
Keeper Security
Keeper Security is a zero-knowledge identity security platform that combines password management, privileged access, secrets, remote connections, endpoints and databases for individuals, families, businesses, MSPs and public sector bodies, with end-to-end AES-256 encryption.
What is Keeper Security?
Keeper Security presents itself as the unified control plane for privileged access, secrets, remote connections, endpoints and databases in a single zero-trust platform. It started life as a password manager, an encrypted vault with autofill and sharing, and has grown into an identity security platform that covers human users, machines and, in its 2026 positioning, AI agents.
The catalog reflects that widening scope: Password Manager in Personal, Family, Business and Enterprise editions, KeeperPAM for privileged access, Endpoint Privilege Manager, KeeperDB, Secrets Manager, Remote Browser Isolation, Connection Manager, Forcefield and the KeeperChat messenger. Underneath all of it sits one design decision. Keeper is zero-knowledge: encryption and decryption happen only on the user's device, with AES-256 and elliptic-curve cryptography and a client key kept separate at rest, so that, in the company's words, only you can decrypt your data. On top of that base, KeeperAI analyzes privileged activity, scores risk in real time, automatically terminates high-risk sessions and produces encrypted summaries that investigators can work from.
Hosting runs on AWS across several regions, the United States, US GovCloud, Europe with Ireland and Frankfurt, Australia, Canada and Japan, with data isolated in the region the customer chooses. The compliance stack is unusually deep for the category: FedRAMP High, GovRAMP High Authorized, FIPS 140-3 validated by the CMVP, ISO 27001, 27017 and 27018, SOC 2 Type 2, PCI DSS Level 1, HIPAA, FDA 21 CFR Part 11 and TRUSTe. NCC Group and CyberTest run quarterly penetration tests, and the bug bounty and vulnerability disclosure program is handled with Bugcrowd.
The company claims more than 150 countries served, over 93,000 business customers and four million people protected, and points to the 2025 Gartner Magic Quadrant for PAM, a 2025 EMA report and seven consecutive years as a G2 Enterprise Leader, with the Atlassian Williams F1 Team as its showcase reference. More than a hundred technology integrations are advertised and deployment is announced in minutes. The publisher is Keeper Security, Inc., headquartered in Chicago, with product development in El Dorado Hills, EMEA sales in Cork and APAC in Tokyo, co-founded by chief executive Darren Guccione and chief technology officer Craig Lurey.
What it does
- Store passwords, passkeys, SSH keys, database credentials and files in an end-to-end encrypted vault
- Open privileged SSH, RDP, VNC and database sessions without exposing credentials, with no agent and no VPN
- Inject secrets into CI/CD pipelines and infrastructure as code instead of hardcoding them, through GitHub Actions, GitLab, Jenkins, Terraform, Kubernetes or Docker
- Share credentials and team folders with granular permissions, or send an expiring One-Time Share link
- Rotate passwords and keys automatically across Active Directory, Azure, AWS, Okta, Cisco, Snowflake, Windows and Linux
- Give AI agents governed access to secrets through MCP and the Keeper Agent Kit
- Watch the dark web for compromised credentials with BreachWatch and report on who has access to what for SOX, HIPAA or ISO 27001 audits
When to use Keeper Security / When not to
A quick filter to help you decide if Keeper Security is the right fit.
When to use Keeper Security
- IT and security teams that need to remove standing privileged access and move to just-in-time, least-privilege sessions
- Organizations under heavy compliance pressure: FedRAMP High, GovRAMP High, HIPAA, PCI DSS Level 1, ISO 27001/27017/27018, SOC 2 Type 2, FIPS 140-3 or FDA 21 CFR Part 11
- US federal agencies and public sector bodies that need a Government Cloud or GovCloud deployment
- DevOps teams that want secrets out of source code and into CI/CD pipelines, Terraform and Kubernetes
- Managed service providers running several client organizations from a single console with KeeperMSP
- Small businesses, families and individuals, from the 5-to-10-seat Business Starter tier down to the Personal and Family vaults
- Teams starting to deploy AI agents and needing governed secret access through MCP, Claude Code, Codex, Cursor or GitHub Copilot
When not to use Keeper Security
- Buyers who need a published price before speaking to anyone: no amount appears in the static HTML of the pricing pages, and Enterprise and KeeperPAM are quote-only
- Anyone looking for a permanently free vault: Keeper offers a free trial, thirty days on the consumer side, but no free tier
- Organizations that need monthly billing or refunds, since subscriptions are charged annually in advance and fees are non-refundable
- Users unwilling to safeguard a master password and a recovery phrase, because zero-knowledge means Keeper cannot restore what it cannot decrypt
- Minors: the services are reserved for users aged 18 and over
- Employees expecting a strictly private vault on a company account, since a business administrator can access and process the account data
How to use Keeper Security
A typical end-to-end flow, from setup to results.
