{
  "slug": "pass",
  "category": "password-managers",
  "name": "Pass",
  "description": "Command-line password manager that stores each password as a GPG-encrypted file in a folder, with optional git for history and syncing. Many third-party clients and extensions exist.",
  "website": "https://www.passwordstore.org",
  "source": "https://git.zx2c4.com/password-store",
  "license": null,
  "platforms": [],
  "jurisdiction": null,
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 69,
  "coverage": 100,
  "summary": "Pass scores 69 out of 100 (grade C) on the password managers criteria. It meets 5 of 7 criteria: open source, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet no trackers or telemetry and independent audit. Automated tests: Mozilla HTTP Observatory grade B.",
  "url": "https://privacyratings.com/password-managers/pass/",
  "markdown": "https://privacyratings.com/password-managers/pass/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://git.zx2c4.com/password-store/tree/COPYING",
      "note": "GPL-2.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.passwordstore.org/",
      "note": "The pass tool has no telemetry, but the website loads Google Analytics and the Twitter widgets script."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.passwordstore.org/",
      "note": "Free software with no ads, accounts or paid tiers."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.passwordstore.org/",
      "note": "Local-only: each password is a separate GPG-encrypted file, with no sync service."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.passwordstore.org/",
      "note": "Passwords are stored in a local folder that can be synced with any git server."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.passwordstore.org/",
      "note": "Passwords are ordinary GPG files in a folder that standard tools can read."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": "B",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:18.846Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}