PrivacyPick

KeePassXC vs LastPass Comparison

Feature
Overview
Rating8.06.0
PricingNot specified
  • $3.00/moPremium (individual, 1-year)
  • $4.00/moFamilies (6 users, 1-year)
Show billing details
  • Premium (individual, 1-year): $36 per year
  • Families (6 users, 1-year): $48 per year
Free tierFree tierLimited free tier
Established20162008
Platforms
WindowsmacOSLinuxBrowser extensionCLI
WindowsmacOSiOSAndroidBrowser extensionCLI
Security
Independent security auditSynacktiv (ANSSI CSPN) 2025
Show audit details

First-level security certification of KeePassXC 2.7.9 on Windows — full source-code review, penetration testing of every security function, and cryptographic and random-number-generator analysis

None on record
Source codeFully open sourceClosed source
EncryptionAES-256, Argon2d
Show details

The database is encrypted with AES-256 by default (Twofish and ChaCha20 are also selectable) in the KDBX 4 format, with an HMAC-SHA-256 integrity check that detects tampering. The master key is derived with Argon2d by default — a memory-hard function that resists GPU and ASIC cracking — with the older AES-KDF still available. The composite master key can combine a password, a key file, and a YubiKey or OnlyKey challenge-response secret.

AES-256-CBC, PBKDF2-SHA256
Show details

The vault is encrypted client-side with AES-256 in CBC mode. The key is derived from the master password with PBKDF2-SHA256 at a default 600,000 iterations for new accounts (older accounts kept far lower counts for years); one extra PBKDF2 round produces the login hash, and further rounds are applied server-side. Passwords, usernames and notes are encrypted, but item URLs and account metadata are stored unencrypted.

Vault 2FAHardware keysTOTP + hardware keys
Second-secret modelNoNo
Past data breachNoYes
TelemetryNo telemetryOn unless you opt out
Features
HostingLocal, no cloudCloud
PasskeysStores for sitesStores + unlocks
Built-in email aliasesNoNo
Company
OwnerKeePassXC Team
Show details

Volunteer, community-run open-source project under the keepassxreboot organization on GitHub — no company and no venture funding behind it. Development is paid for by donations. Forked from KeePassX in 2016; the KeePass lineage goes back to 2003.

LMI Parent, L.P. (ex-GoTo)
Show details

Operated by LastPass US LP under the holding entity LMI Parent, L.P. Spun out of GoTo (formerly LogMeIn) as a standalone company on 1 May 2024; the 2022 breach happened while LastPass was still part of GoTo. GoTo and LastPass continue to share the same private-equity owners, Francisco Partners and Elliott Management.