VPNTruth
📢 This site contains affiliate links. We may earn a commission if you purchase through our links — at no extra cost to you.
📊 Original research · 4 August 2026

13 of 20 Password Managers Can't Show You the Audit They Advertise

By the VPNTruth Editorial TeamPublished Last updated

We read the security pages of 20 password managers and recorded, for each one, whether there is a named auditor, a stated scope, a date, and a result anyone can actually read. Only 7 publish an independent audit covering the consumer product you buy.

What this is not. This is not a security ranking, and a product with no published audit is not therefore insecure. The claim here is narrower and entirely checkable: this is what each vendor lets you verify. Every cell links to the vendor's own page. Where we could not confirm something, the row says so rather than guessing.

There are no affiliate links anywhere on this page. Take the data and use it.

🔎 What We Found

The Headline Numbers

7/20

publish an audit covering the consumer product

Named auditor, stated scope, a date, and a readable result.

4/20

advertise an audit of something else

The published scope is the business product, the parent company, or a different product in the same suite.

9/20

assert an audit without evidence

No auditor, no scope, no date, or no result you can reach.

6/20

publish nothing at all

No audit, no summary, no certification claim with anything behind it.

1. A badge is not an audit, and the gap is where the marketing lives

The most common pattern is not a vendor lying. It is a vendor displaying a real certification whose scope is something other than the product you are buying — a corporate ISO 27001, a SOC 2 over the parent company's antivirus update pipeline, an audit of the business tier, or a no-logs assessment of the VPN sold in the same bundle. All true, none of it about the password vault. 4 of 20 products fall into this category, and a reader skimming for reassurance would not notice.

2. Transparency is moving in the wrong direction at the top end

Several vendors have moved audit material behind trust-centre request forms during the last two years. 1Password's newest publicly readable product audit is from 2020; its 2025 penetration test is listed but gated, so its auditor and scope are not public. Keeper, Dashlane, Kaspersky and Bitdefender all route audit documents through an approval wall. Gating a report is not the same as not having one — but it does mean the claim cannot be checked by the person being asked to trust it.

3. Every product with a fully public report is open source

Of the 5 products whose full audit reports are freely downloadable, the ones publishing on a recurring basis — Bitwarden, Proton Pass, Passbolt, KeePassXC — are all open source. That is not a coincidence so much as a shared disposition: a project that publishes its code has little left to lose by publishing its findings. The two closed exceptions, 1Password and Enpass, publish reports that are either years old or linked from nowhere on their own site.

How we classified each product

Audit covers the product you buyA named auditor, a stated scope that includes the consumer product, a date, and a result you can read.
Audited — but not this productA real, documented assessment whose published scope is the business product, the parent company, or a different product entirely.
Asserted, not evidencedAn audit or certification is claimed with no auditor, no scope, no date, or no readable result — or nothing is published at all.
📋 The Index

All 20, Grouped by What They Publish

Product names link to the vendor page each row was built from. Where a claim could not be verified, the row says so.

Audit covers the product you buy — 7

A named auditor, a stated scope that includes the consumer product, a date, and a result you can read.

Bitwarden

Open sourceRecurring
Auditor named
Cure53, ETH Zurich Applied Cryptography Group, Unit 42, Fracture Labs and others
Most recent
2025
What it covered
Consumer clients explicitly in scope, split across engagements — mobile apps, browser extension, desktop, web app, network, and a separate cryptography review
Can you read it
full report public

The benchmark for this index. One public page lists roughly 19 dated engagements from 2018 onward, each with a directly downloadable full report — no email wall, no NDA, no account. Scope is stated per engagement rather than as a blanket claim.

Caveat: Compliance is the weaker half: no ISO 27001 certificate number or registrar is published, and SOC 2 is available only on request.

Proton Pass

Open sourceRecurring
Auditor named
Recurity Labs (2026), Cure53 (2023)
Most recent
May 2026
What it covered
Browser extensions, mobile and desktop apps and the CLI — the whole consumer surface, with no separate business carve-out
Can you read it
full report public

Publishes the full unredacted Cure53 report including a high-severity finding, and openly documents one medium-severity Android issue left unresolved because of a platform limitation. Publishing an open finding is rare enough to be worth naming.

Passbolt

Open sourceRecurring
Auditor named
Cure53 (most), Quarkslab, Examin
Most recent
July 2026
What it covered
Itemised per component across 15 dated audits — browser extension, API, mobile, Windows app, SSO, cryptography, account recovery
Can you read it
full report public

A dated audit table with 15 entries, 14 linking to public reports. The one exception is labelled openly as withheld rather than quietly omitted. Per-audit findings pages list severity counts and remediation status, including issues deliberately not fixed.

Caveat: Aimed at teams rather than individuals. The SOC 2 claim carries no audit period, firm or reference.

KeePassXC

Open source
Auditor named
Synacktiv, as evaluation centre for the French ANSSI CSPN certification
Most recent
November 2025
What it covered
Desktop client v2.7.9 on Windows only, against seven declared security functions
Can you read it
full report public

The only entry whose certification carries everything a reader could check: a certificate number, the issuing body, the named evaluation centre, the exact version evaluated and an expiry date. Narrow scope, but nothing about it is vague.

