Getting your passwords out of LastPass is straightforward. Deciding where they go next is the part that makes people hesitate.
After the 2022 breach, when attackers walked off with encrypted vaults belonging to millions of users, a lot of people quietly started looking around. Some moved to 1Password or Bitwarden. Others downloaded their export, opened the CSV, saw a few hundred lines of readable credentials, and froze.
If that is where you are right now, CSV downloaded and decision pending, this guide is for you.
The short version: SecureKeep reads a LastPass CSV directly. Every login comes across in one bulk transaction, TOTP secrets and URLs included, on your phone, with no cloud account sitting in the middle. Once the CSV is on your computer, the import itself takes a minute or two.
The long version is below.
What you'll need
Three things, all of which you already have:
- A LastPass account you can still log into in a browser.
- A computer to run the export from. (LastPass's mobile app can't export; the browser extension or web vault can.)
- SecureKeep installed on your phone: iOS or Android. You'll find the CSV import at
Settings โ Import from CSV, or right inside the credentials list.
That's it. You won't need a second password manager, a bridge tool, or any cloud upload.
Step 1: Export your LastPass vault
The cleanest export path is through the LastPass web vault.
- Open
https://lastpass.com/in a browser and sign in. - Click your account name in the bottom-left, then choose Advanced Options โ Export โ LastPass CSV File.
- Re-enter your master password if prompted. LastPass will download a file named something like
lastpass_export.csv.
The file contains every credential you've stored in LastPass: site name, URL, username, password, the extra field (your secure notes attached to logins), and, if you added them, TOTP secrets in a column called totp. Folder names show up in a column called grouping.
It is also plain text from top to bottom. Every password in it is readable. We'll deal with that in Step 4.
Step 2: Open SecureKeep and import the CSV
On your phone:
- Open SecureKeep and unlock your vault. (If you don't have one yet, the first-run wizard will walk you through creating one in about six minutes. Come back here when you're done.)
- From the dashboard, tap Passwords, then tap the Import CSV button in the top-right of the credentials list. (You can also reach it from
Settings โ Tools โ Import from CSV.) - The picker that opens is the standard iOS/Android files picker. Find the
lastpass_export.csvyou downloaded.
One security detail worth mentioning: the document picker doesn't trigger SecureKeep's lock-on-background protection. We exempted file pickers back in v3.0.0, because otherwise the simple act of choosing your CSV would lock the vault and send you back to the start. The exemption is narrow, limited to known system pickers, and it ends the moment the picker closes.
Step 3: Review the detected format and confirm
SecureKeep auto-detects the LastPass format from the columns in the file. You'll see a banner that reads "Detected format: LastPass" along with a count: how many rows the importer found, how many will be skipped because they're empty or duplicates, and the final number ready to import.
Two things happen automatically here:
- Host-based deduplication runs on every row. If you already have a credential for
gmail.com, importing another one formail.google.comwon't create a duplicate; the importer matches by hostname and skips the redundant entry. This matters because most people doing a LastPass export already have a few manually-added entries in SecureKeep, and the importer leaves those alone. - Your TOTP secrets land in the right field. Any
totpvalue in the LastPass CSV becomes a structured TOTP secret on the imported credential, kept separate from the password and from any backup codes. That's part of v3.0.0's structured 2FA, so your authenticator codes no longer get glued onto the back of the password field.
Tap Import and confirm. The whole import is all-or-nothing: if any single row fails to encrypt and write, the entire operation rolls back and your vault is left exactly as it was. You won't end up wondering which 13 of 200 entries failed. There are no partial states.
Step 4: Delete the CSV
Almost every migration guide stops after the import. This last step is the one that actually protects you.
Your lastpass_export.csv is a plain-text copy of every credential you own, sitting in your Downloads folder, indexed by Spotlight, and possibly synced to iCloud Drive or Google Drive depending on your settings.
After the import succeeds:
- Delete the CSV from your Downloads folder.
- Empty your Trash (macOS) or Recycle Bin (Windows). Files in the trash stay recoverable until you do.
- If you saved a copy anywhere else (a USB stick, a folder you named "passwords-temp"), delete those too.
- If you emailed it to yourself for any reason, delete the email and the deleted-items folder.
The mistake we see most often has nothing to do with the export or the import. It's forgetting the CSV afterward and leaving it in Downloads for months. SecureKeep can't reach into your computer to clean that up. Only you can.
