and <em>Export</em> buttons for passkeys.\n\nAfter selecting one or more entries, the following dialog is shown. One or multiple passkeys can be selected for export from the previously selected list of entries.\n\nExported passkeys are stored in JSON format using the <code>.passkey</code> file extension. The file includes all relevant information for importing a passkey to another database or saving a backup.\n\nThe exported passkey file is unencrypted and should be securely stored.\n\nAn exported passkey can be imported directly to a database or to an entry. To import directly, use the <em>Database</em> &#8594; <em>Import Passkey</em> menu item. When right-clicking an entry, a separate menu item for <em>Import Passkey</em> is shown. This is useful if user wants to import a previously created passkey to an existing entry.\n\nAfter selecting a passkey file to import, a separate dialog is shown where you can select which database, group, and entry to target.\n\nClick Done. You will be prompted to select a location to save your database file. The database file is saved on to your computer with the default <code>.kdbx</code> extension. You can store your database wherever you wish, it is fully encrypted at all times preventing unauthorized access.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "dea7cb713f0dd255b6c4a3994eb956ddd22ba5cf0e4bed83ad2bab79fa0db068",
      "source_url": "https://keepassxc.org/docs/KeePassXC_UserGuide",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Verified absence",
      "fetch_event_id": "e7d29188-0894-58b2-b425-17d1df2ffd11",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "KeePassXC and KeePassXC-Browser are run locally on your computer. At no time will any of your stored personal data be sent to us or a third party. That's how it works. Period.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "f73b7eda63063b9f01e0b4180054e2c643fe469f702d2d103a0c7c485ff447d0",
      "source_url": "https://keepassxc.org/privacy/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC says its website deletes visitor logs after 90 days and detailed reports after 12 months, retaining only basic trend metrics after that.",
      "fetch_event_id": "e7d29188-0894-58b2-b425-17d1df2ffd11",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "When you visit our website, we collect the following data:\n\nYour anonymized IP address (we store only the first 2 byte for IPv4 and the first 6 byte for IPv6)\n\nAll collected data is used for statistical purposes only, does not allow personal identification and is not shared with any third parties. Statistics are generated using a self-hosted <a href=\"https://matomo.org/\" target=\"_blank\">Matomo</a> installation.\n\nVisitor logs are deleted after 90 days and detailed reports after 12 months. Only basic trend metrics are kept after this time.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "f73b7eda63063b9f01e0b4180054e2c643fe469f702d2d103a0c7c485ff447d0",
      "source_url": "https://keepassxc.org/privacy/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.separate_app_totp": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC calculates TOTP codes from a secret stored on a database entry and lets users copy, auto-type, or enter those codes through the browser extension; the secret and configuration can also be viewed as a QR code for export to a mobile device.",
      "fetch_event_id": "ab989ebe-5cf8-5e63-897a-77a2e442c722",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Timed One-Time Passwords (TOTP) are a popular choice for two-factor authentication methods. These codes are typically six digits long and change every 30 seconds. They are derived from a shared secret value and the current time. Once set up, KeePassXC can calculate TOTP codes like any authenticator app, such as Google Authenticator. The codes can be used with copy/paste, browser extension, and Auto-Type.\n\nTo add TOTP to a database entry, you must first retrieve the secret string from the website or application you are authenticating to. Often this secret is accompanied with a QR code and can be copy/pasted below. Example:\n\nOnce obtained, right-click the desired entry <strong>(1)</strong>, choose <em>TOTP</em> &#8594; <em>Set up TOTP&#8230;&#8203;</em> <strong>(2)</strong>, and the setup dialog will appear. In that dialog, paste the secret code from the website <strong>(3)</strong>, setup any custom settings (rare) <strong>(4)</strong>, then press OK to save the settings.\n\nAfter an entry is configured with TOTP, you will see a clock icon in that entry&#8217;s row and have the ability to reveal the current code in the preview pane. Additionally, you can navigate to the entry&#8217;s <em>TOTP</em> menu to show the code in a separate window. You can also view the secret and configuration as a QR code for exporting to a mobile device. TOTP codes can be entered into forms with the browser extension, with Auto-Type by using the <code>{TOTP}</code> placeholder, or via menu options in the Auto-Type selection dialog.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "71b1fff44e55a91d7400e415c7f8bfb45ccd42ae646bdf851323379a36c554cf",
      "source_url": "https://keepassxc.org/docs/KeePassXC_GettingStarted",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC is free and open source, runs on Windows, macOS, and Linux, and stores information in an offline encrypted file.",
      "fetch_event_id": "be3703bd-3dbc-5000-beb5-c0f69248643a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your passwords remain encrypted at all times and no data is stored on remote servers, so you stay in full control of your data. No cloud, no ads, no subscriptions.\n\nWe do the heavy lifting in a no-nonsense, ad-free, tracker-free, and cloud-free manner. Free and open source.\n\nYou can run KeePassXC on Windows, macOS, and Linux systems. KeePassXC is for people with extremely high demands of secure personal data management. It saves many types of information, such as usernames, passwords, URLs, attachments, and notes in an offline, encrypted file that can be stored in any location, including private and public cloud solutions.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8622d73c6e63b60348fe7b9fcbad6f883f5dd7e4e052e075f24b2f1b5103a3f7",
      "source_url": "https://keepassxc.org/",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "public_record",
      "display": "KeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING.",
      "fetch_event_id": "f9dd042d-046e-52ec-8f61-e814343ab106",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "## License\n\nKeePassXC code is licensed under GPL-2 or GPL-3. Additional licensing for third-party files is detailed in [COPYING](./COPYING).",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S4",
