Security principles
Audience: Bitwarden engineers and AI agents building or reviewing behavior that touches vault data, and external readers who want to understand Bitwarden's security model.
Principles are the overarching philosophies and commitments that guide Bitwarden's approach to security. They are not actionable rules. They state what Bitwarden aims to achieve and why, and they serve as the justification for the concrete security requirements that follow. Each principle carries an identifier (P01, P02, and so on) that the rest of this documentation references directly, as described in the security section's conventions.
Principles
P01 - Servers are zero knowledge
There is no possibility for an attacker or Bitwarden employee to access your unencrypted data by
P02 - A locked vault is secure
Clients must ensure that highly sensitive vault data cannot be accessed in plain text once the vault
P03 - Limited security for vaults on semi-compromised devices
This principle applies only to unlocked vaults. Refer to P02 for details
P04 - No security on fully compromised systems
This principle applies only to unlocked vaults. Refer to P02 for details
P05 - Controlled access to vault data
Clients must ensure that vault data, whether at rest or in use, is accessible only to authorized
P06 - Minimized impact of security breaches
Even with robust security measures in place, user error or unforeseen vulnerabilities can lead to