# 1Password

> Holds a company’s passwords, keys and credentials in vaults with permissions per person and group, so that access is withdrawn in one place when somebody leaves instead of living on in browsers, spreadsheets and chat histories.

- Vendor: AgileBits Inc., trading as 1Password, Toronto, Canada
- Canonical URL: https://www.convios.com/en/toolbox/1password
- Language version: https://www.convios.com/de/werkzeugkasten/1password
- Area: Governance & security · Cluster: credential management
- Role: Off-the-shelf product · Origin: Established, AI retrofitted
- As of: 2026-08-17 · Reviewed: 2026-08-17 · Author: Dr. Oliver Gausmann, Convios GmbH
- Toolbox: https://www.convios.com/en/toolbox — Markdown: https://www.convios.com/en/toolbox.md

## Verdict

Prevents falling behind: Running central credential management wins nobody a customer. Not running it loses deals: a corporate procurement security questionnaire asks how privileged access is managed, the cyber insurer asks the same, and the first ISO 27001 audit puts the question on the table anyway. The benefit is one-sided and the vendor interchangeable, because Keeper, Bitwarden and the company’s own directory service answer the same question. What separates 1Password from the rest is the key model: the vendor cannot read vault contents even when an authority demands it, and that is what its privacy notice says. This design costs elsewhere, namely in account recovery.

## Suitability by company size

- Solo: suitable — For individuals the vendor publishes prices openly: 2.99 US dollars a month billed annually, 3.99 billed monthly, and for families 4.49 and 5.99 respectively. That is where price transparency ends. Anyone working alone needs neither approval chains nor log export, and the individual plan carries the purpose in full.
- Mid-market: suitable — This is where the use case sits, and where price negotiation starts. On 17 August 2026 the pricing page lists five business products and, next to each, the instruction to request a quote. No entry price appears publicly anywhere. Anyone needing log export into their own analysis system lands on the Business plan, because the Events API hangs off that tier. That is the threshold on which the calculation for a thirty-person firm is decided.
- Enterprise: suitable — The procurement checklist is served: a data processing agreement as an open document, a complete sub-processor list with country and purpose, sign-in through the company’s own directory service, user provisioning via SCIM, log export into Splunk, Microsoft Sentinel, Datadog and a dozen others. One question remains and belongs on the agenda: the core can be run in the EU, while the acquired Privileged Access and Apono areas run exclusively in the United States according to the sub-processor list.

## Vendor staying power

Established: Twenty-one years in market, an equity round of 620 million US dollars in January 2022 and five acquisitions since, the most recent in June 2026. The legal documents are maintained: the data processing agreement and the sub-processor list both carry 30 July 2026. More than 1,400 employees and over 100,000 business customers are the company’s own figures.

- Legal entity and registered office: AgileBits Inc., trading as 1Password, 4711 Yonge St, 10th Floor, Toronto, Ontario M2N 6K8, Canada (source: https://1password.com/legal-center, as of 2026-08-17)
- Founding and headcount, per the company: founded in 2005, more than 1,400 employees (source: https://1password.com/about, as of 2026-08-17)
- Last reported equity round: 620 million US dollars led by ICONIQ Growth, announced on 19 January 2022, with more than 100,000 business customers by the company’s own count (source: https://www.prnewswire.com/news-releases/1password-closes-620m-at-6-8b-valuation-to-bring-human-centric-security-to-all-301463885.html, as of 2022-01-19)
- Most recent acquisition: Apono, a provider of just-in-time access provisioning, announced on 15 June 2026; no purchase price was disclosed (source: https://1password.com/press/2026/june/1password-acquires-apono, as of 2026-06-15)
- Maintenance state of the legal documents: data processing agreement version 4.8 and sub-processor list version 202607, both dated 30 July 2026; the terms of service, by contrast, dated 12 September 2024 (source: https://1password.com/files/legal/agilebits-dpa-012026.pdf, as of 2026-07-30)
- Documented incident and how it was handled: Disclosed by the company on 23 October 2023: using a session leaked at Okta, an attacker reached 1Password’s Okta administration on 29 September 2023. Employee-facing applications were affected; the company’s own investigation found no access to user data. (source: https://1password.com/blog/okta-incident, as of 2023-10-23)