      "source_sha256": "b2cc8a8c80f2fcd8f82d659ff7e063c7b33f84f4da460720a88f97a7a7d655c6",
      "source_url": "https://raw.githubusercontent.com/keepassxreboot/keepassxc/9e0f57a4a4c6c629fa6d0a593acb7d089b1d95cd/README.md",
      "table": "vendor"
    },
    "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "KeePassXC says passwords remain encrypted at all times, no data is stored on remote servers, and users stay in control of their data.",
      "fetch_event_id": "be3703bd-3dbc-5000-beb5-c0f69248643a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Your passwords remain encrypted at all times and no data is stored on remote servers, so you stay in full control of your data. No cloud, no ads, no subscriptions.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "8622d73c6e63b60348fe7b9fcbad6f883f5dd7e4e052e075f24b2f1b5103a3f7",
      "source_url": "https://keepassxc.org/",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.audit_report": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass says Cure53 audited its code throughout May and June 2023, testing all Proton Pass mobile apps, browser extensions, and its API, and links the audit report.",
      "fetch_event_id": "a94288cd-c4e1-5b5d-9f1b-1d17466cde9d",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Proton Pass’s code underwent a security audit by the German security firm Cure53 (new window) throughout May and June. We selected Cure53 to handle the Proton Pass audit because we wanted to ensure that Proton Pass received the most rigorous testing possible, and Cure53 has extensive experience investigating browser extensions and password managers. They tested all Proton Pass mobile apps, browser extensions, and our API.\n\nPublished on July 19, 2023\n\nYou can read the Proton Pass audit report (new window) for yourself. You can also find the audit reports for all Proton services .",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "99c2ad372344e3440c8ac45f616eb9d66071ac6ac5b9448befa974308bccd140",
      "source_url": "https://proton.me/blog/pass-open-source-security-audit",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.data_region_choice": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass says data is stored encrypted on servers exclusively in Switzerland, Germany, or Norway, while some hide-my-email functionality is hosted on contracted European cloud servers through SimpleLogin SAS.",
      "fetch_event_id": "43dcb841-ad88-51f9-ab8e-1a11928f0593",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Data is always stored in encrypted format on our servers, which are exclusively located in Switzerland, Germany or Norway, under the protection of some of the world's strongest privacy laws.\n\nIf you use hide-my-email aliases provided by Proton Pass, some of that functionality is hosted on European cloud servers contracted through Proton's wholly-owned subsidiary SimpleLogin SAS, and not on infrastructure that is owned by Proton itself.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "34eafffd3d11f96e51d0134334b1cd0d33d85f99ee703af08576a93396669494",
      "source_url": "https://proton.me/pass/privacy-policy",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.deletion": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton says deleting a Proton Account permanently deletes the account and all its data from its systems, including Proton Pass, and prevents the username from being reused.",
      "fetch_event_id": "56f973eb-0d7f-58cc-b96a-95ca7998d269",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "When you delete your Proton Account, there is no way to recover it. Your account and all its data will be permanently deleted from our systems.\n\nYour account will be deleted from Proton Mail, Proton Calendar, Proton VPN, Proton Pass, Proton Drive, and any other Proton services you use.\n\nIf you delete your account, your username can’t be used by someone else, or for any new accounts you create in the future.\n\n1. Sign in to your account at account.proton.me . Go to Settings → All settings . 2. Select Account and password from the sidebar. Scroll to Delete account , then click the Delete your account button.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2eb2182b71483e01a6effb9e019e549e9892f6439eec0dac5bb47719a40bd19e",
      "source_url": "https://proton.me/support/delete-account",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.emergency_access": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton lets paid-plan users choose up to five Proton Mail contacts for emergency access, with requests automatically granted after a user-selected wait of 1, 2, 3, 7, 14, or 30 days unless approved or denied earlier.",
      "fetch_event_id": "ca5ab2a9-b91d-568b-8472-2cf0fa2dfa7b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Proton’s Emergency Access feature lets you choose up to five emergency contacts who can gain access to your account in the event of illness, death, or another emergency that stops you from accessing your account.\n\nEmergency Access is available on all paid Proton plans . Both you and your contact must have a Proton Mail email address .\n\nWhen you add an emergency contact in your account settings, you set a waiting period. In an emergency, your contact can request access to your account, and their request is automatically granted at the end of the waiting period.\n\nThis is how long they must wait before access is granted automatically if you don’t approve the request manually.\n\nThe waiting period ensures that nobody can access your account without your permission. We notify you whenever a request is made, so you can deny the request if it’s not a real emergency.\n\nWait time options: 30 days, 14 days, 7 days, 3 days, 2 days, 1 day.\n\nThis will immediately remove them as an emergency contact.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "a5777425851f68cf52a4343bd888470fc80b417111284d50f0b646cbb42919d4",
      "source_url": "https://proton.me/support/emergency-access",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.encrypted_export": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass exports a PGP-encrypted JSON file inside a ZIP from its browser extensions, web app, and Windows app, not its mobile apps, and lets users import that encrypted ZIP directly into Proton Pass.",
      "fetch_event_id": "b7087cbc-e273-5a90-9593-bf95005ef98b",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "You have three options for export: A ZIP file containing a PGP-encrypted JSON file An unencrypted ZIP file A CSV file\n\nYou can export your data from Proton Pass via our browser extensions, web app, and Windows app. Just access the settings menu by clicking or tapping on the gear icon . You cannot export data using the Proton Pass mobile apps.\n\nIf you choose to encrypt your file, you must select a memorable passphrase and enter it in the passphrase field.\n\nYou can import a PGP-encrypted ZIP file directly into Proton Pass (see below). ",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "00856efe70f0094122c4c512a3c2b51b1086473321dfcb03d4c0227c2e8a4d14",
