Start with how you will actually use it, not the feature list
A password manager brings together credentials that might otherwise be scattered across a browser, notes and memory. Choosing one means assessing both how well it protects that collection and whether you can practically use it when you need it. The best option is not necessarily the one with the most tools, but the one that fits your devices, habits and tolerance for temporarily losing access. Before comparing brands, define the problem you want to solve.
Write down the systems you will sign in on: computer, phone, tablet, and whether you need to use more than one platform. Check that compatible apps or extensions are available for your current operating systems and browsers, and find out what happens if one of your devices is unavailable. If you share passwords with other people, distinguish between sharing occasional credentials and maintaining a shared collection with separate permissions. Do not assume an individual plan includes family or team features: check the provider’s documentation for limits and access arrangements.
Make a short list of essential requirements and separate them from features you would merely like to have. For example: access on two operating systems, sharing with one person, storing recovery codes, a way to export the vault and an additional-factor option. Prioritising requirements helps prevent an appealing demonstration or secondary feature from overshadowing basic questions. It also makes the comparison verifiable: for each requirement, look for a current written explanation, not just a promotional claim.
Encryption: ask what it protects and who can decrypt it
The word “encryption” alone is not enough to assess a password manager’s security. Look for documentation explaining which data is encrypted, when encryption takes place, what happens during synchronisation and what information might remain outside the encrypted vault. Also check where and how the key needed to decrypt the data is managed. A technical description should help you understand what the provider can and cannot do, without assuming that a label such as “zero knowledge” answers every question by itself.
One useful distinction is between protecting stored data and protecting the account that allows access to it. Vault encryption does not eliminate the risk of someone obtaining the master password, taking control of an open session or persuading the user to hand over a code. It is therefore worth understanding authentication measures, sign-in notifications and options to close sessions or revoke devices, where available. Encryption is one part of protection, not an absolute guarantee of security.
OWASP’s Cryptographic Storage Cheat Sheet recommends choosing appropriate cryptographic mechanisms and carefully protecting keys, rather than treating an algorithm as a solution in isolation. Apply that idea to concrete questions when comparing services: is the encryption model explained? What secrets are required to open the vault? How is data synchronised? What happens on new devices? If the documentation does not provide understandable answers, do not fill the gaps with assumptions. A commercial security claim is not equivalent to an independent audit, and does not by itself describe the risk of every component.
Recovery: find out what happens before you need it
Recovery deserves as much attention as everyday access. If you forget your master password, lose your phone or change your number, what steps does the service allow? Is there a recovery contact, an emergency key, an already authenticated device or a support process? Check the requirements for each option and who can initiate it. It is not enough for a page to say “recover your account”: you need to know what is recovered, what identity evidence is required and whether someone could reset access without your secrets.
There is an important tension: a process that makes account recovery easier can also create a route for a third party to try to take over the account. Conversely, a design in which only the user controls the necessary secrets can leave the vault inaccessible if those secrets are lost. No single answer suits everyone. What matters is understanding the service’s trade-off and preparing in advance the recovery methods it offers. Do not wait until the day you can no longer sign in to discover the procedure.
Write down, somewhere safe and separate from the phone you normally use, the steps you will need to follow and the items you must not lose. Avoid keeping the only copy of a recovery key inside the very vault that the key would let you access again. If the provider lets you name a trusted person or use an alternative device, confirm the conditions, time limits and information shared. OWASP’s password-reset guidance offers a general framework for assessing account-recovery processes; it does not certify a particular password manager or replace the documentation for the service you choose.
Portability: check the exit before importing anything
Export is a practical test of independence. Confirm whether the service lets you export your records, which categories it includes and what format it uses. A file may contain usernames and passwords but omit attachments, notes, tags, custom fields or shared data. Also check whether exporting works from the app you will use and whether it requires administrator permissions or a particular subscription. The key question is not simply whether you can download something, but how much of your information you could rebuild in another password manager.
