And they get audited, last one quite recently[1]:
The audit confirmed Proton Pass security is exceptionally robust:
- No remote exploits found: Users cannot be hacked simply by visiting a malicious website or clicking a link.
- No encryption bypasses identified: Attackers can’t use shortcuts, backdoors, or weak keys to bypass the encryption layer.
Take it for what it's worth.
[1]: https://proton.me/business/blog/proton-pass-audit-2026