      "source_url": "https://proton.me/support/pass-export",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton may request Proton Captcha, email, or SMS verification for some sensitive operations in addition to account creation and says IP addresses, email addresses, and phone numbers are saved temporarily, or only as a cryptographic hash if saved permanently.",
      "fetch_event_id": "9a4e3aac-73c1-5242-bd89-f912f0b89c0a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Verification may also be requested for some sensitive operations besides account creation in order to protect against brute-force attacks. You may be asked to verify using either Proton Captcha, email, or SMS.\n\nIP addresses, email addresses, and phone numbers provided are saved temporarily in order to send you a verification code and for anti-spam purposes. The period of temporary data retention is determined by our legitimate interests of protecting the service from spam, and also by any applicable Swiss legal requirements we must comply with. If this data is saved permanently, it is always saved as a cryptographic hash, which ensures that the raw values cannot be deciphered by us.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.open_source_client_server": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton says all Proton Pass apps are open source and can be independently reviewed by anyone.",
      "fetch_event_id": "e264e0d9-cb6b-5a4e-9230-bad85edab91f",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All Proton Pass apps are open source (new window) and can be independently reviewed by anyone.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "2fd33a3166f94664de138e6da6cfba55e46e84b1a25cadef91e271994a7fe887",
      "source_url": "https://proton.me/pass/security",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
      "fetch_event_id": "9a4e3aac-73c1-5242-bd89-f912f0b89c0a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The Services are operated by Proton AG (the “Company”, “We”), domiciled at Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland. It is therefore governed by the laws and regulations of Switzerland.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.passkey_support": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass's passkey page is headed \"Store, share and export passkeys\" and says passkeys are supported in its browser extension and on Android and iOS devices, that Android supports passkeys only from Android 14, and that users cannot currently log into Proton Pass apps using passkeys.",
      "fetch_event_id": "f411c94e-7c02-542f-8c1e-7d5b2b229621",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Store, share and export passkeys\n\nPasskeys are a simple and secure cross device authentication technology that enables you to create and sign into accounts without passwords.\n\nNo, currently, you can’t log into Proton Pass apps using passkeys, but with passwords or passphrases, or via biometrics.\n\nPasskeys are supported in our browser extension and on Android and iOS devices. Android only supports passkeys from Android 14, earlier versions of Androids do not support passkeys. Additionally, certain smartphone makers, such as OnePlus and Oppo, haven’t added support for passkeys to their devices. Samsung smartphones have a known issue where they display a gray square instead of Proton Pass.\n\nPasskeys allow you to authenticate yourself for online accounts without using passwords or passphrases. Currently, passkeys are supported in our browser extension and on Android and iOS devices in any Proton Pass plan.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "446787b88685e65bd1481ebe4b066c8a0301b5fa9ab1989932da607d34874694",
      "source_url": "https://proton.me/pass/passkeys",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.request_reporting": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Not disclosed in the captured primary source.",
      "fetch_event_id": "793dba11-2c4b-5ee9-b3ca-30d3f092a8c9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Aggregate statistics of legal orders that we have received for Proton Mail can be found below:",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "69850e516d92678e8f948b8b68f599177bf4a081ffea7f20cee6bc6eae3194b2",
      "source_url": "https://proton.me/legal/transparency",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.retention": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass says alias addresses created in Proton Pass are not encrypted so alias forwarding can function and are retained for as long as the user does not delete them.",
      "fetch_event_id": "43dcb841-ad88-51f9-ab8e-1a11928f0593",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "In order for the alias forwarding option to function properly, alias addresses created in Proton Pass are not encrypted. These aliases are retained for as long as you don't delete them.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "34eafffd3d11f96e51d0134334b1cd0d33d85f99ee703af08576a93396669494",
      "source_url": "https://proton.me/pass/privacy-policy",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.separate_app_totp": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass generates TOTP codes for saved website login items without requiring a separate authenticator app and documents setup through its browser extension, Android app, and iPhone and iPad app.",
      "fetch_event_id": "3c54f684-ebd4-5311-84a7-9612fca013ef",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Proton Pass makes it convenient to use 2FA in this way. Instead of requiring a separate authenticator app , Proton Pass can securely generate TOTP codes for websites that you have saved login details for. Note that Proton Pass 2FA is a premium feature.\n\nHow to configure 2FA using the browser extension How to configure 2FA using the Android app How to configure 2FA using the iPhone and iPad app\n\nInstead of scanning a QR code, select the enter key manually option and copy the numerical key provided .\n\nYou can also configure 2FA codes manually on Android. To do this, tap Paste code instead of Scan code and paste in or enter a 2FA key as described for configuring the browser extension above. ",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "6f916ab495af6effdf726069dfaefc9471bd54c1692acb4005820b3d59ebc422",
      "source_url": "https://proton.me/support/pass-2fa",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.signup_identifiers": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton Pass can be used with a Proton Mail address or an external non-Proton address, which serves as the account identifier.",
