Bramble
A password manager that never uploads your passwords to any company's servers — instead, your devices talk to each other directly to stay in sync, so there's no central vault that could ever get hacked or breached.
🔗 Visit BrambleDescription
Most password managers store an encrypted copy of your vault on the company's servers, which is convenient for syncing across devices — but it also means a single breach at that company (which has happened to major password managers before) puts everyone's encrypted vaults in an attacker's hands at once. Bramble avoids that entirely: your vault stays encrypted on your own devices, and syncing happens directly between them.
Bramble is a free, open-source (GPLv3) local-first password manager using AES-256-GCM encryption with Argon2id key derivation. Instead of a cloud server, it syncs across devices peer-to-peer, encrypted end-to-end over WebRTC, using a Nostr relay only to help devices find each other (the relay never sees your data). The same Rust crypto core powers browser extensions, iOS and Android apps, with native autofill and passkey creation/storage synced across devices — no account and no company vault to be breached.
💬 Our review
The short version: if the idea of a single company holding an encrypted copy of every password you own makes you uneasy, Bramble's no-server, P2P-sync model is a genuinely different architecture — and it's free.
Against 1Password, Bitwarden, Dashlane, LastPass and Proton Pass, all of which rely on a central cloud vault (even when zero-knowledge encrypted), Bramble's differentiator is having no server-side vault to breach at all — the tradeoff is that P2P sync is inherently less mature than a decade of cloud-sync engineering, so expect more edge cases around getting new devices online or recovering from a lost device compared to established competitors. Being free, open source and GPLv3-licensed removes any pricing question; the real evaluation is whether you're comfortable being an early adopter of a newer sync model versus the proven convenience of Bitwarden or 1Password.
💰 Pricing
📊 Global score
🤖 AI-enriched data
GPLv3, entièrement gratuit, aucun compte payant.
Pros
Aucun serveur central détenant le vault — rien à pirater côté entreprise
Chiffrement AES-256-GCM + Argon2id, standards solides
Sync P2P chiffrée de bout en bout (WebRTC), relais Nostr ne voit aucune donnée
Gratuit et open source (GPLv3)
Cons
Modèle de sync P2P moins mature que le cloud sync des leaders établis
Onboarding multi-appareils potentiellement plus complexe que Bitwarden/1Password
Pas de support commercial/entreprise formel
