By the VPNTruth Editorial TeamPublished Last updated
We read the security pages of 20 password managers and recorded, for each one, whether there is a named auditor, a stated scope, a date, and a result anyone can actually read. Only 7 publish an independent audit covering the consumer product you buy.
There are no affiliate links anywhere on this page. Take the data and use it.
Named auditor, stated scope, a date, and a readable result.
The published scope is the business product, the parent company, or a different product in the same suite.
No auditor, no scope, no date, or no result you can reach.
No audit, no summary, no certification claim with anything behind it.
The most common pattern is not a vendor lying. It is a vendor displaying a real certification whose scope is something other than the product you are buying — a corporate ISO 27001, a SOC 2 over the parent company's antivirus update pipeline, an audit of the business tier, or a no-logs assessment of the VPN sold in the same bundle. All true, none of it about the password vault. 4 of 20 products fall into this category, and a reader skimming for reassurance would not notice.
Several vendors have moved audit material behind trust-centre request forms during the last two years. 1Password's newest publicly readable product audit is from 2020; its 2025 penetration test is listed but gated, so its auditor and scope are not public. Keeper, Dashlane, Kaspersky and Bitdefender all route audit documents through an approval wall. Gating a report is not the same as not having one — but it does mean the claim cannot be checked by the person being asked to trust it.
Of the 5 products whose full audit reports are freely downloadable, the ones publishing on a recurring basis — Bitwarden, Proton Pass, Passbolt, KeePassXC — are all open source. That is not a coincidence so much as a shared disposition: a project that publishes its code has little left to lose by publishing its findings. The two closed exceptions, 1Password and Enpass, publish reports that are either years old or linked from nowhere on their own site.
Product names link to the vendor page each row was built from. Where a claim could not be verified, the row says so.
A named auditor, a stated scope that includes the consumer product, a date, and a result you can read.
The benchmark for this index. One public page lists roughly 19 dated engagements from 2018 onward, each with a directly downloadable full report — no email wall, no NDA, no account. Scope is stated per engagement rather than as a blanket claim.
Caveat: Compliance is the weaker half: no ISO 27001 certificate number or registrar is published, and SOC 2 is available only on request.
Publishes the full unredacted Cure53 report including a high-severity finding, and openly documents one medium-severity Android issue left unresolved because of a platform limitation. Publishing an open finding is rare enough to be worth naming.
A dated audit table with 15 entries, 14 linking to public reports. The one exception is labelled openly as withheld rather than quietly omitted. Per-audit findings pages list severity counts and remediation status, including issues deliberately not fixed.
Caveat: Aimed at teams rather than individuals. The SOC 2 claim carries no audit period, firm or reference.
The only entry whose certification carries everything a reader could check: a certificate number, the issuing body, the named evaluation centre, the exact version evaluated and an expiry date. Narrow scope, but nothing about it is vague.
Caveat: Windows desktop only — Linux, macOS and mobile builds are outside the evaluated scope. A volunteer project, so there is no corporate compliance programme by design.
The newest publicly readable product audit is from 2020 — six years old. A "2025 Annual Pentest" is listed in the Trust Center but its auditor and scope are behind an access request, so transparency has moved backwards, not forwards.
Caveat: The 2020 ISE report is still openly downloadable; treat the current audit posture as effectively gated. No certificate numbers or certifying bodies are published for any ISO or SOC claim.
Names the auditor and lists the precise client versions tested, which most of this index does not. Publishes executive summaries for both engagements rather than full reports, and claims no compliance certifications at all — an unusually plain posture.
Caveat: We could not read either summary PDF: the site blocks automated fetching. Their existence and URLs are confirmed from the vendor help centre; their contents are not attested here.
Hosts its own report PDFs, but links to them from nowhere: the security page, the ISO page and the 2025 security whitepaper all omit them entirely. Good evidence made effectively undiscoverable.
Caveat: The trust centre returned 403 to automated fetching, so anything behind it is unverified. Latest published report is roughly three years old.
A real, documented assessment whose published scope is the business product, the parent company, or a different product entirely.
The consumer security page advertises "regular" independent third-party audits, plural. The only audit documented with an auditor, scope and date is of the business product, is five years old, and exists as a blog summary rather than a report.
Caveat: A 2020 consumer audit is referenced in trade press, but the vendor URL that appears to point to it serves the same Business audit content. We could not reach a vendor page presenting a consumer-scope report.
A genuinely rich corporate trust posture, none of which is scoped to the password manager. The Trust Center lists a pentest report, but behind a request gate and with no public scope statement — so there is no basis for assuming it covers this product.
Caveat: The linked ISO 27001 certificate PDF returned no machine-readable text, so its scope, registrar and number could not be verified either way.
Neither published scope statement includes the password manager, its clients or its vault cryptography. Both documents are available only by request.
Caveat: Separately documented: CVE-2020-27020, in which the password generator was seeded from the system clock, making generated passwords brute-forceable. Found by Ledger's Donjon team, disclosed 2021, fixed by the vendor in 2019–2020 releases. The vendor advisory URL cited by NVD no longer resolves to the advisory text.
