Keeper Security logo
Privacy Security · Security Fraud

Keeper Security

Keeper Security is a zero-knowledge identity security platform that combines password management, privileged access, secrets, remote connections, endpoints and databases for individuals, families, businesses, MSPs and public sector bodies, with end-to-end AES-256 encryption.

Active GDPR compliant Free trial Subscription API available 18+ Verified by Guidaio
Overview

What is Keeper Security?

Keeper Security presents itself as the unified control plane for privileged access, secrets, remote connections, endpoints and databases in a single zero-trust platform. It started life as a password manager, an encrypted vault with autofill and sharing, and has grown into an identity security platform that covers human users, machines and, in its 2026 positioning, AI agents.

The catalog reflects that widening scope: Password Manager in Personal, Family, Business and Enterprise editions, KeeperPAM for privileged access, Endpoint Privilege Manager, KeeperDB, Secrets Manager, Remote Browser Isolation, Connection Manager, Forcefield and the KeeperChat messenger. Underneath all of it sits one design decision. Keeper is zero-knowledge: encryption and decryption happen only on the user's device, with AES-256 and elliptic-curve cryptography and a client key kept separate at rest, so that, in the company's words, only you can decrypt your data. On top of that base, KeeperAI analyzes privileged activity, scores risk in real time, automatically terminates high-risk sessions and produces encrypted summaries that investigators can work from.

Hosting runs on AWS across several regions, the United States, US GovCloud, Europe with Ireland and Frankfurt, Australia, Canada and Japan, with data isolated in the region the customer chooses. The compliance stack is unusually deep for the category: FedRAMP High, GovRAMP High Authorized, FIPS 140-3 validated by the CMVP, ISO 27001, 27017 and 27018, SOC 2 Type 2, PCI DSS Level 1, HIPAA, FDA 21 CFR Part 11 and TRUSTe. NCC Group and CyberTest run quarterly penetration tests, and the bug bounty and vulnerability disclosure program is handled with Bugcrowd.

The company claims more than 150 countries served, over 93,000 business customers and four million people protected, and points to the 2025 Gartner Magic Quadrant for PAM, a 2025 EMA report and seven consecutive years as a G2 Enterprise Leader, with the Atlassian Williams F1 Team as its showcase reference. More than a hundred technology integrations are advertised and deployment is announced in minutes. The publisher is Keeper Security, Inc., headquartered in Chicago, with product development in El Dorado Hills, EMEA sales in Cork and APAC in Tokyo, co-founded by chief executive Darren Guccione and chief technology officer Craig Lurey.

What it does

  • Store passwords, passkeys, SSH keys, database credentials and files in an end-to-end encrypted vault
  • Open privileged SSH, RDP, VNC and database sessions without exposing credentials, with no agent and no VPN
  • Inject secrets into CI/CD pipelines and infrastructure as code instead of hardcoding them, through GitHub Actions, GitLab, Jenkins, Terraform, Kubernetes or Docker
  • Share credentials and team folders with granular permissions, or send an expiring One-Time Share link
  • Rotate passwords and keys automatically across Active Directory, Azure, AWS, Okta, Cisco, Snowflake, Windows and Linux
  • Give AI agents governed access to secrets through MCP and the Keeper Agent Kit
  • Watch the dark web for compromised credentials with BreachWatch and report on who has access to what for SOX, HIPAA or ISO 27001 audits
Audience

When to use Keeper Security / When not to

A quick filter to help you decide if Keeper Security is the right fit.

