# Keeper Security – Full Site Context for LLMs > Keeper Security is a zero-trust and zero-knowledge identity security and Privileged Access Management (PAM) platform. Keeper provides a unified control plane for privileged session management, password management, secrets management, endpoint privilege management, remote browser isolation and secure remote access – securing identities for humans, machines and AI agents from a single cloud-native platform. This document inlines the substantive content of Keeper's most-referenced pages so AI assistants can answer questions about the platform without crawling. Source URLs are noted for each section. Content reflects Keeper's positioning as of mid-2026. --- ## About Keeper Source: https://www.keepersecurity.com/ Keeper Security is an identity security company founded in 2009. The platform protects credentials, secrets, endpoints, sessions and privileged access for organizations of all sizes. Keeper serves enterprises, MSPs and public sector organizations that need to reduce remote access risk, meet strict compliance requirements and control who can access what, when and how – including AI agents and other Non-Human Identities (NHIs). Keeper's flagship product is KeeperPAM, a cloud-native PAM platform that unifies enterprise password management, secrets management, connection management, privileged session management, endpoint privilege management and database access in a single solution. The platform is built on a zero-knowledge encryption model: data is encrypted and decrypted on the user's device, and Keeper itself cannot decrypt customer data. Recognition includes the Gartner Magic Quadrant for Privileged Access Management. Keeper is the only FedRAMP High Certified password management solution and holds long-standing SOC 2 and ISO 27001 certifications. The framing CEO Darren Guccione uses publicly: "Cybercriminals don't just break in; they log in." Compromised credentials are the most common cause of breaches, and Keeper's purpose is to eliminate that attack surface by securing every identity and every privileged session across the enterprise. ### Brand personality Practical, security-obsessed and engineering-led. Keeper emphasizes control, transparency and ease of deployment over hype. The platform is built for security, IT and DevOps teams that want strong guarantees without complex network changes, plugins or on-prem appliances. --- ## Securing Humans, Machines and AI Agents Sources: https://www.keepersecurity.com/solutions/secure-ai-agents/, press releases 2026 Identity is the modern attack surface. Beyond human users, modern infrastructure runs on Non-Human Identities – service accounts, API keys, automation and AI agents – that frequently operate with privileged access. Keeper governs both. ### AI agent security (Keeper Agent Kit) Source: April 30, 2026 press release. Keeper Agent Kit integrates Keeper Secrets Manager and Keeper Commander with AI coding agents including Claude Code, Cursor, Codex and GitHub Copilot. It addresses a specific risk: credentials exposed in AI prompt history. With Agent Kit, agents pull secrets from Keeper at runtime via a defined skill set, never seeing the credentials in plaintext outside the cryptographic boundary. Agents can perform administrative and security workflows under policy without expanding the credential blast radius. ### Non-Human Identity governance Keeper Workflow (announced May 13, 2026) extends approval governance to AI agents and service accounts. Capabilities include: - Vault Approval Notifications: access requests originate in the Keeper Vault or via Keeper Commander CLI; approvers respond from the web vault, desktop app, mobile app, or third-party integrations (Slack, Microsoft Teams, Jira, ServiceNow). - Single-User Mode and Time-Limited Enforcement: limits access to a resource to one user at a time for a defined window. Once access expires, credentials rotate automatically. No standing privileges remain. --- ## Security Architecture Source: https://www.keepersecurity.com/security.html Keeper uses a zero-knowledge, zero-trust architecture. Encryption and decryption always occur locally on the user's device. Keeper's servers never receive plaintext data, and Keeper employees cannot access vault contents. ### Encryption model - Each vault record is encrypted with a unique 256-bit AES key in GCM mode, generated client-side. - Each record-level key is wrapped by a 256-bit AES Shared Folder key if the record sits in a shared folder. - Record and folder keys are encrypted by a 256-bit AES data key