Caveat: Windows desktop only — Linux, macOS and mobile builds are outside the evaluated scope. A volunteer project, so there is no corporate compliance programme by design.

Auditor named
Independent Security Evaluators (ISE)
Most recent
2020
What it covered
Consumer client apps by version — web, iOS, Android and Windows
Can you read it
gated

The newest publicly readable product audit is from 2020 — six years old. A "2025 Annual Pentest" is listed in the Trust Center but its auditor and scope are behind an access request, so transparency has moved backwards, not forwards.

Caveat: The 2020 ISE report is still openly downloadable; treat the current audit posture as effectively gated. No certificate numbers or certifying bodies are published for any ISO or SOC claim.

RoboForm

Recurring
Auditor named
Secfault Security
Most recent
2025
What it covered
Consumer clients enumerated by exact version — Windows, macOS, Android, iOS, browser extensions and the online portal
Can you read it
summary only

Names the auditor and lists the precise client versions tested, which most of this index does not. Publishes executive summaries for both engagements rather than full reports, and claims no compliance certifications at all — an unusually plain posture.

Caveat: We could not read either summary PDF: the site blocks automated fetching. Their existence and URLs are confirmed from the vendor help centre; their contents are not attested here.

Auditor named
Cure53 (2023), VerSprite (2018)
Most recent
June 2023
What it covered
Partial — vault password recovery, vault sharing, and Enpass Hub. Not a full audit of the consumer clients
Can you read it
full report public

Hosts its own report PDFs, but links to them from nowhere: the security page, the ISO page and the 2025 security whitepaper all omit them entirely. Good evidence made effectively undiscoverable.

Caveat: The trust centre returned 403 to automated fetching, so anything behind it is unverified. Latest published report is roughly three years old.

Audited — but not this product — 4

A real, documented assessment whose published scope is the business product, the parent company, or a different product entirely.

Auditor named
Cure53
Most recent
October 2021
What it covered
NordPass Business — apps, browser extensions, Admin Panel and Nord Account. The consumer app is not covered
Can you read it
summary only

The consumer security page advertises "regular" independent third-party audits, plural. The only audit documented with an auditor, scope and date is of the business product, is five years old, and exists as a blog summary rather than a report.

Caveat: A 2020 consumer audit is referenced in trade press, but the vendor URL that appears to point to it serves the same Business audit content. We could not reach a vendor page presenting a consumer-scope report.

Auditor named
None named
Most recent
November 2025
What it covered
SOC 2 Type 2 over "the Bitdefender System" at organisation level. The password manager is named in no certificate or report
Can you read it
summary only

A genuinely rich corporate trust posture, none of which is scoped to the password manager. The Trust Center lists a pentest report, but behind a request gate and with no public scope statement — so there is no basis for assuming it covers this product.

Caveat: The linked ISO 27001 certificate PDF returned no machine-readable text, so its scope, registrar and number could not be verified either way.

Auditor named
None named
Most recent
November 2025
What it covered
Parent-company only — SOC 2 over the antivirus database update process, ISO 27001 over Kaspersky Security Network data services and named data centres
Can you read it
gated

Neither published scope statement includes the password manager, its clients or its vault cryptography. Both documents are available only by request.

Caveat: Separately documented: CVE-2020-27020, in which the password generator was seeded from the system clock, making generated passwords brute-forceable. Found by Ledger's Donjon team, disclosed 2021, fixed by the vendor in 2019–2020 releases. The vendor advisory URL cited by NVD no longer resolves to the advisory text.

Auditor named
None named
Most recent
September 2025
What it covered
None for this product. The named independent assessment — VerSprite — covers Norton VPN server infrastructure and no-logs policy, a different product
Can you read it
none

The independent validation Norton points to belongs to something else. The AV-TEST and AV-Comparatives certifications cited when the password manager was relaunched are malware-detection efficacy labs; they do not assess vault cryptography.

Asserted, not evidenced — 9

An audit or certification is claimed with no auditor, no scope, no date, or no readable result — or nothing is published at all.

Auditor named
NCC Group and CyberTest are listed as providers
Most recent
Nothing dated
What it covered
Not stated. No engagement is tied to a scope, a date or a report
Can you read it
gated

The longest certification list in this index — 17 badges — and no readable audit artifact of any kind. "Quarterly pen testing against all solutions and systems" is claimed with zero dated instances to check it against.

Caveat: Two badges do carry verifiable identifiers: a FedRAMP package ID and a NIST CMVP FIPS 140-3 certificate number. Both relate to the government environment, not the consumer product.

Auditor named
None named
Most recent
Nothing dated
What it covered
Not stated. No auditor is named anywhere on the vendor's own properties
Can you read it
gated

Annual penetration tests are asserted, but even the summary is NDA-gated and restricted to enterprise customers — so a consumer subscriber has no route to any audit evidence at all.

Caveat: A "security audit" blog tag contains only how-to content about auditing your own security, which a casual reader could easily mistake for disclosure. The Apple apps are source-available under a non-commercial licence, which is not open source.