The format matters because services do not all interpret fields in the same way. 1Password’s documentation, for example, describes 1PUX as an unencrypted export format. That is a specific reference to one product, not a promise that every password manager can import all its data. Separately check which formats the destination service accepts and which items it recognises. If migration depends on an intermediate file, find out how to protect it and when to delete it. A readable export can make switching easier and, at the same time, expose credentials if it is left unprotected.
Plan migration as a controlled process, not as a download left in your downloads folder. A prudent sequence is to review the source and destination instructions; export only when you are ready to import; keep the file outside synced or shared folders; complete the import; check a sample of important records; and securely delete the temporary file. Do not erase the old vault until you have confirmed that you can access essential data in the new service and are not relying on notes or fields that did not transfer.
Authentication and extra features: assess their practical value
Multifactor authentication adds a check beyond the password, but its value depends on which methods the service supports and how you recover them if you lose the device. Check whether you can register more than one method, save recovery codes and review active sessions. Do not confuse enabling a second factor to sign in to the password-manager service with storing the second-factor codes for other accounts in the vault: these are different uses, and it is worth understanding their dependencies before deciding where each item should be stored.
NIST SP 800-63B addresses digital authentication in the context of identity services; it is not a ranking of commercial password managers or a product certification. It does, however, provide context for asking how authenticators and recovery are managed. For a day-to-day comparison, look for current documentation on supported methods, security notifications and options to close or revoke access. If an important feature is available only on certain platforms or plans, note that limitation and check that it applies to your market and account type.
Assess other features by the risk they reduce or the task they solve. Sharing can be useful for a family, but permissions and access removal need to be clear. Alerts can flag a password worth reviewing, although they do not replace changing it on the affected site. Autofill reduces friction, but it is worth checking how it behaves in the apps and browsers you use. Do not award extra points for tools you will not use: a long feature list does not make up for a recovery process you do not understand or an inadequate export option.
Final checklist and migration with a safety margin
Before creating a permanent vault, take a few minutes to check the aspects that are often hidden behind the interface. Look for recent official documentation and confirm that it covers your platform, plan and region. If an answer affects your decision—for example, how to recover the account or export data—save it or note where to find it later. Pages can change; a screenshot or isolated printout does not guarantee that the terms are still current.
Use this list as a practical filter, not a universal score:
- Compatibility: Does it work on the devices, operating systems and browsers you actually use?
- Protection: Does the documentation explain what is encrypted, how the vault is accessed and how keys are managed?
- Recovery: Do you know what to do if you lose the master password, phone or access to a second-factor method?
- Portability: Can you export your data, and do you know which fields the file preserves and what the destination accepts?
- Sharing and authentication: Are the permissions, access methods and revocation mechanisms right for your situation?
- Terms: Are the features you need available on your platform, plan and in your market?
Conclusion: choose a trade-off you can manage
Comparing password managers is not about finding a risk-free service. It means identifying which risks each design reduces, which responsibilities remain with the user and which limitations cannot be fixed by adding another feature. Everyday security depends on technology as well as operational decisions: retaining recovery methods, protecting devices, not reusing the master password and limiting exposure of exported files. A manager you understand and can maintain is usually a stronger choice than one selected for a promise that is difficult to verify.
Before moving all your credentials, test the process with a non-critical account if the service allows it. Check that sign-in, autofill and synchronisation work on your devices; review recovery; and confirm that you can locate and export your data. Then migrate calmly, change weak or reused passwords on the sites themselves, and enable additional protection methods where available. NIST recommendations on passwords and authentication provide general context, but do not replace the service’s instructions or the policies of the accounts you protect.
You should be able to summarise the final decision clearly: what the password manager protects, how you can get back in if something goes wrong, and how you can leave if you change your mind. If you cannot answer those three questions using verifiable documentation, keep comparing. You do not need to decide based on a popularity table or a single figure: prioritise compatibility, understandable recovery and portability you can carry out safely.