What a password manager does and what problem it solves

A password manager stores credentials in a digital vault and helps you retrieve them when you sign in. Instead of reusing a simple password or trying to memorize a different one for every account, you can create unique passwords and let the app store them. That convenience can encourage better habits, but it does not make every account invulnerable: security also depends on protecting your password-manager account and devices, and on having sound recovery practices.

Before comparing brands, consider what else you intend to store besides passwords. Some services let you keep notes, recovery codes, cards or files; others focus on credentials. If you only want to fill in login details, a straightforward vault may be enough. If you plan to store documents or share items with family members, permissions, sharing options and storage limits become more important. The main value is not collecting features, but reducing password reuse and making secure access easier.

A password manager concentrates valuable information in one place, so it is important to assess both vault protection and the possibility of losing access. Purdue’s educational publication on password managers notes their practical usefulness across different devices and platforms, and also highlights multifactor authentication as part of good practice. This is not an audit of any particular service, nor does it show that all products provide the same protection.

Compatibility: make sure it works where you actually need it

Compatibility is not settled simply by checking whether a phone app exists. Check whether the service offers apps for your operating systems, extensions for the browsers you use, and a reasonable way to access your vault from a secondary computer. Autofill behavior matters too: if it works consistently with your browser or operating system, you may be less tempted to save passwords somewhere improvised.

Check your own devices. If you switch between a phone, a personal computer and a work computer, find out whether apps are available for each platform and whether synchronization is included in the plan you are considering. In a shared or family setting, check whether sharing features are available without revealing the master password. The provider’s documentation should describe limits by operating system, browser, device count or account type; do not assume that an advertised feature applies to every plan.

A short checklist can help you avoid choosing the wrong product:

  • The operating systems and browsers you use today.
  • Availability and limits for syncing across devices.
  • Autofill and offline-access options, if you need them.
  • Accessibility, language and support for your sign-in methods.

Compatibility changes over time. Before paying, consult the official download and help pages, and check that the instructions apply to your region and the current version. A general article on the subject cannot replace that check.

Encryption: what it means and what to ask

A provider’s description of a vault as encrypted is a starting point, not a complete assessment. Ask what data is encrypted, where and when encryption takes place, how keys are managed, and what information remains outside the encrypted vault. The phrase end-to-end encryption can help describe a design, but read the service’s technical documentation for its definition rather than inferring details the provider has not published.

Encryption should also be distinguished from total security. Strong encryption alone cannot protect an infected device, a weak master password, a session left open on someone else’s computer or an account taken over through deception. OWASP recommends paying attention to the selection and management of cryptography in systems that store sensitive data; its guidance does not certify individual products. The practical question is whether the provider explains its controls in enough detail for you to understand what they protect and where their limits lie.

Look for documentation that clarifies, at a minimum, the encryption model, how the master password is handled, synchronization, backups and what happens if you lose your credentials. If the service publishes independent audits, security reports or information about vulnerabilities and updates, treat those as supplementary evidence: an audit has a defined scope and date, and cannot demonstrate that future faults will never occur. Technical transparency is more useful than a generic promise of “military-grade security.”

Multifactor authentication: an extra layer, not a substitute

Multifactor authentication (MFA) requires more than one kind of proof to sign in, such as a password and a temporary code. Its purpose is to reduce the risk that a stolen password alone will be enough to gain access; it does not fix a reused master password or make a compromised device safe. Check which methods the manager supports, whether MFA is optional or mandatory, and what alternatives are available if you lose your phone or authentication device.

Methods are not interchangeable in every situation. Codes from an authenticator app, security keys and recovery mechanisms have different requirements and risks. NIST SP 800-63B-4 covers authentication and authenticator management in the context of digital identity; it is a standards reference, not a certification of password managers. For an everyday decision, check that the service documents supported methods and the steps for adding, replacing or revoking an authenticator.

Before enabling MFA, store recovery codes somewhere separate and secure, if the service provides them. Do not keep them only in the same vault they might be needed to recover. Also check whether an alternative method exists and what verification it requires. MFA strengthens defenses against certain attacks, but weak recovery can become a shortcut around that protection.

Account recovery: plan before you need it

Recovery deserves attention because it can determine who gets back in after losing a master password or second factor. Services do not all use the same model: some may allow account recovery under specific conditions; others may have no way to recover encrypted contents if the necessary credentials are lost. Read the official explanation and distinguish between recovering access to the account, resetting a password and recovering vault data: these are not necessarily the same process.

Do not assume technical support can decrypt the vault. If the design means the provider does not have the necessary keys, that may limit recovery, even if it reduces certain kinds of provider access. The trade-off is specific: more recovery routes can help a legitimate user, but they also create processes that must be protected against impersonation. OWASP’s password-reset guidance stresses careful design of these flows; it provides general criteria, not a description of any particular service’s policies.

Before migrating or paying, use the product documentation to answer these questions:

  • What happens if you forget the master password?
  • Which methods can recover or authorize access?
  • Who can initiate recovery, and what proof is required?
  • Is the account recovered, the vault, or both?
  • What data is lost if you do not retain the necessary keys or codes?

If an answer is unclear, contact the provider before storing irreplaceable information. The decision is not about choosing the easiest recovery option, but understanding the risks you accept with each alternative.

Export and migration: leave without exposing copies

Being able to export data reduces dependence on a service and makes it easier to switch managers. Check which export formats are supported, which fields are preserved and whether the process works on the platforms you use. Do not assume that an import will automatically transfer notes, files, folders, shared items or codes: compatibility depends on the formats and features of both the source and destination.

An exported file may be readable as plain text, depending on the format and process. Treat it as a sensitive copy: keep it only for as long as necessary, avoid emailing it or leaving it in an unprotected synced folder, and securely delete it when you are done. If the manager offers encrypted export, check how it is protected and which keys are needed to import it again. OWASP’s cryptographic storage guidance provides general criteria for protecting sensitive data, but it does not guarantee how a particular export feature behaves.

A careful migration reduces errors and exposure:

  1. Review the export documentation for the current service and the import documentation for the new one.
  2. Export only what you need and keep the file in a controlled environment.
  3. Check that important accounts are present in the destination.
  4. Delete temporary files and check synced or downloaded copies.
  5. Keep access to the old manager until you have confirmed that nothing is missing.

If the service offers no clear way out, consider that cost before getting started. Portability is not a minor technical detail: it is also part of your ability to change providers.

Free or paid: compare terms, not labels

A free plan may be enough for one person if it covers their devices, synchronization and access methods. A paid plan may add features such as sharing, extra storage, support or controls for multiple people, but the list varies by service and may change. You cannot conclude that a paid option is more secure simply because it costs money, or that a free option is inherently inadequate.

Compare the specific plan with your needs, not with an isolated promotional table. Check the number of devices, item or file limits, MFA features, recovery, export options and cancellation terms. If an important feature is available only on a higher tier, consider whether you will actually use it. The provider’s official documentation and terms are the right sources for current prices and limits; this guide does not include prices because rates have not been verified by market and date.

Educational research on password managers describes them as potentially convenient and available at no cost across different devices, but does not compare current commercial plans or test specific brands’ security. That distinction matters: a general source helps explain the category, while purchase terms must be checked on the provider’s site. Choose the simplest plan that meets your verified needs and lets you leave without losing your data.