{
  "slug": "nordpass",
  "category": "password-managers",
  "name": "NordPass",
  "description": "Closed source password manager from Nord Security, the company behind NordVPN, with desktop, mobile and browser apps. Vaults are encrypted on the device with XChaCha20 and synced through NordPass servers.",
  "website": "https://nordpass.com",
  "license": null,
  "platforms": [
    "windows",
    "macos",
    "linux",
    "android",
    "ios",
    "web"
  ],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "D",
  "score": 45,
  "coverage": 100,
  "summary": "NordPass scores 45 out of 100 (grade D) on the password managers criteria. It meets 4 of 11 criteria: no ads or data sales, TLS configuration, end-to-end encrypted vault and full export. It partly meets independent audit and local or self-hosted option. It does not meet open source, no trackers or telemetry, transparency report, tells users about requests and security headers. Automated tests: SSL Labs grade A and Mozilla HTTP Observatory grade C.",
  "url": "https://privacyratings.com/password-managers/nordpass/",
  "markdown": "https://privacyratings.com/password-managers/nordpass/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "no",
      "evidence": null,
      "note": "Closed source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://reports.exodus-privacy.eu.org/en/reports/com.nordpass.android.app.password.manager/latest/",
      "note": "The Android app contains AppsFlyer, Google Firebase Analytics, Crashlytics and Sentry."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://business.nordsec.com/legal/privacy-policy",
      "note": "Funded by subscriptions, and the privacy policy says Nord does not sell or share personal information."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://nordpass.com/blog/nordpass-business-independent-security-audit/",
      "note": "Cure53 audited the apps, but only a summary is public and it is older than three years."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=app.nordpass.com&hideResults=on",
      "note": "Grade A"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "no",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=app.nordpass.com",
      "note": "Grade C (55/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://nordpass.com/security/",
      "note": "Zero-knowledge design: vault data is encrypted on the device and NordPass cannot read it."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://support.nordpass.com/hc/en-us/articles/360007646477-How-to-export-passwords-from-NordPass",
      "note": "Vaults are stored only in the NordPass cloud. Data can be exported."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://support.nordpass.com/hc/en-us/articles/360007646477-How-to-export-passwords-from-NordPass",
      "note": "Exports vault items to a CSV file."
    }
  },
  "tests": {
    "ssllabs": "A",
    "observatory": "C",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T10:59:42.864Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}