Bitwarden vs 1Password vs Keeper: Manager Comparison 2026
Bitwarden, 1Password and Keeper compared on published audits, encryption design, August 2026 pricing, export freedom and lock-in, with an explicit verdict.
A password manager is the single highest-leverage security change most people can make. The market is crowded, but at the top it narrows quickly to three products that each solve a different problem: Bitwarden for verifiability and price, 1Password for experience, Keeper for compliance.
This comparison is built from primary documents — vendor security architecture papers, published third-party audit indexes, and official pricing pages, all retrieved in August 2026 and linked at the end. It is documentation analysis, not a hands-on trial.
At a glance
| Bitwarden | 1Password | Keeper | |
|---|---|---|---|
| Free tier | Yes, unlimited items and devices | No, 14-day trial | No, 30-day trial |
| Individual, annual | $19.80/yr | $47.88/yr | $42.99/yr |
| Family, annual | $47.88/yr, 6 users | $71.88/yr, 5 users | $91.99/yr, 5 users |
| Source code | Open, clients and server | Closed | Closed |
| Self-hosting | Yes, official server or Vaultwarden | No | Yes, on-premises for enterprise |
| Key derivation | PBKDF2-SHA256 600k, or Argon2id | PBKDF2-HMAC-SHA256 plus 128-bit Secret Key | PBKDF2 1,000,000 iterations |
| Named annual audits | 2018 to present, published index | Trust Center pentest reports since Nov 2025 | Quarterly pentests, NCC Group and CyberTest |
| Certifications | SOC 2 Type 2, SOC 3, ISO 27001, HIPAA | SOC 2 Type 2, ISO 27001/27017/27018/27701 | SOC 2 Type 2, SOC 3, ISO 27001/27017/27018, FedRAMP High, FIPS 140-3 |
| Encrypted export | Yes, password-protected JSON | No, plaintext only | Yes, encrypted vault export |
| Standout feature | Free tier and self-hosting | Travel Mode and Watchtower | FedRAMP High and compliance reporting |
Security architecture
Bitwarden
Vault contents are encrypted client-side before anything leaves the device. The vault key derives from the master password using PBKDF2-SHA256 at 600,000 iterations by default, or Argon2id if the user selects it. Bitwarden’s servers hold ciphertext and never receive the master password.
The distinguishing property is verifiability. Clients, browser extensions, mobile apps and the server are all open source, so the cryptography can be inspected rather than taken on trust, and you can run the server yourself — either Bitwarden’s official image or Vaultwarden, the community Rust reimplementation — if you would rather no third party held the ciphertext at all.
One configuration caveat carries real weight: Argon2id is not the default. Existing accounts run PBKDF2 until the user changes it manually in account security settings. The stronger option is present but opt-in.
1Password
The same zero-knowledge foundation, plus one structural addition. Decryption requires both the account password and a 128-bit Secret Key generated locally at signup and never sent to 1Password’s servers. Content encryption is AES-GCM-256 with PBKDF2-HMAC-SHA256 key derivation.
The security benefit is specific and genuine: an attacker who obtains your account password through phishing, malware or reuse still cannot unlock the account from an unenrolled device, and an attacker who exfiltrates encrypted vaults from 1Password’s infrastructure lacks a component that was never stored there.
The cost is recovery complexity. Lose both the account password and the Secret Key and the vault is gone — there is no reset, because the material required to perform one was never held. The printable Emergency Kit exists precisely because the architecture leaves no server-side fallback.
Keeper
Keeper also encrypts client-side, with per-record and per-folder AES-256 keys generated on the device. Its key derivation is the most aggressive of the three at 1,000,000 PBKDF2 iterations, and enterprise SSO deployments use elliptic curve cryptography for device-level key handling rather than a master password. Keeper’s own documentation is explicit that encryption and decryption always occur locally and never on its servers.
Keeper’s clients are closed source. Its differentiation is not transparency but accreditation, which is a different thing and is discussed below.
Audit and certification history
This is where the three genuinely diverge, and where marketing language most often obscures the difference.