      "fetch_event_id": "9a4e3aac-73c1-5242-bd89-f912f0b89c0a",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "Depending on the Services you want to use, you can either create a Proton account with a Proton Mail address, or use an external (non-Proton) address. \n\nYou also have the possibility to use our Proton VPN, Drive and Pass services with an external address. In this case, you have to provide your external address, which will be used as your account identifier.\n\nCreating a Proton account will give you access to all our Services.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "68ea40a13d44b83d72e62eb4fa5c1a6bd510c3c9f0a5cba5d5ea96504fa030ee",
      "source_url": "https://proton.me/legal/privacy",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.source_availability": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton says all Proton apps are open source and have been independently audited and verified by third-party experts.",
      "fetch_event_id": "c8ec0f44-d6ef-5eaf-b742-5dc78975e7d1",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "All Proton apps are open source and have been independently audited and verified by third-party experts. Anyone can see and verify that our apps do what we claim.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "0cdff84fe9ca60988df03e874ecbc8ede01bb249748b4e643658b817f3beb66c",
      "source_url": "https://proton.me/community/open-source",
      "table": "vendor"
    },
    "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit": {
      "additional_sources": null,
      "capture_date": "2026-10-06",
      "claim_type": "vendor_stated",
      "display": "Proton says Proton Pass performs key generation and data encryption locally, its servers never have access to unencrypted keys, data, or credentials, and all fields receive end-to-end encryption, including usernames, web addresses, and notes.",
      "fetch_event_id": "7ae65ea9-43d1-5704-a396-88d71b2d98c9",
      "pinpoint": null,
      "public_reason": null,
      "publish_status": "publish_ready",
      "quote": "The design of Proton Pass uses end-to-end encryption, guaranteeing that all cryptographic operations, including key generation and data encryption, are performed locally on your device. This means that your unencrypted data cannot be accessed by Proton or shared with any third parties. Proton servers never have access to your unencrypted keys, data, or credentials, including your Proton Account password.\n\nProton Pass doesn’t just encrypt the password field but applies end-to-end encryption to all fields, including usernames, web addresses, and all data contained in the encrypted notes section.",
      "readiness": "ready",
      "reason_code": null,
      "rendered": "value",
      "snapshot_path": null,
      "snapshot_resolved": false,
      "source_class": "S5",
      "source_sha256": "d90adf1c1242be1157793283bbbe09ba4c9dfdc13ebff4512b130deb01e671b0",
      "source_url": "https://proton.me/blog/proton-pass-security-model",
      "table": "vendor"
    }
  },
  "class": "MAGNET",
  "content_file_sha256": "6e510cd1aa1fa886278fb39bdb756b41d12d0aad5e1c6c6d3fc1c02e2bb0117b",
  "figure_slots": [],
  "generator": "page-generator/1",
  "held": {
    "cells": [],
    "counts": {
      "gap": 0,
      "no_quote": 0,
      "unconfirmed": 0,
      "unresolved": 0
    },
    "is_held": false
  },
  "last_updated": "2026-10-06",
  "route": "/privacy-tools/password-manager-authenticator-comparison/",
  "schema": "pp-page-sources.v1",
  "tables": {
    "architecture-and-evidence": {
      "field_definitions": {
        "audit_report": "Assessor, scope, standard, period or date, report locator, publication status, and limitations stated by the cell.",
        "open_source_client_server": "Documented client scope, server scope, repository or artifact, license, release context, and limitations stated by the cell.",
        "source_availability": "Named component, repository or artifact locator, version or release locator, license, scope, and limitations stated by the cell.",
        "zero_knowledge_claim_and_audit": "Architecture claim, named data or key material, limitations, audit relationship, scope, and source type stated by the cell."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:architecture-and-evidence",
      "rows": [
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://support.1password.com/security-assessments/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "1Password says Independent Security Evaluators (ISE) performed a penetration test and code review of the 1Password system during April and June 2020, with full details available in the ISE security assessment report."
            },
            "open_source_client_server": {
              "cell_citation_url": "https://api.github.com/orgs/1Password/repos?per_page=100&type=public",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.open_source_client_server",
              "publish_status": "publish_ready",
              "source_field": "open_source_client_server",
              "value": "1Password's repository listing describes Go functions for the Secure Remote Password protocol in 1Password Teams and a client library for desktop-app integrations over IPC."
            },
            "source_availability": {
              "cell_citation_url": "https://api.github.com/orgs/1Password/repos?per_page=100&type=public",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "1Password's srp repository contains Go functions for the Secure Remote Password protocol in 1Password Teams and lists Apache-2.0, master, and a September 2, 2026 timestamp."
            },
            "zero_knowledge_claim_and_audit": {
              "cell_citation_url": "https://support.1password.com/1password-security/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit",
              "publish_status": "publish_ready",
              "source_field": "zero_knowledge_claim_and_audit",
              "value": "1Password says everything in a 1Password account is always end-to-end encrypted, with the keys held only by the user, making it impossible to learn anything by intercepting the data in transit or obtaining it from AgileBits."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "architecture-and-evidence-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://bitwarden.com/assets/4nGworevQqsF1ZStDgiyQg/35f7c3e8acf2badb9bd85cb9ddab1d8f/Bitwarden_-_2026_SOC_3_Report.pdf",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "AuditOne LLP's report examines Bitwarden Inc.'s management assertion that controls within its Password Management System were effective from July 1, 2025, to June 30, 2026, against security and confidentiality trust-services criteria."
