Honest comparison · Apex is in development
Apex Password vs LastPass
LastPass popularized password management: a cloud-stored, client-side-encrypted vault available from any browser. It remains a widely used product with a generous feature set.
At a glance
§ Side by side| Apex Password | LastPass | |
|---|---|---|
| Where the vault lives | On your phone only. No server-side copy, not even an encrypted one. | Encrypted vault stored on LastPass’s cloud servers and synced to clients |
| If malware hits your computer | Vault is never on the computer; with Apex Agent, SSH/GPG keys aren’t either. An info-stealer finds no vault file and no keys to copy - at most the single credential in active use. | The synced vault is cached locally and decrypted in the browser/app; an info-stealer can copy it and attempt the master password offline - the same offline-cracking that made the 2022 server breach so damaging. SSH/GPG keys stay on disk. |
| Open source | MIT license; full repository opens at launch | No - proprietary |
| Self-hosting | Relay is self-hostable via Docker; the vault needs no server | No |
| Breach exposure | No server-side vault copy exists to steal; the relay sees only ciphertext in transit | Server-side vault copies were exfiltrated in the 2022 incident (per LastPass’s own disclosures) |
| Metadata in the vault | Vault is encrypted as a whole on-device | Historically, some fields such as site URLs were stored unencrypted within vault data |
| Account required | No account, no email. Devices pair directly via QR code | Yes - email-based account |
| Independent audits | Not yet independently audited; built on standard primitives (AES-256-GCM, P-256, Argon2id) | Has undergone audits; security record includes the 2022 incident |
| Maturity | In development - launching in stages (mobile app and relay first) | Shipped and mature |
Comparison reflects each product's publicly documented architecture and may change as products evolve. Found something inaccurate? Tell us and we'll fix it.
It is also the clearest real-world illustration of the risk Apex is designed to remove. In its 2022 incident disclosures, LastPass reported that attackers obtained backups of customer vault data. Vault items like passwords were encrypted, but the copies were now in attackers’ hands to attack offline indefinitely - and LastPass disclosed that some fields, such as website URLs, were not encrypted.
No encryption flaw was needed for that to hurt: the mere existence of server-side vault copies turned an infrastructure breach into a permanent, user-by-user cracking campaign. Apex’s answer is structural - the vault stays on your phone, and no server, ours included, ever holds a copy.
Which should you pick?
§ Trade-offsChoose LastPass if…
- You need a shipped product today with browser-anywhere access to your vault.
- You rely on LastPass-specific features like its sharing center or emergency access.
- Cloud convenience outweighs architectural concerns for your threat model.
Choose Apex if…
- The 2022 incident convinced you that server-side vault copies are the problem, not just weak encryption settings.
- You want open-source code rather than a proprietary client.
- You want no account, no email, and no third party in your recovery path.
- You prefer one-credential-at-a-time delivery with biometric approval over a synced vault in the browser.
Bottom line: If you are evaluating LastPass alternatives because of its breach history, understand what actually went wrong: encrypted vault copies lived on servers, and servers get breached. Apex removes that class of failure by never uploading your vault anywhere. The trade-off is that backup and recovery become yours to manage.
Common questions
§ FAQWhat actually happened in the LastPass breach?
According to LastPass’s own disclosures from late 2022, attackers obtained backups of customer vault data from cloud storage. Passwords within the vaults were encrypted, but attackers could attempt to crack them offline, and some fields - notably website URLs - were not encrypted. Users with weak master passwords or old, low iteration counts were most at risk.
Could the same thing happen to Apex?
The specific failure - exfiltration of server-side vault copies - cannot, because no server-side vault copies exist. Apex’s relay routes end-to-end encrypted messages and stores no vaults. Other risks (a compromised phone, a lost master phrase with no backup) remain, and we document them honestly.
Is Apex ready to switch to today?
Not yet - Apex is launching in stages, with the mobile app and relay first. If you need to leave LastPass immediately, a shipped open-source option such as Bitwarden or KeePassXC is the pragmatic move; you can revisit Apex when it launches.
§ Get the suite
Your secrets, your device, your rules.
Apex is launching in stages. The mobile app and the relay are first. The browser extension and desktop agent follow.
No tracking pixels. No newsletter blast. One email when the apps ship.