{
  "slug": "protonpass",
  "category": "password-managers",
  "name": "Proton Pass",
  "description": "End-to-end encrypted password manager from Proton with apps for desktop, mobile and browsers, built-in email aliases and a TOTP authenticator. The apps are open source.",
  "website": "https://proton.me/pass",
  "source": "https://github.com/protonpass/android-pass",
  "license": "GPL-3.0",
  "platforms": [],
  "jurisdiction": {
    "code": "CH",
    "name": "Switzerland",
    "eyes": null,
    "eu": false,
    "gdpr": true,
    "cloud_act": null
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 80,
  "coverage": 100,
  "summary": "Proton Pass scores 80 out of 100 (grade B) on the password managers criteria. It meets 7 of 11 criteria: no ads or data sales, independent audit, transparency report, tells users about requests, TLS configuration, end-to-end encrypted vault and full export. It partly meets open source, no trackers or telemetry, security headers and local or self-hosted option. It is based in Switzerland: Not in the Five, Nine or Fourteen Eyes; GDPR-style data protection law. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade B+.",
  "url": "https://privacyratings.com/password-managers/protonpass/",
  "markdown": "https://privacyratings.com/password-managers/protonpass/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://github.com/protonpass/android-pass/blob/main/LICENSE",
      "note": "Apps are GPL-3.0. The server is not open source."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "partial",
      "evidence": "https://proton.me/support/share-usage-statistics",
      "note": "No third-party analytics, but Proton apps share usage statistics and crash reports by default, and these can be turned off in settings."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://proton.me/pass/pricing",
      "note": "Funded by paid plans."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://drive.proton.me/urls/T9BGC6B11W#seHd3zMpGo5j",
      "note": "Full report from Recurity Labs covering the browser extensions, mobile and desktop apps and CLI."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://proton.me/legal/transparency",
      "note": "Publishes yearly counts of legal orders received, contested and complied with."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://proton.me/legal/law-enforcement",
      "note": "Users are notified of data requests unless Swiss law or a court order temporarily prohibits it."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://www.ssllabs.com/ssltest/analyze.html?d=proton.me&hideResults=on",
      "note": "Grade A+"
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "partial",
      "evidence": "https://developer.mozilla.org/en-US/observatory/analyze?host=proton.me",
      "note": "Grade B+ (80/100+)"
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "pending",
      "evidence": null,
      "note": "Not tested yet."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://proton.me/pass/security",
      "note": "Vault data is end-to-end encrypted on the device before it is synced."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "partial",
      "evidence": "https://proton.me/support/pass-export",
      "note": "Vaults are stored only in Proton's cloud. Data can be exported."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://proton.me/support/pass-export",
      "note": "Exports to JSON in a ZIP file, optionally PGP-encrypted, or to CSV."
    }
  },
  "tests": {
    "ssllabs": "A+",
    "observatory": "B+",
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T07:01:19.554Z"
  },
  "last_modified": "2026-10-01T07:44:20Z"
}