A password manager may protect its vault well and still export a file that an ordinary spreadsheet can read. The export is a temporary working copy with a very different risk profile.
Check the format before exporting
Read the export instructions for your current manager and the import requirements of the new one. Do not assume that the exported file inherits the vault’s encryption. Treat a readable CSV as a collection of credentials, not as harmless account metadata.
Choose a location you control. Avoid a shared folder or one that automatically synchronises to places you have not reviewed. Keep screen sharing off while inspecting sensitive data.
Verify a few entries deliberately
Import the file using the new manager’s official interface. Check a small selection of entries for correct website, username and password, including an entry with unusual characters. Check separately whether notes, passkeys or other items are supported; a successful password import does not establish that every type of item moved.
Keep access to the original vault while verifying the transition.
Remove the temporary copies
After verification, delete the export and review the relevant recycle bin and any unintended synchronised copies. Ordinary deletion is not a guarantee that data is unrecoverable from every device or backup. Prevention is easier: make as few copies as possible and keep the export around for as little time as the migration requires. If it was exposed, address the affected credentials rather than relying on deletion alone.