# Bitwarden privacy rating

Open-source, end-to-end encrypted password manager with apps for Windows, macOS, Linux, Android, iOS, the web and browsers, and an option to self-host.

**Our pick.** Syncs across desktop, mobile and browser apps and supports sharing with family or a team. End-to-end encrypted, audited every year, and it can be self-hosted.

## Summary

Bitwarden scores 73 out of 100 (grade C) on the password managers criteria. It meets 8 of 11 criteria: open source, no ads or data sales, independent audit, TLS configuration, security headers, end-to-end encrypted vault, local or self-hosted option and full export. It does not meet no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

- Website: https://bitwarden.com
- Source code: https://github.com/bitwarden/clients
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Windows, macOS, Linux, Android, iOS, Web, Browser extension
- Home page trackers: Google Tag Manager
- Category: [Password managers](https://privacyratings.com/password-managers/)
- Also rated: [Bitwarden Authenticator](https://privacyratings.com/two-factor-authentication/bitwarden-authenticator/) (Two-factor authentication)
- Grade: C (73/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | Yes | All code is public. The apps are GPL-3.0 and the server is AGPL-3.0, and some business features in the same public repositories use the source-available Bitwarden License. | https://github.com/bitwarden/server/blob/main/LICENSE.txt |
| No trackers or telemetry | No | The website loads Google Tag Manager. | https://bitwarden.com/privacy/ |
| No ads or data sales | Yes | Funded by paid plans. | https://bitwarden.com/pricing/ |
| Independent audit | Yes | Full reports are published yearly, including recent audits by Cure53, Fracture Labs, Unit 42 and ETH Zurich. | https://bitwarden.com/assets/5yO7sKgjdwGYg7SXVqD2Vc/4a7ef3cce23d8e929ef3cd8238d3d392/2025_Bitwarden_Core_Application_Security_Report.pdf |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=vault.bitwarden.com&hideResults=on |
| Security headers | Yes | Grade A+ (110/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=vault.bitwarden.com |
| Modern web standards | Not tested yet | Not tested yet. |  |
| End-to-end encrypted vault | Yes | Vault data is encrypted on the device with a key derived from the master password before it is synced. | https://bitwarden.com/help/bitwarden-security-white-paper/ |
| Local or self-hosted option | Yes | The server can be self-hosted. | https://bitwarden.com/help/install-on-premise-linux/ |
| Full export | Yes | JSON (plain or encrypted), CSV, and ZIP with attachments. | https://bitwarden.com/help/export-your-data/ |

Source: https://privacyratings.com/password-managers/bitwarden/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/password-managers/bitwarden.md
