Passwords remain the weakest component of most security architectures, not because the technology is poor but because the demands it places on people are impossible. Nobody can remember eighty distinct high-entropy strings, so they reuse them, and a single breach at one service becomes a credential for many others. Password managers exist to remove that human requirement from the system.
1Password began as a consumer product solving that problem and has since expanded well past it. The enterprise business covers shared credentials across teams, secrets used by applications and infrastructure rather than people, device trust, and support for passkeys, the emerging standard intended to replace passwords with cryptographic keys held by the device. That last transition is a long one, and a company positioned across both the old model and the new is well placed for it.
The company passed US$400 million in revenue in 2025 and carries a valuation in the multi-billion range. It sits in the small group of Canadian software companies that reached global scale without relocating, which is worth noting given how many did not.
The security economics of this category are unusual and worth understanding. A password manager is a concentration of risk by design: it holds the credentials to everything. That makes the company’s own security posture, its encryption architecture and its transparency about both into the actual product. Customers in this market are buying an assurance more than a feature set, and the companies that endure are the ones that treat that as the primary obligation.
The architectural answer to that concentration of risk is to make the vendor incapable of reading what it stores. Encryption and decryption happen on the user’s device with keys the company never holds, so a breach of its servers yields ciphertext rather than credentials. That design imposes real product constraints, including the awkward reality that a forgotten master key cannot be recovered by support, and living with those constraints rather than engineering around them is itself the security guarantee.
The move from consumer to enterprise was the commercially decisive one. Individual subscriptions are a modest business with meaningful churn. Organisational deployments are larger, stickier and expand as the customer grows. Enterprise buyers also bring requirements that deepen the moat, including provisioning integration, audit logging, policy enforcement and compliance attestation, none of which a consumer-focused competitor has any reason to build.
Machine credentials are the larger long-term market and the less visible one. Applications, build pipelines and infrastructure authenticate to each other constantly using API keys, tokens and certificates, and those secrets vastly outnumber human passwords in any modern software organisation. They have historically been managed badly, frequently ending up committed to source control, and the tooling to handle them properly is a substantial category in its own right.
Passkeys represent both the opportunity and the eventual question. As cryptographic device-held credentials replace passwords, the thing being managed changes, and a company whose name is a password is navigating a transition away from the problem it was founded on. Doing that successfully means becoming the layer that manages identity credentials generally rather than passwords specifically, which appears to be the direction of travel.
The company grew for many years without outside capital, which shaped it in ways still visible in the product. A business funded by its customers rather than by investors has to make something people will pay for immediately, and it tends to accumulate a reputation for not doing the things that irritate users, since there is no growth mandate pushing against that. The later venture funding accelerated an enterprise expansion rather than rescuing a struggling business, which is a materially different position to raise from.
Security in this market is not a feature list but a track record, and track records are asymmetric. A password manager that operates for two decades without a catastrophic breach accumulates trust slowly. A single serious failure would destroy it immediately and permanently, because the product is a promise about safekeeping and a broken promise of that kind is not repairable. That asymmetry disciplines every engineering decision the company makes and explains its conservatism about features that would weaken the model.
The shift toward device trust and workforce identity moves the company into a more crowded market. Managing which devices may access which resources under what conditions puts it closer to established identity providers and endpoint management vendors, several of them very large. The counter-argument is that credential management is where developers and security teams already live day to day, and expanding outward from a position of daily use is easier than expanding inward from a position of administrative control.
As a Canadian outcome the company is notable for what did not happen to it. It reached global scale and did not relocate, did not sell early, and did not become a division of a larger American security vendor. Given how many Canadian security companies followed one of those paths, remaining independent and headquartered in Toronto at this size is itself the interesting fact.
At a glance
- Headquarters
- Toronto, Ontario
- Sector
- Credential and secrets management
- Revenue
- Passed US$400M (2025)
- Covers
- Consumer, enterprise, developer secrets, passkeys
Go to the source
This profile is a summary written from public information. For current products, pricing, hiring and company statements, go to the company itself.
Visit 1Password
