How we compare
Where we're different — and honest about where we're early.
The incumbents are mature and audited. We're new, AI-ready, developer-focused and EU-hosted. Here's the honest picture — including the rows where they win.
Built for your AI, safely
The only one here with an MCP server: your agent (Emily) can list vaults and create items, with secret values redacted by default — never handed over. Automation without handing an AI your passwords.
Developer-native
Paste a whole .env and it splits into named variables like Vercel does. Config, API keys and SSH keys are first-class item types, not notes.
European by default
Portugal-first, European Portuguese, and your data lives in an EU Supabase project you control — not a US SaaS you rent.
Honest about security
Zero-knowledge encryption in your browser, and a roadmap we don't dress up. We tell you what's shipped, what's coming, and what we haven't earned yet (like an external audit).
Feature by feature
The full picture.
| Feature | RP Secrets | 1Password | Bitwarden | LastPass | Dashlane |
|---|---|---|---|---|---|
End-to-end encryption (zero-knowledge) | |||||
Independent security audit We're new and not yet audited — we say so. | Soon | ||||
Open-source core | |||||
Personal + shared team vaults | |||||
Sharing with roles (owner/admin/member) | |||||
Password generator + live strength | |||||
Vault health (weak / reused / old) | |||||
Breach check (Have I Been Pwned) | |||||
One-time secret share links | Partial | ||||
MFA / 2FA on the vault | |||||
Bulk .env import + dev config grouping Paste a whole .env; it splits into fields like Vercel. | Partial | Partial | |||
MCP server for AI agents (redaction-first) Your AI can list and create items — never see raw secrets. | |||||
EU data residency (your own Supabase project) | Partial | Partial | |||
European Portuguese interface | Partial | Partial | Partial | Partial | |
Self-host / own your data Runs on a Supabase project you control. | Partial | ||||
Browser extension + autofill | Soon | ||||
Mobile apps | Soon | ||||
Passkey / WebAuthn login | Soon | Partial |
Comparison reflects our understanding of publicly documented features as of 2026. Products change constantly — check each vendor's site for the latest. Names and trademarks belong to their respective owners; this is a good-faith comparison, not an endorsement or affiliation.
Where we're early — plainly
No browser extension or autofill, no mobile apps, no passkey login, and no independent audit yet — all on the roadmap. If you need those today, the incumbents are the safer pick, and we'd rather tell you than oversell.
Straight answers
The questions people actually ask.
The encryption model is the same class: zero-knowledge, keys derived in your browser, the server only stores ciphertext. Where we're genuinely behind is track record and an independent audit — we're new, and we won't pretend otherwise. For the crypto itself, we use standard primitives (Argon2id, AES-GCM, RSA-OAEP).