            },
            "open_source_client_server": {
              "cell_citation_url": "https://raw.githubusercontent.com/bitwarden/clients/main/README.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.open_source_client_server",
              "publish_status": "publish_ready",
              "source_field": "open_source_client_server",
              "value": "Bitwarden's clients repository houses its non-mobile client applications and links separate repositories for the server, iOS apps, and Android apps."
            },
            "source_availability": {
              "cell_citation_url": "https://raw.githubusercontent.com/bitwarden/clients/main/LICENSE.txt",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Bitwarden's clients repository uses GPL v3.0 by default, while code in its /bitwarden_license directory uses the Bitwarden License v1.0."
            },
            "zero_knowledge_claim_and_audit": {
              "cell_citation_url": "https://bitwarden.com/help/is-bitwarden-audited.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit",
              "publish_status": "publish_ready",
              "source_field": "zero_knowledge_claim_and_audit",
              "value": "Bitwarden says every piece of vault information is encrypted under its zero-knowledge approach and says ETH Zurich's Applied Cryptography Group audited its core cryptography operations under a fully malicious-server assumption."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "architecture-and-evidence-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://keepassxc.org/audits/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "KeePassXC's audit page lists a November 17, 2025 ANSSI Security Visa for KeePassXC 2.7.9 on Windows 10 and links a certification report, certificate, security target, and full technical report."
            },
            "open_source_client_server": {
              "cell_citation_url": "https://raw.githubusercontent.com/keepassxreboot/keepassxc/9e0f57a4a4c6c629fa6d0a593acb7d089b1d95cd/README.md",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.open_source_client_server",
              "publish_status": "publish_ready",
              "source_field": "open_source_client_server",
              "value": "KeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING."
            },
            "source_availability": {
              "cell_citation_url": "https://raw.githubusercontent.com/keepassxreboot/keepassxc/9e0f57a4a4c6c629fa6d0a593acb7d089b1d95cd/README.md",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "KeePassXC says its code is licensed under GPL-2 or GPL-3, with additional licensing for third-party files detailed in COPYING."
            },
            "zero_knowledge_claim_and_audit": {
              "cell_citation_url": "https://keepassxc.org/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit",
              "publish_status": "publish_ready",
              "source_field": "zero_knowledge_claim_and_audit",
              "value": "KeePassXC says passwords remain encrypted at all times, no data is stored on remote servers, and users stay in control of their data."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "architecture-and-evidence-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "audit_report": {
              "cell_citation_url": "https://proton.me/blog/pass-open-source-security-audit",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.audit_report",
              "publish_status": "publish_ready",
              "source_field": "audit_report",
              "value": "Proton Pass says Cure53 audited its code throughout May and June 2023, testing all Proton Pass mobile apps, browser extensions, and its API, and links the audit report."
            },
            "open_source_client_server": {
              "cell_citation_url": "https://proton.me/pass/security",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.open_source_client_server",
              "publish_status": "publish_ready",
              "source_field": "open_source_client_server",
              "value": "Proton says all Proton Pass apps are open source and can be independently reviewed by anyone."
            },
            "source_availability": {
              "cell_citation_url": "https://proton.me/community/open-source",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.source_availability",
              "publish_status": "publish_ready",
              "source_field": "source_availability",
              "value": "Proton says all Proton apps are open source and have been independently audited and verified by third-party experts."
            },
            "zero_knowledge_claim_and_audit": {
              "cell_citation_url": "https://proton.me/blog/proton-pass-security-model",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.zero_knowledge_claim_and_audit",
              "publish_status": "publish_ready",
              "source_field": "zero_knowledge_claim_and_audit",
              "value": "Proton says Proton Pass performs key generation and data encryption locally, its servers never have access to unencrypted keys, data, or credentials, and all fields receive end-to-end encryption, including usernames, web addresses, and notes."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "architecture-and-evidence-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    },
    "export-and-recovery": {
      "field_definitions": {
        "emergency_access": "Designated actor, trigger, waiting or approval process, access scope, revocation, plan, and limitations stated by the cell.",
        "encrypted_export": "Artifact, format, protection, creation and restore paths, plan, platform, scope, and limitations stated by the cell."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:export-and-recovery",
      "rows": [
        {
          "cells": {
            "emergency_access": {
              "cell_citation_url": "https://support.1password.com/recovery/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.emergency_access",
              "publish_status": "publish_ready",
              "source_field": "emergency_access",
              "value": "1Password lets a family organizer, team administrator or owner, or a member of a custom group with Recover Accounts permission restore access for a family or team member who cannot sign in or unlock 1Password."
            },
            "encrypted_export": {
              "cell_citation_url": "https://support.1password.com/export/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.encrypted_export",
              "publish_status": "publish_ready",
              "source_field": "encrypted_export",
              "value": "1Password says its exported data files are unencrypted plaintext readable by anyone with access; 1Password 8 exports .1pux or CSV files, and passkeys can currently be exported only on iOS and Android."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "export-and-recovery-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "emergency_access": {
              "cell_citation_url": "https://bitwarden.com/help/emergency-access.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.emergency_access",
              "publish_status": "publish_ready",
              "source_field": "emergency_access",
              "value": "Bitwarden lets premium users appoint same-server account holders as trusted emergency contacts with view or takeover access, subject to account-holder approval or expiry of a wait time."
