Password · guide

Is Bitwarden safe? The audits, and the part they leave open

By Alberto Gulotta · Updated · 18 min read

Yes, on evidence anyone can open and check: Bitwarden publishes twenty-five dated third-party assessments by eight named firms, each with its report linked, and the newest of them examined the vault under an assumption of hostile servers. The part to know before you commit is the other half — nobody, Bitwarden included, can reset your master password.

What an AI summary says about Bitwarden audits, and what Bitwarden publishes The wording in the left box is the search summary’s own, which promises independent audits without naming one. Bitwarden’s compliance page lists twenty-five dated assessments between 2018 and 2025 by eight named firms, each with a linked report, plus SOC 2 Type 2, SOC 3, ISO 27001 and HIPAA. THE SAME QUESTION, TWO ANSWERS The summary Bitwarden regularly undergoes third-party security and cryptographic audits no firm, no year, no finding The maker’s own page 25 dated assessments, 2018 to 2025 8 named firms, every report linked 9 of them in 2025 alone plus SOC 2 Type 2, SOC 3, ISO 27001 The question was “is it safe”. One answer is an opinion with a link to a forum; the other is a list you can open and read. Counted from the page, not estimated. AI Tools Primer · figure
The evidence was always there, on a page the summary itself cites. Figure drawn by AI Tools Primer.

The audits, with names and dates, because that is what the question is asking

Bitwarden publishes a compliance page, and it is the answer to this question in a form nobody repeats. It lists twenty-five dated third-party assessments between 2018 and 2025, each with the firm that carried it out and a link to the report. Nine of them are from 2025 alone. Eight different firms appear: Cure53, the Applied Cryptography Group at ETH Zurich, Unit 42 by Palo Alto Networks, Fracture Labs, IOActive, Paragon Initiative Enterprises, Mandiant and Insight Risk Consulting.

Alongside them sit the certifications, which are a different kind of evidence and worth keeping separate: SOC 2 Type 2 and SOC 3, ISO 27001, and HIPAA — where Bitwarden says it “annually undergoes a third-party audit for HIPAA Security Rule compliance”. GDPR, CCPA and the Data Privacy Framework are compliance statements rather than audits.

What the assessments actually cover is stated plainly: “these annual audits include source code assessments and penetration testing across Bitwarden IPs, servers, and web applications”. Reading the list you can see the shape of it — the browser extension, the desktop app, the mobile apps, the web vault, the network, the SDK, the Rust cryptography crates, each with its own year and its own report.

None of that makes a product safe by itself. A list of audits is a claim that someone looked, not a promise that nothing was found. But it is a checkable claim, and it is the difference between an answer you can act on and an answer that tells you what people on a forum think.

The published third-party assessments, counted from Bitwarden’s own compliance page on 9 September 2026
YearDated assessmentsWho carried them out
20259 Cure53; the Applied Cryptography Group at ETH Zurich; Unit 42 by Palo Alto Networks; Fracture Labs
20245 IOActive; Paragon Initiative Enterprises; Mandiant; Fracture Labs; Cure53
20235Cure53
20222Cure53, alongside SOC 2 Type 2 and SOC 3
20212Insight Risk Consulting; Cure53
2020 and 20182Insight Risk Consulting; Cure53
Total25Eight named firms, each report linked

What the most recent audit found, including the part that was not fixed

The newest report on that list is the 2025 Bitwarden Cryptography Report, carried out by the Applied Cryptography Group at ETH Zurich and written up on Bitwarden’s blog in February 2026. It is worth reading rather than counting, because of the assumption it starts from.

The researchers used a fully malicious server threat model, which Bitwarden quotes as “meaning that it can deviate arbitrarily from its expected behaviour” — in other words, they assumed Bitwarden’s own infrastructure had been taken over completely and asked what your vault would still be protected from. Bitwarden explains why anyone would test that: the team “intentionally selected this particular edge-case threat model to test the strength of zero-knowledge encryption across popular password management products”. It also notes which products could be tested at all, and the answer says something about the field: others were “not selected due to the closed source nature of the solution” or would have needed “extensive reverse engineering”.

