Security & Compliance · Engineering, IT & AI
Should you build or buy Password Manager?
Consumer and business credential vaults that store, generate, autofill, and share passwords and secrets (1Password, Bitwarden, Dashlane, Keeper, LastPass, NordPass). Distinct from passwordless/phishing-resistant authentication.
The build-vs-buy call for a Password Manager hinges on whether you treat the vault as commodity security hygiene you buy, or as something worth self-hosting for data control and residency. Mature open-source servers make self-hosting genuinely real for teams with the ops capacity, but the trust, audit, breach-monitoring, and enterprise-identity machinery is what most teams end up paying for.
Build it, buy it, or bridge?
When building makes sense
Self-hosting a password manager earns its place when data control, residency, or air-gap requirements are hard constraints, or when open-source transparency is itself the requirement — and when you already run the security operations to do it well. Vaultwarden and self-hosted Bitwarden are documented, widely-run production alternatives that cover the core (storage, generation, autofill, sync, sharing, browser extensions), and Bitwarden's OSS route even preserves SSO/SCIM. What the build path does not hand you is the assurance layer: crypto operations, backups, patching, recovery testing, breach monitoring, and fleet administration all move onto your team, and getting any of them wrong on a credential vault is a serious incident. Rolling your own vault from scratch is a different thing entirely and is broadly treated as a security anti-pattern — the hard parts were never the storage.
When buying makes sense
Buying is the default for good reason: a password manager is commodity security hygiene where a failure is expensive, and per-seat pricing ($3.75–$8/user/month) is cheap relative to what it would cost to run the equivalent safely yourself. Incumbents like 1Password, Bitwarden, Keeper, and Dashlane absorb the hard, unglamorous parts — zero-knowledge architecture, cross-platform client reliability, breach and dark-web monitoring, SSO/SCIM provisioning, admin policy, audit logs, and passkey support — and package the compliance evidence enterprise procurement expects. For the roughly 94% of teams that do not self-host, the fully-burdened 3-year cost of running a vault in-house (server, integration, patching, recovery, security review, often 1–2 FTE) outweighs the license savings, and the switch math simply does not pencil out.
The desk read
Build-versus-buy analysis for Password Manager is being written. In the meantime, the framework that drives every B4 call is on the B4 Index page.
Vendors in Password Manager
Each file covers what the product is, its funding history, and when the index last verified it alive.
Frequently asked
What is a Password Manager?
A credential vault that stores, generates, autofills, and shares passwords and secrets for consumers and businesses, with cross-platform sync, shared vaults, breach monitoring, and enterprise admin controls. It is distinct from passwordless/phishing-resistant authentication.
Can you self-host a password manager instead of buying one?
Yes — Vaultwarden, self-hosted Bitwarden, Passbolt, and KeePass are mature, production-grade options that cover most of the core. But self-hosting is a special case (roughly 6% of regulated SMBs), it moves crypto ops, backups, patching, and recovery onto your team, and building your own vault from scratch is a security anti-pattern.
When does buying a password manager make sense?
Almost always. Per-seat pricing is cheap ($3.75–$8/user/month), and vendors absorb zero-knowledge crypto, cross-platform clients, breach monitoring, SSO/SCIM, and compliance packaging. For most teams the fully-burdened cost of running a vault safely in-house outweighs the license savings.
What are the main Password Manager vendors?
Representative vendors include 1Password, Bitwarden, Dashlane, Keeper, LastPass, and NordPass, with Vaultwarden and Passbolt as open-source self-host options. B4 Pro scores the full set.