Last updated: September 1, 2026
Ask six cybersecurity professionals to name the best password manager, and you may get six different answers.
That does not necessarily mean five of them are wrong.
Choosing among the best password managers is a little like choosing a car. A Toyota Camry, Ford F-150, Porsche 911, Honda CR-V and Jeep Wrangler can all be excellent vehicles, but they are excellent for different people. The person hauling equipment every weekend has different priorities from the commuter who values fuel economy, and neither is making a bad choice.
Password managers have reached a similar point.
Once you eliminate questionable products and narrow the field to established, well-designed password managers, the decision becomes surprisingly personal. Security is still the price of admission, but usability, platform support, autofill behavior, privacy philosophy, family sharing, business administration, recovery options and price can determine which product is actually the best for you.
For 2026, six products deserve particularly serious consideration:
1Password, Bitwarden, Keeper, RoboForm, Proton Pass and NordPass.
All six can generate and store strong passwords, synchronize credentials between devices, autofill logins, support modern authentication technologies such as passkeys and multifactor authentication, and protect vault data using strong encryption.
That does not mean they are identical.
It means there is no need to declare one universal champion.
First: Yes, You Should Probably Be Using a Password Manager
Before comparing products, it is worth establishing something more important: using a good password manager is considerably better than trying to invent and remember unique passwords yourself.
NIST explicitly recommends password managers for accounts that still require passwords, noting that they make it practical to generate long, complex and unique credentials rather than reusing passwords across multiple services. NIST also recommends protecting the password-manager account itself with multifactor authentication.
CISA similarly recommends password managers while advising users to consider device compatibility, cloud versus local storage, account recovery and MFA when selecting one.
That last part is important.
The question isn’t simply:
“Which password manager has the strongest encryption?”
A better question is:
“Which reputable password manager will I actually use correctly every day?”
A theoretically perfect password manager that frustrates you enough to stop using it is not the best password manager for you.
The Six at a Glance
| Password Manager | Particularly Strong For | Potential Tradeoff |
|---|---|---|
| 1Password | Best all-around experience, families, polished business use | No permanent free personal tier |
| Bitwarden | Value, open source, transparency, technical users | Interface can feel more utilitarian |
| Keeper | Security controls, organizations, enterprise environments | Some desirable features/add-ons increase cost |
| RoboForm | Autofill, form filling, simplicity, long-time users | Less fashionable interface/philosophy than newer rivals |
| Proton Pass | Privacy, open source, email aliases, Proton ecosystem | Younger product than some competitors |
| NordPass | Modern interface, ease of use, straightforward experience | Free plan has more limitations than Bitwarden |
There isn’t a bad choice in that table for the average user.
There are, however, some very different personalities.
1Password: The Polished All-Rounder
If password managers were cars, 1Password might be the premium midsize SUV.
It does almost everything well, it is comfortable for technical and nontechnical users, it works for individuals and families, and it scales into serious corporate environments without feeling like enterprise software when you’re using it at home.
That balance is probably 1Password’s biggest advantage.
Tom’s Guide currently rates 1Password as its best password manager overall, praising its usability, family features, broad platform support and passkey capabilities.
What makes 1Password’s security model interesting
The standout feature is its Secret Key.
Your account is not protected solely by the password you remember. 1Password generates an additional Secret Key containing 128 bits of entropy, and the Secret Key and your account password are both required to derive the keys protecting your vault.
Importantly, 1Password says the Secret Key is never sent to the company. That provides another layer of protection against an attacker who might obtain encrypted account data from 1Password’s infrastructure.
1Password also uses end-to-end encryption and states that it cannot access your vault contents. The company publishes information about independent security assessments and maintains SOC 2 Type 2 certification.
Where 1Password shines
The biggest strength isn’t one cryptographic specification. It’s the complete experience.
Apps are available across the major desktop and mobile platforms, browser integration is mature, sharing is straightforward, Watchtower identifies compromised or otherwise risky credentials, and family accounts are easy enough to administer without turning one family member into an unpaid IT department.
Its current individual plan is advertised from $2.99 per month when paid annually, although introductory pricing and promotions can change. Family plans support five family members in the base subscription.
Who should choose 1Password?
Choose it if you want something polished, mature and easy to recommend to almost anyone.
It is especially compelling if several people with very different levels of technical ability will be using the same password-management system.
Why someone might choose something else
There is no permanent free personal tier.
And users who strongly prioritize fully open-source software may prefer Bitwarden or Proton Pass.
Best description: The easiest all-around recommendation.
Bitwarden: The Open-Source Value King
If 1Password is the polished SUV, Bitwarden is the extremely capable car that costs far less than you’d expect and lets you open the hood yourself.
Bitwarden has built a huge following partly because of price, but calling it merely the “cheap password manager” undersells it.
Its more important differentiator is transparency.
Bitwarden’s code is open source, and the company publishes extensive information about third-party security assessments. Its 2025 assessment program included reviews involving Cure53, Palo Alto Networks Unit 42, Fracture Labs and ETH Zurich’s Applied Cryptography Group.
