1Password Review (2026): Pricing, Security, and Who It's For

Last reviewed September 25, 2026 · pricing snapshot 2026-09-25

Evidence base: evaluated on the published audits, attestations, and documented pricing cited below — listed by component, with the vendor's assessments page as the authoritative inventory. No in-house lab testing, no ratings. How we evaluate

1Password is the paid-only password manager with the deepest published audit trail in its class — public Cure53 pentest reports, an ISE assessment, SOC 2 Type II and the full ISO 27001 family, and a security design (2SKD) that external reviewers have examined. Its strengths: the Secret Key model, Watchtower security alerts, Travel Mode, and flat-rate team pricing. Its weaknesses are equally documented: no free tier beyond the 14-day trial, v8's removal of local vaults and third-party sync, Electron-based apps that draw performance complaints, publicized price increases (~33% individual per press/forum reporting), and an account that is unrecoverable if you lose your Secret Key. It fits families and teams that want audited security and will pay for it; it does not fit anyone who needs a free tier.

What is 1Password?

1Password is a zero-knowledge password manager built by AgileBits, Inc. — founded in 2005 and headquartered in Toronto, Canada. It runs on a two-secret design (the account password plus a machine-generated Secret Key), stores vaults on its own cloud infrastructure, and publishes its security evidence — audit reports, attestations, and a design whitepaper — for public download. It is one of the oldest commercial password managers and the only one in our pack set with this depth of published third-party testing.

What the independent audits say

1Password's published evidence, per the deep fact pack (all search-served captures, 2026-09-25):

Cure53 engagements (public PDFs). Berlin-based Cure53 has published pentest/source-review reports on 1Password's core crypto/Rust engine (2021), the B5 web app and automations, and mobile clients. The reports are hosted both by Cure53 and by 1Password itself — all three are linked in the Sources section.

Scope, stated precisely. The pack records these engagements by component — the core engine, the web app, mobile clients — not as a blanket “everything audited” claim. The authoritative inventory is 1Password's own security-assessments page; the pack's instruction is to quote a total count only after checking that page, so this review lists the named reports and defers the count. The honest framing is that the published engagements cover the components most relevant to individual users (core, web, mobile), and the assessments page is where the full inventory lives.

ISE (2020) and Onica. Independent Security Evaluators performed a 2020 assessment (report hosted at bucket.agilebits.com), and an Onica engagement is listed alongside. Both are recorded in the pack as part of the published assessment set.

Attestations. SOC 2 Type II and the ISO family — 27001:2022 plus 27017/27018/27701 — are cited via 1Password's SOC page and its ISO certification announcement. These certify operational controls around the product, not vault outcomes.

Bug bounty. A HackerOne-hosted program covers the web app, server infrastructure, desktop/mobile clients, and extensions, with published payout tiers (~Critical $6k–$30k+, High $600–$6k, Medium $300–$600, Low $50–$300 — verify the current tier table on the policy page), a $1,000,000 CTF challenge for breaching a target vault without credentials, and a Gold Standard Safe Harbor for researchers.

The precision rule that matters here: there is no VPN-style Deloitte/KPMG “no-logs” audit for 1Password, and per the pack there cannot be — the comparable assurance class for a vault is pentests/code audits plus SOC 2/ISO attestations, which is exactly what exists. The absence of a no-logs-style engagement is not a flaw for a password manager; it's a category mismatch, and this review says so rather than leaving the gap unexplained.

The design the audits examined: 2SKD

The security story underneath the audits is the 2SKD model, documented in 1Password's public Security Design Whitepaper (GitHub-hosted):

  • Two secrets, both local. Your account password plus a machine-generated Secret Key (128-bit, 34 characters) are combined to derive your keys — and the Secret Key never leaves your devices for 1Password's servers.
  • Zero-knowledge authentication. SRP (RFC 5054) is used for authentication, so servers never see the password. Vault encryption is AES-256-GCM, and metadata is encrypted client-side — even a breached server holds only SRP verifiers and encrypted blobs.
  • External review. ETH Zurich reviewed the malicious-server model (published on 1Password's blog).
  • The designed consequence: support cannot reset your password or recover a lost Secret Key on solo accounts. Families and Business plans use recovery keys and admin provisioning — still zero-knowledge, per the whitepaper.

That design explains both of this review's ends: the security strength (two independent secrets, servers holding only encrypted blobs) and the honest failure mode (a lost Secret Key is unrecoverable — covered below).

Pricing

Four published tiers plus Enterprise, per the deep pack (snapshot 2026-09-25 — promo first-year rates change often, so verify on 1password.com/pricing on publish day):

PlanPrice (snapshot)Notes
Individual$3.99/mo billed annually (~$47.88/yr)Promo first-year rates lower than the standard rate
Families$5.99/mo annual, 5 members+$1/mo per extra member
Teams Starter$24.95/mo flatUp to 10 users
Business$8.99/user/moEU/US data regions configurable
EnterpriseCustom—

The free-tier honesty, stated plainly: there is no free tier. A 14-day trial is the only no-cost option on every plan. Bitwarden and NordPass both run usable free tiers — that contrast is a real cost difference, not a nitpick. Data resides on 1Password's own infrastructure, per the pack.