## Cost of leaving

Moderate: The data comes out. Every vault can be exported as CSV or in the vendor’s own 1PUX format, and the privacy notice states explicitly that the company locks nobody out of their own data. The export is also the risk, because it produces an unencrypted file holding every credential in the company, sitting somewhere for the duration of the move. What the export does not carry is the order above it: which group sees which vault, which grant was time-limited, who accessed what and when. That structure is rebuilt by hand at the new vendor. On top come the op:// references in build definitions and deployment pipelines, all of which must be replaced after a switch.

## Regulation and data

| Point | Finding | Evidence | As of |
|---|---|---|---|
| Data processing agreement | public PDF, version 4.8 dated 30 July 2026 — The agreement sits in the legal document library without any login and declares itself part of the respective main contract, so it applies without separate execution. AgileBits acts as processor within it. Anyone needing a signed copy for their own files has to approach sales, which the library states explicitly. Validity does not depend on it. What can be shown in an audit does. | evidenced | 2026-07-30 |
| Storage location | EU, US or Canada selectable, but only for the core — The privacy notice commits to holding encrypted vault contents wherever the customer chooses at sign-up, with the European Union, the United States and Canada on offer. Two limits only surface in the sub-processor list: a shared item is stored in the European Union for as long as the share lasts, regardless of the region chosen, and the Privileged Access and Apono areas run exclusively in the United States. Anyone running the core in the European Union who later adds privileged access leaves the chosen region again at that point. For administrative and diagnostic data the choice does not apply at all: the privacy notice records that these are accessed from and transferred to other countries. | partially evidenced | 2026-07-30 |
| Subprocessors | complete public list with purpose and country — The list in its version of 30 July 2026 names every recipient with entity, product concerned, activity and processing country. Amazon Web Services is the only data centre operator named, with Canada, the European Union and the United States. The four affiliates Apono, Kolide, Trelica and Apono Tech in Israel each carry their own entry, which makes the acquisitions of recent years traceable. Among the further recipients are Google, Datadog, Sentry and Mixpanel, which analyse usage data. | evidenced | 2026-07-30 |
| Third-country transfer | standard contractual clauses in the contract, allocation per recipient not public — The data processing agreement carries the European Commission’s standard contractual clauses under Module 2 in full as Appendix I, and the United Kingdom transfer addendum of the ICO as Appendix II. Both are therefore part of the contract in their full wording. For the vendor’s own seat, the Commission’s adequacy decision for Canada applies in addition, covering organisations subject to the Canadian data protection act. Which of the twenty-one listed recipients operates on which of the two bases is not assigned individually in any of the public documents. | partially evidenced | 2026-07-30 |
| Training on customer data | vault contents excluded, administrative data included — This is the finding that makes the review worthwhile. The privacy notice distinguishes three classes. Vault contents it calls Secure Data, recording that the vendor has no way to decrypt them or pass them on in readable form. Separate from those sit Service Data and Diagnostic Data, and it is precisely these two, alongside contact details, for which the vendor claims a legitimate interest in order to develop and train new technology. Reading the enumeration one level deeper turns up vault names under Service Data. The contents therefore stay sealed. The labels on the cabinets do not. The privacy notice grants a right to object; anyone who does not exercise it stays inside this processing. | partially evidenced | 2025-12-29 |
| Retention and deletion | 60 days on request, at the latest one year after the contract ends — Both periods sit in the data processing agreement under clause 11: on request the vendor deletes or returns customer data within sixty days, and without a request within one year of the services ceasing in any event. Anyone reading only the privacy notice finds none of this; it stays with the formula that data is kept as long as the stated purposes require. For the data protection officer’s file it is therefore the contract that counts. One year is the ceiling and long enough to be worth shortening explicitly in the contract. | evidenced | 2026-07-30 |
| Certifications | ISO 27001, 27017, 27018, 27701 and SOC 2 Type 2 named, evidence only via a form — The legal document library names four ISO standards and a SOC 2 Type 2 attestation, for the vendor itself; the data centre operators carry their own. Anyone wanting to see the certificate fills in a form with name, company, job title, company size and country. Publicly, therefore, neither the version of each standard nor the scope nor the audit period is stated. For a first pass in procurement the naming is enough. The file needs the certificate itself. | partially evidenced | 2026-08-17 |
| EU AI Act, Article 50 | no statement on the regulation, contract older than the AI offering — The vendor advertises access control for AI agents on every page and runs a dedicated solution area for it. Neither the terms of service nor the privacy notice says anything about it: both mention artificial intelligence only in the navigation rendered around the contract text. The terms of service carry the date 12 September 2024 and therefore predate the advertised products. For the vendor’s own duty under Article 50 of the regulation this is tolerable, because no AI in the product faces people and generates content. Anyone deploying the agent controls carries the classification of their own deployment themselves. | partially evidenced | 2024-09-12 |
| Audit logging | export into the customer’s own analysis systems, from the Business plan upwards — The Events API delivers sign-in attempts, item usage and administrative events into the customer’s own analysis system, and the documentation names the destinations, among them Splunk, Microsoft Sentinel, Datadog, Elastic and CrowdStrike. The interface is tied to the Business plan; the documentation says so in its first paragraph. Retention is therefore decided by the customer in their own system, which removes the question of a period at the vendor. Anyone staying below that plan has the events only in the vendor’s own interface. | partially evidenced | 2026-08-17 |