That level of scrutiny is a major reason technically inclined users like Bitwarden.
The free plan is legitimately useful
This is another major distinction.
Bitwarden’s free tier supports unlimited passwords and unlimited devices rather than giving users a deliberately crippled demo. It also includes passkey management, password generation, autofill and basic secure sharing.
Premium is currently advertised at $19.80 per year, making Bitwarden unusually inexpensive even after upgrading.
Security architecture
Bitwarden uses end-to-end, zero-knowledge encryption. Its current documentation describes AES-CBC 256-bit encryption with HMAC authentication and supports PBKDF2-SHA-256 or Argon2id for key derivation.
New accounts currently default to 600,000 PBKDF2 iterations, while users can switch to Argon2id. Bitwarden’s 2026.2.1 release also raised the minimum permitted PBKDF2 setting to 600,000 iterations.
Advanced users can even self-host Bitwarden rather than relying on Bitwarden’s cloud infrastructure.
That does not automatically make self-hosting safer — badly maintained infrastructure can make things worse — but having the option matters to some organizations and technically sophisticated users.
Where Bitwarden gives up ground
Polish.
Bitwarden has improved enormously, but people migrating from something like 1Password or RoboForm may find parts of the interface and workflow less intuitive.
Tom’s Guide reaches essentially the same conclusion: tremendous value and security, but some functionality is less intuitive than competing products.
For a technically comfortable user, that may not matter at all.
For an organization trying to persuade hundreds of reluctant employees to adopt a password manager, those small UX differences can matter considerably.
Who should choose Bitwarden?
People who care about transparency, open source, value, cross-platform support or self-hosting.
It is also probably the first password manager I would recommend to someone who says, “I want a really good password manager, but I don’t want another expensive subscription.”
Best description: Maximum capability for the money.
Keeper: The Security-and-Control Specialist
Keeper feels different from Bitwarden and 1Password.
If these were cars, Keeper would be the armored luxury SUV — very usable, but clearly engineered with security controls and business deployment near the top of the priority list.
Keeper uses end-to-end encryption with a zero-knowledge architecture. Its current security documentation describes AES-256 encryption, elliptic-curve cryptography and local encryption/decryption of vault information. For master-password accounts, Keeper currently documents PBKDF2 with 1,000,000 iterations.
Keeper also says it began rolling out an additional quantum-resistant cryptography wrapper in Q1 2026.
For organizations, Keeper has accumulated an extensive collection of security and compliance capabilities, including SOC 2 and ISO-related controls, privileged-access products, secrets management, advanced reporting and enterprise administration.
Keeper’s recovery model is worth noting
Keeper now supports a 24-word recovery phrase based on the BIP39 word list.
That creates an interesting balance between zero-knowledge security and recoverability. The recovery phrase protects an encrypted copy of the user’s data key; Keeper says recovery also involves email verification and 2FA.
Some users prefer strict “lose the secret and everything is gone” security.
Others strongly prefer having a carefully designed recovery mechanism.
Again: personal preference.
Where Keeper shines
Keeper is particularly attractive when password management is part of a larger organizational security program rather than simply an individual convenience.
Its business offerings extend far beyond storing passwords into secrets management, privileged access, connection management and enterprise reporting.
Tom’s Guide currently categorizes Keeper as its top security-focused password manager, while TechRadar particularly praises its syncing, sharing and business functionality.
The downside
Pricing can become more complicated because capabilities such as enhanced breach monitoring, secure storage and other enterprise features may be packaged separately depending on the plan.
Keeper Unlimited currently lists at $42.99 annually, while Keeper Family is $91.99 annually, before temporary discounts.
That isn’t unreasonable, but Bitwarden wins the pure price competition.
Who should choose Keeper?
Security-conscious professionals, businesses, IT departments and anyone who values extensive administrative and security capabilities more than having the cheapest possible subscription.
Best description: Serious security with serious administrative controls.
RoboForm: The Autofill Veteran That Still Deserves Respect
RoboForm is the one people sometimes forget when discussing fashionable password managers.
That is a mistake.
RoboForm has existed since 1999, meaning form filling is not some secondary feature bolted onto the product. Filling login screens and complicated web forms is part of its DNA.
If the others are newer vehicles loaded with touchscreens, RoboForm is the model that has been refining the same drivetrain for decades.
It may not always get the most attention, but it is exceptionally good at the thing many people interact with 50 times per day: entering credentials.
TechRadar currently ranks RoboForm second overall in its 2026 password-manager testing and particularly recommends it for mobile use.
RoboForm’s security deserves more credit than it sometimes receives
RoboForm uses AES-256 encryption and a zero-knowledge model in which decryption occurs on the user’s device and the master password isn’t transmitted to RoboForm’s servers.
Current RoboForm documentation for its iOS and Android applications specifies PBKDF2-SHA-256 with 8,388,608 iterations.