The independent validation Norton points to belongs to something else. The AV-TEST and AV-Comparatives certifications cited when the password manager was relaunched are malware-detection efficacy labs; they do not assess vault cryptography.
An audit or certification is claimed with no auditor, no scope, no date, or no readable result — or nothing is published at all.
The longest certification list in this index — 17 badges — and no readable audit artifact of any kind. "Quarterly pen testing against all solutions and systems" is claimed with zero dated instances to check it against.
Caveat: Two badges do carry verifiable identifiers: a FedRAMP package ID and a NIST CMVP FIPS 140-3 certificate number. Both relate to the government environment, not the consumer product.
Annual penetration tests are asserted, but even the summary is NDA-gated and restricted to enterprise customers — so a consumer subscriber has no route to any audit evidence at all.
Caveat: A "security audit" blog tag contains only how-to content about auditing your own security, which a casual reader could easily mistake for disclosure. The Apple apps are source-available under a non-commercial licence, which is not open source.
The vendor with the most to prove publishes the least. After the 2022 breach in which a backup of customer vault data was taken, no independent post-breach security assessment of the product has been published. The only new third-party attestation since is a privacy-management certification.
Caveat: The current security page does not mention the 2022 incident; it is reachable only via a Trust Center link to the original disclosure.
Vault is named in the SOC 2 applicable-services list, which is more than most here manage, but no product-level audit is published in any form — not even a summary.
Caveat: Unusually, Zoho does publish ISO certificate numbers and validity dates — though not the certifying registrar. That is better badge hygiene than almost every dedicated password manager in this index.
The most direct answer any vendor here gives. Asked on Avira's own support forum whether the product had been audited, a community manager replied that it had undergone third-party penetration testing "for internal hardening" but that "there has been no publication of the results", and declined to name the firms.
Caveat: That is a community post rather than a formal security page — the most specific statement Avira has published, but it carries less weight than a signed report.
The technical security whitepaper is version 3, dated September 2015, and contains no audit or certification language. Its only third-party reference is an OEM licensing relationship, which is a commercial arrangement rather than an assessment.
Asked directly on its own support forum whether an audit was on the roadmap, a staff member answered that it was "on our radar" with no timeline. Two major versions have shipped since with no audit accompanying either.
Three vendor-controlled pages contain no reference to any audit, auditor, certification or report. The entire security statement in the privacy policy is one sentence about having "implemented security measures".
Invites scrutiny without enabling it: the encryption page says "security researchers can audit our encryption implementation", while publishing no source code, no specification and no report that would let anyone do so.
Between 1 and 4 August 2026 we read the security, trust and compliance pages of 20 password managers, plus any audit announcements or reports they linked to. Everything recorded comes from the vendor's own properties. Where we used anything else, the row says so.
A security assessment of the product, performed by a named party that is not the vendor, with a scope statement and a date. A bug bounty is not an audit. A malware-detection efficacy certification is not an audit. A compliance certification is not a security audit of a product — it is an attestation about an organisation's controls, and we recorded those separately for exactly that reason.
"Independently audited" is a sentence a vendor can write truthfully while the audit in question covers a different product. This came up often enough that it became the spine of the index. Where an audit is real but covers the business tier, the parent company, or a sibling product in the same bundle, we placed the vendor in the middle group rather than the bottom one — the work was done, it just is not evidence about the thing being sold.
Some of this will be out of date within months, and some of it may be wrong now. Vendors move and gate these pages constantly. Two specific known gaps: RoboForm's summary PDFs could not be read because the site blocks automated fetching, so their contents are not attested here; and Bitdefender's ISO certificate PDF returned no readable text, so its scope is genuinely unknown rather than assumed either way. Both are flagged on their rows.
If you are a vendor and a row is wrong, or an audit exists that we missed, tell us and we will correct it and note the correction. That is not a formality — it is the point of publishing something checkable.
VPNTruth earns affiliate commission on some of the products in this table, including NordPass. NordPass is in the middle group, below several products we earn nothing on, and the products at the top of the index — Bitwarden, Proton Pass, Passbolt, KeePassXC — pay us nothing. There are no affiliate links on this page. You can read oureditorial policyfor how we handle this generally.
Journalists, researchers and other reviewers are welcome to reuse this data with attribution. If you want the underlying notes, including the per-vendor source URLs behind each row, ask us and we will send them.
Editorial team, VPNTruth
An independent review site covering VPNs and privacy tools. We are not owned by, employed by, or operated on behalf of any provider we write about.
We synthesise published testing from independent labs and testing sites — CyberInsider and West Coast Labs among them — and check provider claims against their published audits. We do not run our own speed lab, and we cite the source and test date for every figure.
Affiliate commissions, paid by the provider when you buy through our links. You pay the same price either way. Commission rates play no part in how we rank or score anything.
Edited by Andrius Vaitiekunas.
Read our full editorial policy →