            },
            "encrypted_export": {
              "cell_citation_url": "https://bitwarden.com/help/encrypted-export.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.encrypted_export",
              "publish_status": "publish_ready",
              "source_field": "encrypted_export",
              "value": "Bitwarden offers account-restricted and password-protected encrypted JSON exports for individuals and organizations, with password-protected files importable to any Bitwarden account."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "export-and-recovery-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "emergency_access": {
              "cell_citation_url": "https://keepassxc.org/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.emergency_access",
              "publish_status": "publish_ready",
              "source_field": "emergency_access",
              "value": "Verified absence"
            },
            "encrypted_export": {
              "cell_citation_url": "https://keepassxc.org/docs/KeePassXC_UserGuide",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.encrypted_export",
              "publish_status": "publish_ready",
              "source_field": "encrypted_export",
              "value": "KeePassXC says exports made for transfer, printing, or archiving store passwords and sensitive information in an unencrypted format, while its database file remains fully encrypted and can be backed up."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "export-and-recovery-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "emergency_access": {
              "cell_citation_url": "https://proton.me/support/emergency-access",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.emergency_access",
              "publish_status": "publish_ready",
              "source_field": "emergency_access",
              "value": "Proton lets paid-plan users choose up to five Proton Mail contacts for emergency access, with requests automatically granted after a user-selected wait of 1, 2, 3, 7, 14, or 30 days unless approved or denied earlier."
            },
            "encrypted_export": {
              "cell_citation_url": "https://proton.me/support/pass-export",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.encrypted_export",
              "publish_status": "publish_ready",
              "source_field": "encrypted_export",
              "value": "Proton Pass exports a PGP-encrypted JSON file inside a ZIP from its browser extensions, web app, and Windows app, not its mobile apps, and lets users import that encrypted ZIP directly into Proton Pass."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "export-and-recovery-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    },
    "identity-and-verification": {
      "field_definitions": {
        "later_verification_triggers": "A later trigger, requested identifier, requesting actor, and scope stated by the current cell.",
        "signup_identifiers": "Identifiers, requiredness, collecting actor, plan, region, platform, and scope stated for signup or initial use."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:identity-and-verification",
      "rows": [
        {
          "cells": {
            "later_verification_triggers": {
              "cell_citation_url": "https://1password.com/legal/privacy/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "1Password says it may ask a requester to verify their identity to help it respond securely and efficiently."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://support.1password.com/explore/get-started/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "1Password says account confirmation uses an email and is followed by choosing a strong account password to unlock 1Password."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "identity-and-verification-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "later_verification_triggers": {
              "cell_citation_url": "https://bitwarden.com/privacy.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Bitwarden may request additional information to verify a California privacy-rights requester who has no account or whose account may be compromised, matching it against existing records."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://bitwarden.com/terms.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Bitwarden requires a valid email address to complete signup and says other requested information is optional unless the user represents a legal entity or chooses a paid account requiring billing information."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "identity-and-verification-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "later_verification_triggers": {
              "cell_citation_url": "https://keepassxc.org/privacy/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "KeePassXC says KeePassXC and KeePassXC-Browser run locally and do not send stored personal data to KeePassXC or a third party."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://keepassxc.org/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "KeePassXC is free and open source, runs on Windows, macOS, and Linux, and stores information in an offline encrypted file."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "identity-and-verification-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "later_verification_triggers": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.later_verification_triggers",
              "publish_status": "publish_ready",
              "source_field": "later_verification_triggers",
              "value": "Proton may request Proton Captcha, email, or SMS verification for some sensitive operations in addition to account creation and says IP addresses, email addresses, and phone numbers are saved temporarily, or only as a cryptographic hash if saved permanently."
            },
            "signup_identifiers": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.signup_identifiers",
              "publish_status": "publish_ready",
              "source_field": "signup_identifiers",
              "value": "Proton Pass can be used with a Proton Mail address or an external non-Proton address, which serves as the account identifier."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "identity-and-verification-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    },
    "operation-and-data-lifecycle": {
      "field_definitions": {
        "data_region_choice": "Documented storage or processing region, choice mechanism, eligibility, plan, and scope stated by the cell.",
        "deletion": "Deletion initiation, controller, completion statement, timeframe, exceptions, and scope stated by the cell.",
        "operating_entity": "The legal operating entity and jurisdictional details stated by the current cell.",
        "retention": "Data category, controller, trigger, duration, exceptions, and scope stated by the captured source."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:operation-and-data-lifecycle",
      "rows": [
        {
          "cells": {
            "data_region_choice": {
              "cell_citation_url": "https://support.1password.com/regions/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.data_region_choice",
              "publish_status": "publish_ready",
              "source_field": "data_region_choice",
              "value": "1Password lets an account be created in the United States, Canada, or European Union region; data stays in the chosen region, and changing regions requires a new account."
            },
            "deletion": {
              "cell_citation_url": "https://support.1password.com/delete-account/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "1Password says deleting an account starts deletion of all information from its service, with permanent deletion after 30 days; some individual account holders, family organizers, or team owners may be able to restore it through Support within that period."
            },
            "operating_entity": {
              "cell_citation_url": "https://1password.com/legal/privacy/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario."