## Cost

- Entry: For individuals 2.99 US dollars a month billed annually and 3.99 billed monthly, for families 4.49 and 5.99 respectively. For the five business products the pricing page names no amount on 17 August 2026, but instead, throughout, the instruction to request a quote. (as of 2026-08-17)
- Where it gets expensive: The split into five separately sold products. Password management, discovery of the services in use, privileged access, device posture and the joint bracket above them are priced one by one. Anyone starting with the password manager who later needs evidence about privileged access buys a second product. It does not exist as an added feature. The second threshold is the Business plan, because log export hangs off it. No amounts can be named here, because the vendor publishes none for business customers.

## Three routes compared

### The directory service you already pay for

Microsoft Entra ID already sits in most companies’ subscriptions and makes passwords unnecessary for everything that supports single sign-on. Corporates stay with it because the directory service is the source for joiners and leavers anyway, and because one access management system is less to audit than two. For privileged accounts on servers and in databases they reach for CyberArk, which records sessions and rotates credentials automatically. The gap stays the same one 1Password gets bought for: the service with no directory connection, the shared account at the payment provider, the key in the deployment script.

### Access for machines and agents

The young class leaves people aside and picks up the accounts that belong to nobody: service accounts, deployment pipelines and, more recently, AI agents. Astrix Security and Entro Security inventory these accesses and withdraw them once they are no longer needed. The price difference cannot be quantified in either direction, because none of those vendors publishes amounts either. What has to be given up is what the established class brings: management of human access. How the two halves grow together is shown by the vendor itself, since Apono, from exactly that class, has belonged to 1Password since 15 June 2026.

### Vaultwarden for people, Infisical for machines

Building this yourself is cheap here, and therefore worth taking seriously. Vaultwarden is an open-source server that speaks to the Bitwarden applications and runs on a small rented server for around ten euros a month. For keys in deployment pipelines, Infisical from this catalogue is available, likewise self-hosted. Going by the vendor documentation, both are set up in a day. Reckoned at a 1,200 euro day rate, setup therefore costs roughly 1,200 euros once plus 120 euros of server cost a year. Setup is the cheap part. Recovery is the expensive one: when a managing director loses her master password, somebody must have built a recovery route that has itself been tested. On top come the browser extensions for four browsers across three operating systems, which need updating after every browser change, emergency access for when the builder leaves, and a log an auditor will accept. Those four things are the price, and they recur every month rather than once.