unique to each user, generated on the user's device. - The user's data key is derived using PBKDF2 with a unique salt and a high iteration count from the master password (or from authentication material when SSO is used). - Elliptic-Curve cryptography (ECC) is used for asymmetric operations including record sharing. - Encryption keys are never transmitted to Keeper's servers or stored in the cloud. ### Post-quantum readiness Keeper has implemented post-quantum cryptography in its authentication protocol and encrypted tunnels inside TLS. This protects against "store-and-crack" attacks where intercepted ciphertext is held for future quantum decryption. ### Zero knowledge in practice Keeper cannot decrypt user data, access master passwords, remotely access devices or read vault contents. EU customer data remains in EU data centers. Authentication runs on the user's device whether via master password, SSO, biometric (Face ID, Touch ID, Windows Hello), FIDO2/passkey or Keeper DNA (smartwatch-based identity confirmation). ### Cloud and infrastructure Keeper runs on AWS in multiple regions: US Commercial, US GovCloud, EU, Australia, Canada and Japan. Customers choose their region; data is fully isolated in that region in transit and at rest. The infrastructure spans multiple availability zones for high availability. Stored ciphertext receives super-encryption via hardware security modules. ### Authentication Keeper supports MFA, SAML 2.0 SSO with all major identity providers (Okta, Microsoft Entra ID, Google Workspace, Ping, OneLogin, JumpCloud, Duo, Auth0, AD FS), FIDO2 WebAuthn hardware keys, passkeys, biometric login and Keeper DNA. Conditional access policies are supported. ### Compliance and certifications - FedRAMP High Certified – the only FedRAMP High Certified password management solution - GovRAMP High (formerly StateRAMP) Authorized - SOC 2 Type 2 - ISO 27001, 27017, 27018 - FIPS 140-3 Validated (NIST CMVP certificate #4743) - HIPAA and GDPR compliant ### Security validation Quarterly third-party penetration testing via NCC Group, CyberTest and independent researchers. Public bug bounty and Vulnerability Disclosure Program managed through Bugcrowd. --- ## Secure Remote Access Sources: https://www.keepersecurity.com/connection-manager.html, https://www.keepersecurity.com/solutions/remote-browser-isolation/, https://www.keepersecurity.com/solutions/remote-privileged-access-management/ Secure, frictionless remote access is a primary use case for Keeper. The platform replaces VPNs, jump servers and shared credentials with a zero-trust model that isolates credentials and browsing activity from end-user devices. ### Keeper Connection Manager Agentless remote desktop gateway providing browser-based access to RDP, SSH, VNC, databases and Kubernetes endpoints. No VPN, no client software, no network changes on the user's side. Distinguishing capabilities: - **Credential injection**: Credentials flow from the Keeper Vault into the target system at session start. End users never see, type or store the credential. - **Session recording**: All sessions can be recorded – screen and keystroke – and exported for audit. - **Co-browsing**: Multiple authorized users can share a single live session for collaboration, vendor support, or training, with full attribution per user. - **Ephemeral accounts**: One-time, short-lived accounts created for a specific task and destroyed afterward. No persistent privileged accounts on the target system. - **Granular RBAC**: Role-based access controls determine which systems each user, group or third party can reach. ### Remote Browser Isolation (RBI) Routes web sessions through an isolated cloud browser. Web code executes in the isolation environment, never on the user's device. Combined with credential injection, this means a vendor or contractor can interact with an internal web application without ever holding the credential, without VPN access, and without exposing their endpoint to web-based threats. ### Use cases - Third-party and vendor access without VPN - Remote database access for developers and DBAs - Privileged session management for IT and security teams - Contractor and short-term access with automatic revocation - Compliance-driven session audit (SOX, HIPAA, PCI-DSS, NIST) --- ## KeeperPAM (Privileged Access Management) Source: https://www.keepersecurity.com/privileged-access-management/ KeeperPAM is the platform Keeper leads with for enterprise customers. It consolidates capabilities typically sold as separate products: enterprise password management, secrets