Auditor named
None named
Most recent
Nothing dated
What it covered
Not stated. ISO 27001 and ISO 27701 cover the company management system, not the consumer app
Can you read it
gated

The vendor with the most to prove publishes the least. After the 2022 breach in which a backup of customer vault data was taken, no independent post-breach security assessment of the product has been published. The only new third-party attestation since is a privacy-management certification.

Caveat: The current security page does not mention the 2022 incident; it is reachable only via a Trust Center link to the original disclosure.

Auditor named
None named
Most recent
Nothing dated
What it covered
Not stated. "External penetration tests performed in July 2023" with no firm, no components and no report
Can you read it
gated

Vault is named in the SOC 2 applicable-services list, which is more than most here manage, but no product-level audit is published in any form — not even a summary.

Caveat: Unusually, Zoho does publish ISO certificate numbers and validity dates — though not the certifying registrar. That is better badge hygiene than almost every dedicated password manager in this index.

Auditor named
None named
Most recent
Nothing dated
What it covered
Not stated, and explicitly not published
Can you read it
none

The most direct answer any vendor here gives. Asked on Avira's own support forum whether the product had been audited, a community manager replied that it had undergone third-party penetration testing "for internal hardening" but that "there has been no publication of the results", and declined to name the firms.

Caveat: That is a community post rather than a formal security page — the most specific statement Avira has published, but it carries less weight than a signed report.

Auditor named
None named
Most recent
Nothing dated
What it covered
Nothing published, for any component
Can you read it
none

The technical security whitepaper is version 3, dated September 2015, and contains no audit or certification language. Its only third-party reference is an OEM licensing relationship, which is a commercial arrangement rather than an assessment.

Auditor named
None named
Most recent
Nothing dated
What it covered
Nothing published, for any component
Can you read it
none

Asked directly on its own support forum whether an audit was on the roadmap, a staff member answered that it was "on our radar" with no timeline. Two major versions have shipped since with no audit accompanying either.

Auditor named
None named
Most recent
Nothing dated
What it covered
Nothing published, for any component
Can you read it
none

Three vendor-controlled pages contain no reference to any audit, auditor, certification or report. The entire security statement in the privacy policy is one sentence about having "implemented security measures".

Auditor named
None named
Most recent
Nothing dated
What it covered
Nothing published, for any component
Can you read it
none

Invites scrutiny without enabling it: the encryption page says "security researchers can audit our encryption implementation", while publishing no source code, no specification and no report that would let anyone do so.

🔬 Method

How This Was Built, and How to Argue With It

Between 1 and 4 August 2026 we read the security, trust and compliance pages of 20 password managers, plus any audit announcements or reports they linked to. Everything recorded comes from the vendor's own properties. Where we used anything else, the row says so.

What counted as an audit

A security assessment of the product, performed by a named party that is not the vendor, with a scope statement and a date. A bug bounty is not an audit. A malware-detection efficacy certification is not an audit. A compliance certification is not a security audit of a product — it is an attestation about an organisation's controls, and we recorded those separately for exactly that reason.

Why scope is the pivotal field

"Independently audited" is a sentence a vendor can write truthfully while the audit in question covers a different product. This came up often enough that it became the spine of the index. Where an audit is real but covers the business tier, the parent company, or a sibling product in the same bundle, we placed the vendor in the middle group rather than the bottom one — the work was done, it just is not evidence about the thing being sold.

What we got wrong, probably

Some of this will be out of date within months, and some of it may be wrong now. Vendors move and gate these pages constantly. Two specific known gaps: RoboForm's summary PDFs could not be read because the site blocks automated fetching, so their contents are not attested here; and Bitdefender's ISO certificate PDF returned no readable text, so its scope is genuinely unknown rather than assumed either way. Both are flagged on their rows.

If you are a vendor and a row is wrong, or an audit exists that we missed, tell us and we will correct it and note the correction. That is not a formality — it is the point of publishing something checkable.

Our own conflict of interest

VPNTruth earns affiliate commission on some of the products in this table, including NordPass. NordPass is in the middle group, below several products we earn nothing on, and the products at the top of the index — Bitwarden, Proton Pass, Passbolt, KeePassXC — pay us nothing. There are no affiliate links on this page. You can read oureditorial policyfor how we handle this generally.

Use it

Journalists, researchers and other reviewers are welcome to reuse this data with attribution. If you want the underlying notes, including the per-vendor source URLs behind each row, ask us and we will send them.

VPNTruth Editorial Team

Editorial team, VPNTruth

What VPNTruth is

An independent review site covering VPNs and privacy tools. We are not owned by, employed by, or operated on behalf of any provider we write about.

How we evaluate

We synthesise published testing from independent labs and testing sites — CyberInsider and West Coast Labs among them — and check provider claims against their published audits. We do not run our own speed lab, and we cite the source and test date for every figure.

How we make money

Affiliate commissions, paid by the provider when you buy through our links. You pay the same price either way. Commission rates play no part in how we rank or score anything.

Edited by Andrius Vaitiekunas.

Read our full editorial policy →