More importantly, RoboForm has undergone independent assessment.
Secfault Security conducted comprehensive audits and penetration tests in both 2023 and 2025. RoboForm says the 2025 assessment covered its Windows and macOS clients, Android and iOS apps, browser extensions, online portal and password-generator source.
That is exactly the sort of external scrutiny you want to see from a company entrusted with a password vault.
RoboForm’s secret weapon: autofill
RoboForm is exceptionally strong at filling more than username/password pairs.
Addresses, identities, payment details and complex forms remain areas where its long history shows.
It also offers an integrated TOTP authenticator, passkey management, passwordless unlocking, emergency access, breach monitoring, secure sharing and even Windows application logins.
Another interesting option is Local Only mode, which allows users who do not want cloud synchronization to store their RoboForm data locally.
Pricing
RoboForm Premium currently renews at $29.88 per year, while its Family subscription supports five Premium accounts and currently renews at $47.75 per year.
RoboForm Business is currently advertised at $3.33 per user per month when billed annually and includes centralized administration, SSO, SCIM provisioning, role-based controls, security policies, reporting and activity logs.
That makes RoboForm surprisingly competitive for organizations as well.
Why someone might overlook RoboForm
Brand perception.
1Password feels newer. Bitwarden attracts the open-source crowd. Proton has the privacy audience. NordPass has the modern Nord Security ecosystem.
RoboForm sounds like something that might have arrived on a CD-ROM with Windows XP.
But judging password managers by branding would be like refusing to consider a 100-year-old automaker because a startup has cooler commercials.
The technology matters more.
Who should choose RoboForm?
Anyone who values excellent autofill, wants a mature product, fills a large number of forms or simply prefers how RoboForm behaves in everyday browser use.
Best description: The autofill specialist — and much more competitive overall than its age suggests.
Proton Pass: The Privacy-First Choice
Proton Pass is the youngest product in this group, but it has something the others cannot easily replicate:
the Proton ecosystem and its privacy philosophy.
Proton is headquartered in Switzerland and has built its reputation around encrypted email, VPN services, cloud storage and privacy-oriented software.
Proton Pass carries that philosophy into password management.
Encryption goes beyond the obvious fields
Proton Pass uses end-to-end encryption and encrypts not only passwords but also metadata such as usernames and web addresses.
Vault information is protected with AES-256-GCM, while its sharing architecture incorporates OpenPGP and Curve25519.
That emphasis on encrypting metadata is particularly attractive to privacy-focused users.
Open source and independently audited
Like Bitwarden, Proton Pass is open source.
Its original 2023 audit was performed by Cure53, and in 2026 Proton commissioned another extensive assessment from Recurity Labs covering its browser extensions, desktop and mobile applications and command-line interface.
The fact that Proton continues commissioning audits as the product evolves is more meaningful than simply pointing to a single audit conducted years ago.
Hide-my-email aliases are a killer feature
Proton Pass integrates email aliases directly into the account-creation process.
Instead of handing every online service your real email address, you can create an alias that forwards mail to you. If that address starts receiving spam or appears in a breach, it can be disabled without changing your actual inbox.
For people concerned about data brokers, spam and identity correlation, this is arguably more valuable than another fancy password-strength meter.
Proton Pass also includes an integrated authenticator, dark-web monitoring, secure sharing and Proton Sentinel, an enhanced account-protection system combining automated detection with human security analysis.
And in 2026, Proton added a particularly interesting new feature: scoped access tokens allowing AI agents to access specifically authorized vaults with expiration controls and audit logs.
Where Proton Pass gives up ground
Age.
1Password, Keeper and RoboForm have had considerably longer to encounter bizarre websites, edge cases, corporate deployment scenarios and obscure autofill problems.
Proton Pass is developing quickly — including autofill improvements released in July 2026 — but it remains a younger product.
Who should choose Proton Pass?
Privacy-focused users, existing Proton Mail/VPN customers, open-source advocates and anyone who considers email aliases almost as important as password storage.
Best description: Password management built around privacy rather than just credentials.
NordPass: The Modern, Easy-to-Live-With Option
NordPass comes from Nord Security, the company best known for NordVPN.
That background has allowed NordPass to enter a crowded field with a polished product rather than slowly evolving from a barebones password vault.
If password managers were cars, NordPass would be the modern crossover with a clean dashboard and practically no learning curve.
TechRadar currently ranks NordPass as its best password manager overall for 2026, while Tom’s Guide specifically recommends it for iPhone users.
The XChaCha20 difference
NordPass uses XChaCha20-Poly1305 as part of its encryption architecture rather than the AES implementations more commonly seen elsewhere in this group.
Its private encryption key is encrypted locally, and NordPass operates under a zero-knowledge architecture in which the master password and decryption keys are not sent to NordPass servers.
Should you pick NordPass solely because it says XChaCha20 while another product says AES-256?
No.
Both can provide extremely strong security when implemented correctly.
