To address concerns about provider hacks, you can use local-only managers like KeePass, which keep your vault on your own device rather than the cloud. Alternatively, cloud-based services like 1Password, Bitwarden, or Proton Pass offer zero-knowledge encryption, ensuring that even if the provider is compromised, your sensitive data remains unreadable without your master password.
Best open-source option for security. It offers zero-knowledge cloud sync alongside a self-hosting option, allowing advanced users to run their own infrastructure and eliminate third-party provider risks entirely.
78%
21PasswordBest for balancing ease of use with high security. Its zero-knowledge architecture and use of a secret key ensure your data cannot be accessed by the service provider, even in the event of a sophisticated server-side hack.71%
4KeePassBest for complete control. By keeping your encrypted database file locally on your device rather than a cloud server, it removes the possibility of a third party being breached and exposing your stored information.55%
Recommendations by AI engine
Recommended in · Sep 15 – Sep 29, 2026
BitwardenChatGPT Search5 of 5 answersGoogle AI Mode5 of 5 answers
1PasswordChatGPT Search5 of 5 answersGoogle AI Mode5 of 5 answers
KeePassXCChatGPT Search5 of 5 answersGoogle AI Mode5 of 5 answers
Proton PassChatGPT Search3 of 5 answersGoogle AI Mode3 of 5 answers
KeePassChatGPT Search1 of 5 answersGoogle AI Mode4 of 5 answers
VaultwardenChatGPT Search0 of 5 answersGoogle AI Mode4 of 5 answers
It is a completely valid fear—cloud providers can get hacked (as seen with historical breaches like LastPass). However, modern password managers use strict architectural designs to make sure that even if a server is completely compromised, the attackers get nothing readable.
Your options range from zero-knowledge cloud setups (high security + convenience) to local-only or self-hosted vaults (ultimate control).
1. Zero-Knowledge Cloud Providers (The Balanced Approach)
How it works: Data is encrypted and decrypted locally on your device before it ever touches the cloud. The provider only stores scrambled code (ciphertext) and literally does not possess the mathematical key to unlock it. If they get hacked, the attackers only see gibberish.
Top choices:
1Password : Uses a master password plus an extra locally generated "Secret Key" that never goes to their servers.
How it works: Your encrypted database file lives strictly on your hard drive or local device. There is no cloud sync unless you manually move the file around. Zero server exposure because there is no server.
Top choices:
KeePass (or cross-platform variants like KeePassXC): The gold standard for offline, local database management.
The Catch: Syncing between your phone and computer requires manual file transfers (e.g., via USB or a private local network) or setting up your own sync mechanism. If your hard drive dies and you didn't back up the file, your passwords are gone.
3. Self-Hosted Password Managers (The Tech-Savvy Route)
How it works: You run your own password manager backend server on a home server, a Raspberry Pi, or a private virtual private server (VPS). You get the multi-device sync convenience of a cloud provider, but you own the infrastructure.
Top choices:
Vaultwarden : An unofficial, lightweight alternative server implementation of Bitwarden that you can easily host yourself (using Docker) and connect standard Bitwarden clients to.
The Catch: You are now your own IT department. You are responsible for server updates, security hardening, and disaster backups.
If you want to narrow this down, tell me:
Do you need seamless syncing across your phone and computer , or is an offline desktop setup fine?
How comfortable are you with tech tinkering (like setting up a self-hosted server)?
I can help you pick the exact path that fits your comfort level.
Yes—you can use a password manager without having to trust the provider with the actual contents of your vault. The key distinction is where encryption happens and who holds the decryption key.
Your main options
Approach
If provider is hacked
Convenience
Main trade-off
Zero-knowledge cloud manager
Attacker gets encrypted vault, not plaintext passwords
⭐⭐⭐⭐⭐
You still trust the software/provider not to introduce a malicious client update
Self-hosted manager
You control the server and encrypted vault
⭐⭐⭐
You become responsible for server security/backups
Local encrypted vault
Provider isn't involved at all
⭐⭐–⭐⭐⭐
Sync/backup across devices is your responsibility
Browser/device password storage
Depends heavily on your account/device security
⭐⭐⭐⭐
Less control and portability
1. Zero-knowledge cloud managers — probably the sweet spot
Services such as Bitwarden and 1Password are designed so that your vault is encrypted before it reaches their servers.
For example, Bitwarden says its servers store encrypted/hashed data and that it cannot see the contents of your vault. bitwarden.combitwarden.com 1Password similarly uses a model where your account password, Secret Key, and encrypted vault data are required to decrypt the vault.