The result: “the analysis tested ten distinct attacks against Bitwarden zero-knowledge encryption architecture, later split to twelve attacks by the researchers in their publication after initial disclosure”, all rated medium or low impact, “largely because they require a highly sophisticated attacker who already has control over Bitwarden server infrastructure”.

And then the sentence that makes this page worth writing, because it is the one a rating out of five cannot contain: “Seven of which have been resolved or are in active remediation by the Bitwarden team. The remaining three issues have been accepted as intentional design decisions necessary for product functionality.” Three findings were not closed. That is a normal engineering outcome and it is published by the company itself, which is more than most makers do — but it is a fact about the product, and “yes, widely considered safe” is not a summary of it.

What the ETH Zurich cryptography audit found, and what happened to each finding The audit assumed a fully malicious server and tested ten attacks, split to twelve in the researchers’ publication. Seven findings are resolved or in active remediation; three were accepted as intentional design decisions. THE 2025 CRYPTOGRAPHY REPORT, PUBLISHED FEBRUARY 2026 A fully malicious server the threat model chosen: Bitwarden’s own servers hostile Ten attacks tested later split to twelve in the researchers’ publication Medium and low impact all require an attacker who already controls the servers Seven resolved or in active remediation Three accepted as design decisions The three are the interesting number, and they are on the maker’s own blog. AI Tools Primer · figure
An audit that finds nothing is a press release; this one has a remainder, and Bitwarden published it. Figure drawn by AI Tools Primer.

Why this is the fact to lead with, rather than a verdict. An AI summary of this question answers “yes” and attributes it to a forum, then promises “independent audits” without naming a single one: not the firm, not the year, not the finding. That is the shape of answer that is useless to anyone actually deciding, because it cannot be checked and it cannot be wrong. The evidence was on a page it already cites. Counting it took ten minutes, and it is the same test being applied across this group of guides: not which manager is best, but what each one does on its worst day, and whether the maker says so.

The price of the design: the one password nobody can reset

The same architecture that makes the audits meaningful is the one that can lock you out for good. Bitwarden states it in the first line of its own help page on the subject: “Bitwarden operates with zero-knowledge encryption. This means that Bitwarden has no way to access, retrieve, or reset your master password.” And on a second page, as advice: “Bitwarden employees and systems have no knowledge of, way to retrieve, or way to reset your master password. Do not forget your master password.

There are seven documented ways back, and six of them have to exist before you need them. Check you are signing in to the right server region, because accounts do not cross regions. Try a device where the vault is already unlocked with a PIN or biometrics — and here Bitwarden gives a genuinely practical instruction rather than a platitude: unlock it, copy the entries out by hand into a .csv, and import that into a new account. Ask for the master password hint by email, if you set one. Use emergency access, if you named a trusted contact. Ask an organisation administrator, if you are in one. Log in with a known device, or with a registered encryption-enabled passkey.

If none of them works, Bitwarden does not soften the ending: “there is no way for Bitwarden to recover the account or its data. You will need to delete your account and create a new one.”

So the honest answer to “is Bitwarden safe” has two halves. It is audited repeatedly, by named firms, with the reports published. It is also unforgiving in a way a browser’s built-in manager is not, because there is no company-held key to fall back on. Set the hint and name an emergency contact on the day you sign up, not the day you need them.

The documented ways back into a Bitwarden vault when the master password is gone Bitwarden lists seven routes: the right server region, another device where the vault is already unlocked with a PIN or biometrics, the master password hint by email, emergency access, organisation account recovery, log in with a known device, and a passkey. If none works, the account has to be deleted and remade. SEVEN DOORS, AND WHAT IS BEHIND THE LAST ONE 1 · The right server region accounts do not cross regions 2 · A device still unlocked PIN or biometrics, then copy it out 3 · The hint by email only if you set one 4 · Emergency access a contact you named first 5 · An administrator only inside an organisation 6 and 7 · Known device or a registered passkey If none of them works, Bitwarden’s own instruction is to delete the account “there is no way for Bitwarden to recover the account or its data” AI Tools Primer · figure
Six of the seven have to be set up before you need them. Figure drawn by AI Tools Primer.