            },
            "retention": {
              "cell_citation_url": "https://1password.com/legal/privacy/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "1Password says it retains personal information as long as necessary for the stated purposes unless law requires or permits longer retention or the person instructs deletion; updated, modified, or deleted information may remain for a period or as business records."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "operation-and-data-lifecycle-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "data_region_choice": {
              "cell_citation_url": "https://bitwarden.com/help/server-geographies.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.data_region_choice",
              "publish_status": "publish_ready",
              "source_field": "data_region_choice",
              "value": "Bitwarden stores cloud data in United States and European Union regions, lets users select a region at login or registration, and says it cannot migrate customer accounts between regions."
            },
            "deletion": {
              "cell_citation_url": "https://bitwarden.com/terms.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Bitwarden says cancelling an account purges all information from its databases and makes that information unrecoverable, with account deletion available from web-vault settings."
            },
            "operating_entity": {
              "cell_citation_url": "https://bitwarden.com/terms.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise."
            },
            "retention": {
              "cell_citation_url": "https://bitwarden.com/privacy.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Bitwarden says it retains Administrative Data for as long as a person remains a customer and as required by law, then deletes personal information under its retention policies after termination."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "operation-and-data-lifecycle-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "data_region_choice": {
              "cell_citation_url": "https://keepassxc.org/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.data_region_choice",
              "publish_status": "publish_ready",
              "source_field": "data_region_choice",
              "value": "KeePassXC says it stores passwords in an offline encrypted file that can be kept in any location, including private or public cloud storage, while no data is stored on remote servers."
            },
            "deletion": {
              "cell_citation_url": "https://keepassxc.org/docs/KeePassXC_GettingStarted",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "KeePassXC prompts the user to move a deleted entry to the Recycle Bin when it is enabled; with the Recycle Bin disabled, the entry is permanently removed, and an entry in the Recycle Bin can be permanently deleted with the Delete key."
            },
            "operating_entity": {
              "cell_citation_url": "https://keepassxc.org/team/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Verified absence"
            },
            "retention": {
              "cell_citation_url": "https://keepassxc.org/privacy/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "KeePassXC says its website deletes visitor logs after 90 days and detailed reports after 12 months, retaining only basic trend metrics after that."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "operation-and-data-lifecycle-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "data_region_choice": {
              "cell_citation_url": "https://proton.me/pass/privacy-policy",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.data_region_choice",
              "publish_status": "publish_ready",
              "source_field": "data_region_choice",
              "value": "Proton Pass says data is stored encrypted on servers exclusively in Switzerland, Germany, or Norway, while some hide-my-email functionality is hosted on contracted European cloud servers through SimpleLogin SAS."
            },
            "deletion": {
              "cell_citation_url": "https://proton.me/support/delete-account",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.deletion",
              "publish_status": "publish_ready",
              "source_field": "deletion",
              "value": "Proton says deleting a Proton Account permanently deletes the account and all its data from its systems, including Proton Pass, and prevents the username from being reused."
            },
            "operating_entity": {
              "cell_citation_url": "https://proton.me/legal/privacy",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
              "publish_status": "publish_ready",
              "source_field": "operating_entity",
              "value": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations."
            },
            "retention": {
              "cell_citation_url": "https://proton.me/pass/privacy-policy",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.retention",
              "publish_status": "publish_ready",
              "source_field": "retention",
              "value": "Proton Pass says alias addresses created in Proton Pass are not encrypted so alias forwarding can function and are retained for as long as the user does not delete them."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "operation-and-data-lifecycle-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    },
    "passkeys-and-totp": {
      "field_definitions": {
        "passkey_support": "Documented passkey role, storage or synchronization statement, platform, plan, scope, and limitations stated by the cell.",
        "separate_app_totp": "Whether TOTP is documented inside the vault, in a separate app, or in a companion context, with plan and platform scope."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:passkeys-and-totp",
      "rows": [
        {
          "cells": {
            "passkey_support": {
              "cell_citation_url": "https://support.1password.com/save-use-passkeys/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.passkey_support",
              "publish_status": "publish_ready",
              "source_field": "passkey_support",
              "value": "1Password supports saving passkeys and using them to sign in through a browser; Business administrators can control whether team members may save or use browser passkeys."
            },
            "separate_app_totp": {
              "cell_citation_url": "https://support.1password.com/one-time-passwords/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.separate_app_totp",
              "publish_status": "publish_ready",
              "source_field": "separate_app_totp",
              "value": "1Password lets users save and access one-time passwords through its browser extension, apps, or 1Password.com for websites using two-step verification."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "passkeys-and-totp-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "passkey_support": {
              "cell_citation_url": "https://bitwarden.com/help/storing-passkeys.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.passkey_support",
              "publish_status": "publish_ready",
              "source_field": "passkey_support",
              "value": "Bitwarden supports saving and autofilling encrypted passkeys through its browser extension and mobile apps, including iOS 17.0+ and Android 14.0+."
            },
            "separate_app_totp": {
              "cell_citation_url": "https://bitwarden.com/help/bitwarden-authenticator.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.separate_app_totp",
              "publish_status": "publish_ready",
              "source_field": "separate_app_totp",
              "value": "Bitwarden offers a standalone Authenticator app on iOS and Android as well as a distinct Password Manager authenticator, and says codes can synchronize between the two apps."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "passkeys-and-totp-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "passkey_support": {
              "cell_citation_url": "https://keepassxc.org/docs/KeePassXC_UserGuide",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.passkey_support",
              "publish_status": "publish_ready",
              "source_field": "passkey_support",
              "value": "KeePassXC supports passkeys through the KeePassXC Browser Extension with a connected database; passkeys can be stored, viewed, imported, and exported, but exported .passkey files are unencrypted."
