KeePassXC vs LastPass Comparison
| Feature | ||
|---|---|---|
| Overview | ||
| Rating | 8.0 | 6.0 |
| Pricing | Not specified |
Show billing detailsHide billing details
|
| Free tier | Free tier | Limited free tier |
| Established | 2016 | 2008 |
| Platforms | ||
| Security | ||
| Independent security audit | Synacktiv (ANSSI CSPN) 2025Show audit detailsHide audit detailsFirst-level security certification of KeePassXC 2.7.9 on Windows — full source-code review, penetration testing of every security function, and cryptographic and random-number-generator analysis | None on record |
| Source code | Fully open source | Closed source |
| Encryption | AES-256, Argon2dShow detailsHide detailsThe database is encrypted with AES-256 by default (Twofish and ChaCha20 are also selectable) in the KDBX 4 format, with an HMAC-SHA-256 integrity check that detects tampering. The master key is derived with Argon2d by default — a memory-hard function that resists GPU and ASIC cracking — with the older AES-KDF still available. The composite master key can combine a password, a key file, and a YubiKey or OnlyKey challenge-response secret. | AES-256-CBC, PBKDF2-SHA256Show detailsHide detailsThe vault is encrypted client-side with AES-256 in CBC mode. The key is derived from the master password with PBKDF2-SHA256 at a default 600,000 iterations for new accounts (older accounts kept far lower counts for years); one extra PBKDF2 round produces the login hash, and further rounds are applied server-side. Passwords, usernames and notes are encrypted, but item URLs and account metadata are stored unencrypted. |
| Vault 2FA | Hardware keys | TOTP + hardware keys |
| Second-secret model | No | No |
| Past data breach | No | Yes |
| Telemetry | No telemetry | On unless you opt out |
| Features | ||
| Hosting | Local, no cloud | Cloud |
| Passkeys | Stores for sites | Stores + unlocks |
| Built-in email aliases | No | No |
| Company | ||
| Owner | KeePassXC TeamShow detailsHide detailsVolunteer, community-run open-source project under the keepassxreboot organization on GitHub — no company and no venture funding behind it. Development is paid for by donations. Forked from KeePassX in 2016; the KeePass lineage goes back to 2003. | LMI Parent, L.P. (ex-GoTo)Show detailsHide detailsOperated by LastPass US LP under the holding entity LMI Parent, L.P. Spun out of GoTo (formerly LogMeIn) as a standalone company on 1 May 2024; the 2022 breach happened while LastPass was still part of GoTo. GoTo and LastPass continue to share the same private-equity owners, Francisco Partners and Elliott Management. |