Bitwarden publishes an index of every third-party engagement it has commissioned, running unbroken from 2018 to the present: Cure53 across web vault, desktop, browser extension, core library and network; IOActive and Mandiant on client and mobile applications; Fracture Labs on web and network; Unit 42 on mobile; Paragon Initiative on web properties; and a full cryptography report from the Applied Cryptography Group at ETH Zurich that stress-tests the zero-knowledge design against a compromised-server scenario. It also holds SOC 2 Type 2, SOC 3, ISO 27001 and annual HIPAA audits.
1Password publishes an Independent Security Evaluators penetration test and code review of the full system, an Onica infrastructure and architecture audit, ISO 27001:2022, 27017:2015, 27018:2019 and 27701:2019 certifications, SOC 2 Type 2, and a public HackerOne bug bounty. Since November 2025 the annual penetration test reports are released through its Trust Center rather than as occasional blog posts.
Keeper has the deepest accreditation stack of the three: SOC 2 Type 2 sustained for over a decade, SOC 3, ISO 27001, 27017 and 27018, FedRAMP High authorization hosted in AWS GovCloud, FIPS 140-3 validation, plus HIPAA, GDPR and PCI DSS Level 1 compliance. Quarterly penetration testing is performed by NCC Group and CyberTest, with a Bugcrowd bug bounty running alongside.
Reading that honestly requires separating two things. Certifications are process assurances — they attest that controls exist and were examined against a standard. Code audits and open source are implementation assurances — they say something about the cryptography itself. Keeper leads decisively on the first. Bitwarden leads decisively on the second. 1Password sits between them, with strong certification coverage and a closed implementation you are asked to trust auditors about.
For a federal contractor, FedRAMP High is not a nice-to-have, it is the entire decision. For a privacy-motivated individual, it is close to irrelevant, and open code plus a published cryptography review is worth far more.
Pricing
All figures retrieved from vendor pricing pages in August 2026, in USD, excluding tax.
| Plan | Bitwarden | 1Password | Keeper |
|---|---|---|---|
| Free | Unlimited items, unlimited devices, all platforms, passkey storage | None | None |
| Individual | $1.65/mo billed annually, $19.80/yr | $3.99/mo billed annually, $47.88/yr | $42.99/yr |
| Family | $3.99/mo billed annually, $47.88/yr for 6 users | $5.99/mo billed annually, $71.88/yr for 5 users | $91.99/yr for 5 users, 10 GB storage |
| Small business | Teams $4/user/mo billed annually | Teams Starter Pack $24.95/mo for up to 10 | Business plans quoted separately |
| Enterprise | $6/user/mo billed annually | Business $8.99/user/mo billed annually | Enterprise, quote-based |
| Trial | Not needed, free tier | 14 days | 30 days |
Two notes belong with those numbers. 1Password raised individual and family pricing by up to 33% effective 27 March 2026; the figures above are post-increase, and its personal pricing page currently shows a lower first-year promotional rate for new annual customers that reverts at renewal — budget on the standard rate. Bitwarden’s per-seat family maths is the outlier in the whole category: six seats for $47.88 a year works out at $7.98 per person, less than a fifth of Keeper’s per-seat cost and a sixth of 1Password’s.
Platform coverage
All three ship native applications for Windows, macOS, Linux, iOS and Android, plus browser extensions for Chrome, Firefox, Safari, Edge and Brave, and all three now store and autofill passkeys.
Practical differences that survive that parity:
- Autofill reliability. 1Password’s extension is the most consistent on awkward login flows — iframed forms, two-step username-then-password sequences, banking portals with custom components. Bitwarden requires the right-click fallback more often. Keeper sits between them.
- Interface complexity. Keeper’s consumer product carries visible enterprise inheritance: more concepts, more configuration surface, more screens than a household needs. 1Password is the most refined. Bitwarden is functional and fast rather than pleasant.
- Command line and automation. Bitwarden’s CLI is the most widely used for scripting and CI secret injection, and it is available on the free tier. 1Password’s CLI with secret references is more polished but tied to a paid account.
- Self-hosting. Bitwarden is the only one of the three that a private individual can realistically self-host. Keeper offers on-premises deployment for enterprise customers; 1Password offers none.
