Klavox vs Bitwarden vs 1Password vs Proton Pass
| Criteria | Klavox | Bitwarden | 1Password | Proton Pass |
|---|---|---|---|---|
| Zero-knowledge architecture | Yes | Yes | Yes | Yes |
| Key derivation | Argon2id + HKDF-SHA256 | PBKDF2 / Argon2id (configurable) | PBKDF2 + Secret Key (256-bit) | Argon2id (bcrypt for auth) |
| Entry encryption | AEAD XChaCha20-Poly1305 / AES-256-GCM | AES-256-CBC + HMAC / AES-256-GCM | AES-256-GCM | AES-256-GCM |
| Publisher | SANTVIA (France) | Bitwarden Inc. (United States) | AgileBits / 1Password (Canada) | Proton AG (Switzerland) |
| Default hosting | France / EU | United States (EU self-hosting option) | Canada / United States | Switzerland |
| Open crypto core | Yes, portable TypeScript | Yes, full source code | No, proprietary | Yes, client apps |
| Free local vault, no account | Yes | No — account required | No — limited trial then paid | No — account required |
| Autofill / browser | Extension + native Navkrypt (roadmap) | Extensions on every platform | Extensions on every platform | Extensions on every platform |
| Apps | Web, Android, iOS (roadmap) | Web, desktop, mobile | Web, desktop, mobile | Web, desktop, mobile |
Sources: each publisher's public security documentation (Bitwarden, 1Password, Proton Pass) and Klavox's architecture (security page). Comparison established at publication date; vendors evolve their implementations — check their official documentation for the latest detail. Klavox is in development (crypto core shipped, web/mobile vault upcoming).
What sovereignty changes in practice
Applicable jurisdiction
A publisher and host based in France/EU fall under EU law (GDPR), with no exposure to the US Cloud Act.
A single crypto core
Where others reimplement encryption per platform, Klavox shares one tested TypeScript module, identical on web, Android and iOS.
Local vault, no account
An encrypted vault usable immediately, without sign-up or server, for anyone who wants to try it before syncing.
See the full security architecture
Argon2id derivation, HKDF, protected vaultKey, per-entry AEAD: it's all documented.