{
  "slug": "strongbox",
  "category": "password-managers",
  "name": "Strongbox",
  "description": "Open source password manager for iOS and macOS that works with KeePass (KDBX) and Password Safe databases stored locally, in iCloud or in other cloud storage. It supports AutoFill, TOTP, passkeys and YubiKey.",
  "website": "https://strongboxsafe.com",
  "source": "https://github.com/strongbox-password-safe/Strongbox",
  "license": "AGPL-3.0",
  "platforms": [
    "ios",
    "macos"
  ],
  "jurisdiction": {
    "code": "GB",
    "name": "United Kingdom",
    "eyes": "Five Eyes",
    "eu": false,
    "gdpr": true,
    "cloud_act": "agreement"
  },
  "pick": false,
  "pick_reason": null,
  "disclosure": null,
  "grade": "B",
  "score": 88,
  "coverage": 100,
  "summary": "Strongbox scores 88 out of 100 (grade B) on the password managers criteria. It meets 6 of 7 criteria: open source, no trackers or telemetry, no ads or data sales, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet independent audit. It is based in the United Kingdom: Five Eyes member; GDPR-style data protection law; CLOUD Act data access agreement with the US.",
  "url": "https://privacyratings.com/password-managers/strongbox/",
  "markdown": "https://privacyratings.com/password-managers/strongbox/index.md",
  "answers": {
    "open_source": {
      "title": "Open source",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://github.com/strongbox-password-safe/Strongbox/blob/master/LICENSE.md",
      "note": "AGPL-3.0."
    },
    "no_trackers": {
      "title": "No trackers or telemetry",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://strongboxsafe.com/privacy/",
      "note": "No third-party trackers, and the app uses no analytics. The website's Plausible analytics are cookieless and aggregate-only."
    },
    "no_ads": {
      "title": "No ads or data sales",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://strongboxsafe.com/pricing/",
      "note": "Funded by paid Pro subscriptions and lifetime licenses, with no ads."
    },
    "independent_audit": {
      "title": "Independent audit",
      "weight": 2,
      "answer": "no",
      "evidence": null,
      "note": "No independent audit is published."
    },
    "transparency_report": {
      "title": "Transparency report",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "user_notice": {
      "title": "Tells users about requests",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "tls": {
      "title": "TLS configuration",
      "weight": 2,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "security_headers": {
      "title": "Security headers",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "web_standards": {
      "title": "Modern web standards",
      "weight": 1,
      "answer": "n/a",
      "evidence": null,
      "note": "Only applies to hosted services with a website to test."
    },
    "e2ee_vault": {
      "title": "End-to-end encrypted vault",
      "weight": 3,
      "answer": "yes",
      "evidence": "https://strongboxsafe.com/privacy/",
      "note": "Local-only: databases are encrypted KeePass or Password Safe files, and the developer has no sync service."
    },
    "self_host_or_local": {
      "title": "Local or self-hosted option",
      "weight": 2,
      "answer": "yes",
      "evidence": "https://strongboxsafe.com/privacy/",
      "note": "Databases are local files or files in the user's own cloud storage."
    },
    "export": {
      "title": "Full export",
      "weight": 1,
      "answer": "yes",
      "evidence": "https://github.com/strongbox-password-safe/Strongbox/blob/master/README.md",
      "note": "Databases are KDBX or Password Safe files, open formats read by many apps."
    }
  },
  "tests": {
    "ssllabs": null,
    "observatory": null,
    "internetnl_web": null,
    "internetnl_mail": null,
    "trackers": [],
    "tested_at": "2026-10-01T10:59:36.208Z"
  },
  "last_modified": "2026-10-01T11:14:42Z"
}