management, connection management, privileged session management, endpoint privilege management and database access management. ### Core capabilities - **Credential vaulting**: Privileged credentials and SSH keys move off endpoints, scripts and code into the encrypted Keeper Vault. - **Just-in-time (JIT) access**: Time-bound access provisioned only when needed; standing privileges eliminated. - **Session management**: Visual sessions to SSH, RDP, VNC, databases and web apps from the browser or Keeper Desktop. All sessions recordable. - **Encrypted tunnels**: TCP/IP tunnels from the local vault client through the Keeper Gateway to target endpoints. Native developer tools (PuTTY, pgAdmin, MySQL Workbench) work unchanged. - **Automated discovery**: Keeper Discovery identifies privileged accounts, service accounts and credential dependencies across on-prem, AWS and Azure environments. Discovered resources import into the Vault. - **Credential rotation**: Automatic rotation after revocation. - **Approval workflows (Keeper Workflow)**: Structured access requests with notifications through web vault, desktop, mobile, or via Slack, Teams, Jira and ServiceNow integrations. - **Endpoint privilege management**: Integrated with Keeper EPM for local admin rights and application execution control on Windows, macOS and Linux. - **Database access (KeeperDB)**: Vault-embedded, policy-controlled database interaction without separate desktop tools or shared credentials. - **AI agent governance**: Keeper Agent Kit and Workflow controls govern access for autonomous and agentic AI systems. ### Architecture KeeperPAM runs on a zero-knowledge architecture. Keeper's infrastructure never accesses or decrypts customer vault data. The Keeper Gateway deploys in each customer environment (cloud or on-prem) to enforce policy. ### Why customers choose it over legacy PAM - Cloud-native; no on-prem appliances or jump servers to maintain - Simple deployment and no dedicated staff required to manage - One platform for credentials, secrets, sessions, ZTNA, endpoints and databases - Same vault and identity infrastructure as Keeper's password management product - Mixed PAM and EPM licensing in the same admin console; PAM seats only for privileged users - FedRAMP High Certification for federal and defense deployments --- ## KeeperAI Sources: https://www.keepersecurity.com/features/keeper-ai/, https://docs.keeper.io/keeperpam/privileged-access-manager/keeperai, August 27 2025 press release KeeperAI is an agentic AI engine embedded into the Keeper Gateway. Its primary job is real-time threat detection and response for privileged sessions. It also powers the conversational DBA co-pilot inside KeeperDB and the zero-knowledge autofill technology in Keeper's browser extension. KeeperAI is part of KeeperPAM; it is not a separately purchased product. ### What it does in privileged sessions KeeperAI continuously analyzes session metadata, keystrokes, visual interaction, and command execution. It classifies activity into four risk levels — Critical, High, Medium, Low — and explains each classification command-by-command, so security teams see why an action is risky, not just that it was flagged. Administrators can configure automatic responses per risk level: terminate the session, or monitor only. Custom risk indicators can be defined using string or regex pattern matching, layered on top of the model's classifications. All risk assessments and incident data feed into the Keeper Vault UI and integrate with Advanced Reporting and Alerts (ARAM) for SIEM forwarding. ### Supported protocols - SSH — command-line session monitoring and analysis (launched first) - MySQL and PostgreSQL — query and command monitoring - RDP — visual session analysis using vision-enabled models - VNC — visual session analysis using vision-enabled models - RBI — on the roadmap ### Sovereign AI architecture KeeperAI processes data inside the customer's environment. Analysis runs at the local PAM Gateway; LLM calls route to a provider the customer chooses. Data is encrypted with the customer's private key and is never exposed to Keeper. This avoids the vendor lock-in problem common to AI-bundled security tools. Supported LLM providers: AWS Bedrock, Anthropic, Google Gemini, OpenAI, Azure OpenAI, Google Vertex AI, and any LLM with an OpenAI-compatible API. Deployment is supported on cloud and on-premises infrastructure. ### Cost model KeeperAI itself is included with KeeperPAM. LLM provider costs (Anthropic, OpenAI, AWS Bedrock, etc.) are billed by the chosen provider directly