When to use Keeper Security

  • IT and security teams that need to remove standing privileged access and move to just-in-time, least-privilege sessions
  • Organizations under heavy compliance pressure: FedRAMP High, GovRAMP High, HIPAA, PCI DSS Level 1, ISO 27001/27017/27018, SOC 2 Type 2, FIPS 140-3 or FDA 21 CFR Part 11
  • US federal agencies and public sector bodies that need a Government Cloud or GovCloud deployment
  • DevOps teams that want secrets out of source code and into CI/CD pipelines, Terraform and Kubernetes
  • Managed service providers running several client organizations from a single console with KeeperMSP
  • Small businesses, families and individuals, from the 5-to-10-seat Business Starter tier down to the Personal and Family vaults
  • Teams starting to deploy AI agents and needing governed secret access through MCP, Claude Code, Codex, Cursor or GitHub Copilot

When not to use Keeper Security

  • Buyers who need a published price before speaking to anyone: no amount appears in the static HTML of the pricing pages, and Enterprise and KeeperPAM are quote-only
  • Anyone looking for a permanently free vault: Keeper offers a free trial, thirty days on the consumer side, but no free tier
  • Organizations that need monthly billing or refunds, since subscriptions are charged annually in advance and fees are non-refundable
  • Users unwilling to safeguard a master password and a recovery phrase, because zero-knowledge means Keeper cannot restore what it cannot decrypt
  • Minors: the services are reserved for users aged 18 and over
  • Employees expecting a strictly private vault on a company account, since a business administrator can access and process the account data
Get started

How to use Keeper Security

A typical end-to-end flow, from setup to results.

  1. Choose your entry point: the Personal and Family trial, the Business and Enterprise trial, or the MSP trial
  2. Create the account and pick your data center region on the sign-up screen
  3. Install what you need: the Web Vault, the Mac, Windows or Linux app, the iOS or Android app, and the Chrome, Firefox, Safari, Edge, Opera or Brave extension
  4. Import your existing credentials from a competing manager or a CSV file with the import tool in the Web Vault or the desktop app
  5. Set the 24-word recovery phrase and second factor: with email verification and 2FA, this is the only way back into a zero-knowledge account
  6. Open the Admin Console to create users, roles, vault policies and security settings
  7. Provision the organization at scale through SCIM, Active Directory or LDAP with Keeper Bridge, and SAML single sign-on with SSO Connect
  8. Start privileged sessions over native SSH, RDP or VNC from the browser or the desktop app, with no agent to install
  9. Move secrets into code with the Secrets Manager SDKs for Java/Kotlin, JavaScript, Python, .NET, Go, Ruby and Rust, the Commander CLI, the VS Code extension, the Terraform provider and the CI/CD plugins
  10. Extend to AI agents with the Keeper Agent Kit, installed from the Claude Code plugin marketplace or the Skills CLI, and a self-hostable MCP server
Quick read

Pros & Cons

Pros

  • A zero-knowledge architecture documented in detail on a public technical page, not merely asserted in marketing copy
  • A rare depth of certification: FedRAMP High, GovRAMP High, FIPS 140-3 validated by the CMVP, ISO 27001/27017/27018, SOC 2 Type 2 and PCI DSS Level 1
  • Data residency chosen by the customer among six AWS regions, with isolation: EU data stays in the EU
  • One platform stretching from a consumer vault to enterprise PAM, MSP fleets and US federal agencies
  • More than a hundred technology integrations, covering SSO and SCIM, SIEM, ITSM, IaC, CI/CD and cloud secret stores, plus native hooks into AI coding assistants and the MCP protocol
  • Agentless privileged connections that need no VPN and no firewall change
  • Quarterly third-party penetration tests, a public Bugcrowd bug bounty, 24/7 chat, phone and ticket support, and a free family plan for every Business user

Cons

  • No price is readable without JavaScript: the pricing grids render as empty slots in static HTML
  • No permanently free vault, only trials
  • KeeperPAM and the Enterprise tier are quote-only, with no public range to anchor a budget
  • Annual billing in advance and non-refundable fees
  • No public sub-processor list could be retrieved, the Trust Center being a JavaScript application with no static content, and no GDPR Article 27 representative is named despite the Irish entity
  • No support email address is published: support runs through a form, live chat, phone or ServiceNow tickets, and the help subdomain is not readable without a browser
  • A very wide catalog mixing consumer, business, MSP and public sector offers, with paid add-on modules such as BreachWatch, file storage, Advanced Reporting and Concierge on top
Pricing

