Keenvale

Password managers compared: which one fits how you live

Three questions decide this, and none of them is about features. Answer them here and get a straight recommendation, with the reasoning shown.

Some links on this page are commercial. If you buy through them we may earn a commission, at no extra cost to you. It never changes what we recommend or what we write — see our disclosure and editorial policy.

Every password manager will store your passwords. That part is solved, and it is why feature tables are so unhelpful here: they compare the part that no longer differs.

What still differs is what happens when you cannot get in — and which answer suits you depends less on the software than on two things about you: whether you will really keep a piece of paper safe, and whether you will really pay.

So we built the decision as a decision. The selector above asks the three questions that actually separate these products; the rest of this page explains why those are the three.

Why these three questions

They are not arbitrary. Each one maps to a real structural difference documented by the vendors themselves, covered in full in our guide on what happens when you lose access.

The paper question exists because 1Password derives your encryption key from two secrets: your password and a 34-character Secret Key generated on your device. 1Password states plainly that it has "no record of your Secret Key and can't recover it". That is excellent security and an unforgiving failure mode. If the Emergency Kit will end up in a downloads folder, this is not your tool.

The free question exists because Bitwarden's free tier is genuinely usable — but Emergency Access, the recovery feature most likely to save you, sits behind the paid plan. "Free Bitwarden" and "Bitwarden" are not the same product where it matters most.

The trusted-contact question exists because it is the only recovery path that does not depend on an object you have to keep. If there is someone, Bitwarden's model gets considerably stronger.

The short version, if you would rather just read it

You are Pick The catch to know about
Willing to print and store a kit, and to pay 1Password Lose either half of the key and there is no recovery. None.
Wanting free, with someone to trust Bitwarden Emergency Access is a paid feature. Free plus no trusted contact means your only net is an export.
Unwilling to depend on paper Proton Pass Resetting by email returns the account with the vault still encrypted. Keep the 12-word phrase.
Would rather trust a phone than paper or a phrase LastPass Recovery needs a device you were already logged in on, set up in advance. Lose every device and there is nothing left to recover from.

A fourth option, outside the three questions

LastPass answers "what happens when you cannot get in" differently from the other three, and differently enough that it does not fit the selector above. 1Password, Bitwarden and Proton Pass all recover through something you store: a printed kit, an export plus a trusted contact, a twelve-word phrase. LastPass recovers through something you already have logged in — a device, tied to email, SMS or biometrics, configured before you need it.

That is a real trade-off, not a lesser one. A phone you carry every day is harder to lose than a sheet of paper you filed away three years ago. But the artifact-based approach travels; the device-based one does not — wipe or lose every device you have ever authenticated from, and LastPass has nothing left to recover from either, same as the others.

LastPass also disclosed a significant security incident in 2022: an attacker exfiltrated a backup copy of customer vault data, including some fields that were not encrypted (such as website URLs) alongside fields that were. No plaintext password was exposed — the encryption held — but it is the most consequential incident among the four products compared here, and worth knowing before you choose.

What none of them save you from

Whichever you pick: export your vault today and store the file offline. Every failure described above ends well if you have an export and badly if you do not. It costs five minutes and makes the rest of this page academic.

How we reached this

Everything here comes from each vendor's own documentation, quoted rather than paraphrased, with sources listed in the full guide. The detailed breakdown of each option, including current pricing and the specification table, follows below.

Which one fits you

Three questions, one answer. Nothing is sent anywhere — this runs entirely in your browser.

Will you reliably keep a printed sheet of paper safe for years?
Does it need to be free?
Is there someone you would trust with emergency access to everything?

Answer the questions above and the recommendation appears here, with the reasoning shown.

Side by side

 1PasswordAgileBitsBitwardenBitwarden, Inc.Proton PassProton AGLastPassLastPass
What derives the keyPassword + Secret KeyPassword onlyPassword, with key backupMaster password only
Artifact you must keepEmergency Kit (PDF)Export, plus a trusted contact12-word recovery phraseA trusted device or phone number, set up in advance
Vendor can restore accessNoNoAccount yes, data noNo
Trusted-person recoveryFamily organiserEmergency AccessNot offered
Free tierNoYesYesYes, limited to one device type
Worst realistic outcomeTotal lossTotal loss — delete and start overAccount restored, vault lostTotal loss — no trusted device, phone or channel left
Price
Individual US$48.00/yr
Family (up to 5) US$72.00/yr
Checked 5 Aug 2026
Free Free
Premium US$10.00/yr
Family (up to 6) US$40.00/yr
Checked 5 Aug 2026
Free Free
Pass Plus US$23.88/yr
Checked 5 Aug 2026

Who each one is for

1Password

People willing to print and store an Emergency Kit, and to pay for it.

Catch: Lose either half of the key and there is no recovery. None.

Bitwarden

People who want a real free tier and have someone to name as a trusted contact.