The implementation, key derivation, architecture, software security and your own master password matter far more than treating encryption algorithm names like horsepower figures.
Independent verification
NordPass and NordPass Business have undergone independent security reviews by Cure53. NordPass Business has also obtained SOC 2 Type 2 attestation and ISO 27001 certification.
Where NordPass shines
Ease of use.
The interface is modern, uncluttered and consistent. It supports password and passkey management, breach scanning, password-health analysis, email masking, file attachments, secure sharing and emergency access on paid plans.
NordPass also continued refining vault navigation and search functionality during 2026 rather than simply adding security features nobody interacts with every day.
That’s important.
A password manager is an application you may interact with dozens of times a day. Tiny annoyances compound.
The free-tier caveat
NordPass Free can synchronize data across your devices, but only one device can have an active session at a time. Paid accounts remove that limitation and add the more advanced monitoring and security features.
Bitwarden therefore remains the stronger choice if your primary concern is getting the most functionality possible without paying.
Who should choose NordPass?
Someone who wants modern design, strong security and straightforward operation without wanting to spend time configuring or thinking about the password manager itself.
Best description: The clean, modern choice that mostly gets out of your way.
So Which Password Manager Is Actually the Best?
There isn’t one.
And that isn’t a cop-out.
Once a password manager passes a sufficiently high security threshold, human factors become part of security.
If RoboForm fills your logins correctly every time while another password manager annoys you, RoboForm may make you safer because you’ll actually use it consistently.
If Bitwarden’s open-source model makes you more comfortable entrusting a company with your credentials, Bitwarden may be the right choice.
If your entire family needs something easy to understand, 1Password may be worth paying more for.
If you’re deploying password management across an organization and want extensive policy and privileged-access capabilities, Keeper could make considerably more sense.
If your digital life already runs through Proton Mail and Proton VPN, adding Proton Pass may be almost effortless.
And if you simply love NordPass’s interface, that is a legitimate reason to choose it.
Security products do not exist in a laboratory. They exist on your phone at 6:45 a.m. when you’re trying to log into your bank account.
Usability matters.
My Picks by Personality
For the person who says “Just give me something excellent”, I’d start with 1Password.
For “I want excellent security without spending much money”, choose Bitwarden.
For “Security controls and business administration matter most”, look closely at Keeper.
For “I want autofill to work extremely well and I don’t care which brand is fashionable”, RoboForm deserves serious consideration.
For “Privacy is my obsession”, Proton Pass is probably the most natural fit.
For “I want something modern, easy and polished”, NordPass may be the winner.
Those conclusions are also a good illustration of why different professional reviewers reach different rankings. Tom’s Guide currently puts 1Password first, whereas TechRadar currently puts NordPass first and RoboForm second. Both publications have tested large numbers of password managers.
They aren’t necessarily contradicting each other.
They are weighting different characteristics differently.
Exactly like car reviewers.
What Matters More Than Which of These Six You Pick
There is one final point that tends to get lost in product comparisons.
Moving from password reuse, spreadsheets, sticky notes or memorized variations of the same password to any one of these six reputable password managers is likely a much more important security improvement than agonizing over whether Bitwarden is 3% better than 1Password or RoboForm is 4% better than NordPass.
Whichever one you choose, protect the password-manager account with a long, unique master password or passphrase, enable strong multifactor authentication, securely store whatever recovery information the product provides, keep the apps and browser extensions updated, and gradually replace reused passwords with randomly generated unique credentials.
And where good passkey support is available, use it.
NIST’s current consumer guidance boils account protection down to the same fundamentals: use MFA, use a password manager and, when a password is necessary, make it long.
The Bottom Line
The argument over the single “best password manager” is becoming less useful.
1Password, Bitwarden, Keeper, RoboForm, Proton Pass and NordPass are six different approaches to solving largely the same problem.
They differ in interface, philosophy, pricing, recovery, privacy features, business controls and technical architecture.
But among these established choices, selecting a password manager increasingly resembles selecting a car.
There are objective standards. A vehicle needs to be safe and reliable. A password manager needs strong encryption, sound architecture, trustworthy development practices and modern account protection.
Once those requirements are met, however, personal preference takes over.
The best password manager is not necessarily the one that wins the most comparison charts.
It’s the secure one you trust, understand and actually use every day.
Editor’s Note: Ownership, Outside Investment and Corporate Structure
Because a password manager ultimately safeguards some of a user’s most sensitive digital information, we believe the company behind the software is worth considering alongside encryption, audits, features and usability.
RoboForm and Bitwarden have notably different corporate histories.
RoboForm is owned and operated by Siber Systems, Inc., a privately held Virginia company headquartered in Fairfax, Virginia. Siber Systems identifies RoboForm as one of its flagship products and says RoboForm has been continuously developed since 2000. The company remains led by CEO Vadim Maslov, its longtime founder. RoboForm’s privacy policy specifically identifies Siber Systems as a Virginia corporation and states that RoboForm is wholly owned and operated by Siber Systems.