- Choose your entry point: the Personal and Family trial, the Business and Enterprise trial, or the MSP trial
- Create the account and pick your data center region on the sign-up screen
- Install what you need: the Web Vault, the Mac, Windows or Linux app, the iOS or Android app, and the Chrome, Firefox, Safari, Edge, Opera or Brave extension
- Import your existing credentials from a competing manager or a CSV file with the import tool in the Web Vault or the desktop app
- Set the 24-word recovery phrase and second factor: with email verification and 2FA, this is the only way back into a zero-knowledge account
- Open the Admin Console to create users, roles, vault policies and security settings
- Provision the organization at scale through SCIM, Active Directory or LDAP with Keeper Bridge, and SAML single sign-on with SSO Connect
- Start privileged sessions over native SSH, RDP or VNC from the browser or the desktop app, with no agent to install
- Move secrets into code with the Secrets Manager SDKs for Java/Kotlin, JavaScript, Python, .NET, Go, Ruby and Rust, the Commander CLI, the VS Code extension, the Terraform provider and the CI/CD plugins
- Extend to AI agents with the Keeper Agent Kit, installed from the Claude Code plugin marketplace or the Skills CLI, and a self-hostable MCP server
Pros & Cons
Pros
- A zero-knowledge architecture documented in detail on a public technical page, not merely asserted in marketing copy
- A rare depth of certification: FedRAMP High, GovRAMP High, FIPS 140-3 validated by the CMVP, ISO 27001/27017/27018, SOC 2 Type 2 and PCI DSS Level 1
- Data residency chosen by the customer among six AWS regions, with isolation: EU data stays in the EU
- One platform stretching from a consumer vault to enterprise PAM, MSP fleets and US federal agencies
- More than a hundred technology integrations, covering SSO and SCIM, SIEM, ITSM, IaC, CI/CD and cloud secret stores, plus native hooks into AI coding assistants and the MCP protocol
- Agentless privileged connections that need no VPN and no firewall change
- Quarterly third-party penetration tests, a public Bugcrowd bug bounty, 24/7 chat, phone and ticket support, and a free family plan for every Business user
Cons
- No price is readable without JavaScript: the pricing grids render as empty slots in static HTML
- No permanently free vault, only trials
- KeeperPAM and the Enterprise tier are quote-only, with no public range to anchor a budget
- Annual billing in advance and non-refundable fees
- No public sub-processor list could be retrieved, the Trust Center being a JavaScript application with no static content, and no GDPR Article 27 representative is named despite the Irish entity
- No support email address is published: support runs through a form, live chat, phone or ServiceNow tickets, and the help subdomain is not readable without a browser
- A very wide catalog mixing consumer, business, MSP and public sector offers, with paid add-on modules such as BreachWatch, file storage, Advanced Reporting and Concierge on top
Pricing & Plans
Keeper Security has no permanently free plan. A free trial is offered on all three tracks, Personal and Family, Business and Enterprise, and MSP, announced as 30 days on the consumer side, but every ongoing plan is paid. No starting price can be quoted here: no amount appears in the static HTML of the pricing pages, the figures being injected by client-side script and localized by country and currency. Consumer plans, Keeper Unlimited and Keeper Family, are billed annually and shown as an equivalent monthly price, with a 57% per-user saving advertised on Family compared with Personal. Business Starter, sized for 5 to 10 users, Business and Enterprise are priced per user per month, billed annually; Enterprise, KeeperPAM and KeeperMSP require a quote or a sales conversation. Several modules are charged as add-ons: BreachWatch, secure file storage, Advanced Reporting and Alerts, compliance reporting, support services, Concierge and secure messaging. Subscriptions are charged a year in advance on a standard 365-day cycle, fees are non-refundable, added users are prorated, and VAT or GST applies on top where relevant. Students receive 50%, and military and medical staff have a dedicated offer verified through ID.me.