So imagine:
Provider's server gets breached → attacker downloads your vault → they get ciphertext rather than a list of your passwords.
That's a very different situation from a conventional website database breach.
The important caveat is that "encrypted vault" doesn't mean invulnerable. If an attacker gets your master password, compromises your computer/phone, or a malicious/compromised password-manager client steals your secrets while the vault is unlocked, encryption of the server-side database doesn't save you.
2. Local-only: KeePassXC
If your concern is specifically:
"I don't want my password database sitting on somebody else's servers at all."
Then KeePassXC is worth looking at.
It stores everything in an encrypted .kdbx database locally. You can put that encrypted file wherever you want—including cloud storage—and the cloud provider sees only the encrypted database.
You can even add a separate key file or hardware key such as a YubiKey to the database.
The downside is that you become the IT department: backups, synchronization, recovery, and making sure you don't lose the database/password are your responsibility.
3. Self-hosting
There's a middle ground: run your own password-manager server.
Bitwarden, for example, supports self-hosting. bitwarden.combitwarden.com This gives you control over the infrastructure, but it doesn't automatically make things safer. An improperly secured, unpatched internet-facing server can create more risk than using a professionally maintained service.
What I'd look for
Regardless of the particular product, I'd want:
End-to-end/zero-knowledge encryption
The provider doesn't possess your vault's decryption key
For example, Bitwarden publishes its encryption architecture and security audits, while Proton Pass says its vaults use end-to-end encryption, AES-256-GCM, open-source apps, and independent audits.
One subtle but important point
A password manager actually reduces your exposure to website breaches.
Instead of:
100 websites → 1 password reused everywhere
you get:
100 websites → 100 unique random passwords → one encrypted vault
If one website gets hacked, the attacker gets that site's password—not your password for everything else.
If I were optimizing for your particular concern, I'd narrow it to two designs:
Convenience: a reputable zero-knowledge manager such as Bitwarden/1Password/Proton Pass. Maximum control: KeePassXC with an encrypted database + carefully managed backups.
The interesting question is then what happens if the password-manager company itself is malicious or its software-update system gets compromised—that's the remaining risk that server-side encryption alone doesn't completely solve.
Yes — and your concern is exactly the right one to have. The key distinction is “the provider gets hacked” vs. “the provider can decrypt my vault.” A good password manager is designed so those are very different events.
Your main options
Cloud password manager with end-to-end/zero-knowledge encryption.
Your vault is encrypted on your device before being uploaded. If the provider's servers are breached, an attacker should get encrypted vault data rather than your plaintext passwords.
Two examples:
bitwarden.com — open-source, end-to-end encrypted, and publishes security/audit information.
1password.com — uses end-to-end encryption plus a separate Secret Key, meaning a server-side attacker doesn't have the Secret Key needed to decrypt your vault.
Local/offline password manager.
With something like keepassxc.org, your vault is an encrypted file you control rather than an account held by a password-manager company. You can keep that file locally or synchronize the encrypted file through cloud storage. The cloud provider never gets the unencrypted passwords. KeePassXCKeePassXC
The tradeoff is that you become responsible for backups, synchronization, and recovery.
The important catch
Even with excellent encryption, a password manager isn't magic. There are several different things that can go wrong:
Threat
What protects you?
Password manager's servers hacked
End-to-end/zero-knowledge encryption
Attacker steals your master password
Strong, unique master password + MFA
Phishing
Passkeys/security keys + careful login habits
Malware on your computer
Device security; encryption can't protect data you've already unlocked
You lose your master password
Carefully designed recovery/backup strategy
Provider goes out of business
A particularly important point: MFA protects your account, but it isn't a substitute for encryption. You want both.
What I'd look for
If your primary worry is “What happens if the password manager itself gets hacked?”, I'd specifically look for:
End-to-end/zero-knowledge encryption
Encryption keys controlled by you
A strong master-password-based key derivation scheme
MFA/security-key support
Public security documentation and independent audits
An easy way to export your vault
A recovery/backup strategy that doesn't give the provider the ability to decrypt your vault
For example, 1Password's additional Secret Key is specifically designed to make offline attacks against stolen server data substantially harder. 1Password Bitwarden similarly states that its servers store encrypted vault data and that even Bitwarden cannot decrypt it.
So you don't necessarily need to avoid cloud password managers because you're worried about a breach. A well-designed one can actually be safer than keeping passwords in a browser, spreadsheet, or notes app because the vault is encrypted before it reaches the provider.