Recovery and emergency access
All three support designating a trusted contact who can request vault access after a delay you configure, and all three refuse to reset an account without user-held credentials — which is the correct behaviour for a zero-knowledge system and the reason a physical backup of your credentials is not optional.
The differences are in what happens when it goes wrong. 1Password families have organiser-initiated recovery, the only sanctioned route back into an account whose owner has lost their Secret Key. Bitwarden offers emergency access on paid tiers and organisation-level account recovery for Enterprise. Keeper’s Family plan includes emergency access positioned explicitly for estate planning, alongside enterprise account transfer policies.
Export freedom
The most under-examined dimension in this category, and the one that determines whether a choice is reversible.
- Bitwarden exports the full vault to unencrypted JSON or CSV, or to encrypted JSON protected by a password of your choosing. There is no paywall on export and no restriction on which client can perform it. The password-protected form is a genuine backup format.
- 1Password exports .1pux or CSV from the desktop and mobile apps, but not the browser extension. CSV drops security questions, custom fields, linked items and 2FA backup codes. Exports are plaintext — 1Password’s own warning states that anyone with access to the file can read your passwords — and there is no encrypted export option. Critically, accounts that unlock through SSO cannot export at all.
- Keeper supports encrypted vault export as well as plaintext formats, with export permissions controllable by administrators on business plans.
If reversibility matters to you, the ranking on this dimension is Bitwarden first, Keeper second, 1Password last.
Verdict
Overall pick for privacy-motivated individuals: Bitwarden.
- Bitwarden wins on verifiability, price and exit. Open clients and server, a seven-year published audit record including an academic cryptography review, a free tier that is a complete product rather than a trial, self-hosting for people who want no third party holding ciphertext at all, and unrestricted encrypted export. Set key derivation to Argon2id on day one and it is the strongest position available at any price.
- 1Password wins on experience and on one specific threat. The Secret Key is a real architectural advantage against server-side compromise and credential stuffing, autofill is the most reliable, Watchtower pushes problems at you instead of waiting to be asked, and Travel Mode has no equivalent anywhere. Choose it if a household needs it to work without support calls, or if you cross high-scrutiny borders. Accept that the code is closed and the export path is restricted.
- Keeper wins on accreditation. FedRAMP High, FIPS 140-3 and a decade of SOC 2 Type 2 make it the correct answer for federal, healthcare and regulated environments where a procurement checklist decides the outcome. For a private individual it is the most expensive of the three, with a consumer interface shaped by enterprise requirements and no free tier — the accreditation you are paying for buys you nothing personally.
The one-line rule: individuals and families should take Bitwarden and spend the difference elsewhere; households that will not tolerate friction should take 1Password; organisations with a compliance mandate should take Keeper.
Whichever you choose matters far less than choosing one. All three are zero-knowledge, all three are audited, and all three are dramatically better than reused passwords. The audit evidence and jurisdiction questions that decide a claim like that are the same ones set out in what makes a VPN actually private, and the scoring rules behind every ranking on this site are in our ranking methodology. If you want the rest of the stack assembled around it, the privacy stack builder works through browser, VPN, email and manager together, and our private email provider comparison covers the account those password resets land in.
Sources
- Bitwarden Pricing
- Is Bitwarden Audited? (official audit index)
- 1Password Personal Pricing
- 1Password Security Assessments and Certifications
- 1Password Support: Export Your Data
- Keeper Security: How Keeper Secures Passwords, Secrets and Access
- Keeper Support: How Much Is Keeper?
- 1Password March 2026 Price Increase (MacRumors)
Related
Best VPN for Torrenting Privacy in 2026: Ranked by Evidence
Proton VPN is the best VPN for torrenting privacy in 2026, Mullvad the runner-up, PIA the budget pick. Audits, court records and port forwarding compared.
Tor Browser vs Mullvad Browser: Key Differences
Tor Browser and Mullvad Browser share anti-fingerprinting defenses but differ in IP masking, network routing, speed, and the threat models they suit.
Tor Browser vs VPN for Anonymity: Key Differences
Tor distributes trust across relays, while a VPN centralizes trust in one provider; the comparison covers anonymity, speed, app coverage, and limitations.