We found no publicly announced venture-capital or private-equity financing for Siber Systems comparable to Bitwarden’s major institutional investment rounds. Siber Systems describes itself simply as privately held. Because Siber Systems is a private corporation, however, its complete shareholder register is not publicly available. Therefore, it would be inappropriate to claim that its founder owns 100% of the company, that no outside shareholder exists, or that no foreign investor could hold any economic interest. What can be said is that we found no publicly disclosed major institutional investor, private-equity sponsor or outside investor board role comparable to those disclosed by Bitwarden.
Bitwarden has followed a different path. In September 2022, Bitwarden announced a $100 million growth investment led by PSG Equity. Bitwarden explicitly stated that PSG acquired a minority position in the company and would join Bitwarden’s board of directors. Existing investor Battery Ventures also participated in the transaction. The exact percentage owned by PSG, Battery Ventures, founder Kyle Spearrin and other shareholders has not been publicly disclosed.
That distinction is important. Bitwarden was not acquired outright by PSG, based on the company’s disclosure. PSG’s investment was specifically described as a minority position. Nevertheless, Bitwarden has institutional investors with both an economic interest in the company and, in PSG’s case, formal board representation. Like most venture-capital and growth-equity investors, those firms ultimately seek financial returns from the companies in which they invest.
Both investment firms also operate internationally, including in Israel. Battery Ventures describes itself as a global technology investment firm with offices in Boston, San Francisco, Silicon Valley, New York, London and Tel Aviv. Battery’s current U.S. Securities and Exchange Commission registration additionally identifies Battery Ventures Israel Ltd. as a “relying adviser” under Battery Management Corp.’s registration.
PSG Equity likewise has operated from Tel Aviv in addition to its offices in Boston, Kansas City, London, Madrid, Paris and other locations. PSG’s own materials were already identifying Tel Aviv as one of its offices in 2022, the year it invested in Bitwarden.
Those facts should not, however, be misrepresented as evidence that “Israel owns Bitwarden” or that Bitwarden’s $100 million financing consisted of Israeli capital.
Private investment funds typically combine money from numerous limited partners, which may include pension funds, endowments, financial institutions, family offices and other investors from multiple countries. Publicly available information does not provide a complete look-through showing exactly which underlying investors supplied each dollar ultimately invested in Bitwarden. We have not found evidence demonstrating that an Israeli government entity, sovereign fund or specific Israeli institutional investor directly owns or controls Bitwarden.
Likewise, maintaining a Tel Aviv office, employing Israeli investment professionals or investing in Israeli technology companies does not establish the nationality of the money used for a particular portfolio-company investment.
The accurate distinction is therefore more limited:
Bitwarden is a U.S.-based password-management company with disclosed institutional investors, including PSG Equity and Battery Ventures. Both are global U.S.-based investment organizations with established Israeli operations. PSG holds a minority position and received Bitwarden board representation. The underlying sources and nationalities of all capital within the relevant investment funds are not fully public.
By comparison:
RoboForm is operated by privately held Siber Systems, a Virginia-based software company that remains led by longtime founder and CEO Vadim Maslov. We found no publicly disclosed PSG/Battery-style institutional financing, outside investment-firm board position or comparable Israeli investment-company connection involving Siber Systems. Its private ownership structure nevertheless means that its complete shareholder composition cannot independently be verified from public information.
This difference may reasonably matter to users who consider corporate continuity, outside-investor influence and ownership structure when deciding whom to trust with a password vault.
It should not be confused with a technical security conclusion.
Nothing about PSG or Battery Ventures investing in Bitwarden demonstrates that Bitwarden’s encryption has become weaker, that investors can access users’ vault contents, or that Bitwarden is less secure than RoboForm. Bitwarden’s open-source architecture, zero-knowledge design and independent security assessments must be evaluated on their own merits.
Likewise, RoboForm’s longer history, private-company structure and founder continuity do not by themselves prove that RoboForm’s cryptography is superior.
Instead, the comparison highlights two different forms of organizational trust:
RoboForm offers an unusually long record of corporate and leadership continuity. Bitwarden offers considerably greater source-code transparency, but operates today within a more complex institutional-investment structure.
For some users, that distinction will matter very little. For others, particularly those choosing a company they expect to entrust with their credentials for many years, it is a legitimate factor to include alongside security architecture, independent audits, product quality, recovery procedures and everyday usability.
Editor’s Note: Who Owns and Controls the Other Major Password Managers?
For consistency, we also examined the corporate structure, leadership and major outside investment behind the other four password managers discussed in this article: 1Password, Keeper, Proton Pass and NordPass.
The comparison is revealing because these companies follow four quite different ownership models. Some remain founder-led while accepting large institutional investments. One has placed controlling influence under a nonprofit foundation. Others have private-equity or venture-capital representatives directly serving on their boards.
