Independent decision guides

Choose a password manager by its security and recovery model

Evaluate a password manager by the failures it can survive: a lost device, a forgotten account credential, a family emergency, an administrator departure, or a provider switch. Price and autofill matter, but recovery ownership, factor separation, export paths, and tested portability determine whether access lasts.

Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.

Fair-comparison note: login.com has no affiliate relationship with the products compared, accepts no placement payment, and makes no universal winner claim.

Last reviewed: 2026-08-17 · Report a change

Short answer

What to know before you start

A password manager should be judged by more than price or autofill. Compare how it protects the vault account, stores passkeys and one-time codes, supports recovery, separates family or business access, exports data, and responds to a lost device. The best choice is the model you can secure, understand, test, and leave without losing access.

01 · decision point

Begin with the account that unlocks every other account

A password manager concentrates credentials so people can use unique, random passwords instead of remembering or reusing them. That is a major security benefit, but it makes the vault account high impact. Review the provider's sign-in design, key derivation or account-secret model, multifactor options, device authorization, session controls, and alerts. Marketing claims about encryption matter only when paired with an understandable recovery and device lifecycle.

Use a unique master password and phishing-resistant authentication when the provider supports it. Protect the email account that receives notices or recovery messages. Keep emergency information outside the locked vault and test the recovery route before travel or a device replacement. A vault that is perfectly encrypted but impossible for its owner to recover can still fail the user's real need.

02 · decision point

Separate password, passkey, and authenticator questions

Modern managers may save passwords, passkeys, TOTP secrets, recovery codes, secure notes, and identity records. Those features are not interchangeable. A passkey uses public-key cryptography bound to a service; a TOTP entry stores a shared secret that creates relayable codes; a recovery code is usually a static bypass. Ask where each item is stored, how it syncs, which devices can use it, and what happens during export or account recovery.

Convenience can change risk. Storing a password and its one-time code in the same vault makes strong daily protection easier but reduces separation if the unlocked vault is compromised. Saving passkeys in a manager can improve cross-platform availability but makes the provider account part of their recovery model. Use separate hardware keys for high-impact accounts when the additional custody burden is justified.

03 · decision point

Compare recovery without looking for a magic reset

Zero-knowledge or end-to-end encrypted products generally cannot offer an ordinary support-agent password reset that reveals the existing vault. Providers use different combinations of recovery codes, account secrets, trusted devices, family organizers, enterprise administrators, emergency access, and data export. Document exactly which path applies to the chosen plan. A family feature may not exist on an individual account, and an administrator reset may restore access without exposing prior private data.

Rehearse device loss while a working session remains open. Verify another approved device, print or protect the required emergency information, and confirm who owns organization recovery. Avoid putting every dependency on one phone or mailbox. If the model cannot be explained in a short private note, the user is not ready to rely on it for irreplaceable credentials.

04 · decision point

Evaluate portability before lock-in becomes urgent

Exports help users change providers and create controlled backups, but export files can contain a readable copy of the entire credential collection. Check which item types transfer: passwords often move more easily than passkeys, attachments, custom fields, TOTP seeds, sharing permissions, or historical records. Perform migrations on a trusted computer, protect temporary files, verify the imported data, and remove unneeded copies from downloads and cloud sync.

Do not judge portability only by the presence of an Export button. Review the documented format, encryption state, supported import targets, and whether shared collections preserve ownership. A clean exit plan reduces pressure during a price, policy, platform, or employment change. It also reveals which credentials need independent recovery rather than depending entirely on one vendor.

05 · decision point

Use the comparison pages as a starting framework

The comparisons below rely on current first-party documentation for security architecture, passkeys, authenticator features, and account protection. They do not declare a universal winner or test proprietary cryptography. Each comparison identifies differences that can change a real deployment decision and leaves plan-specific or undocumented behavior unverified. Product availability and packaging can change, so verify the provider's live plan page before purchasing.

Start with Bitwarden versus 1Password for an open-source and account-secret contrast, Dashlane versus 1Password for passkey and recovery workflow differences, or Proton Pass versus Bitwarden for ecosystem and portability questions. Then test the finalists with non-critical accounts. Confirm browser and mobile behavior, import accuracy, passkey support, device replacement, and family or team administration before moving the accounts that control email, domains, finances, or work access.

Practical sequence

Use this checklist before changing the account

  1. 01

    Protect the vault account with a unique secret and strongest factor.

  2. 02

    Map recovery, trusted devices, organizers, and administrator roles.

  3. 03

    Decide whether passwords and TOTP codes should share a vault.

  4. 04

    Verify passkey support on every operating system you use.

  5. 05

    Inspect export coverage and the sensitivity of temporary files.

  6. 06

    Pilot with low-risk accounts before migrating high-impact identities.

Side-by-side comparison

Compare the relevant trade-offs

Decision areaQuestion to answerEvidence to collectFailure to rehearse
Vault accessHow is the manager account authenticated?Official security and MFA documentationLost or compromised primary device
RecoveryWho can restore access, and to what?Recovery-code, organizer, and admin policyMaster secret forgotten
Credential typesWhich passwords, passkeys, and TOTP items sync?Feature and platform documentationNew operating system or browser
PortabilityWhat can be exported and in which form?Official import and export guidanceProvider or employment exit

Common questions

Choose a password manager by its security and recovery model FAQ

Which password manager is safest?

There is no universal winner. Choose a well-documented product whose authentication, recovery, device, sharing, and export model fits the people and accounts involved.

Should a password manager store 2FA codes?

Integrated TOTP improves usability but shares a security boundary with passwords. Keep phishing-resistant or separate factors for the highest-impact accounts when practical.

Can I move passkeys between managers?

Portability varies by provider, platform, and evolving standards. Verify current export and import documentation before relying on a migration path.

Continue on login.com

Related independent guidance

Continue the decision

More decision guides

Primary-source ledger

Official documentation reviewed

Product features, plan packaging, and interfaces can change. The claims above are limited to the official documentation linked here and the review date shown on this page. Recheck the live provider material before changing a high-impact account or buying a subscription.

  1. NIST SP 800-63B-4: Password managers ↗Checked 2026-08-17
  2. FIDO Alliance: Passkeys ↗Checked 2026-08-17