{
  "slug": "passbolt",
  "category": "password-managers",
  "name": "Passbolt",
  "description": "Open source password manager for teams built on OpenPGP end-to-end encryption, with browser extensions, mobile and desktop apps. It can be self-hosted or used as a hosted cloud service.",
  "website": "https://www.passbolt.com",
  "source": "https://github.com/passbolt/passbolt_api",
  "license": "AGPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "LU",
    "name": "Luxembourg",
    "eyes": null,
    "eu": true,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "C",
  "score": 66,
  "coverage": 100,
  "summary": "Passbolt scores 66 out of 100 (grade C) on the password managers criteria. It meets 7 of 11 criteria: no ads or data sales, independent audit, TLS configuration, security headers, end-to-end encrypted vault, local or self-hosted option and full export. It partly meets open source. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in Luxembourg: Not in the Five, Nine or Fourteen Eyes; EU member (GDPR). Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.",
  "url": "https://privacyratings.com/password-managers/passbolt/",
  "markdown": "https://privacyratings.com/password-managers/passbolt/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/passbolt/passbolt_api/blob/master/LICENSE.txt",
      "note": "The Community Edition server and apps are AGPL-3.0, but Pro and Cloud features are proprietary."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "no",
      "evidence": "https://www.passbolt.com/privacy",
      "note": "The website loads Google Tag Manager, and the privacy policy lists Google Analytics, Matomo, Plausible, Google Ads and LinkedIn."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.passbolt.com/pricing/pro",
      "note": "Funded by paid Pro and Cloud plans, and the privacy policy says personal information is not sold."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.passbolt.com/docs/files/PBL-13-report.pdf",
      "note": "Full Cure53 and Quarkslab reports are published, including an audit of the version 5 browser extension and API."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No transparency report or government request policy is published."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "no",
      "evidence": null,
      "note": "No published policy on notifying users about data requests."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=www.passbolt.com&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=www.passbolt.com",
      "note": "Grade A+ (115/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://www.passbolt.com/security",
      "note": "Secrets are end-to-end encrypted with OpenPGP keys held by each user."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.passbolt.com/docs/hosting/install/",
      "note": "The server can be self-hosted."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://www.passbolt.com/docs/user/basic-features/browser/export/",
      "note": "All resources can be exported to KDBX, or to CSV when an administrator allows it."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "A+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [
      {
        "name": "Google reCAPTCHA",
        "host": "www.google.com",
        "effect": "none"
      },
      {
        "name": "Google Tag Manager",
        "host": "www.googletagmanager.com",
        "effect": "no"
      },
      {
        "name": "Matomo Cloud",
        "host": "cdn.matomo.cloud",
        "effect": "partial"
      },
      {
        "name": "Plausible",
        "host": "plausible.io",
        "effect": "partial"
      }
    ],
    "tested_at": "2026-10-01T07:01:18.960Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}