Passwords were supposed to be on their way out. Instead, we now have passwords, passkeys, secrets, service accounts, AI agents, and a growing collection of credentials that need to be protected. For companies in particular, identity security is becoming more important to proactively address.
Bitwarden says that increasing need for managing all types of credentials is helping drive demand for its trusted open source security products. The company has now surpassed 15 million users and 80,000 businesses worldwide, with its services reaching people across 180 countries and more than 50 languages.
Those are impressive numbers for a company that continues to put open source at the center of its identity. Bitwarden offers a free password manager for individuals, while its paid Premium, Families, Teams, and Enterprise plans add features for people and organizations with more advanced requirements.
The growth isn’t limited to individual users, either. Bitwarden says total new business subscriptions increased more than 70 percent year-over-year during the second quarter of 2026. For the first half of the year, new business subscriptions were up 60 percent compared with the same period in 2025.
Why are businesses paying more attention to credentials? Unfortunately, attackers know that getting someone’s login information can sometimes be much easier than finding and exploiting a complicated software vulnerability.
Bitwarden points to research showing that 48 percent of IT managers without a password management solution report that their current system for monitoring password health and access is ineffective. Employees also take an average of nine days to update weak or compromised credentials.
Nine days is a really long time for a known bad password to remain in use.
This is also no longer just about employees remembering not to use “Password123.” Modern organizations need to deal with credentials belonging to employees, developers, applications, service accounts, automated systems, and increasingly, AI agents.
Bitwarden has been expanding its products accordingly. Recent additions include Access Intelligence, risk-over-time reporting, Vault Health Alerts, and Password Coaching. These tools are designed to help organizations and individual users find weak, reused, or exposed credentials and do something about them.
Passkeys are another part of the company’s strategy. Bitwarden has been working with Microsoft on native operating system passkey management and support for passkey-based login with Windows 11.
For businesses, Bitwarden has also introduced Automatic Login with SSO, while developers can use the Agent Access SDK, designed to provide AI agents with controlled access to credentials. The latter is particularly interesting as companies experiment with autonomous and semi-autonomous AI systems.
Giving an AI agent unrestricted access to accounts and services creates an obvious problem. The agent may need credentials to perform useful work, but handing software unrestricted access to sensitive secrets isn’t exactly a comforting proposition. The Bitwarden approach enables human-approved credential access to be incorporated into those workflows.
The company is making changes internally as it expands these products, too. Bitwarden recently appointed Andrew Hartnett as chief technology officer. Hartnett previously served as CTO at One Identity and brings experience in identity security and enterprise software development.
“Bitwarden growth reflects the trust people place in products that protect the most sensitive parts of their digital lives,” said Mike Sullivan, chief executive officer at Bitwarden. “That responsibility starts with a simple belief: security should be easy to use, built on trust, and available for everyone.”
The Bitwarden open source model remains one of its most interesting characteristics. Security software ultimately asks users to place an enormous amount of trust in the company producing it. With something as sensitive as a password manager, being able to inspect the underlying code provides an additional degree of transparency that proprietary alternatives cannot offer in quite the same way.
Of course, open source alone isn’t enough, and no password manager eliminates every security risk. Users still need strong authentication practices, while businesses need sensible policies governing who and what can access sensitive systems.
What has changed is the size of the identity security problem. Password managers were once primarily convenient places to store website logins. Today, they are becoming part of a much larger security layer involving passwords, passkeys, developer secrets, enterprise authentication, and machine access.
With more than 15 million users and 80,000 businesses now using its products, Bitwarden is betting that managing all of those identities can happen while retaining its trusted open source roots.
This article is sponsored by Bitwarden.
Support independent tech journalism
NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.
Support NERDS.xyz