Recommendation by size:

- Solo: Take it: the individual plan carries the purpose and costs under three US dollars a month.
- Mid-market: Buy it, but negotiate log export into the same quote.
- Enterprise: Settle first what already runs through the directory service, then scope the remainder.

## Context

- Implements method: ["Context: Moat or Wall?" Test](https://www.convios.com/en/methods/context-moat-or-wall-test) — The test separates what creates an edge from what merely prevents falling behind, and credential management reliably lands on the second side when the question is played through honestly.
- Implements method: [Regulatory Density Test](https://www.convios.com/en/methods/regulatory-density-test) — The density of evidence duties decides whether log export is an add-on or the condition of purchase, and that is exactly what the jump to the next plan hangs on here.
- Implements method: [Leading AI Agents as Team Members](https://www.convios.com/en/methods/ai-agents-as-team-members) — As soon as agents take on tasks they need their own credentials with their own permissions, and the question of who gives an agent a password and takes it away again is decided here.
- Alternative: [Infisical](https://www.convios.com/en/toolbox/infisical)
- Alternative: [Ory](https://www.convios.com/en/toolbox/ory)
- Displaces: Shared passwords in spreadsheets, chat histories and sticky notes, A collective account at a service provider whose password nobody rotates any more, The access that survives an employee’s departure because nobody holds the list

## Evidence

- Legal entity, registered office and the complete library of legal documents including the naming of ISO and SOC 2 attestations — https://1password.com/legal-center (as of 2026-08-17)
- Separation of vault contents, service data and diagnostic data, the training clause based on legitimate interest, the choice of storage location and disclosure to authorities in encrypted form only — https://1password.com/legal/privacy (as of 2025-12-29)
- Processing by AgileBits, standard contractual clauses as Appendix I and the United Kingdom transfer addendum as Appendix II, deletion within sixty days on request and within one year of the contract ending — https://1password.com/files/legal/agilebits-dpa-012026.pdf (as of 2026-07-30)
- Sub-processors with purpose and country, Amazon Web Services as sole data centre operator, hosting of Privileged Access and Apono exclusively in the United States, shared items always in the European Union — https://1password.com/files/legal/1password-subprocessor-list.pdf (as of 2026-07-30)
- The terms of service dated 12 September 2024 and the absence of any provision on artificial intelligence in the contract text — https://1password.com/legal/terms-of-service (as of 2024-09-12)
- No price for any of the five business products, replaced throughout by the instruction to request a quote — https://1password.com/pricing (as of 2026-08-17)
- Prices for individuals and families in both billing modes — https://1password.com/pricing/personal (as of 2026-08-17)
- The Events API being tied to the Business plan, the scope of events and the named destinations — https://support.1password.com/events-reporting/ (as of 2026-08-17)
- The acquisition of Apono on 15 June 2026 and its focus on access provisioning for people, machines and AI agents — https://1password.com/press/2026/june/1password-acquires-apono (as of 2026-06-15)
- The equity round of 620 million US dollars led by ICONIQ Growth and the number of business customers by the company’s own count — https://www.prnewswire.com/news-releases/1password-closes-620m-at-6-8b-valuation-to-bring-human-centric-security-to-all-301463885.html (as of 2022-01-19)
- The self-disclosed incident connected to the session leaked at Okta, including timing and scope — https://1password.com/blog/okta-incident (as of 2023-10-23)
- Founding year and headcount by the company’s own account — https://1password.com/about (as of 2026-08-17)
- Access to the certificates solely through a form requiring name, company, job title, company size and country — https://1password.com/resources/iso27001 (as of 2026-08-17)