Getting out, and the export that only works back into itself

Leaving is documented and straightforward: Tools, then Export, then a format. There are four — .json and .csv in plain text, .json encrypted, and .zip with attachments — and Bitwarden notes that “no unencrypted data is transferred over the internet, because data is decrypted locally by the client before exporting”. The usual warning applies, and Bitwarden gives it: unless the export is encrypted, “do not store or send the exported file over insecure channels, like email, and delete the file immediately after use”.

Two limits are worth knowing before you rely on an export as a backup. The first is coverage: only the .json formats carry cards, identities, stored passkeys and SSH keys, and “no export formats include trash items or Sends”. The second is a setting with consequences. If you choose the encrypted .json and leave it set to account restricted, the file “can only be imported to the same account where it originated” — not to an account with the same email address on a different server, and not even to a new account with the same address if the original was deleted. Rotating your account’s encryption key makes such a file undecryptable too.

Which turns a backup into a decoration in exactly the situation you made it for. If the export is meant to survive losing the account, it has to be the password-protected kind rather than the account-restricted kind, and that choice sits in a dropdown inside an optional step.

How the standard says to answer a question like this one

Quoted from NIST SP 800-63B, Digital Identity Guidelines, read in full on 9 September 2026.

Use one — that part is not in doubt “Verifiers SHALL allow the use of password managers and autofill functionality”, and managers “have been shown to increase the likelihood that subscribers will choose stronger passwords”.
And check the one you use, in those words “Agencies should carefully evaluate password managers before making recommendations or mandates to confirm that they meet expectations for secure implementation.” That is the same instruction as this page, addressed to institutions: look at the evidence, do not take the reputation.
Because the risk is named, not hypothetical In the table of ways a credential gets duplicated: “a vulnerability in an insufficiently secure password manager is exploited”. Which is exactly what an independent audit is looking for, and why the dates on those reports matter more than the adjective in front of them.

A word about who is speaking. Six of the seven sources below are Bitwarden writing about Bitwarden, which is a limit worth stating rather than hiding. It matters less than it sounds for the things this page takes from them, because those are dated, named and linked — a list of audits with the auditors on it is checkable by anyone who opens the reports, and so are the export formats and the recovery routes. It matters more for the sentences that are claims rather than records, such as never having been breached; those are attributed to Bitwarden here and not repeated as findings of ours.

And the case where none of this is the real problem. If you are choosing between a dedicated manager and the one already in your browser, the comparison worth making is what each does on the day something goes wrong: the Apple password manager and the Firefox one answer that very differently. And if a password of yours has turned up in a leak, that is what to do after a data breach, whichever manager you end up with.

Where to start

Three ways in.

“Who has actually checked it?”
The names and the dates — the audits
“What did they find?”
The newest report, in full — what the last audit found
“What if I forget the master password?”
Seven doors, and the last one — the master password

The managers you already have

Before paying for anything, it is worth knowing what the manager already installed on your machine does, and where it stops.

When the vault is not the problem

Most password trouble is not about the manager: it is about the account whose password the manager is holding.

Questions people also ask

Has Bitwarden ever been hacked?

Bitwarden states on its own blog that it “has never experienced any security breach”. That is the company’s statement about itself, reported here as such. What can be checked independently is the audit trail: twenty-five dated third-party assessments with the reports published.

Who audits Bitwarden, and how often?

Eight named firms appear on its compliance page — Cure53, ETH Zurich’s Applied Cryptography Group, Unit 42 by Palo Alto Networks, Fracture Labs, IOActive, Paragon Initiative Enterprises, Mandiant and Insight Risk Consulting — across twenty-five dated assessments from 2018 to 2025, nine of them in 2025.

Did the ETH Zurich audit find problems?

Yes, and Bitwarden publishes the outcome. Twelve attacks were examined under an assumption of a fully hostile server, all rated medium or low. Seven findings are resolved or in active remediation; three “have been accepted as intentional design decisions necessary for product functionality”.

Can Bitwarden see my passwords?