If you tell me what devices you use (iPhone/Android, Mac/Windows/Linux) and whether you'd rather have maximum convenience or maximum control, I can lay out the best 2–3 approaches for you.
For example, 1Password's additional Secret Key is specifically designed to make offline attacks against stolen server data substantially harder. Bitwarden similarly states that its servers store encrypted vault data and that even Bitwarden cannot decrypt it.
That is a completely rational fear—especially given past high-profile incidents in the industry (like the LastPass breaches). When a cloud provider gets hacked, you want to know your data remains gibberish to the attacker.
Fortunately, the industry standard for secure options revolves around Zero-Knowledge Architecture and alternative offline/self-hosted setups. If a provider's servers are compromised, a zero-knowledge setup means the attacker only gets a file of scrambled, un-decryptable code.
Your options range from highly secure cloud conveniences to completely offline local vaults:
Zero-Knowledge Cloud Providers
How it works: Your data is encrypted and decrypted locally on your device using your Master Password before it ever touches their servers. The company literally doesn't know your master password and cannot read your data.
Top choices: 1Password (uses an extra "Secret Key" generated locally that the server never sees), Bitwarden (fully open-source and independently audited), and Proton Pass (backed by Swiss privacy laws and end-to-end encryption).
The risk: If the provider is breached, your data is safe unless your individual master password is weak or you fall victim to a targeted keylogger.
Local-Only (Offline) Password Managers
How it works: There is no cloud server involved at all. Your password database is stored as an encrypted file sitting directly on your hard drive.
Top choice: KeePass (or its mobile/cross-platform derivatives like KeePassXC).
The tradeoff: Because there is no cloud syncing, you have to manually transfer the database file between your computer and phone (via USB, local Wi-Fi sync, or a private self-hosted sync folder). If your hard drive dies without a backup, your passwords are gone.
Self-Hosted Password Managers
How it works: You host your own password sync server at home (e.g., via a Raspberry Pi or a personal NAS) using open-source server emulators like Vaultwarden paired with official Bitwarden client apps.
The tradeoff: You get the seamless multi-device syncing of a cloud manager, but the data lives on hardware you control. It requires some technical setup and maintaining your own backups.
To help narrow down the best path for you, tell me:
Do you need seamless syncing across your phone and computer, or do you prefer a strictly offline setup?
Are you comfortable with technical setups (like self-hosting), or do you want something that just works out of the box?
Yes — and your concern is exactly the right one. The key distinction is “the provider gets hacked” vs. “the provider can read my vault.” A well-designed password manager is built so that a breach of its servers does not automatically expose your passwords.
Your main options
Cloud password manager with end-to-end/zero-knowledge encryption.
Your vault is encrypted on your device before being uploaded. For example, Bitwarden says its servers store encrypted vault data and that the company does not possess the keys needed to decrypt it. It also publishes its source code and undergoes third-party security assessments. BitwardenBitwarden
This is the easiest option for most people because your vault can sync between your phone, computer, and browser.
Self-hosted password manager.
You run the server yourself, so you're not depending on the provider's infrastructure. Bitwarden, for example, supports self-hosting. Bitwarden
The catch is that you become the security team: server updates, backups, TLS, access controls, and protecting the server all become your responsibility. Self-hosting isn't automatically safer.
Local/offline password manager.
Tools such as KeePass-style managers keep an encrypted vault file under your control rather than requiring a password-manager cloud account. You can store/sync that encrypted file yourself. This minimizes the amount of trust you place in a provider, but syncing across devices is more hands-on.
What happens if the password-manager company is breached?
Suppose an attacker steals the company's database.
With a properly implemented zero-knowledge design, they ideally get something like:
encrypted vault + account metadata
rather than:
your actual passwords
For example, Bitwarden says vault data—including usernames, passwords, URLs, notes, and other vault contents—is encrypted before being stored on its servers.
The remaining threat is offline password cracking. An attacker who obtains your encrypted vault can try to guess your master password repeatedly on their own equipment. That's why your master password matters enormously.
The setup I'd recommend for a security-conscious person
You don't necessarily need to avoid cloud password managers. I'd use:
A reputable zero-knowledge password manager.
A long, unique master passphrase that you've never used anywhere else.
Hardware security key/passkey or strong 2FA on the password-manager account.
Randomly generated passwords for everything stored in the vault.
An encrypted offline backup of your vault, so you're not completely dependent on the provider.