Pricing & Plans

Keeper Security has no permanently free plan. A free trial is offered on all three tracks, Personal and Family, Business and Enterprise, and MSP, announced as 30 days on the consumer side, but every ongoing plan is paid. No starting price can be quoted here: no amount appears in the static HTML of the pricing pages, the figures being injected by client-side script and localized by country and currency. Consumer plans, Keeper Unlimited and Keeper Family, are billed annually and shown as an equivalent monthly price, with a 57% per-user saving advertised on Family compared with Personal. Business Starter, sized for 5 to 10 users, Business and Enterprise are priced per user per month, billed annually; Enterprise, KeeperPAM and KeeperMSP require a quote or a sales conversation. Several modules are charged as add-ons: BreachWatch, secure file storage, Advanced Reporting and Alerts, compliance reporting, support services, Concierge and secure messaging. Subscriptions are charged a year in advance on a standard 365-day cycle, fees are non-refundable, added users are prorated, and VAT or GST applies on top where relevant. Students receive 50%, and military and medical staff have a dedicated offer verified through ID.me.

Personal (Keeper Unlimited)
  • unlimited password storage
  • unlimited devices
  • unlimited secure sharing
  • unlimited identities and payments
  • biometric login
  • web app and browser extensions
  • 24/7 support
Business Starter (Password Manager)
  • encrypted vault and admin console
  • sharing and autofill
  • sized to protect 5 to 10 users
Business (Password Manager)
  • adds shared team folders
  • delegated administration
  • advanced organizational structure and integrations
  • plus a free family plan for every user
Enterprise (Password Manager)
  • adds advanced provisioning through SCIM
  • Active Directory and LDAP
  • SSO/SAML
  • advanced 2FA
  • role-based access control and the developer API
KeeperPAM
  • the full platform
  • with secrets for CI/CD
  • IaC
  • ITSM and MCP for AI agents
  • agentic AI detection and response
  • database management
  • endpoint privilege management
  • automated rotation
KeeperPAM volume tiers
  • up to 24 active non-human identities per year through the Keeper Gateway and 5
  • 000 monthly endpoint workloads included
  • then Tier 1 for 25-99 NHI and 5
  • 001-25
  • 000 workloads
  • and Tier 2 for 100-249 NHI and 25
  • 001-250
  • 000 workloads
KeeperMSP
  • password management
  • infrastructure secrets
  • endpoints and privileged access managed across a provider's client organizations
Dedicated tiers
  • Student with 50% off
  • Military and Medical verified through ID.me
  • and Public Sector / Government Cloud
Special offers — 50% student discount · Dedicated offer for military and medical personnel, with identity verification through ID.me · A free family plan given to every user on a Business tier · A 57% per-user saving advertised on the Family plan compared with Personal · Free trial on all three tracks: Personal and Family, Business and Enterprise, and MSP · KeeperPAM includes at no extra cost up to 24 active non-human identities per year and 5,000 monthly endpoint workloads
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Keeper Security handles your data.

GDPR overview

Keeper publishes a dedicated page stating that it is GDPR compliant and describing the compliance work carried out with TrustArc, whose seal it displays. It is certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. DPF for the web client, the mobile apps and the browser extensions, and is audited annually for SOC 2 Type 2 and ISO 27001. A Data Processing Agreement is incorporated into the terms, downloadable as a PDF and available on request. The Data Protection Officer answers at privacy@keepersecurity.com; deletion runs through deleteme@keepersecurity.com and export through exportme@keepersecurity.com. Access, rectification, erasure, portability, objection, restriction and third-party disclosure opt-out are covered, with the Irish Data Protection Commission and the UK ICO named as supervisory authorities. No Article 27 representative is named, although Keeper Security EMEA Limited operates from Cork under Irish law.

Who owns the data?

