{
  "slug": "lesspass",
  "category": "password-managers",
  "name": "LessPass",
  "description": "Stateless password manager that derives each site's password from the site name, login and a master password, so no vault is stored or synced. The hosted profile server is closed to new users, who can self-host one.",
  "website": "https://lesspass.com",
  "source": "https://github.com/lesspass/lesspass",
  "license": "GPL-3.0",
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 71,
  "coverage": 100,
  "summary": "LessPass scores 71 out of 100 (grade C) on the password managers criteria. It meets 6 of 10 criteria: open source, no trackers or telemetry, no ads or data sales, TLS configuration, end-to-end encrypted vault and local or self-hosted option. It does not meet independent audit, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade D.",
  "url": "https://privacyratings.com/password-managers/lesspass/",
  "markdown": "https://privacyratings.com/password-managers/lesspass/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/lesspass/lesspass/blob/main/LICENSE",
      "note": "GPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.lesspass.android/latest/",
      "note": "Exodus finds no trackers in the Android app, and the website loads no third-party scripts."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://opencollective.com/lesspass",
      "note": "Funded by donations through Open Collective, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=lesspass.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=lesspass.com",
      "note": "Grade D (30/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/lesspass/lesspass#readme",
      "note": "No vault exists: passwords are generated on the device and never stored or synced."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://github.com/lesspass/lesspass#readme",
      "note": "Works without a server, and the optional profile server can be self-hosted."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Passwords are derived on demand and never stored, so there is no vault to export."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "D",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:18.281Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}