For the former, use auth app-based 2FA against your master password to guard against unwarranted access, preferably using a physical key.
For the latter, review the security protocols your third-party provider specifies for how they protect your data. That should give you confidence about the likelihood of database leakage. If even that doesn't give you confidence, look at keepass where you can control where and how your passwords are stored.
Remember: you always had a password database in one place (your head), you just leaked information about it everywhere because you invested in a mnemonic for easy lookup. With a password manager, you've only increased the number of database accessors by one while guaranteeing significantly less leakage of your mnemonic, which was always the most likely danger.