Honest comparison · Apex is in development

Apex Password vs Proton Pass

Proton Pass comes from Proton, the Swiss company behind Proton Mail, and inherits its strengths: end-to-end encryption, open-source clients, a privacy-first business model, and niceties like built-in email aliases.

At a glance

§ Side by side
Apex Password Proton Pass
Where the vault lives On your phone only. No server-side copy, not even an encrypted one. Encrypted client-side, stored on Proton’s servers, synced to all clients
If malware hits your computer Vault is never on the computer; with Apex Agent, SSH/GPG keys aren’t either. An info-stealer finds no vault file and no keys to copy - at most the single credential in active use. The synced vault is cached locally and decrypted in memory when unlocked; an info-stealer can target the local data and the unlock. SSH/GPG keys stay on disk.
Open source MIT license; full repository opens at launch Clients are open source
Self-hosting Relay is self-hostable via Docker; the vault needs no server No - tied to Proton’s infrastructure
Account required No account, no email. Devices pair directly via QR code Yes - Proton account
Email aliases Not a feature Yes - hide-my-email aliases built in
Ecosystem Standalone suite (password app, extension, relay, SSH/GPG agent) Part of the wider Proton suite (Mail, Drive, VPN, …)
Independent audits Not yet independently audited; built on standard primitives (AES-256-GCM, P-256, Argon2id) Yes - published third-party audits
Maturity In development - launching in stages (mobile app and relay first) Shipped and actively developed

Comparison reflects each product's publicly documented architecture and may change as products evolve. Found something inaccurate? Tell us and we'll fix it.

Architecturally, though, Proton Pass is still a cloud password manager: your vault is encrypted on your device and then stored on Proton’s servers so every client can sync it. The encryption is sound - but an encrypted copy of your vault exists on infrastructure you don’t control, tied to your Proton account.

Apex removes that copy. The vault exists in one place - your phone - and other devices receive individual credentials on demand, each approved biometrically and delivered end-to-end encrypted. No account, no email address, no server-side blob.

Which should you pick?

§ Trade-offs

Choose Proton Pass if…

  • You already live in the Proton ecosystem and want passwords integrated with Mail, aliases, and family plans.
  • You want a shipped, audited product today with automatic sync everywhere.
  • Email aliasing as a first-class feature matters to you.

Choose Apex if…

  • You want end-to-end encryption and no stored vault: not even an encrypted blob on a privacy-focused company’s servers.
  • You don’t want your password manager tied to an account or email identity.
  • You want per-login biometric approval on your phone rather than a synced vault in every browser.
  • You want the SSH/GPG story (Apex Agent) from the same trust model.

Bottom line: Proton Pass is an excellent E2EE cloud password manager backed by a credible privacy company. Apex is for people who want to go one step further: no cloud-stored vault, no account, and a phone-anchored approval flow - accepting self-managed recovery as the price.

Common questions

§ FAQ
Both are end-to-end encrypted - what is actually different?

What the encryption protects. Proton Pass encrypts your vault and stores that encrypted vault on Proton’s servers for sync. Apex encrypts individual messages between your own devices and stores the vault nowhere but your phone. With Apex there is no server-side ciphertext to steal, crack, or be compelled to hand over.

Proton is privacy-focused - why avoid their cloud?

It is not about distrusting Proton specifically. Any server-side vault copy is a standing target that outlives every breach, subpoena, and policy change. Apex’s design goal is that the question "what if the server is compromised?" has a boring answer: the server only ever saw ciphertext in transit.

Is Apex available now?

Apex is launching in stages - the mobile app and relay come first, then the browser extension and desktop agent. Join the launch list on the homepage to get one email when it ships.

§ Get the suite

Your secrets, your device, your rules.

Apex is launching in stages. The mobile app and the relay are first. The browser extension and desktop agent follow.

No tracking pixels. No newsletter blast. One email when the apps ship.