RoboForm
Published September 21, 2026· By Juan Martinez
In This Article
RoboForm has been shipping since 2000, which makes it older than most of the category it now competes in, and it is still built by the same privately held company that released it — Siber Systems of Fairfax, Virginia, never venture-funded and never acquired. That continuity shows up in the product as unusually wide platform coverage and renewal pricing that sits near the bottom of the consumer market: $29.88 a year for one person, $47.75 for a five-account household. The tradeoff is that the code is closed and the whole security model rests on a single Master Password, with no secondary account secret to fall back on.
Security
The vault is encrypted with AES-256 using a key derived from the Master Password through PBKDF2 with SHA-256, a random 32-byte salt, and 1,000,000 iterations by default — a figure RoboForm’s own whitepaper calls “sufficiently large,” and one that matches the highest iteration counts used anywhere in this category. PBKDF2 is still not memory-hard, so it gives a GPU-equipped attacker more leverage per dollar than a modern memory-hard derivation function would, but at a million iterations the practical margin against a strong Master Password is substantial.
The architecture is zero-knowledge in the strict sense: only a one-way server-side password derived from the Master Password is ever transmitted, while the Master Password itself and the AES-256 key stay on the device. RoboForm states that recovering either from what the servers hold is computationally infeasible. The enforced minimum for a consumer Master Password is 12 characters including at least four non-numerical ones — Business administrators can raise that bar by policy but not lower it. Sharing between RoboForm users uses a hybrid scheme: a random per-share AES-256 key encrypts the item, and that key is wrapped with RSA-2048 against each recipient’s public key, so only the intended recipient can unwrap it.
Account-level two-factor authentication covers the options that actually matter — TOTP authenticator apps, hardware security keys (RoboForm’s own documentation walks through a YubiKey Security Key C NFC over the WebAuthn flow on both Windows and Mac), and passkeys — alongside the older email and SMS one-time codes. RoboForm’s help center makes a point worth following: storing the 2FA passkey in the device’s own OS-level manager rather than inside RoboForm keeps the second factor outside the vault and preserves access on a new or reset device. Storing it inside RoboForm works too, and is more convenient, but it puts both factors in one place.
What is missing is a second secret. There is no account-level key separate from the Master Password, so an attacker who obtains that one string, plus the server-side data, has everything the derivation needs. One historical note belongs here: in July 2014 researcher Paul Moore disclosed a technique for skipping the app-level PIN lock on older RoboForm mobile apps by editing a preference file — it required a rooted or jailbroken device, and the Master Password was still needed to decrypt anything, and RoboForm committed to re-requiring the Master Password after a reboot once it reproduced the report. No vault data was confirmed exposed then or since.
Privacy & Trust
Secfault Security ran a grey-box penetration test commissioned by Siber Systems, and the summary report — dated 13 February 2025 — is downloadable without a login or an email gate. The scope was unusually broad for this category: the Windows and macOS desktop clients, the Safari extension, the Android and iOS apps, the Chrome, Edge and Firefox extensions, the online portal, and the password-generator source code, tested across 20 person-days of manual dynamic testing and binary analysis between 26 August and 20 September 2024. Secfault found “several vulnerabilities of varying criticality,” reported them, and then retested twice — in late November 2024 and again in February 2025 — confirming the in-scope issues were fully fixed with no directly exploitable vulnerabilities remaining. Its conclusion was that RoboForm “meets an industry-accepted standard of security.” A CISA-aligned vulnerability disclosure and bug bounty program runs alongside it.
That audit is doing heavy lifting, because the code itself is closed. There is no public repository and no way for an outside party to inspect what the clients do beyond what a commissioned tester reports. Closed source is a real limit on verifiability, and the counterweight here is that the published audit is broader and more specific than many open commitments in this market.
Telemetry is the strongest part of the privacy picture. The privacy policy describes account and support data for account management, payment data handled through Stripe, and licensing data — a device-derived Computer ID and Disk ID, both one-way hashed, plus a license GUID — used for activation and license checks. The only diagnostic transmission tied to the product is the version and OS information sent during auto-update checks, and the policy states flatly that the user must opt in to that. It goes on: “Siber only uses minimum of user data necessary to manage user account or to process payment. No other information is collected.” Nothing about vault contents or usage behavior appears anywhere in it. The public marketing site does run Google Analytics, which is a fact about roboform.com and not about the client software.
Ownership adds stability rather than risk. Siber Systems has been privately held and independently run since the 2000 release, with Vadim Maslov as CEO; there is no acquisition history and no investor pressure behind a change of direction. RoboForm is not the company’s only product — GoodSync, a file-synchronization tool, comes from the same shop.
Features
The subscription tiers cover the working set most people need. Data Breach Monitoring scans up to five email addresses against known breach corpora, alerts on exposure, and suggests fixes. A built-in TOTP authenticator generates 2FA codes for other sites and stores them in the vault. Emergency Access hands a designated contact a path into the vault under defined conditions. Secure Shared Folders share logins and notes with four permission levels — owner, manager, regular user, limited user — and the limited-user level is the useful one: it lets someone autofill and log in with a credential without ever seeing the password value itself.
Passkey handling runs in both directions. RoboForm stores and autofills passkeys for third-party sites, saving them into the vault alongside ordinary logins when a site offers passkey login, and a passkey can also be used to authenticate to RoboForm itself.
