Both are US-owned with corresponding sub-processor and CLOUD Act exposure.
Passbolt vs 1Password / LastPass
Luxembourg-based open-source vault that can run entirely inside EU infrastructure. — a detailed comparison to help European teams evaluate the switch.
Luxembourg-based open-source password manager with end-to-end encryption and full self-hosting support.
Side-by-side comparison
How Passbolt compares to 1Password / LastPass on key dimensions.
| Dimension | 1Password / LastPass | Passbolt |
|---|---|---|
| Headquarters | US-based | Luxembourg |
| Jurisdiction | US law | Luxembourg |
| Hosting Region | Global / US default | Self-hosted or managed cloud |
| Company location | US vendor | Passbolt SA, Luxembourg |
| Source model | Proprietary | AGPL-3.0 open source |
| Deployment choice | Vendor-managed cloud only | Self-hosted, managed cloud, or hybrid |
| Encryption model | Vendor-managed key escrow | Client-side OpenPGP key pairs |
Key capabilities of Passbolt
- End-to-end encrypted password and secrets vault
- OpenPGP-based encryption with public/private key architecture
- Team and organization-level sharing with granular permissions
- Browser extensions and CLI client
- Fully self-hostable on Docker or Linux servers
Passbolt is operated by Passbolt SA, incorporated in Luxembourg, with open-source software under AGPL-3.0 and full self-hosting documentation.
Frequently asked questions
Is Passbolt a good replacement for 1Password / LastPass?
Luxembourg-based open-source vault that can run entirely inside EU infrastructure. Passbolt is headquartered in Luxembourg with data hosted in Self-hosted or managed cloud, providing clearer GDPR compliance for European teams.
Where is Passbolt hosted?
Passbolt operates from Self-hosted or managed cloud under Luxembourg jurisdiction, keeping data within European legal frameworks.
Is Passbolt open source?
Yes, Passbolt is open source under the AGPL-3.0 license. It can also be self-hosted for full data control.
Tools that work well with Passbolt
Complement your European stack with these pairings.
Hetzner
One of the most practical EU infrastructure defaults for startups that want predictable costs and regional clarity.
Scaleway
Public cloud and infrastructure platform for teams that want an explicitly European cloud provider with a modern product surface.
ZITADEL
Open-source IAM for customer and workforce identity with OIDC, SAML, SCIM, and machine identity support.