Compliance: ISO 27001

Achieve ISO 27001 compliance with Keeper

Support ISO/IEC 27001:2022 alignment with zero-knowledge security, identity-first access controls and auditable enforcement of policies across your organization.

Keeper is ISO 27001 certified and audited annually by accredited third-party assessors. Organizations using Keeper can leverage Keeper's certified controls as part of their own ISMS implementation.

Talk to a Keeper Expert

loading... loading...
What is ISO/IEC 27001:2022?

What is ISO/IEC 27001:2022?

ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS). It provides a systematic approach to managing sensitive company information by addressing people, processes and technology through a risk-based set of security controls defined in Annex A.

ISO 27001 certification requires assessment by an accredited certification body across the full scope of an organization's ISMS, covering governance, risk management, policy, physical security and technical controls. Keeper supports the technical controls layer of that implementation.

How does Keeper help with ISO 27001 compliance?

Zero-knowledge security for ISO 27001

Keeper helps organizations achieve ISO/IEC 27001:2022 compliance by strengthening core information security controls related to access management, identity protection, encryption, monitoring and auditability. Keeper supports a risk-based ISMS by enabling least-privilege access, separation of duties and strong authentication through Role-Based Access Control (RBAC), centralized policy enforcement and integration with enterprise identity providers. Secure remote access to credentials and secrets is provided without exposing sensitive information or relying on network-based trust.

Encryption, audit logs and continuous monitoring

Keeper protects all stored credentials and secrets with zero-knowledge encryption, meaning Keeper's servers hold only encrypted data and Keeper itself cannot access vault contents. All data in transit is protected using TLS 1.2 or higher. Comprehensive audit logs support accountability, traceability and continuous improvement activities required by an ISMS.

Note: Keeper addresses the technical controls dimension of ISO 27001. A complete ISMS implementation also requires governance documentation, risk assessment processes, policy frameworks and physical and human resources security controls that fall outside Keeper's scope.

Keeper features for ISO 27001

Primary controls are those Keeper directly implements. Supporting controls are those capabilities of Keeper that contribute evidence toward, but do not independently fulfill, the requirements.

Access controls
Control name
Status
Keeper capability
A.5.3Segregation of duties
Primary
Keeper enables administrative role separation so security administrators can manage policies and users without access to sensitive vault contents. Role-based permissions can also be configured to separate duties across vault owners, administrators and auditors.
A.5.15Access control
Primary
Keeper supports access control policies through RBAC, shared folder permissions and centralized enforcement of access rules across users and systems.
A.5.16Identity management
Primary
Keeper supports identity lifecycle management through SCIM provisioning, SSO integration and automated deprovisioning, ensuring user identities are managed consistently across the organization.
A.5.18Access rights
Primary
Keeper supports access rights management by enabling administrators to provision, modify and revoke user access to credentials and secrets in accordance with access control policies.
A.8.2Privileged access management
Primary
KeeperPAM enables controlled access to privileged credentials using just-in-time access, workflow-based approvals and automated password rotation.
A.6.7Secure remote access
Primary
Keeper provides secure access to credentials and secrets without exposing passwords or relying on traditional VPN-based access models.
Logging and monitoring
Control name
Status
Keeper capability
A.8.15Event logging
Supporting
Keeper generates detailed audit logs for authentication events, credential access, sharing actions and administrative changes.
A.8.16Log monitoring
Supporting
Keeper audit logs can be exported or integrated with SIEM platforms to support continuous monitoring and incident detection.
Cryptography and data protection
Control name
Status
Keeper capability
A.8.24Cryptographic controls
Primary
Keeper encrypts all credentials and secrets using a zero-knowledge architecture with AES-256 and RSA-2048, with cryptographic modules validated to FIPS 140-3 by the NIST Cryptographic Module Validation Program (CMVP). Keeper further enhances its security posture through the adoption of Quantum-Resistant Cryptography (QRC) to mitigate emerging post-quantum threats.
A.5.14Data in transit
Primary
Keeper protects data in transit using TLS 1.2+ with strong cipher suites.
Threat detection and integrity
Control name
Status
Keeper capability
A.8.16Monitoring activities
Primary
Keeper identifies and logs unauthorized access attempts and policy violations within the vault environment.
A.5.25Assessment of security events
Supporting
KeeperAI analyzes session activity and behavioral patterns to support security event assessment, flagging anomalous activity for review and enabling security teams to evaluate and respond to potential incidents.

Be ready for ISO 27001 assessments

Secure your data and simplify compliance with Keeper.

Withdraw Cookie ConsentWe value your privacy

We use cookies on our site to give you the best browsing experience, serve personalized ads about our products and content, and analyze website traffic. To learn more, please refer to our Privacy Policy.

Sign up for a Free Trial

Buy Now