Bitwarden’s answer to that question in its own security FAQ is “A: No.” Its explanation is that data is “encrypted locally on your personal device before ever being sent to our cloud servers”, and that its servers hold only encrypted and hashed data.

What happens if I forget my Bitwarden master password?

There is no reset. Bitwarden documents seven ways back — server region, a device still unlocked, the hint by email, emergency access, an organisation administrator, a known device, a passkey — and if none works, “there is no way for Bitwarden to recover the account or its data”.

Can I export my Bitwarden vault and take it elsewhere?

Yes: Tools, then Export, in .json, .csv, encrypted .json or .zip. Two limits matter. No format includes trash items or Sends, and an encrypted export left on “account restricted” can only be imported back into the account that made it.

Not covered here. It does not give a score or a place in a ranking. “Is it safe” is answered by what has been checked, by whom and when, and an honest ranking would need paid subscriptions and months of use; the way in from here is the guides on passwords and the ways in.

It does not cover prices or plans, and it does not judge the self-hosted option, which is a different question with a different attack surface.

And it does not re-verify the auditors’ reports: it names them, dates them, and says who publishes them. What holds instead is simple: the audit count and the firm names are counted from Bitwarden’s own compliance page rather than estimated, the findings of the newest report are quoted from the write-up Bitwarden published, six of the seven sources are the maker writing about itself and the page says so where that matters, and the clauses on evaluating managers are quoted from the NIST publication.

Sources

  1. Bitwarden Help — Compliance, Audits, and Certifications: the dated list of third-party assessments from 2018 to 2025 with the firm behind each and a link to each report, and the compliance statements for SOC 2 Type 2, SOC 3, ISO 27001, HIPAA, GDPR, CCPA and the Data Privacy Framework — bitwarden.com, read 9 September 2026.
  2. Bitwarden blog — Security through transparency: ETH Zurich audits Bitwarden cryptography against malicious server scenarios, 16 February 2026: the fully malicious server threat model, the ten attacks later split to twelve, the medium and low ratings, and the split between seven findings resolved or in remediation and three accepted as intentional design decisions — bitwarden.com, read 9 September 2026.
  3. Bitwarden Help — Forgot My Master Password: that Bitwarden has no way to access, retrieve or reset it, the seven documented routes back including copying a still-unlocked vault out by hand, and the statement that otherwise the account has to be deleted and remade — bitwarden.com, read 9 September 2026.
  4. Bitwarden Help — My Master Password: that employees and systems have no knowledge of it, the twelve-character minimum for passwords made after the 2023.3.0 release, the hint and the emergency contact as the two preparations, and the optional check against known data breaches — bitwarden.com, read 9 September 2026.
  5. Bitwarden Help — Security FAQs: that Bitwarden stores encrypted versions rather than passwords, the flat answer to whether Bitwarden can see them, how the derived key is held in memory only while the vault is unlocked, and that the infrastructure runs on Microsoft Azure managed services — bitwarden.com, read 9 September 2026.
  6. Bitwarden Help — Export Vault Data: the four export formats, that decryption happens locally before export, what the formats do and do not include, and the account-restricted encrypted export that can only be imported back into the account that created it — bitwarden.com, read 9 September 2026.
  7. NIST SP 800-63B, Digital Identity Guidelines: the requirement that verifiers allow password managers, the instruction to evaluate a manager carefully before recommending it, and the entry naming an insufficiently secure password manager among the ways a credential is duplicated — pages.nist.gov, read 9 September 2026.

Written by Alberto Gulotta

Founder and editor of AI Tools Primer, writing from Palermo, Italy. Thirty-five years of taking computers apart, starting with a Commodore 64 — the long version is on the about page.

Something wrong on this page? Write to aitoolsprimer@gmail.com and it gets fixed.

Written on 9 September 2026.

Independence and limits

No affiliate links and no paid placements anywhere on this site. Nobody pays to appear here, and no company has seen this page before you did.

This is general information, not professional advice. Where a page touches money, health, safety or the law, it names its source and the date it was read — and your situation may still differ. See the privacy page and the cookie policy.