Vault content stays the customer's. Encryption and decryption happen only on the user's device: the data key is derived from the master password through PBKDF2 with 1,000,000 iterations, or from an elliptic-curve private key under SSO, and every record is sealed with its own randomly generated 256-bit AES key. Keeper states that no employee can ever reach vault data. Legally, Keeper is the controller when it sells directly to consumers and the processor when it sells to organizations, where the employer controls the account and its administrator can access it. Users can export their own data from the Web Vault in CSV or PDF; Keeper cannot decrypt it on their behalf.

Reuse rights

Keeper states it never mines vault data, by policy and because its architecture makes reading that data impossible, and that collection is limited to what is needed to run the account and provide support. The terms do allow Keeper to collect and analyze aggregated, anonymized usage, telemetry and operational data, provided it contains no Customer Data and cannot identify the customer. Confidential information may only be submitted to AI tools inside a secure, access-controlled environment that does not train models on it. Keeper says it does not sell or share personal information under US state privacy laws, and carries out no automated decision-making or profiling with legal or similarly significant effects. Cookie consent can be withdrawn and marketing opt-out is available at any time. Within those limits customers reuse, share and export their own vault data freely, without asking permission.

Data retention & training

Retention summary
Keeper keeps information for as long as an account is active or as long as needed to provide the service. Actual durations depend on the purpose of the processing, on contractual and legal obligations, and on the need to resolve disputes or enforce agreements. Deletion is requested at deleteme@keepersecurity.com, and deleting the account also cancels the active subscription. An expired account not renewed within 90 days may have its records containing files deleted after prior notice, and an account inactive for twelve consecutive months may be terminated and deleted after notice to the associated email address. Confidential information exchanged between the parties is destroyed at the end of the contract unless a law or regulation requires it to be kept. No figure is published for logs, telemetry or backups. Users can freeze their account to stop any new data being sent.
Trains on customer data
No
DPA available
Yes

Hosting summary

Hosting is entirely on AWS, on hardened infrastructure spread over several regions. A business customer selects a primary region at the outset, among the United States, US GovCloud, Europe, Australia, Canada and Japan; consumers pick their data center on the account creation screen. Each primary region replicates across multiple availability zones and regions: the US commercial region uses East and West sites, as does US GovCloud, Europe uses Ireland and Frankfurt, Australia falls back to Canada, Canada replicates internally, and Japan is primary in Tokyo with replication to Osaka. Data and access are isolated in the selected region, which Keeper sums up as EU data stays in the EU. Everything is encrypted in transit with TLS and at rest with AES-256, on top of the zero-knowledge model in which keys never leave the user's device. Jurisdiction follows the contracting entity rather than the hosting region: Keeper Security, Inc. in the United States, Keeper Security EMEA Limited in Ireland and Keeper Security APAC KK in Japan.

Hosting countries
🇺🇸 United States🇮🇪 Ireland🇩🇩 Germany🇦🇺 Australia🇨🇦 Canada🇯🇵 Japan
Hosting regions
United StatesUnited States GovCloudEUAustraliaCanadaJapan
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Keeper Security.

  • No price is displayed without JavaScript, so the offers cannot be compared from the pricing page itself, and prices, fees and discounts can change at renewal on written notice
  • Fees are billed annually in advance and are non-refundable, which makes an ill-fitting tier expensive to leave
  • Dormant accounts are at risk: twelve consecutive months of inactivity can lead to termination and deletion, and an expired account not renewed within 90 days may lose records containing files, in both cases after notice
  • Zero-knowledge cuts both ways: lose the master password without the recovery phrase and the data is unrecoverable, since no support desk can decrypt it for you
  • On a business account the administrator can reach account data and usage information, so a work vault should never be treated as a private one
  • A single vault concentrates every credential you own: comfortable autofill can breed complacency about the one password you still have to remember, about who is looking over your shoulder, and about the device left unlocked
  • Three contracting entities depending on where you are, in the United States, Ireland and Japan, under Delaware, Irish and Tokyo law respectively, with no public sub-processor list and no named Article 27 representative
Setup