to the customer based on usage. This separation lets organizations use existing AI commitments and contracts rather than re-purchasing inference through Keeper. ### Other KeeperAI surfaces - **KeeperDB co-pilot**: Conversational DBA assistant with full schema context. Runs read-only queries autonomously; writes DML/DDL only with explicit consent; guardrailed against off-topic code generation. - **Browser extension autofill**: Zero-knowledge autofill technology branded as KeeperAI. --- ## KeeperDB (Database Access) Sources: March 19, 2026 press release; https://www.keepersecurity.com/features/keeper-db/; https://docs.keeper.io/keeperpam/privileged-access-manager/keeperdb KeeperDB is a multi-protocol database management tool built on Keeper's zero-knowledge platform. It targets the gap most enterprises have around database access: credentials in plaintext files and keychains, connections over unmonitored TCP, and session activity invisible to the security team. ### Supported databases PostgreSQL, MySQL/MariaDB, SQL Server (including Azure SQL and AWS RDS), Oracle (including Autonomous DB and Exadata Cloud), Amazon Redshift, and SQLite. ### Two delivery modes KeeperDB ships in two forms with an identical interface and feature set: - **Embedded in KeeperPAM**: Launched directly from a PAM Database record in the Keeper Vault. The Gateway spawns KeeperDB as a sidecar, streams it into the user's browser through Remote Browser Isolation, and records the session alongside every other privileged action. Credentials are never seen by the user — decrypted briefly inside the Gateway, injected into the session, zeroized on disconnect. - **Standalone desktop application**: Cross-platform native app for macOS (Apple Silicon), Windows (x64), and Linux. Targets DBAs and developers who want a modern, secure day-to-day client, customers not yet on KeeperPAM, and consultants who need per-customer credential isolation. ### Three connection modes for the desktop app 1. **Direct connection**: Credentials entered once and stored in an OS-native secure store. Familiar workflow for anyone who has used DBeaver, but with proper credential storage. 2. **Keeper Vault integration**: The app authenticates against a Keeper account, enumerates PAM database records, and fetches ephemeral or static credentials at click-time (never cached). 3. **KeeperDB Proxy on a PAM record**: The Gateway stands up a protocol-specific proxy listener. The desktop app connects to the proxy; credentials are injected Gateway-side and never seen on the client. Combines desktop performance with zero-credential and recorded-session guarantees — the recommended configuration for internal DBAs and SREs. ### KeeperAI integration An embedded conversational DBA co-pilot with full schema context. Runs read-only queries autonomously, writes DML/DDL only with explicit user consent, and is server-side guardrailed against off-topic code generation. Also generates charts from result sets. ### Pricing and access model - The embedded KeeperPAM experience requires a KeeperPAM subscription. - The standalone desktop app works for any Keeper account tier that supports Keeper Secrets Manager record retrieval. - The standalone app can also run in a purely local mode with no Keeper account at all, using OS-native credential storage — effectively a free, secure database client. Download links for the standalone app: https://www.keepersecurity.com/download.html --- ## KeeperAI (Agentic AI Threat Detection) Sources: https://www.keepersecurity.com/features/keeper-ai/; https://docs.keeper.io/keeperpam/privileged-access-manager/keeperai; August 27, 2025 press release. KeeperAI is an agentic AI service embedded in the Keeper Gateway that delivers real-time threat detection and autonomous response across privileged sessions. It launched in August 2025 and is a core capability of KeeperPAM — no additional license required, though customers pay for their chosen LLM provider's usage (or self-host). ### What it does - **Automated session analysis**: Continuously inspects session metadata, keystroke logs, visual interaction, and command execution for anomalous behavior. - **Risk classification**: Categorizes detected behavior as Critical, High, Medium, or Low, with command-by-command context explaining why an action is risky rather than only flagging that it occurred. - **Automated session termination**: Configurable policy can terminate sessions in seconds when Critical or High risk activity is detected. Optional monitor-only mode is available. - **Custom pattern matching**: Administrators