1. Vendors
  2. Security and backup
  3. Bitwarden
Bitwarden · bitwarden.com · Security and backup

Bitwarden’s security documents, tracked since February 2026.

Bitwarden’s public security whitepaper, compliance page, security policy and enterprise policies, with every notable change in plain English.

At a glance
Documents monitored8
Last notable changeOct 5, 2026Bug Bounty Program
Notable changes3 in 8 monthstypical vendor on these pages: 2 in 8 months
Updates detected since February 202613including formatting and page changes
Sub-documents identified so far1linked from Bitwarden’s own documents
MonitoringActivesince Feb 3, 2026
Public page updated monthly · Last updated October 8, 2026 · Next update November 1, 2026Legal Sentinel tracks these documents continuously. See it in a demo
What RIAs should know

Bitwarden published a 2026 SOC 3 report and a cryptography audit.

In September 2026, Bitwarden’s Security Whitepaper began pointing to a 2026 SOC 3 report, a public summary of its SOC 2 report, in place of the 2025 version.

In July 2026, Bitwarden added a 2025 cryptography report: an audit of its core cryptography by the Applied Cryptography Group at ETH Zurich, which assumed a fully malicious server.

Bitwarden says it uses approved transfer mechanisms, such as EU Standard Contractual Clauses or the EU-U.S. Data Privacy Framework, where required.

What the terms say

What Bitwarden’s documents say about client data.

Quoted from the current version of each document. The right-hand column shows how many of the 75 vendors we monitor have a matching clause.

Sharing data with third parties

Addressed

“We use applicable, approved information transfer mechanisms where required, such as EU Standard Contractual Clauses (SCCs), or the EU - U.S. Data Privacy Framework.”

Bug Bounty Program · as of Oct 8, 2026 · view source
92%
of monitored vendors (69 of 75)
Change history

What changed, and when.

Notable changes since monitoring began in February 2026, newest first. Each is written from our automated comparison of the before and after versions, then reviewed by a person.

Oct 5, 2026Bug Bounty ProgramSecurity

Published 2025 Cure53 security assessments of its apps

Adds 2025 Cure53 penetration tests and audits of the browser extension, core application and desktop application.

Sep 19, 2026Security WhitepaperSecurity

Updated its public SOC 3 report to the 2026 edition

The Security Whitepaper now links to the 2026 SOC 3 report, a public summary of Bitwarden’s SOC 2 report.

Jul 5, 2026Bug Bounty ProgramSecurity

Published a 2025 cryptography audit by ETH Zurich

The Applied Cryptography Group at ETH Zurich audited Bitwarden’s core cryptography operations under the assumption of a fully malicious server.

+ 10 other updates detected, such as formatting, page layout and wording changes.
  • Oct 5, 2026: Bug Bounty Program
  • Oct 5, 2026: Enterprise Policies
  • Sep 21, 2026: Security Compliance
  • Sep 4, 2026: Security Compliance
  • Sep 2, 2026: Security Policy
  • Aug 28, 2026: Bitwarden Security Whitepaper
  • Aug 28, 2026: Security Compliance
  • Aug 3, 2026: Security Compliance
Documents monitored

8 Bitwarden documents.

Sub-documents are other Bitwarden documents that its policies link to, such as addenda and product terms. We list the ones identified so far; there may be others.

DocumentFirst capturedLast changed
Privacybitwarden.com/privacyOct 5, 2026No change detected
Termsbitwarden.com/termsOct 5, 2026No change detected
Security Compliancebitwarden.com/complianceFeb 5, 2026Oct 2, 2026
Bitwarden Security Whitepaperbitwarden.com/help/bitwarden-security-white-paperFeb 3, 2026Sep 19, 2026
Security Policybitwarden.com/help/securityAug 6, 2026Sep 2, 2026
Cookie Settingsbitwarden.comJul 5, 2026No change detected
Bug Bounty Programbitwarden.com/help/is-bitwarden-audited
Links to 1 sub-document identified so far
Feb 5, 2026Oct 5, 2026
Enterprise Policiesbitwarden.com/help/policiesFeb 8, 2026Oct 5, 2026
Questions

Bitwarden terms: common questions.

Does Bitwarden publish a SOC report?

Yes. Since September 2026, Bitwarden’s Security Whitepaper links to a 2026 SOC 3 report, which is a public summary of its SOC 2 report.

Has Bitwarden's cryptography been independently audited?

Bitwarden published a 2025 cryptography report from an audit by the Applied Cryptography Group at ETH Zurich, conducted under the assumption of a fully malicious server. We detected it in July 2026.

Scope and limitations. This page describes what Bitwarden’s public documents say as of the dates shown. We monitor the documents listed above; we don’t verify how Bitwarden operates in practice, test its security controls or confirm regulatory compliance. It isn’t legal advice, and it doesn’t cover negotiated agreements or order forms. Request a correction · No vendor pays to be listed.