End-to-End Encrypted
Your master key never leaves your device. Keestash encrypts everything locally before syncing — we cannot read your passwords even if we wanted to.
Keestash is a zero-knowledge password manager built in Germany. Use our European cloud — or deploy the open source server on your own infrastructure.
Features
Keestash combines strong encryption, team collaboration, and self-hosting freedom in a single open-source package.
Your master key never leaves your device. Keestash encrypts everything locally before syncing — we cannot read your passwords even if we wanted to.
Run Keestash on your own server with Docker in minutes, or use our managed European cloud. Your choice — switch anytime, export your data whenever.
Share credentials securely within your organisation. Manage access by role, revoke sharing instantly, and maintain a full audit trail.
Instantly detect weak, reused, and potentially compromised passwords. Keestash's health dashboard gives you an actionable security score.
The Keestash server backend is published under AGPLv3 on GitHub. Audit every line of encryption logic, deploy it yourself, or contribute. No black boxes.
Built from the ground up to meet European data-protection standards. Data hosted in Germany, no third-party trackers, right to deletion included.
Privacy & Data Protection
We built Keestash in Germany because we believe European data-protection standards are the gold standard. Here's what that means for you:
Engineering and operations based in Germany, covered by German and EU law.
Data protection by design and by default — not an afterthought.
Independent security researchers can audit every line. No security through obscurity.
Pricing
No hidden fees. No surprise bills. Free forever if you self-host.
Inspect, fork, contribute. Security through transparency, not obscurity. Licensed under MIT / AGPLv3.
Get Started
Join thousands of users and teams who trust Keestash to keep their credentials safe — open source, made in Germany.