Catch: Emergency Access is a paid feature. Free, with no trusted contact, means your only net is an offline export.

Proton Pass

People unwilling to depend on a piece of paper staying safe for years.

Catch: Resetting by email returns the account with the vault still encrypted. Keep the twelve-word phrase.

LastPass

People who would rather rely on a phone they already carry than a printed kit or a memorised phrase.

Catch: Recovery needs a device you were already logged in on. Lose every device and there is nothing left to recover from.

Visit LastPass

1Password

Derives the encryption key from two secrets — your password and a 34-character Secret Key generated on your own device.

What works

  • The Secret Key adds entropy no human memorises, which defends against a server breach in a way single-secret models do not.
  • The vendor never held the Secret Key, so there is no copy to compel or leak.
  • Family organiser can reset an individual member's account.

What to watch

  • Lose either half and there is no recovery. The Secret Key does not rescue you from a forgotten password, and the password does not rescue you from a lost Secret Key.
  • No free tier — a 14-day trial only.
  • The Emergency Kit is handed to you at signup and is easy to treat as onboarding paperwork.

Bitwarden

Derives everything from the master password alone, which makes the model simpler to explain and simpler to lose.

What works

  • The free tier is genuinely usable for storing and syncing passwords.
  • Emergency Access lets a trusted contact take over, which is the only recovery path that does not depend on keeping an object safe.
  • Open source, with a published account-recovery model.

What to watch

  • Emergency Access — the recovery feature most likely to save you — is a paid feature. Free Bitwarden and Bitwarden are not the same product where it matters most.
  • Administrator-driven account recovery is an organisation feature, not a personal one.
  • The documented last resort is to delete the account and create a new one.

Proton Pass

Splits recovery into two outcomes that can happen separately — you can get the account back without getting the vault back.

What works

  • The recovery phrase encrypts a backup copy of your key, so resetting with it keeps everything.
  • Recovery does not depend on keeping a physical document safe.
  • Free tier with unlimited logins and devices.

What to watch

  • Resetting by email or SMS returns the account with the data still encrypted — you log in successfully and the vault is unreadable.
  • The email reset behaves unlike email resets everywhere else on the internet, which is exactly what makes it a trap.
  • The third path, activating a recovery file from a previously trusted device, requires having such a device to hand.

LastPass

Recovery runs through a device you already trust — email, SMS or biometrics — set up before you need it, not a portable artifact like a printed kit or a phrase.

What works

  • Zero-knowledge architecture — LastPass states it has no record of your master password and cannot recover or reset it on your behalf.
  • Three separate recovery channels if configured in advance: an email-triggered local recovery on a trusted device, SMS, or mobile biometrics.
  • Free plan exists, with no trusted-contact or paid step required to enable basic account recovery.

What to watch

  • Recovery depends on still holding a device you used before — not a portable artifact you can store somewhere safe. Lose every device you were ever logged in on and the built-in channels have nothing to recover from.
  • The free plan restricts you to one device type (computers only, or mobile only), which is narrower than Bitwarden's free tier.
  • Disclosed a significant 2022 security incident: an attacker exfiltrated a backup copy of customer vault data, including some unencrypted fields (such as website URLs) alongside the still-encrypted vault contents. No plaintext passwords were exposed, but it is the most consequential incident among the four products on this page.

What we compared, and why

What happens on the day you cannot get in
It is the only event where these products behave differently in kind rather than in degree, and it is the one you will experience once, badly, and possibly permanently.
What you have to keep, and where
Every recovery model depends on an artifact you had to store in advance. Whether that artifact is paper, a phrase or a person is the choice you are actually making.
What the free tier excludes
In this category the paywall tends to sit in front of recovery rather than in front of storage, so the free version and the paid version differ most where it matters most.

What we have not tested yet

Everything here comes from each vendor's own documentation, quoted rather than paraphrased, with sources listed in the full guide. We have not yet run each recovery flow end to end on a live account. When we do, this page gets updated and the change log will say what changed.

Questions

Do I actually need a password manager?

If you reuse passwords anywhere, yes, and the reason is not the strength of any individual password but the blast radius of a single breach. The choice between these three is a smaller decision than the choice to use one at all.

Which is safest?

All three are zero-knowledge, meaning the vendor never holds anything that can decrypt your vault. On cryptographic story alone 1Password is the strongest, because the Secret Key defends against a class of server-side attack the others do not. That is a different question from which is safest for you, which depends on whether you will keep the Emergency Kit.

What if I choose wrong and want to switch later?

All three export your vault, so switching is possible and not especially painful. That is another reason the recovery model matters more than the feature list: features you can change your mind about, a lost vault you cannot.

Sources

  1. 1Password — About your Secret Key
  2. Bitwarden — Forgot my master password
  3. Proton — Recovery phrase
  4. LastPass — Recover your lost master password