{
  "slug": "2of3-by-ente",
  "category": "password-managers",
  "name": "2of3 by Ente",
  "description": "Splits a recovery key, password or other secret into three cards with Shamir secret sharing, so that any two cards recover it. It runs entirely in the browser and includes an offline recovery page.",
  "website": "https://2of3.ente.com",
  "source": "https://github.com/ente/ente/tree/main/web/apps/twoof3",
  "license": "AGPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "US",
    "name": "United States",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": false,
    "cloud_act": "provider"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 73,
  "coverage": 100,
  "summary": "2of3 by Ente scores 73 out of 100 (grade C) on the password managers criteria. It meets 7 of 11 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit, transparency report, tells users about requests and security headers. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/password-managers/2of3-by-ente/",
  "markdown": "https://privacyratings.com/password-managers/2of3-by-ente/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/ente/ente/blob/main/LICENSE",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/ente/ente/blob/main/web/apps/twoof3/package.json",
      "note": "The page loads no third-party scripts and the app has no analytics dependencies."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://ente.com/privacy/",
      "note": "Free tool from Ente, which is funded by subscriptions and states it does not sell personal information."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=2of3.ente.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=2of3.ente.com",
      "note": "Grade D (35/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://2of3.ente.com/",
      "note": "Secrets are split in the browser and never sent to a server."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://2of3.ente.com/",
      "note": "Cards are printed or downloaded and kept offline, with a standalone recovery page."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://2of3.ente.com/",
      "note": "Cards can be printed or downloaded as images along with an offline recovery page."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:17.631Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}