Choosing a Password Manager for Sovereign Key Storage

Bitwarden vs Proton Pass, both zero-knowledge and end-to-end encrypted — and how to use one as the single home for every recovery key, seed phrase, and backup code you actually depend on.

Why does this guide exist?

Because the first two guides in this series both end the same way: with a recovery key you now have to put somewhere. GrapheneOS gives you an Auditor pairing to keep track of. A hardened Windows machine gives you a 48-digit BitLocker recovery key. Neither of those is useful sitting in a text file on the same computer, or on a sticky note. This guide is where they actually go.

In my experience running IT for a living, the moment a client says “it's written down somewhere safe,” it's a sticky note. My own recovery keys, seed phrases, and backup codes all live inside a password manager's encrypted secure notes instead — never a spreadsheet, never a notes app, never a screenshot in a camera roll. This guide covers two options that genuinely qualify for that job: Bitwarden and Proton Pass. Both are end-to-end encrypted. Both are zero-knowledge. The differences that actually matter are narrower than the marketing on either site suggests.

What does “end-to-end encrypted” and “zero-knowledge” actually mean here?

In plain terms: your master password never leaves your device. It's used locally, on your phone or computer, to unlock a key that decrypts your vault — the password manager's own servers only ever store and sync data that's already encrypted before it arrives. Bitwarden states this directly: “you are the only party with access to the keys required to decrypt the vault data.” Proton Pass makes the same structural claim: “your data is never accessible to us and only you can decrypt it using your secret password.”

That's the actual substance behind “the provider can't hand over your vault even under a subpoena” — it isn't a policy promise either company is making about what they'd choose to do. It's a structural claim about what they're able to do, because they never hold the key in the first place. One honest caveat worth knowing: this covers your vault's contents, not everything about your account. Both providers still see ordinary account metadata to run the service — your email address, billing details, roughly when you log in. Don't mistake either product for total anonymity; that was never the claim.

Bitwarden or Proton Pass — what's the real difference?

Fewer than you'd think, and the marketing pages for both undersell how close they've become. Both now offer full apps across browser, desktop, and mobile, both support passkeys, and both do the zero-knowledge encryption described above properly.

The one structural difference worth knowing: Bitwarden is fully open source, server included, and can be self-hosted if you want to run your own copy on your own infrastructure. Proton Pass's client apps are open source and independently audited, but the server side is closed, and there's no self-hosting option — you're using Proton's infrastructure or nothing.

On price, as of writing: Bitwarden's free tier covers unlimited passwords and secure notes with no real restriction, and its paid tier (around $1.65/month, billed annually) adds emergency access and encrypted file attachments. Proton Pass's free tier is comparably generous, and its paid tier (around $1.99/month, billed annually) adds similar extras plus dark-web monitoring. Proton also bundles Pass into its wider Proton Unlimited plan if you already use Proton Mail or Proton VPN. Check both current pricing pages before you commit — these numbers move, and neither company publishes Australian-dollar pricing directly, so expect a currency-converted charge on your card either way.

How do you actually store a recovery key or seed phrase in one?

Through a secure note — a distinct item type in both products, separate from a login or a card entry, built specifically for freeform text rather than a username-and-password pair. Bitwarden's Secure Note and Proton Pass's equivalent note type both get the exact same end-to-end encryption as every other item in the vault. Paste your BitLocker recovery key, your GrapheneOS Auditor pairing details, a hardware wallet's seed phrase, or a set of one-time backup codes straight into a secure note, and it's protected the same way your logins are. There's no meaningful difference between the two products here — pick based on the rest of this guide, not this feature specifically.

What happens if you forget your master password?

This is the honest, uncomfortable trade-off of zero-knowledge design, and it deserves stating plainly rather than glossed over: because neither company holds your master password, neither can reset it for you. Lose it with no recovery method set up in advance, and your vault is gone — cryptographically, permanently, no support ticket fixes it. That's the exact same property that keeps a subpoena from reaching it.

Both products offer a way to plan for this before you need it. Bitwarden's Emergency Access (a paid-tier feature) lets you nominate someone you trust in advance, who can request access if something happens to you; you set a wait period, and it releases automatically if you don't respond, so a genuine emergency doesn't get stuck waiting on you specifically. Proton takes a different approach: a 12-word recovery phrase generated when you set up your account, which functions as your own self-managed backup key — powerful, but it does mean you now have to think about where that phrase lives too, which is worth being honest about rather than pretending the problem disappears.

Why not just use your hardware wallet's own backup feature?

Because the whole point of holding your own keys is keeping them out of any one company's hands — including the hardware wallet vendor's. In May 2023, Ledger — a company whose marketing had spent years insisting private keys never leave the device — announced Ledger Recover, an opt-in service that splits an encrypted copy of your key across three separate custodians and requires government ID to use. The backlash was immediate: it directly contradicted the company's own founding promise, and Ledger's own leadership acknowledged that key-related metadata could, in principle, be produced under a court order. Ledger delayed the rollout, apologised for how it was communicated, then shipped it anyway later that year. Separately, in 2020 Ledger's e-commerce database was breached via a misconfigured API key — not the wallets themselves — exposing around a million customer email addresses and leading to real phishing and, in a handful of extreme cases, physical threats against people whose home addresses leaked alongside the knowledge that they owned crypto hardware.

Neither event means Ledger devices themselves are insecure. The lesson is narrower and more useful: even a vendor built entirely around “your key never leaves the device” got breached on ordinary customer data, and separately shipped a feature that quietly walked back its own core promise a few years later. Keep your seed-phrase backup somewhere architecturally separate from whoever made your hardware wallet — your own zero-knowledge password manager, encrypted under a secret only you hold — rather than trusting the manufacturer's own recovery service to do it for you.

Bringing the series together

This is where everything the first two guides generated actually lives: the BitLocker recovery key from the Windows guide, the account and pairing details from the GrapheneOS guide, and anything else you'd otherwise be tempted to write on a sticky note. One password manager, one master password you actually remember, everything else inside it.

That closes the loop this series opened with the piece on TOLA and why any of this is worth doing in the first place. The privacy technology archive collects all three how-to guides together if you're setting this up from scratch.

Share your love
The Privacy Technologist
The Privacy Technologist

The Privacy Technologist covers privacy technology, digital sovereignty, and financial freedom from an Australian perspective. Built on cypherpunk principles and real-world experience — including life on the wrong side of the banking system. Every tool recommended here is one we actually use.

Articles: 6