Setup & Integrations

Technical difficulty

Two very different levels. For an individual, setup takes minutes and no technical skill: create the account, choose a data center, install an extension or an app, import from a competitor or a CSV file. For an organization, deployment is announced in minutes and privileged connections need no agent, no VPN and no firewall change, but SSO Connect, Keeper Bridge for AD and LDAP, SCIM provisioning, the Keeper Gateway and a self-hosted MCP server all call for an IT team, and developer use assumes DevOps skills. Onboarding, Keeper University, Keeper 101 videos, docs.keeper.io and paid professional services are available.

Deployment

Web appMobile appBrowser extensionDesktop appAPIPluginSlack appChrome extensionIOS appAndroid app

Apps stores

Integrations

Okta Microsoft Entra ID Ping Identity PingOne IBM Verify Google Workspace OneLogin Auth0 Microsoft ADFS AWS JumpCloud Rippling SecureAuth Shibboleth Duo HENNGE CloudGate UNO F5 Imprivata RSA SecurID Access Thales SafeNet Trusted Access HYPR Trusona TraitWare Transmit Security Secret Double Octopus Veridium PureID Active Directory LDAP SCIM Microsoft Windows Active Directory Terraform Ansible Ansible Automation Platform Chef Puppet Kubernetes External Secrets Operator Docker Jenkins GitHub Actions GitLab Bitbucket Azure DevOps TeamCity Octopus Deploy Harness Heroku JFrog Artifactory Git HashiCorp Vault AWS Secrets Manager AWS KMS Azure Key Vault Azure Logic Apps Google Cloud Secret Manager Google Cloud Key Management Oracle Cloud Infrastructure Vault Entrust HSM Snowflake Splunk Microsoft Sentinel Datadog Elastic Stack Sumo Logic Securonix Exabeam LogRhythm Logpoint Devo Scalyr SolarWinds Rapid7 InsightIDR IBM Security QRadar ManageEngine Log360 AT&T Cybersecurity Google Security Operations CrowdStrike Falcon Next Gen SIEM Cortex XSOAR ServiceNow Jira Freshservice Slack SailPoint Saviynt ConductorOne Opal Lumos Devolutions Visual Studio Code JetBrains IDEs PowerShell Raycast ITerm2 Linux Keyring Claude Code Model Context Protocol (MCP) GitHub Copilot Cursor Codex OpenClaw Chrome Firefox Safari Microsoft Edge Brave Opera YubiKey Google Authenticator Microsoft Authenticator Titan Security Key Apple Watch Android Smartwatch Cisco Meraki Cisco IOS XE Cisco APIC 1Password LastPass Dashlane Bitwarden KeePass KeePassXC MacPass RoboForm Enpass MSecure SplashID Sticky Password True Key Passpack Password Boss Zoho Vault Kaspersky Avast Excel Python Java Kotlin JavaScript .NET Go Rust

Supported languages

EnglishSpanishGermanFrenchDutchPortugueseJapaneseChinesePolishItalianRussianArabic
Company

Behind Keeper Security

Company name
Keeper Security, Inc.
Founded
10/12/2011
Country of origin
🇺🇸 United States
Headquarters
311 W. Monroe Street, Suite 406, Chicago, IL 60606, United States
EU office
5A King's Terrace, Lower Glanmire Road, Cork T23 DX49, Ireland
US office
311 W. Monroe Street, Suite 406, Chicago, IL 60606, United States
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States

Fundraising

Insight Partners is named on the About page as a strategic investor: <i>Keeper is backed by Insight Partners, a leading, global venture capital and private equity firm.</i>
Summit Partners is named as a second strategic investor on the same page
No amount, no date and no funding round for Keeper itself is published on the site; the only figures quoted concern the funds themselves, not Keeper
Insight Partners' own article, Behind the Investment: Keeper Security, is cited as background reading

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement Keeper Security.