As with our discussion of RoboForm and Bitwarden, none of these corporate relationships by themselves demonstrate that a password manager is secure or insecure. They are relevant primarily to questions of long-term corporate incentives, control, independence and whom users are ultimately trusting.
1Password: Canadian Company With Significant Institutional Investment
1Password is operated by AgileBits Inc. dba 1Password, an Ontario corporation whose current principal place of business is in Toronto, Ontario, Canada. (1password.com)
1Password was originally built by founders including Sara Teare and Dave Teare and has since evolved into a much larger identity-security company.
The company is no longer run by one of its original founders. Its current CEO is David Faugno, who assumed the CEO position in 2024 after joining 1Password as president and COO in 2023. Before joining 1Password, Faugno was a venture partner at Accel, one of 1Password’s institutional investors. (1password.com)
The founders nevertheless remain represented in the company’s governance. Founder Sara Teare currently sits on 1Password’s board of directors, alongside CEO David Faugno and former CEO Jeff Shiner, who is now executive chairman. (1password.com)
1Password has raised considerably more institutional capital than either RoboForm or Bitwarden.
In January 2022, 1Password raised $620 million at a reported $6.8 billion valuation. That round was led by ICONIQ Growth, with participation from Accel, Tiger Global, Lightspeed Venture Partners, Salesforce Ventures, Slack Fund, Backbone Angels and numerous individual investors. Earlier rounds included a $200 million Series A led by Accel and another $100 million financing. (1password.com)
The scale of that financing makes 1Password one of the most heavily institutionally financed companies in this group.
Its board also reflects that investment structure. Current directors include Arun Mathew of Accel and Will Griffith of ICONIQ, in addition to management, founder and independent directors. (1password.com)
Exact ownership percentages for ICONIQ, Accel and other investors are not publicly disclosed, so it would be inappropriate to claim that any particular investment firm controls 1Password based solely on the funding amounts.
ICONIQ itself is a major global investment organization with more than $100 billion in assets under management and offices in San Francisco, Palo Alto, New York, London and Singapore. (iconiq.com)
Accel is likewise a major global venture-capital organization. In August 2026, Accel announced a new $3.5 billion collection of funds supporting investment strategies in the United States, Europe, Israel and India. (accel.com)
That should not be interpreted as evidence that Israeli money funded 1Password. Venture funds pool money from numerous investors, and publicly available information does not provide a complete look-through showing the nationality of every limited partner whose capital ultimately reached 1Password.
There is, however, a separate and more direct Israeli operating connection worth disclosing.
In June 2026, 1Password acquired Apono, an access-governance cybersecurity company. Prior to the acquisition, Apono maintained both a New York headquarters and an office on Menachem Begin Road in Tel Aviv. The acquisition terms were not publicly disclosed. (1password.com) (apono.io)
Again, an acquisition of a company with Israeli operations says nothing about whether 1Password employees, investors or governments can access encrypted customer vaults. It is simply part of the complete corporate picture.
In broad terms:
1Password is a Canadian-founded and Canadian-headquartered company with substantial U.S. and global institutional investment, investor representation on its board, professional management and increasingly international cybersecurity operations.
Keeper: Founder-Led, but Backed by Two Major Growth-Equity Firms
Keeper Security presents an interesting middle ground between RoboForm’s largely founder-led story and 1Password’s extensive institutional financing.
Keeper was founded in 2011 by Darren Guccione and Craig Lurey.
Unlike 1Password and Bitwarden, both founders still occupy the company’s two principal technical and executive positions:
Darren Guccione — CEO and Co-Founder
Craig Lurey — CTO and Co-Founder
Keeper identifies Chicago, Illinois as its global headquarters, with additional operations including product development in California, EMEA sales in Cork, Ireland, and APAC sales in Tokyo, Japan. (keepersecurity.com)
But Keeper is not financially independent of institutional investors.
In August 2020, Keeper raised $60 million from Insight Partners. Keeper described the transaction as a minority investment and said it was the company’s first equity financing since its founding.
Following that investment, Insight executive Thomas Krane joined Keeper’s board of directors. (prnewswire.com)
Keeper subsequently accepted another major outside investment.
In May 2023, Summit Partners completed what was again described as a significant minority investment in Keeper. Summit managing director Len Ferrington joined Keeper’s board as part of the transaction. Existing investor Insight Partners remained involved. (summitpartners.com)
Keeper’s current board therefore includes representatives of both Insight Partners and Summit Partners, alongside CEO/co-founder Darren Guccione and independent directors. (keepersecurity.com)
The exact ownership percentages held by Keeper’s founders, Insight, Summit and any other shareholders have not been publicly disclosed.
There is also an Israeli institutional connection similar in some respects to the one discussed regarding Bitwarden’s investors.
Insight Partners operates a Tel Aviv office.