Keep your computer/phone and browser updated and protected.
The interesting thing is that a password manager can actually reduce your overall risk: instead of reusing memorable passwords because you have too many to remember, you can have a different random password for every site.
If you tell me iPhone/Android + Windows/Mac/Linux and whether you're comfortable managing your own files/server, I can lay out the tradeoffs between Bitwarden, 1Password, KeePass/KeePassXC, and self-hosting specifically for your situation.
For example, Bitwarden says vault data—including usernames, passwords, URLs, notes, and other vault contents—is encrypted before being stored on its servers.
It is a completely rational fear. Handing all your digital keys to a single company makes that company a massive target.
Fortunately, the password manager industry solved this problem using a concept called zero-knowledge architecture.
How Zero-Knowledge Protection Works
In a proper zero-knowledge setup (used by reputable providers like 1Password or Bitwarden ), your master password is used to generate a cryptographic key locally on your device.
Your data is encrypted and decrypted only on your phone or computer.
The company's servers only ever see scrambled, unreadable gibberish.
If the provider's servers are hacked and all their data is stolen, the hackers get a database of locked, encrypted files that they cannot open because they don't have your device-generated key.
Even with this safety net, if you still don't want your data sitting on someone else's cloud, you have distinct tiers of options depending on how much control you want.
Your Options Based on Control Level
1. Zero-Knowledge Cloud Providers (The Balanced Approach)
How it works: Your encrypted vault lives on the provider's cloud, but thanks to zero-knowledge encryption, a server breach exposes nothing useful. They also use an extra "Secret Key" or account key generated on your device that the server doesn't have.
Pros: Seamless syncing across all devices (phone, tablet, laptop), easy autofill, effortless backups.
Cons: You still have to trust the company’s code and infrastructure (though reputable ones undergo rigorous independent security audits).
2. Open-Source Cloud or Self-Hosted (The Transparent Approach)
How it works: The source code is entirely public, meaning security researchers worldwide can inspect it for backdoors or flaws. You can use their cloud servers or—if you are tech-savvy—run your own server (self-host) using lightweight alternatives like Vaultwarden.
Top choices: Bitwarden (managed cloud or self-hosted) or Proton Pass.
Pros: Ultimate transparency; if you self-host, your data never touches a commercial third-party cloud.
Cons: Self-hosting requires maintaining your own server, backups, and uptime.
3. Local-Only / Offline File Storage (The "Zero-Trust-Anyone" Approach)
How it works: There is no cloud syncing at all. Your passwords are saved in a single encrypted database file (.kdbx) that lives strictly on your hard drive. If you want it on your phone, you have to manually copy or sync the file via a cable or a private local tool.
Top choices:KeePassXC (for desktop) or apps like Strongbox (for iOS/Mac).
Pros: Completely immune to remote server hacks because there is no server.
Cons: Syncing between devices is a manual chore, and if you lose your device and forget to back up that file to an external drive, your passwords are gone forever.
The Verdict: Which should you pick?
If you want convenience with strong safety , a mainstream zero-knowledge provider like 1Password or Bitwarden is statistically millions of times safer than reusing passwords or writing them on a notepad.
If you want absolute paranoia-level control , use KeePassXC and manage your database file locally.
If you'd like to narrow this down, let me know:
Do you need to sync seamlessly between a phone and a computer , or is an offline desktop setup fine?
Are you comfortable with a paid subscription for polished apps, or do you prefer free/open-source?
It is completely normal to worry about a central vault getting hacked—after all, it feels like putting all your eggs in one digital basket. However, modern password managers use an architecture called zero-knowledge encryption , meaning your data is encrypted and decrypted locally on your device using a master password only you know. Even if a provider’s server is breached, the attackers only see scrambled, unreadable data.
If you still prefer minimizing your exposure or want maximum control, you have several distinct options ranging from standard cloud-hosted zero-knowledge providers to completely self-hosted systems.
Zero-Knowledge Cloud Providers (e.g., 1Password or Bitwarden ): These are the most popular cloud options. They store encrypted data on their servers, but they cannot read it because they never see your master password or the encryption keys. If they get hacked, your vault remains locked tight behind your secret key or master password.
Self-Hosted Password Managers (e.g., Vaultwarden or KeePassXC ): If you don't trust corporate servers, you can host your own Bitwarden-compatible backend (like Vaultwarden) on a home server or a private virtual private server. Alternatively, KeePassXC stores an encrypted database file locally on your machine that you can sync manually via a trusted service or local network.
