Compare password managers by security model
Compare how password managers protect, recover, synchronize, and export your vault before trusting one with your accounts.
Compare the security model
Check whether the provider explains where encryption and decryption occur, who can access vault data, how independent security findings are handled, which devices are supported, and whether autofill, two-step login, recovery, and protected exports meet your needs.
Understand recovery before depending on it
A provider may be unable to recover a forgotten master password. Organization-managed recovery can follow a different model. Before migrating, confirm the exact recovery route, test two-step login, store its recovery code separately, and make sure you can regain access without weakening account security.
For the separate choice of how to protect the password-manager account itself, use Compare two-step verification methods before choosing one.
Use a pass-or-reject migration test
- Import only a few non-critical entries first.
- Verify those entries on every device and browser you expect to use.
- Test autofill, manual copy, synchronization, two-step login, and the documented recovery route.
- Confirm that you can export your data in a usable format and understand whether that export is encrypted.
Reject a service if its encryption or recovery model is unclear, required autofill does not work reliably, it lacks a practical export route, or it requires you to weaken two-step login. Do not delete the old vault until the new vault has been checked, recovery works, and a protected backup exists. Securely remove any unencrypted export after the migration is verified.
Last verified: 6 September 2026 · Bitwarden security whitepaper · Export guidance · Account recovery