            },
            "separate_app_totp": {
              "cell_citation_url": "https://keepassxc.org/docs/KeePassXC_GettingStarted",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.separate_app_totp",
              "publish_status": "publish_ready",
              "source_field": "separate_app_totp",
              "value": "KeePassXC calculates TOTP codes from a secret stored on a database entry and lets users copy, auto-type, or enter those codes through the browser extension; the secret and configuration can also be viewed as a QR code for export to a mobile device."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "passkeys-and-totp-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "passkey_support": {
              "cell_citation_url": "https://proton.me/pass/passkeys",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.passkey_support",
              "publish_status": "publish_ready",
              "source_field": "passkey_support",
              "value": "Proton Pass's passkey page is headed \"Store, share and export passkeys\" and says passkeys are supported in its browser extension and on Android and iOS devices, that Android supports passkeys only from Android 14, and that users cannot currently log into Proton Pass apps using passkeys."
            },
            "separate_app_totp": {
              "cell_citation_url": "https://proton.me/support/pass-2fa",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.separate_app_totp",
              "publish_status": "publish_ready",
              "source_field": "separate_app_totp",
              "value": "Proton Pass generates TOTP codes for saved website login items without requiring a separate authenticator app and documents setup through its browser extension, Android app, and iPhone and iPad app."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "passkeys-and-totp-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    },
    "request-reporting": {
      "field_definitions": {
        "request_reporting": "Published period, jurisdiction, unit, scope, counts, process statements, and limitations stated by the current cell."
      },
      "last_updated": "2026-10-06",
      "matrix_id": "vendor-vault:request-reporting",
      "rows": [
        {
          "cells": {
            "request_reporting": {
              "cell_citation_url": "https://1password.com/legal/law-enforcement/",
              "cell_locator": "1password.1password.vendor-documented.vendor-documented.vendor-documented.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "1Password says it checks law-enforcement authority, provides only reasonably required user information, and notifies the customer or user before disclosure unless law, law enforcement, suspected illegal or malicious conduct, or risk of harm prevents notice."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#1password.1password.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://1password.com/legal/privacy/",
          "operating_entity_citation_url": "https://1password.com/legal/privacy/",
          "operating_entity_subline": "1Password says AgileBits Inc. does business as 1Password and that 1Password is a Canadian company headquartered in Toronto, Ontario.",
          "row_anchor": "request-reporting-1password",
          "row_id": "1password",
          "state": "1Password"
        },
        {
          "cells": {
            "request_reporting": {
              "cell_citation_url": "https://bitwarden.com/privacy.md",
              "cell_locator": "bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Bitwarden says it may disclose information when reasonably necessary to comply with law, legal process, or lawful government requests, including national-security or law-enforcement requirements."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://bitwarden.com/terms.md",
          "operating_entity_citation_url": "https://bitwarden.com/terms.md",
          "operating_entity_subline": "Bitwarden says Bitwarden Inc. is incorporated in Delaware, owns 8bit Solutions LLC, and uses United States federal law and California law for its agreement except where applicable law provides otherwise.",
          "row_anchor": "request-reporting-bitwarden",
          "row_id": "bitwarden",
          "state": "Bitwarden"
        },
        {
          "cells": {
            "request_reporting": {
              "cell_citation_url": "https://keepassxc.org/privacy/",
              "cell_locator": "keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Verified absence"
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#keepassxc.keepassxc.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://keepassxc.org/team/",
          "operating_entity_citation_url": "https://keepassxc.org/team/",
          "operating_entity_subline": "Verified absence",
          "row_anchor": "request-reporting-keepassxc",
          "row_id": "keepassxc",
          "state": "KeePassXC"
        },
        {
          "cells": {
            "request_reporting": {
              "cell_citation_url": "https://proton.me/legal/transparency",
              "cell_locator": "proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.request_reporting",
              "publish_status": "publish_ready",
              "source_field": "request_reporting",
              "value": "Not disclosed in the captured primary source."
            }
          },
          "last_checked": "2026-10-06",
          "name_cell": "vendor#proton-pass.proton-pass.vendor-documented.vendor-documented.vendor-documented.operating_entity",
          "official_source_url": "https://proton.me/legal/privacy",
          "operating_entity_citation_url": "https://proton.me/legal/privacy",
          "operating_entity_subline": "Proton states that Proton AG operates the services, is domiciled in Geneva, Switzerland, and is governed by Swiss laws and regulations.",
          "row_anchor": "request-reporting-proton-pass",
          "row_id": "proton-pass",
          "state": "Proton Pass"
        }
      ],
      "scope_label": "4 products"
    }
  },
  "template": "matrix",
  "tier": "T1",
  "warnings": [
    "cell vendor#bitwarden.bitwarden.vendor-documented.vendor-documented.vendor-documented.source_availability: the display text still carries bitwarden_license",
    "sideways label \"Email Alias Service Comparison\" differs from the known title \"Email-Alias Service Comparison: Identity, Retention, Replying, and Limits\" of /privacy-tools/email-alias-service-comparison/",
    "sideways label \"Private Phone Number App Comparison\" differs from the known title \"Private Phone-Number App Comparison: Identity, Retention, Porting, and Limits\" of /privacy-tools/private-phone-number-app-comparison/"
  ]
}