Form filling is where the product’s age works in its favor. One-click login and form completion work across websites and, on Windows, inside native desktop applications too — a capability that most of this category never built.
The gaps are specific. There is no email-alias generation, so the address you hand a site is the address you own. And the feature list, as published, includes a compromised-password scan but no named password-health report of the kind that grades a whole vault for weak and reused credentials.
Usability & Platforms
Platform coverage is the widest of any password manager reviewed on this site: Windows, macOS, Linux, iOS, Android, Chrome OS, and extensions for Chrome, Firefox, Edge, Safari and others. A Linux desktop and a Chrome OS build are both places where coverage in this category routinely thins out. There is no official command-line client, which is the one notable absence and matters mostly to people scripting credential access.
Third-party reception is the strongest here too. RoboForm holds a 4.6 out of 5 “Excellent” Trustpilot score across 542 reviews — the highest of any password manager reviewed on this site to date — and app-store ratings follow the same pattern at much larger volume: 4.7 on the Apple App Store across 43,200 reviews, 4.6 on Google Play across 32,700, 4.5 on the Chrome Web Store across 3,600, and 4.6 on Edge Add-ons across 657.
Price & Value
The free tier gives you unlimited passwords but locks you to a single device, which makes it a genuine single-machine option rather than a trial — it includes one-click login, the password generator, secure cloud backup, form filling, the compromised-password scan, the built-in TOTP authenticator, Passwordless Unlock and Advanced 2FA. What it does not include is sync, which is the reason most people pay.
Premium renews at $29.88 a year, or $2.49 a month, and unlocks access across all devices, web access, Secure Shared Folders, Emergency Access, Data Breach Monitoring, a local-only mode that skips cloud sync entirely, and priority 24/7 support. Family renews at $47.75 a year for five Premium accounts under one subscription — $3.98 a month for the whole household, under a dollar per person. Those are renewal figures, not first-year promotional rates, and they are among the lowest steady-state prices in the consumer cloud password-manager market. The local-only mode deserves a separate mention: paying for a cloud subscription and then declining the cloud is an option few competitors offer at all.
Pros and Cons
- PBKDF2-SHA256 at 1,000,000 iterations by default, with a random 32-byte salt — the highest order of iteration count used in this category
- Publicly downloadable independent pentest by Secfault Security (Feb 2025) covering desktop clients, mobile apps, browser extensions and the web portal, with every in-scope finding verified fixed on retest
- Account 2FA covers TOTP apps, hardware security keys over WebAuthn, and passkeys — and RoboForm's own docs recommend storing the 2FA passkey outside the vault
- Diagnostic telemetry is opt-in only; the privacy policy describes no vault-content or usage-behavior collection at all
- Widest platform coverage of any password manager reviewed here: Windows, macOS, Linux, iOS, Android, Chrome OS and all major browser extensions
- Premium renews at $29.88/year and Family at $47.75/year for five accounts — among the lowest renewal prices in the category
- Privately held by Siber Systems since the 2000 release, never venture-funded and never acquired
- Closed source with no public repository, leaving the commissioned audit as the only external check on the clients
- No second account secret beyond the Master Password — compromise that one string and the derivation has everything it needs
- PBKDF2 is not memory-hard, so GPU-based cracking gets more leverage per dollar than against a memory-hard derivation function
- No email-alias generation, so every signup uses an address you actually own
- No named password-health report that grades the whole vault for weak and reused credentials
- The free tier is restricted to a single device, which rules out the sync that most people want a manager for
- No official command-line client for scripted credential access
Our Rating
- Security7.5/10
AES-256 with PBKDF2-SHA256 at 1,000,000 iterations by default, zero-knowledge architecture with only a one-way server-side password ever leaving the device, and a full spread of account 2FA — TOTP, hardware security keys, and passkeys. Held back by no memory-hard KDF and no secondary secret beyond the Master Password
- Privacy & Trust7.0/10
Closed source, but backed by a broad-scope, publicly downloadable independent pentest (all major clients, verified retest of every finding) — more transparent than several competitors with no public audit report at all. Privately held since 2000, never venture-funded or acquired, opt-in-only diagnostic telemetry, and no confirmed breach — only an 11-year-old, since-addressed mobile PIN-bypass disclosure
- Features6.5/10
Data Breach Monitoring, built-in TOTP generator, Emergency Access, Secure Shared Folders, and passkeys that are both stored for sites and usable to unlock the vault itself. Missing email aliasing and a dedicated password-health/weak-password report as a named feature
- Usability & Platforms8.0/10
The widest platform spread in this category — Windows, macOS, Linux, iOS, Android, Chrome OS, and browser extensions — paired with the best third-party reputation of any manager reviewed here: a 4.6 Trustpilot score and consistently high app-store ratings across tens of thousands of reviews
- Price & Value8.5/10
Premium renews at $29.88/year ($2.49/mo) and Family at $47.75/year for five accounts — among the lowest renewal prices in this category, well under the mid-market cloud incumbents
Security 30% · Privacy & Trust 25% · Features 20% · Usability 15% · Price 10%
RoboForm lands as the low-cost, wide-reach option with a stronger audit record than its closed source would suggest. The Secfault report is broad, public and ungated, the iteration count is at the top of the category, and the renewal price for a five-person household is under a dollar a month each. Whether that is enough depends on how much weight you put on inspectable code and on a second account secret — neither of which RoboForm offers, and neither of which it pretends to.