KeePassXC vs Keeper Comparison
| Feature | ||
|---|---|---|
| Overview | ||
| Rating | 8.0 | 7.1 |
| Pricing | Not specified |
Show billing detailsHide billing details
|
| Free tier | Free tier | Limited free tier |
| Established | 2016 | 2011 |
| Platforms | ||
| Security | ||
| Independent security audit | Synacktiv (ANSSI CSPN) 2025Show audit detailsHide audit detailsFirst-level security certification of KeePassXC 2.7.9 on Windows — full source-code review, penetration testing of every security function, and cryptographic and random-number-generator analysis | None on record |
| Source code | Fully open source | Closed source |
| Encryption | AES-256, Argon2dShow detailsHide detailsThe database is encrypted with AES-256 by default (Twofish and ChaCha20 are also selectable) in the KDBX 4 format, with an HMAC-SHA-256 integrity check that detects tampering. The master key is derived with Argon2d by default — a memory-hard function that resists GPU and ASIC cracking — with the older AES-KDF still available. The composite master key can combine a password, a key file, and a YubiKey or OnlyKey challenge-response secret. | AES-256-GCM, PBKDF2 1MShow detailsHide detailsEach record is encrypted client-side with its own 256-bit AES-GCM key; those record keys are wrapped by a per-user Data Key, which is in turn wrapped by a key derived from the master password with PBKDF2-HMAC-SHA256 at 1,000,000 iterations (128-bit salt) — the highest iteration count among the managers reviewed here. Every field is encrypted, including URLs, titles, notes, custom fields, TOTP secrets and file attachments. The offline cache uses a separate randomly generated Client Key protected with PBKDF2-HMAC-SHA512. A hybrid Kyber key-encapsulation layer began rolling out across the clients in November 2025. |
| Vault 2FA | Hardware keys | Hardware keys |
| Second-secret model | No | No |
| Past data breach | No | No |
| Telemetry | No telemetry | On unless you opt out |
| Features | ||
| Hosting | Local, no cloud | Cloud |
| Passkeys | Stores for sites | Stores + unlocks |
| Built-in email aliases | No | No |
| Company | ||
| Owner | KeePassXC TeamShow detailsHide detailsVolunteer, community-run open-source project under the keepassxreboot organization on GitHub — no company and no venture funding behind it. Development is paid for by donations. Forked from KeePassX in 2016; the KeePass lineage goes back to 2003. | Keeper Security, Inc.Show detailsHide detailsFounder-led (Darren Guccione, CEO; Craig Lurey, CTO), headquartered in Chicago with a product office in El Dorado Hills, California and sales offices in Cork, Ireland and Tokyo. Two minority growth-equity investments: Insight Partners ($60M, August 2020 — the company's first outside equity) and Summit Partners (May 2023). No majority-stake acquisition; the founders retain control. |