C CyberArkB BeyondTrustD DelineaO One IdentityI Island BrowserA AWST TeleportD DBeaverE Evo Security1 1PasswordL LastPassD DashlaneB BitwardenN NordPassK KeePassN N-able PassportalP Password Boss
FAQ

Frequently asked questions

Can Keeper read what is in my vault?
No. The architecture is zero-knowledge: encryption and decryption happen only on your device, and Keeper states that no employee is ever able to access customer vault data.
Is my data used to train AI models?
No. Keeper states it will never mine customer vault data for any purpose, and its terms only allow confidential information to be submitted to AI tools in a secure, access-controlled environment that does not train models on it.
Where is my data hosted?
On AWS, in the region the customer selects: United States, US GovCloud, Europe with Ireland and Frankfurt, Australia, Canada or Japan. Data and access are isolated within the chosen region.
Is Keeper GDPR compliant?
Keeper states it is, on a dedicated GDPR page. A Data Processing Agreement is downloadable and available on request, and the Data Protection Officer can be reached at privacy@keepersecurity.com. No Article 27 representative is named on the site.
Which certifications does Keeper hold?
FedRAMP High, GovRAMP High, FIPS 140-3, ISO 27001, 27017 and 27018, SOC 2 Type 2, PCI DSS Level 1, HIPAA, FDA 21 CFR Part 11 and TRUSTe.
Is there an API?
Yes. A REST API covers vault management, provisioning and audit logs, alongside Secrets Manager SDKs for seven languages, the Commander CLI, a VS Code extension and a Terraform provider.
Is there a free plan?
No. There is a free trial, announced as 30 days on the consumer side and available for Business, Enterprise and MSP as well, but no permanently free tier. Business users do get a free family plan for personal use.
How do I export my data or delete my account?
You can export from the Web Vault in CSV or PDF at any time; Keeper cannot decrypt the data for you. Deletion is requested at deleteme@keepersecurity.com and assisted export at exportme@keepersecurity.com. The minimum age to use the service is 18.
Which apps are available?
Web vault, Mac, Windows and Linux desktop apps, iOS and Android apps, and extensions for Chrome, Firefox, Safari, Edge, Opera and Brave, plus the KeeperChat encrypted messenger and a Slack app.
Does Keeper work with AI assistants?
Yes. The Keeper Agent Kit and the Model Context Protocol give AI agents governed access to secrets, with named integrations for Claude Code, Codex, Cursor and GitHub Copilot. Support is 24/7 through documentation, chat, phone and tickets, but no support email address is published.
Conclusion

Should you pick Keeper Security?

Keeper Security is a mature product from a Chicago company that also operates from Ireland and Japan, on a domain registered in 2007 and first archived by the Wayback Machine in December 2011. Its differentiator is the combination of a zero-knowledge architecture documented in public technical detail, an unusually deep stack of regulatory certifications, and a scope that now reaches well beyond password management into privileged access, secrets, endpoints and databases. Few vendors cover a family vault and a FedRAMP High federal deployment from the same platform.

The natural audience is IT and security teams in regulated organizations, managed service providers and US federal agencies, with individuals and families served by the consumer tiers. DevOps teams that need secrets out of source code, and the growing number of teams wiring AI agents into production, will find first-class support through the SDKs, the Terraform provider, the CI/CD plugins and the MCP server.

The main obstacle is not the product but the buying process. No price appears in the HTML of the pricing pages, so nothing can be compared or budgeted without going through the site with JavaScript enabled or asking for a quote, and everything above the consumer and Business tiers is quote-only. Billing is annual, in advance and non-refundable, which raises the cost of being wrong.

Three things are worth settling before signing: the actual price in your currency and for your seat count, the exact scope of the tier you are buying, since add-on modules are charged separately, and the documentation you need for your own compliance file, meaning the sub-processor list, which is not publicly readable, and the Data Processing Agreement. Finally, remember what zero-knowledge implies: the recovery phrase is your only safety net, and no one at Keeper can replace it.