What gets imported, what doesn't
LastPass stores more than just logins. Its CSV export is the logins-only file, and SecureKeep imports it accordingly:
| LastPass field | Imported into SecureKeep |
|---|---|
name |
Credential label |
url |
URL (normalized โ http:// upgraded to https:// where applicable) |
username |
Username |
password |
Password |
extra |
Notes |
totp |
TOTP secret (structured 2FA) |
grouping (folder) |
Not imported in v3.0.0 โ folders are flat in SecureKeep; tags are coming |
fav (favourite flag) |
Not imported in v3.0.0 |
LastPass secure notes, form fills, bank account records, and payment cards aren't part of the standard CSV export. If you relied on those, export them separately (LastPass has an "Export โ Form Fills" option) and keep them in SecureKeep as secure notes or as document attachments. SecureKeep stores those data types too, just not through this CSV path.
Why people leave LastPass
This guide should be useful no matter why you're switching. Still, three reasons come up over and over in the email we get:
On the breaches: the 2022 incident shook people less because LastPass got attacked (every service gets attacked) and more because customers' encrypted vaults were actually copied. The discussion that followed, about iteration counts and key derivation, made clear that some users' vaults were far less protected than others. If your account predates LastPass raising its PBKDF2 iteration count, your master password did less work than a newer user's, and that difference matters once an offline attacker has your encrypted vault on their disk.
On price: LastPass Premium runs $36 a year, and Families is $48 a year. Over five years that's $180 to $240, all for software that lives on someone else's servers. SecureKeep costs $7.99 one time. (We wrote a longer post on the no-subscription angle here.)
On architecture: LastPass syncs your encrypted vault up to its servers. The encryption means staff can't read it, but the vault still sits on their infrastructure, and anyone who exfiltrates it walks away with an offline copy to grind against. SecureKeep doesn't sync at all. Your vault stays on your phone, encrypted under a key derived from your master password, and it only leaves the device when you deliberately export a backup. Nobody can steal a copy of your vault off our servers, for the simple reason that we don't run any.
None of this is a reason to bolt from a password manager you're happy with. It's a reason to get clear on what you actually want from one.
After the import: a five-minute cleanup
Once the import lands, take five minutes to:
- Open the Password Health dashboard (Settings โ Password Health) and look at the reuse and age summary. A LastPass export won't tell you which passwords you reused across sites. SecureKeep will. Start with the top three offenders.
- Walk through any TOTP codes you imported. Open one and confirm the 6-digit code matches what your authenticator app shows. If it lines up, you can retire that authenticator entry whenever you like.
- Set up your Emergency Card and name your trusted person. The reason to gather everything in one place is so the people who depend on you can actually reach it when they need to, and the Emergency Card is what makes that concrete.
- Delete your LastPass account once you're sure about the switch. (Account โ Delete Account in the web vault.) Deleting it also removes the encrypted vault from LastPass's servers, leaving your phone as the only place your passwords live.
Frequently asked questions
Is the import secure? The CSV is read on your device, parsed in memory, and each credential is encrypted with your vault's per-vault data encryption key (AES-256-GCM) before being written to disk. The plaintext CSV exists only in memory during the import and is discarded as soon as the transaction completes.
Can I import to a specific vault if I have multiple? Yes. The import lands in whichever vault is currently open. Switch vaults from the picker before you tap Import CSV if you want it to go to your spouse's vault or a parent vault.
What if some passwords fail to import? The import is transactional and all-or-nothing. If any row fails (e.g., malformed CSV), the whole import is rolled back and you can fix the issue and try again. You won't end up with a partial vault.
Will it overwrite my existing credentials? No. Host-based dedupe means existing credentials are kept; only new ones are added. If you want to replace an existing entry, edit it manually after the import.
Does the import work on iPad / Mac Catalyst? Yes. The same Files-based picker is used on iPad. The import flow is identical.
Can I delete the CSV from my phone too? SecureKeep doesn't keep a copy of your CSV. The picker hands the file to the importer, the importer reads it once, and the import never writes the CSV anywhere. Whatever copy your file system has is the only one, so clean it up wherever you stored it.
What if I had a YubiKey or second factor on LastPass? The export still works with second-factor enabled; LastPass prompts for it at export time. The resulting CSV doesn't carry your YubiKey configuration, so you'll set up second factors fresh on each account inside SecureKeep using the structured 2FA fields.
Related reading: