Identification [CUI Data]
3.5.1
Keeper ensures unique user identification through individual Keeper Vault accounts integrated with enterprise IdPs (SSO) and enforced MFA, providing auditable attribution of all access to CUI. Each access event is tied to a verified user identity, reducing shared credentials and strengthening accountability.
Authentication
3.5.2
Keeper enforces strong authentication using SSO integration, cryptographic key derivation, and policy-based access controls.
Multifactor Authentication
3.5.3
Keeper supports MFA using TOTP, push notifications, hardware security keys (FIDO2), and SSO-enforced MFA.
Replay-Resistant Authentication
3.5.4
Keeper uses encrypted challenge-response authentication and ephemeral session tokens resistant to replay attacks.
Password Complexity
3.5.7
Keeper enforces configurable password complexity policies and includes a built-in password and passphrase generator.
Password Reuse
3.5.8
Keeper reduces password reuse through visibility, reuse detection, and reporting across enterprise vaults.
Temporary Passwords
3.5.9
Keeper supports time-limited access through controlled sharing and just-in-time privileged access.
Cryptographically-Protected Passwords
3.5.10
All passwords and secrets are encrypted using zero-knowledge, client-side cryptography before storage or transmission.
Obscure Feedback
3.5.11
Keeper obscures sensitive authentication feedback and prevents password exposure on screen or in logs.