Insight announced the opening of that office in 2019 and stated at the time that it had already invested more than $700 million in Israeli companies, including Checkmarx, Lightricks, Monday.com and WalkMe. (insightpartners.com)
Insight continues to identify Keeper as a current portfolio investment. (insightpartners.com)
Summit Partners, meanwhile, currently lists offices in Boston, Menlo Park, New York, London and Luxembourg. We did not find an Israeli Summit Partners office comparable to Insight’s Tel Aviv operation. (summitpartners.com)
Once again, Insight’s Israeli operations do not demonstrate that Israeli capital financed Keeper. The identities and nationalities of all underlying limited partners in Insight’s investment funds are not completely public.
The appropriate characterization is therefore:
Keeper remains operationally founder-led, with its original CEO and CTO still running the company, but it also has two substantial institutional growth-equity investors—Insight Partners and Summit Partners—with representatives from both firms sitting on Keeper’s board.
That makes Keeper’s corporate structure meaningfully more complicated than RoboForm’s publicly visible structure, even though Keeper retains unusually strong founder continuity.
Proton Pass: The Most Unusual Ownership Model in the Group
Proton Pass is structurally very different from nearly every other password manager discussed here.
Proton Pass is part of Proton AG, a Swiss company founded in 2014 by scientists and engineers who met at CERN.
Its founder, Dr. Andy Yen, remains Proton’s CEO. (proton.me)
Proton’s global headquarters is in Geneva, Switzerland. The company also currently lists offices in Zurich, Paris, London, Barcelona, Skopje, Vilnius, Prague and Taipei. (proton.me)
Most importantly, Proton states that it does not have venture-capital investors.
Instead, the company underwent a significant governance restructuring in 2024.
The newly established Proton Foundation, a Swiss nonprofit organization, became the primary shareholder of Proton AG after founder Andy Yen, co-founder Jason Stockman and early employee Dingchao Lu donated shares to the foundation.
Proton describes the arrangement as deliberately designed to protect the company from being pushed away from its privacy mission by conventional investors or future owners. (proton.me)
According to Proton’s current ownership disclosure:
The Proton Foundation is Proton AG’s primary shareholder.
Proton employees own the vast majority of shares not owned by the Foundation.
The remaining shares are held by the Fondation Genevoise pour l’Innovation Technologique (FONGIT)—a Swiss nonprofit innovation foundation—and by Proton users who previously participated in Proton crowdfunding. (proton.me)
Proton also says it receives support from Innosuisse, the Swiss Federal Innovation Agency, and the European Commission, but specifically states that neither organization owns Proton shares or exercises control over the company. (proton.me)
The Proton Foundation’s board currently includes founder Andy Yen along with Antonio Gambardella, privacy academic Carissa Véliz, World Wide Web inventor Sir Tim Berners-Lee, and Proton engineering leader Dingchao Lu. (proton.me)
Among the six password managers examined in this article, Proton therefore has perhaps the most unusual protection against conventional investor pressure.
It remains a for-profit company that needs to earn money and remain financially sustainable, but its primary shareholder is a nonprofit foundation whose stated purpose is maintaining Proton’s mission rather than maximizing financial return to outside investors.
We also found no publicly disclosed Proton office in Israel and no PSG-, Battery-, Insight-, ICONIQ- or Warburg-style institutional shareholder behind Proton.
As always, a privately held company’s ownership disclosure can only be evaluated using information that is made public. But Proton itself is unusually explicit about its ownership structure.
In simplified form:
Proton Foundation
↓
Primary shareholder of Proton AG
↓
Proton AG
↓
Proton Pass
with employees owning most of the shares not held by the Foundation.
For users who place a particularly high value on corporate independence from venture capital and private equity, Proton’s ownership model is a legitimate differentiator.
It does not automatically make Proton Pass cryptographically safer than its competitors, but it does substantially reduce the conventional investor-pressure concern that exists with several other companies on this list.
NordPass: Bootstrapped for a Decade, Then Took Major Growth Investment
NordPass is developed by Nord Security, the cybersecurity group behind NordVPN and several other security products.
Nord Security was founded in Lithuania in 2012 by Tomas “Tom” Okmanas and Eimantas Sabaliauskas. Its main headquarters operation is located at Cyber City in Vilnius, Lithuania, where Nord moved hundreds of employees from NordVPN, NordPass, NordLayer and NordLocker under one roof. (nordsecurity.com)
Nord Security is therefore the only one of these major password-manager companies whose corporate origins are distinctly Lithuanian/Baltic.
The company was initially unusual because it bootstrapped itself for approximately a decade without institutional investment.
That changed in 2022.
In April 2022, Nord Security announced its first-ever outside financing, raising $100 million at a $1.6 billion valuation.
The financing was led by Novator Ventures, with participation from Burda Principal Investments and General Catalyst. Individual founders and technology executives also participated, including Matt Mullenweg of Automattic. (nordsecurity.com)
Only about a year later, Nord Security raised another $100 million.
That 2023 financing was led by global private-equity firm Warburg Pincus, with existing investors Novator Ventures and Burda Principal Investments also participating.