1Password — pending approval

Our 1Password affiliate application (CJ advertiser 5140517, 25% first-year) is not approved yet, so no commission link appears here. When it lands, this slot becomes a disclosed affiliate CTA (“Check current price at 1Password”) under the site's standard: disclosure above the link, rel="sponsored nofollow", no fake codes (a CJ rule). Until then, 1Password's pricing page is the plain reference.

Where it falls short

1Password vs the alternatives

Comparisons are where this product gets judged, so the named ones, each traceable to the packs:

NordPass (our review is live): the budget contrast — a genuinely usable free tier, Premium at ~$1.49–1.99/mo intro, Cure53-audited zero-knowledge design, EU/GDPR jurisdiction. Choose 1Password over it when you need Watchtower/Travel Mode, the Secret Key model, or team flat-pricing; choose NordPass when free or cheap is the point.

Dashlane: the comparison term carries the highest CPC found in the wave-2 map ($31.08) — evidence of real decision intent. The pack records no Dashlane fact rows, so this review makes no Dashlane claims; a dedicated comparison page is the right home for that matchup.

Bitwarden: referenced in the pack only as the free-tier contrast — the honest statement is exactly that.

The head-to-head is live: our NordPass vs 1Password comparison covers the two side by side on audits, pricing, and jurisdiction.

Check current price at NordPass

Intro rates bill upfront and renewals are higher — confirm current numbers on the official plans page. 30-day money-back guarantee.

Tracker: pending affiliate registration — this link is the vendor's direct page until the IncomeGenius CJ property goes live.

Who should (and shouldn't) use it

Use it if you want the deepest published audit trail in the class (public Cure53 PDFs, ISE, ETH Zurich review), the two-secret Secret Key model, Watchtower and Travel Mode, or flat-rate team pricing (Teams Starter $24.95/mo for up to 10 users) — and you're fine paying for it with no free tier.

Skip it if you need a free tier (NordPass or Bitwarden fit there), if local vaults or third-party sync are requirements (v8 removed both), if Electron app performance is a dealbreaker, or if the risk of an unrecoverable account from a lost Secret Key is a dealbreaker for your situation. As with every review on this site, this is evaluated on published audits and data — not first-hand testing.

FAQ

Is 1Password secure?

By its published evidence, yes within the appropriate class: public Cure53 pentest reports (Rust core 2021, B5 web app, mobile clients), an ISE 2020 assessment, SOC 2 Type II, ISO 27001:2022 plus 27017/27018/27701, a HackerOne bug bounty with a $1M CTF challenge, and a publicly documented 2SKD design reviewed externally by ETH Zurich. Note the precision: these are pentest/code-audit and attestation classes — the right evidence type for a vault — not a VPN-style no-logs audit, which doesn't apply to a vault with no traffic to log.

Is 1Password free?

No. There is no free tier — a 14-day trial is the only no-cost option on every plan. Individual is $3.99/mo billed annually (~$47.88/yr), Families $5.99/mo (5 members).

What happens if I lose my Secret Key?

On solo accounts, the account is unrecoverable — by design. The Secret Key never reaches 1Password's servers, so support cannot reset it. Families and Business plans offer recovery keys and admin provisioning instead.

1Password vs Dashlane vs Bitwarden?

What the fact packs support: Bitwarden and NordPass have free tiers, 1Password doesn't; 1Password's distinguishing published evidence is the audit depth (Cure53/ISE/ETH Zurich) and the 2SKD design. Dashlane fact rows aren't in our packs yet, so we make no Dashlane claims — a dedicated comparison page is the right place for that matchup when the data exists.

Why is 1Password more expensive?

The pack records the documented increases (~33% individual, ~20% families per press/forum reporting) but no company explanation of pricing composition; what the price buys, per the published record, is the audit trail, the 2SKD design, Watchtower/Travel Mode, and team infrastructure (SOC 2/ISO attestations, configurable data regions on Business). We state what's documented and don't speculate beyond it.

The honest bottom line

1Password is the most heavily audited password manager in our pack set — public Cure53 reports, ISE, SOC 2 Type II, the full ISO family, a $1M bug-bounty challenge, and a whitepaper-documented zero-knowledge design. You pay for that with the highest-profile trade-offs: no free tier, cloud-only storage, Electron apps, documented price hikes, and an unrecoverable solo account if the Secret Key is lost. For families and teams that want audited security and will pay, it's the reference point; for free-tier needs, NordPass or Bitwarden fit better.

Where to next

Sources

All facts trace to the deep fact pack (retrieved 2026-09-25, search-served captures unless noted), which cites:

Pricing and bug-bounty tiers are snapshots (2026-09-25) — verify on official pages on publish day (promo first-year rates change often; quote audit counts only after checking the assessments page). No invented test results, ratings, or first-hand testing claims appear on this page; 1Password's affiliate program is PENDING approval — no live affiliate links until approved.