Bitwarden is an open-source password and secrets manager that keeps your logins, cards, notes and files in an encrypted vault, unlocked by a single master password. This page introduces the product and shares an independent, evidence-based plan for testing it thoroughly before you trust it with your secrets.

Bitwarden equips individuals and organizations to securely store, generate and share passwords and other sensitive information online. Founded in 2016 and built on a transparent, open-source approach, it serves more than 15 million users and 80,000+ organizations across 180+ countries and 50+ languages. Everything you save lives in an encrypted vault that is locked and unlocked with one master password — so you remember one strong secret instead of dozens.
The defining idea is end-to-end, “zero-knowledge” encryption: your information is scrambled on your own device before it ever leaves it, so the service storing it — cloud or self-hosted — only ever holds ciphertext it cannot read. Bitwarden runs everywhere you do: a web vault, browser extensions, desktop apps for Windows/macOS/Linux, native iOS and Android apps, and a command-line tool for automation.
Because Bitwarden is open source, you are not locked into one way of running it. The vault encryption is identical in every case; what changes is who hosts and maintains the service.
Subscribe and install the apps; your encrypted vault is hosted and maintained by Bitwarden, with automatic updates, high availability and support.
Best for: individuals, families and most businesses who want it to just workDeploy Bitwarden’s official container images on your own servers — the same software, hosted on infrastructure you control, in a cloud or data centre of your choice.
Best for: businesses and IT teams needing data residency or full operational controlCompile the public source code yourself, for maximum transparency, customisation, or air-gapped and highly regulated environments.
Best for: security-sensitive organizations, auditors and developersOptions 2 and 3 give you data sovereignty; some premium and enterprise features still require a Bitwarden licence, and mobile push notifications relay through Bitwarden’s infrastructure.
A password manager is only as good as your confidence in it — you are, after all, about to hand it every secret you own. When we looked, we could not find a single complete, plain-language test plan that a prospective user or organization could follow to satisfy themselves the product is safe and fit for purpose before committing their vault to it.
So we built one. The result lets anyone — an individual, an IT team, or an enterprise evaluator — test Bitwarden thoroughly before they start storing secrets in it, and re-test it at every release. It turns “trust us” into “verify for yourself,” which is exactly the spirit of an open-source product — and it measurably improves customer confidence.
The plan is not generic — it is built, step by step, from the product’s own material.
@bitwarden/cli 2026.4.0) was briefly available on the public npm registry for roughly 1.5 hours. The tampered package — part of the “Shai-Hulud” campaign and linked to a breach of a third-party build service — ran hidden code at install time that harvested developer and cloud secrets and tried to spread itself further. Bitwarden withdrew it and published a clean release the same day. A telling detail: the package version was bumped, but the core code inside still carried the previous version’s fingerprint — a clear tamper signal.
Our Verification plan includes a dedicated “trustworthy software supply chain” area whose checks target exactly this class of attack:
Read the overview report, or take the full working detail as spreadsheets you can run and track.
This product exists because of an open, global community. Founded in 2016 and built on a transparent, open-source approach, it is shaped by contributors and users around the world who share the mission of helping people manage sensitive information safely. Its stated values — responsibility, inclusion, and transparency — are reflected directly in this plan’s emphasis on evidence, honest limitations, and coverage for every kind of user.
We gratefully acknowledge:
Serving a community of more than 15 million users and 80,000+ organizations across 180+ countries — the scale that makes this rigor necessary. Learn more at the Bitwarden about page.