Local-Only File-Based Managers (e.g., KeePass ): This approach completely eliminates the cloud. Your passwords live in a single .kdbx file stored entirely on your hard drive. You are responsible for backing it up and moving it between your phone and computer manually (via USB, local Wi-Fi sync, or a private sync tool like Syncthing).
Apple iCloud Keychain / Google Password Manager : Built directly into your ecosystem, these use heavy hardware-backed encryption (secure enclaves) and account recovery protections. While they are cloud-hosted by Big Tech, they are deeply integrated into your operating system's security model.
Hardware-Key Secured Vaults : Many advanced managers (like Bitwarden or 1Password) allow you to require a physical security key (like a YubiKey ) for authentication. Even if someone intercepts your master password, they cannot access your account without physically possessing your key.
If you'd like to narrow this down, tell me:
Are you comfortable self-hosting a server at home, or do you need a managed service?
Which devices do you primarily use (e.g., Mac, Windows, iPhone, Android)?
I can recommend the safest setup for your technical comfort level.
Your concern is legitimate—but a password manager getting hacked does not necessarily mean the attacker gets your passwords. The key question is what the provider can decrypt if its servers are compromised.
Your main options
Cloud password manager with end-to-end/zero-knowledge encryption. This is the easiest option for most people. Your vault is encrypted on your device, and the provider stores ciphertext rather than a readable list of passwords.
1Password uses your account password plus a separate, device-generated 128-bit Secret Key. Its current documentation says the provider cannot decrypt your vault, even if its authentication infrastructure were compromised.
Proton Pass uses end-to-end encryption, is open source, and says even its metadata is encrypted so Proton cannot access it.
Bitwarden is another widely used option with a similar zero-knowledge/end-to-end-encryption approach; I'd be happy to compare its current security model with the others.
Self-managed/local password manager. If you don't want a password-manager company holding even encrypted copies of your vault, KeePassXC is an excellent example. It stores an encrypted database file locally rather than operating a password vault service. You can optionally put that encrypted file on cloud storage for synchronization—the storage provider sees only the encrypted database.
The tradeoff is that you become responsible for backups, synchronization, recovery, and device security.
What I'd focus on
The architecture matters more than simply asking whether a company has ever been hacked.
A good setup looks roughly like this:
Your device → encrypt vault locally → provider stores encrypted vault → attacker steals encrypted vault → attacker still doesn't have the key
For example, 1Password specifically separates your account password from its Secret Key, while Proton Pass says its vault data is encrypted such that Proton itself cannot decrypt it.
There's also a practical middle ground
You don't necessarily have to choose between "trust a company completely" and "run everything yourself."
I'd consider:
Use a reputable end-to-end-encrypted manager for convenience.
Make the master/account password long, unique, and never reused anywhere else.
Turn on strong account protection/2FA where appropriate.
Keep a secure offline recovery method.
Make sure your computers and phone are themselves well secured—because once your vault is unlocked on a compromised device, encryption at the provider doesn't save you.
Periodically export/backup your vault in a secure way so you're not completely dependent on one company.
And there's an important distinction: a provider breach and an attacker taking over your individual account are different threats. End-to-end encryption is particularly valuable against the former; strong authentication and device security are crucial against the latter.
If you tell me whether you're on Windows/Mac/iPhone/Android and whether you want something free or don't mind paying, I can compare 1Password vs Bitwarden vs Proton Pass vs KeePassXC specifically around "what happens if the company itself gets hacked?" without focusing on marketing claims.
It’s a completely rational fear—especially given high-profile breaches in the past where cloud vaults were compromised.
The good news is that modern password managers use zero-knowledge architecture , meaning encryption and decryption happen strictly on your device. If a provider's server is hacked, the attackers only get an unreadable chunk of encrypted math (ciphertext), provided you use a strong master password.
However, if you still don't want to trust a third-party cloud server with your encrypted data, you have fantastic alternative options depending on how much control or convenience you want:
Local-Only (Offline) Password Managers
KeePass / KeePassXC: The gold standard for offline security. Your entire database is saved as a single encrypted file (.kdbx ) that lives only on your machine or phone. The provider literally has no server to hack because there is no server. If you want to sync between devices, you have to move the file yourself (via USB, or a private sync tool like Syncthing or a trusted personal setup).
Password Safe: Originally created by security legend Bruce Schneier, this is another classic, highly trusted open-source local database utility.