The transaction valued Nord Security at approximately $3 billion. (nordsecurity.com)
Nord Security said the money would support product development, international expansion and strategic mergers and acquisitions.
Warburg Pincus is a very large global private-equity and growth-investment organization with offices throughout the United States, Europe, Asia and the Middle East, including New York, San Francisco, London, Berlin, Luxembourg, Mumbai, Hong Kong, Singapore, Beijing, Shanghai and Dubai. (warburgpincus.com)
General Catalyst likewise operates internationally, with current offices including San Francisco, New York, Cambridge, Washington, London, Berlin and Bengaluru. (generalcatalyst.com)
We did not find evidence establishing that an Israeli government institution or sovereign investor owns Nord Security, nor did we find evidence demonstrating that Israeli capital specifically funded either of Nord Security’s $100 million investment rounds.
The exact ownership percentages held by Nord Security’s founders, Warburg Pincus, Novator, Burda and other investors are not publicly disclosed.
Nord Security therefore has an interesting corporate history:
approximately ten years of bootstrapped founder-controlled growth, followed by $200 million in disclosed institutional financing and a multibillion-dollar valuation.
That history distinguishes it from both RoboForm, where we found no comparable major institutional financing, and Proton, which has deliberately placed primary ownership under a nonprofit foundation.
Putting All Six Companies Side by Side
The corporate structures behind the six password managers can therefore be summarized roughly as follows:
| Password Manager | Corporate Structure | Founder Still Running Company? | Major Outside Investment? | Investor Board Influence? |
|---|---|---|---|---|
| RoboForm | Privately held Siber Systems | Yes — CEO | None comparable publicly identified | None identified |
| Bitwarden | Private U.S. company with institutional shareholders | Founder remains senior executive, not CEO | Yes — PSG/Battery | Yes |
| 1Password | Private Canadian company with extensive institutional investment | Founder remains on board, not CEO | Yes — very substantial | Yes — Accel/ICONIQ |
| Keeper | Private U.S. company, still founder-led | Yes — CEO & CTO | Yes — Insight/Summit | Yes |
| Proton Pass | Swiss company primarily owned by nonprofit foundation | Yes — CEO | No conventional VC investors | Foundation governance |
| NordPass | Lithuanian-founded Nord Security group | Founders remain deeply involved | Yes — Warburg/Novator/Burda/etc. | Private governance details limited |
This reveals something that ordinary “best password manager” rankings rarely discuss:
The companies may provide broadly comparable password-management functionality while having radically different corporate incentives.
RoboForm represents the traditional long-established, privately held, founder-led software company.
Bitwarden represents a founder-created open-source company that subsequently accepted significant institutional growth capital.
1Password has evolved into a large, professionally managed identity-security company backed by some of the world’s most prominent technology investors.
Keeper combines strong founder continuity with major private-equity/growth-equity participation and investor board representation.
Proton has deliberately moved in the opposite direction, placing its controlling ownership structure under a Swiss nonprofit foundation.
Nord Security spent approximately a decade bootstrapped before ultimately accepting hundreds of millions of dollars of institutional growth capital.
None of those models is automatically good or bad.
Outside investment can fund better engineering, additional security personnel, third-party audits, acquisitions, infrastructure and faster product development.
At the same time, institutional investors ultimately expect financial returns. Those incentives can influence pricing, product strategy, acquisition decisions, enterprise focus and eventually whether a company pursues an IPO, recapitalization or sale.
Founder control brings a different set of advantages and risks. It can provide continuity and insulation from short-term investor demands, but it can also create succession questions and concentrate decision-making in a small number of people.
A nonprofit-controlled structure such as Proton’s reduces some conventional shareholder pressures, but it does not eliminate the ordinary operational, technological or management risks faced by any software company.
That is why we consider corporate ownership one factor rather than a security score.
A user deciding among these products should still give considerably greater weight to encryption architecture, zero-knowledge implementation, independent security audits, vulnerability-response practices, multifactor authentication, passkey support, recovery mechanisms and—in the case of open-source products—the ability of outsiders to inspect the software.
But when six products all meet a high baseline of technical competence, it is entirely reasonable to ask a second question:
“What kind of company do I want holding this relationship for the next 10 or 20 years?”
On that question, these six password managers offer very different answers.
Still With Us?
If you made it through private equity, minority stakes, board seats, limited partners, Swiss foundations and Israeli advisory affiliates without opening another tab, congratulations: you now know more about the ownership structure of password managers than roughly 99.9% of the people using them.
For everyone else, here’s the short version:
RoboForm is the old-school founder-led company. Bitwarden, 1Password, Keeper and NordPass have varying degrees of outside investment. Proton built a Swiss nonprofit structure to keep investors from eventually turning the place into Password Manager: The Subscription Experience.
None of this means one of them is secretly reading your Netflix password.
It just means that when you hand one company the keys to your entire digital life, it’s not completely insane to ask who owns the locksmith.

Leave a Reply