- unlimited password storage
- unlimited devices
- unlimited secure sharing
- unlimited identities and payments
- biometric login
- web app and browser extensions
- 24/7 support
- everything in Personal plus 5 users
- unlimited shared folders
- 10 GB of secure file storage and emergency access for estate planning
- encrypted vault and admin console
- sharing and autofill
- sized to protect 5 to 10 users
- adds shared team folders
- delegated administration
- advanced organizational structure and integrations
- plus a free family plan for every user
- adds advanced provisioning through SCIM
- Active Directory and LDAP
- SSO/SAML
- advanced 2FA
- role-based access control and the developer API
- the full platform
- with secrets for CI/CD
- IaC
- ITSM and MCP for AI agents
- agentic AI detection and response
- database management
- endpoint privilege management
- automated rotation
- up to 24 active non-human identities per year through the Keeper Gateway and 5
- 000 monthly endpoint workloads included
- then Tier 1 for 25-99 NHI and 5
- 001-25
- 000 workloads
- and Tier 2 for 100-249 NHI and 25
- 001-250
- 000 workloads
- password management
- infrastructure secrets
- endpoints and privileged access managed across a provider's client organizations
- Student with 50% off
- Military and Medical verified through ID.me
- and Public Sector / Government Cloud
Data, GDPR & hosting
A consolidated view of how Keeper Security handles your data.
GDPR overview
Keeper publishes a dedicated page stating that it is GDPR compliant and describing the compliance work carried out with TrustArc, whose seal it displays. It is certified under the EU-U.S. Data Privacy Framework, its UK extension and the Swiss-U.S. DPF for the web client, the mobile apps and the browser extensions, and is audited annually for SOC 2 Type 2 and ISO 27001. A Data Processing Agreement is incorporated into the terms, downloadable as a PDF and available on request. The Data Protection Officer answers at privacy@keepersecurity.com; deletion runs through deleteme@keepersecurity.com and export through exportme@keepersecurity.com. Access, rectification, erasure, portability, objection, restriction and third-party disclosure opt-out are covered, with the Irish Data Protection Commission and the UK ICO named as supervisory authorities. No Article 27 representative is named, although Keeper Security EMEA Limited operates from Cork under Irish law.
Who owns the data?
Vault content stays the customer's. Encryption and decryption happen only on the user's device: the data key is derived from the master password through PBKDF2 with 1,000,000 iterations, or from an elliptic-curve private key under SSO, and every record is sealed with its own randomly generated 256-bit AES key. Keeper states that no employee can ever reach vault data. Legally, Keeper is the controller when it sells directly to consumers and the processor when it sells to organizations, where the employer controls the account and its administrator can access it. Users can export their own data from the Web Vault in CSV or PDF; Keeper cannot decrypt it on their behalf.
Reuse rights
Keeper states it never mines vault data, by policy and because its architecture makes reading that data impossible, and that collection is limited to what is needed to run the account and provide support. The terms do allow Keeper to collect and analyze aggregated, anonymized usage, telemetry and operational data, provided it contains no Customer Data and cannot identify the customer. Confidential information may only be submitted to AI tools inside a secure, access-controlled environment that does not train models on it. Keeper says it does not sell or share personal information under US state privacy laws, and carries out no automated decision-making or profiling with legal or similarly significant effects. Cookie consent can be withdrawn and marketing opt-out is available at any time. Within those limits customers reuse, share and export their own vault data freely, without asking permission.
