Locke
A password manager built around stopping phishing specifically — instead of just storing your passwords, it gives you disposable email addresses and warns you when a site is impersonating a real one.
🔗 Visit LockeDescription
Most password managers focus on remembering credentials for you, which is useful but doesn't actually stop the underlying problem: phishing sites tricking people into typing real passwords into fake pages. Locke frames itself differently, as a stack specifically built to prevent phishing, with password storage as one part of a bigger picture rather than the whole product.
Locke combines a standard password manager with anonymous email aliases (a 'Secure Inbox' so your real address is never exposed to sites you sign up for), a browser extension that detects impersonation attempts in real time, and passkey authentication cryptographically bound to the correct domain so it can't be tricked by a lookalike site. It uses post-quantum hybrid encryption (X25519Kyber768) alongside standard end-to-end encryption, supports TOTP codes, and offers 'Trusted Circle' encrypted account recovery plus multi-tenant support for MSP partners managing several clients. Its passkey library is open source (MIT license). Pricing is a genuinely usable free tier ($0, unlimited passwords and devices, 500MB storage, 1 Secure Inbox) and a Pro/Families tier at $4.99/month (unlimited inboxes, up to 10 family members, 5GB storage), with Business/Enterprise pricing available on request.
💬 Our review
The short version: Locke is a password manager that takes phishing seriously as its main threat model, not just password storage — the anonymous email aliases and domain-bound passkeys are real, structural defenses rather than marketing language.
Against 1Password or Bitwarden, Locke's free tier is unusually generous (unlimited passwords and devices) and its $4.99/month Pro tier undercuts 1Password's family pricing while adding phishing-specific features neither incumbent emphasizes as heavily. Post-quantum encryption is a genuine forward-looking touch, though it matters more as insurance against a future threat than a problem most users face today. The tradeoffs are the ones any newer identity-security product carries: less third-party security auditing history than Bitwarden (which is open source end-to-end) or 1Password (much longer track record), and the blog being inactive is a minor but noticeable signal about how actively the company is communicating right now, even though the product endpoints themselves are live and functioning.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Gratuit (illimité mots de passe/appareils, 500MB, 1 boîte sécurisée) ; Pro/Familles $4.99/mo ; Business/Enterprise sur devis
Pros
Alias email anonymes intégrés (Secure Inbox) pour ne jamais exposer sa vraie adresse
Détection d'usurpation en temps réel via l'extension navigateur
Passkeys liées cryptographiquement au bon domaine, donc infalsifiables par un site imitateur
Plan gratuit généreux (mots de passe et appareils illimités)
Cons
Moins d'historique d'audit de sécurité tiers que Bitwarden ou 1Password
Blog inactif, signal faible sur la communication actuelle de l'entreprise
Chiffrement post-quantique utile en prévention mais pas un besoin urgent pour la plupart des usagers
Écosystème d'intégrations entreprise moins mature que les leaders établis
