I trust 1P cloud storage more with their well thought out security concept than Dropbox or self-hosted nextcloud. The 1P security whitepaper goes into great detail why their cloud concept is not at all comparable to just hosting the vault on block storage.
There are companies who are pulling in the rein with regard to its placement of sensitive data, encrypted at rest or not. That is, going cloud-less (or more accurately, privately-owned public cloud, and more often, private cloud)
The prevailing concern isn't insecurity of using public cloud by using zero
knowledge, but the containment/confinement of potential damage when an end user lose control of their password manager app (hacked, laptop-stolen or accidentally leaked) by having this delete feature at the self-hosted server. This is something that Netwirx PasswordSafe really excels at.
SOC 2, HIPAA, ISO 27001 and various military guidelines are a few reasons why.
And yes, apps should also password-protect and event-log the URL configuration field separately from the password used in database(s) as well ... from any change, accidentally or maliciously.
That is following inline with still-so Common Criteria guideline.