Data retention & training
Hosting summary
Hosting is entirely on AWS, on hardened infrastructure spread over several regions. A business customer selects a primary region at the outset, among the United States, US GovCloud, Europe, Australia, Canada and Japan; consumers pick their data center on the account creation screen. Each primary region replicates across multiple availability zones and regions: the US commercial region uses East and West sites, as does US GovCloud, Europe uses Ireland and Frankfurt, Australia falls back to Canada, Canada replicates internally, and Japan is primary in Tokyo with replication to Osaka. Data and access are isolated in the selected region, which Keeper sums up as EU data stays in the EU. Everything is encrypted in transit with TLS and at rest with AES-256, on top of the zero-knowledge model in which keys never leave the user's device. Jurisdiction follows the contracting entity rather than the hosting region: Keeper Security, Inc. in the United States, Keeper Security EMEA Limited in Ireland and Keeper Security APAC KK in Japan.
Things to keep in mind
Risks and trade-offs to weigh before adopting Keeper Security.
- No price is displayed without JavaScript, so the offers cannot be compared from the pricing page itself, and prices, fees and discounts can change at renewal on written notice
- Fees are billed annually in advance and are non-refundable, which makes an ill-fitting tier expensive to leave
- Dormant accounts are at risk: twelve consecutive months of inactivity can lead to termination and deletion, and an expired account not renewed within 90 days may lose records containing files, in both cases after notice
- Zero-knowledge cuts both ways: lose the master password without the recovery phrase and the data is unrecoverable, since no support desk can decrypt it for you
- On a business account the administrator can reach account data and usage information, so a work vault should never be treated as a private one
- A single vault concentrates every credential you own: comfortable autofill can breed complacency about the one password you still have to remember, about who is looking over your shoulder, and about the device left unlocked
- Three contracting entities depending on where you are, in the United States, Ireland and Japan, under Delaware, Irish and Tokyo law respectively, with no public sub-processor list and no named Article 27 representative
Setup & Integrations
Technical difficulty
Two very different levels. For an individual, setup takes minutes and no technical skill: create the account, choose a data center, install an extension or an app, import from a competitor or a CSV file. For an organization, deployment is announced in minutes and privileged connections need no agent, no VPN and no firewall change, but SSO Connect, Keeper Bridge for AD and LDAP, SCIM provisioning, the Keeper Gateway and a self-hosted MCP server all call for an IT team, and developer use assumes DevOps skills. Onboarding, Keeper University, Keeper 101 videos, docs.keeper.io and paid professional services are available.
Deployment
Apps stores
Integrations
Supported languages
Behind Keeper Security
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Keeper Security.
Frequently asked questions
Can Keeper read what is in my vault?
Is my data used to train AI models?
Where is my data hosted?
Is Keeper GDPR compliant?
Which certifications does Keeper hold?
Is there an API?
Is there a free plan?
How do I export my data or delete my account?
Which apps are available?
Does Keeper work with AI assistants?
Should you pick Keeper Security?
Keeper Security is a mature product from a Chicago company that also operates from Ireland and Japan, on a domain registered in 2007 and first archived by the Wayback Machine in December 2011. Its differentiator is the combination of a zero-knowledge architecture documented in public technical detail, an unusually deep stack of regulatory certifications, and a scope that now reaches well beyond password management into privileged access, secrets, endpoints and databases. Few vendors cover a family vault and a FedRAMP High federal deployment from the same platform.
The natural audience is IT and security teams in regulated organizations, managed service providers and US federal agencies, with individuals and families served by the consumer tiers. DevOps teams that need secrets out of source code, and the growing number of teams wiring AI agents into production, will find first-class support through the SDKs, the Terraform provider, the CI/CD plugins and the MCP server.
The main obstacle is not the product but the buying process. No price appears in the HTML of the pricing pages, so nothing can be compared or budgeted without going through the site with JavaScript enabled or asking for a quote, and everything above the consumer and Business tiers is quote-only. Billing is annual, in advance and non-refundable, which raises the cost of being wrong.
Three things are worth settling before signing: the actual price in your currency and for your seat count, the exact scope of the tier you are buying, since add-on modules are charged separately, and the documentation you need for your own compliance file, meaning the sub-processor list, which is not publicly readable, and the Data Processing Agreement. Finally, remember what zero-knowledge implies: the recovery phrase is your only safety net, and no one at Keeper can replace it.
- Choosing a selection results in a full page refresh.
- Opens in a new window.