Self-Hosted Cloud Solutions
Bitwarden (Self-Hosted): Bitwarden is open-source, but you don't have to use their cloud. You can host the server backend yourself on a local home server (like a Raspberry Pi or a NAS) or a private virtual private server (VPS). You get the convenience of cloud syncing across your devices, but you own the server infrastructure.
Zero-Knowledge Cloud with High Trust & Transparency
Bitwarden (Official Cloud) or Proton Pass: If you decide convenience wins out, use an open-source, independently audited provider based in strict privacy jurisdictions (like Proton in Switzerland). Because of zero-knowledge encryption, a server hack still yields no usable passwords as long as your master password is long and unique.
1Password: Uses a unique local "Secret Key" combined with your master password—meaning even if their servers are breached, an attacker missing your local Secret Key cannot brute-force your data.
To help narrow down which path fits you best, tell me:
Do you need seamless syncing across a phone and multiple computers, or do you prefer a strictly offline/local setup?
Are you comfortable with technical setups (like self-hosting), or do you want something out-of-the-box?
Your concern is actually one of the main things modern password managers are designed to address. A provider getting hacked does not necessarily mean the attacker gets a readable copy of your passwords.
The key distinction is where encryption happens.
The safest options
1. Cloud password manager with end-to-end/zero-knowledge encryption
This is probably the best balance for most people.
With a properly designed manager, your vault is encrypted on your device before it reaches the company's servers. The provider stores an encrypted blob rather than a readable database of your passwords.
For example:
Bitwarden — open source, independently audited, and uses end-to-end/zero-knowledge encryption. It also offers self-hosting if you want additional control.
1Password — uses end-to-end encryption plus a separate Secret Key. That means an attacker who obtained your encrypted vault would still need additional information to decrypt it. 1Password also publishes independent security assessments.
Proton Pass — open source, end-to-end encrypted, and independently audited. Proton says even metadata is encrypted in its system.
This is the option I'd recommend for most people.
2. Local-only password manager
If you really don't want to trust any password-manager company, there's another approach: keep an encrypted vault file yourself.
KeePassXC is the classic example. Your passwords live in an encrypted database on your own devices. You can decide whether/how to synchronize backups.
The tradeoff is that you become the administrator. If you lose the database and your backups, there's no company that can recover it for you. If your synchronization or backup setup is poorly configured, you can also create your own security problems.
3. Self-hosting
There's a middle ground: run a password manager server yourself.
Bitwarden supports self-hosting, for example.
But I'd be cautious about assuming "self-hosted = safer." You're now responsible for server security, updates, backups, TLS, authentication, monitoring, and recovery. For an ordinary individual, a professionally operated service with a strong cryptographic design can actually be the safer choice.
What happens if the provider is hacked?
Imagine the provider's database is stolen.
With a good zero-knowledge architecture, the attacker ideally gets something like:
8f4a...encrypted...93bd
rather than:
Gmail → hunter2
Bank → correct-horse-battery-staple
They then have to crack your master password/encryption key to turn that encrypted vault into something useful.
That's why your master password becomes extremely important.
For example, 1Password's architecture requires both your account password and its Secret Key to derive the encryption keys, while Bitwarden says its vault data is encrypted locally before being sent to its servers.
What I'd do
If your concern is specifically "What if the company gets hacked?", I'd narrow it down to:
Option
Provider breach protection
Convenience
My take
Bitwarden
⭐⭐⭐⭐⭐
⭐⭐⭐⭐⭐
Best practical choice
1Password
⭐⭐⭐⭐⭐
⭐⭐⭐⭐⭐
Excellent, especially for families
*The cryptography can be excellent, but your overall security becomes much more dependent on your own setup.
One important caveat
No password manager can protect you if your own device is compromised. Malware that can read what you're doing while your vault is unlocked can potentially steal passwords regardless of how beautifully the vault was encrypted.
So I'd prioritize:
A long, unique master password/passphrase.
MFA/passkey protection on the password-manager account where supported.
Keep your phone/computer updated.
Don't reuse the master password anywhere else.
Keep an offline/recovery backup of your vault or recovery information.
Prefer managers with public security documentation, independent audits, and ideally open-source clients.
If you want the simplest answer: I'd personally put Bitwarden, 1Password, and Proton Pass on the shortlist, rather than avoiding cloud password managers altogether. Their security model means that "the provider got hacked" and "the attacker got all my passwords" are very different events.
If you tell me whether you're iPhone/Android + Windows/Mac, I can also narrow those three down based on your setup and how paranoid you want to be.