Dashlane knows your email, IP address, which devices you use, when you log in, and how you use the app. 'Zero-knowledge' only applies to vault contents. Everything around your vault is visible to Dashlane and anyone who gets access to their systems. Bitwarden publishes full Cure53 audit reports. 1Password publishes SOC 2 reports. Dashlane just says 'we do SOC 2' without showing the results. You're trusting their word, not independent evidence.
What they claim: Dashlane claims 'zero-knowledge' means they have no access to user data
What we found: Dashlane collects: email address, IP address, billing information, device identifiers, usage analytics, and support message records. Their privacy policy states they can 'disclose personal data if it believes it is necessary to protect its rights.' Zero-knowledge applies only to vault contents, not the substantial metadata collected around it.
What they claim: Dashlane claims 'zero-knowledge' architecture — 'we never see your master password or data'
What we found: Dashlane Inc. is incorporated in New York, USA — subject to the CLOUD Act, which compels US companies to provide data to law enforcement regardless of where the data is stored. While vault contents are encrypted, account metadata (registration info, IP addresses, device IDs, login timestamps) is accessible to Dashlane and therefore to US authorities via legal process.
What they claim: Dashlane operates a dual-entity structure: Dashlane Inc. (US) and Dashlane SAS (Paris)
What we found: Dashlane SAS acts as GDPR data controller for EU users, but Dashlane Inc. (US) is the parent company. Data may be 'transferred to, stored by, and processed outside your home country, including in the United States' per their privacy policy. The dual structure provides legal cover but not architectural separation.
What they claim: Dashlane uses Argon2d for key derivation — stronger than PBKDF2
What we found: Dashlane uses Argon2d rather than Argon2id. Argon2d is optimised for resistance against GPU attacks but is vulnerable to side-channel attacks (timing attacks can leak memory access patterns). Argon2id combines both defences. For a cloud-based password manager, Argon2id would be the more conservative choice.
What they claim: Dashlane claims a zero-knowledge security architecture where encrypted vaults are protected by industry-leading security
What we found: In May 2026, attackers brute-forced Dashlane's device registration API by guessing 6-digit one-time tokens at high volume. Once a valid token was matched, the attacker's device was registered as legitimate and the encrypted vault was automatically downloaded. Fewer than 20 users had vaults exfiltrated. The stolen vaults can now be subjected to unlimited offline brute-force cracking with no server-side rate limiting — the same attack that led to cryptocurrency theft after the 2022 LastPass breach.
What they claim: Dashlane dropped native desktop apps in 2023, moving to browser-extension-only
What we found: The web-only architecture means all password management runs inside the browser — the most attacked software on any computer. Browser extensions operate within the browser's security model, which is less isolated than native applications. CVE-2017-11657 demonstrated DLL hijacking in the previous desktop app.
What they claim: Dashlane markets its zero-knowledge architecture as ensuring "no one but you can read the sensitive information you encrypt in the application"
What we found: Attackers brute-forced 2FA protections on May 31, 2026, registered new devices on existing accounts, and downloaded encrypted vaults belonging to fewer than 20 personal plan users. While the vaults remain encrypted, ETH Zurich researchers had already found in early 2026 that Dashlane and other password managers have architectural weaknesses that "undermine zero-knowledge encryption promises and risk vault exposure."
What they claim: Dashlane claims zero-knowledge architecture means "we are unable to provide Secured Data to any third parties, even if we are subject to a valid order"
What we found: ETH Zurich researchers published findings in early 2026 showing that several popular password managers including Dashlane have serious vulnerabilities where features like account recovery and sharing "open attack vectors that undermine" zero-knowledge guarantees. The brute-force incident confirmed the architectural concern: attackers were able to register new devices on accounts by brute-forcing 2FA.
What they claim: Dashlane claims to use "patented security architecture" with multiple layers of protection
What we found: The device registration API that distributes encrypted vaults lacked adequate rate limiting on 6-digit OTP verification, allowing automated high-volume brute-force attempts. A 6-digit token has only 1 million possible combinations. Dashlane's automated defences eventually detected the attack and locked accounts, but not before vaults were exfiltrated. The company is now implementing "additional verification layers" — an implicit admission that the original design was insufficient for a security-critical endpoint.
What they claim: Dashlane references SOC 2 as a compliance framework
What we found: Unlike Bitwarden (published Cure53 audits) and 1Password (published ISE/Onica reports), Dashlane does NOT publish completed third-party security audit reports. They reference SOC 2 as a framework but provide no public evidence of completed audits. Cure53 audits are mentioned historically but current reports are not publicly available.
What they claim: Dashlane claims its "built-in security controls" protect users and their accounts from unauthorized access
What we found: Dashlane's security response to the brute-force attack was to lock out its own customers. Users received vague suspension emails before Dashlane publicly explained what was happening. Users who needed their 2FA codes — stored in Dashlane — couldn't access them because their accounts were locked. The incident was marked "RESOLVED" on May 31 at 22:30 UTC, then changed back to "monitoring" the next day.