| Storage model | Cloud-synced encrypted vault | Cloud-synced encrypted vault |
|---|
| Key derivationKey derivation sets how expensive each attacker guess is. A vendor that does not publish its parameters cannot be independently compared on this. | PBKDF2-HMAC-SHA256, 650,000 iterations | PBKDF2-HMAC-SHA256 at 600,000 iterations (default), or Argon2id at 32 MiB / 6 iterations / 4 lanes |
|---|
| Source code | Proprietary | Source available; clients are open source, some server components use the Bitwarden License rather than AGPL |
|---|
| Independent audits | Publishes independent assessments, including a 2020 ISE code review, plus ongoing penetration testing via its Trust Center. | Numerous published reports from Cure53, IOActive, ETH Zurich and Unit 42. |
|---|
| Free tier | No permanent free tier | Yes — unlimited items and devices |
|---|
| Main free-tier limit | No free tier | Emergency Access is premium-only, and free organisation sharing is capped at two users |
|---|
| Account recovery | Reusable recovery codes for individual and family accounts; family organisers and business admins can recover other members. | No master-password reset for personal accounts unless Emergency Access was configured in advance. Enterprise admins can perform enrolled account recovery. |
|---|
| Passkeys | Saves, syncs, shares and uses website passkeys. | Stores and uses website passkeys; passkey login to the Bitwarden account itself requires a PRF-capable browser. |
|---|
| Platforms | macOS, Windows, Linux, iOS, Android, plus major browser extensions. | All major desktop and mobile OSes, browsers, a web vault and a CLI. |
|---|
| Documented incidents“None found” means no authoritative report surfaced during research. It is not a claim that no incident has ever occurred. | September 2023: an attacker used a session tied to the Okta support breach to reach 1Password's employee Okta tenant. 1Password reported no compromise of user data. | None found in published sources |
|---|