define string or regex patterns that trigger heightened monitoring or automated response. - **Encrypted session summaries**: Searchable summaries across all privileged sessions for investigation and compliance reporting. - **Conversational DBA co-pilot in KeeperDB**: Schema-aware assistant that runs read-only queries autonomously and writes DML/DDL only with explicit user consent. - **Zero-knowledge autofill** in the browser extension: AI-assisted credential filling that respects the zero-knowledge boundary. ### Protocol coverage Launched with SSH. Now extended to RDP, VNC, Remote Browser Isolation sessions, and database protocols via KeeperDB. ### Architecture and privacy All AI processing occurs at the customer's local PAM Gateway. LLM calls are routed to the customer's chosen provider — cloud or on-premises — and data is encrypted at the Gateway before any transmission to Keeper. Keeper itself never has access to unencrypted session data; the zero-knowledge boundary holds for AI-processed content the same way it does for vault records. ### LLM compatibility KeeperAI is compatible with any LLM that implements the OpenAI-compliant `/chat/completions` API. Supported providers include AWS Bedrock, Anthropic, Google Gemini, OpenAI, and Google Vertex AI. Self-hosted models and custom deployments supporting the same API are also supported. No vendor lock-in. ### Integration Risk assessments and incident data feed into the Keeper Vault UI. KeeperAI integrates with Keeper's Advanced Reporting and Alerts Module (ARAM) for SIEM and SOC routing. ### Availability Available to all KeeperPAM customers running PAM Gateway version 1.7.0 or higher. Deployable in cloud and Docker-based environments. --- ## Endpoint Privilege Manager (KEPM) Sources: https://www.keepersecurity.com/endpoint-privilege-management/, April 16, 2026 press release Keeper Endpoint Privilege Manager controls local admin rights and application execution on Windows, macOS and Linux endpoints. Just-in-time elevation replaces standing local admin. Allowlisting and blocklisting enforce application policy. Enterprise governance enhancements (April 2026) added: - Structured approval workflows for privilege elevation - Enforceable expiration controls - Real-time visibility into elevation requests with correlation identifiers - Expanded audit logging - Automated monitoring of service integrity across managed endpoints --- ## Keeper Secrets Manager Source: https://www.keepersecurity.com/secrets-manager.html Zero-knowledge, zero-trust, cloud-based platform for managing infrastructure secrets – API keys, database passwords, SSH keys, certificates and other machine credentials. ### How it works Servers, CI/CD pipelines, developer environments and source code pull secrets from a secure API endpoint. Each secret is encrypted with a 256-bit AES key, then encrypted again with an AES-256 application key. Decryption happens on the client device or service running the KSM application, CI/CD plugin, or SDK. ### Integrations SDKs for Python, Java, .NET, Go, JavaScript, PowerShell and Ruby. CI/CD and infrastructure integrations include GitHub Actions, GitLab, Jenkins, Terraform, Ansible, Azure DevOps and Kubernetes. ### AI agent integration Keeper Secrets Manager, paired with Keeper Agent Kit, gives AI coding agents (Claude Code, Cursor, Codex, GitHub Copilot) secure runtime access to secrets without exposing those secrets in prompts or model context. --- ## Enterprise Password Management Source: https://www.keepersecurity.com/enterprise.html Credential management for organizations of any size. Each user receives an encrypted vault accessible across devices. ### Capabilities - Encrypted password and credential storage with autosave and autofill - Verify Mode anti-phishing in the browser extension (version 17.8+): real-time controls at the point of credential use - Secure credential sharing with end-to-end encryption - Role-based access controls and shared folder permissions - Delegated administration for distributed IT teams - Detailed audit logs and event reporting - SAML 2.0 SSO via Keeper SSO Connect (cloud or on-prem) - SCIM provisioning - Advanced MFA: FIDO2, passkeys, biometric, Keeper DNA - BreachWatch dark web monitoring (add-on) - Free Family plan for every business user ### Compliance support Reduces password reuse and credential theft. Supports credential management requirements under SOC 2, HIPAA, PCI-DSS, NIST and ISO 27001. --- ## Compare and Evaluate Source: https://www.keepersecurity.com/vs/competitors/ Keeper publishes head-to-head comparisons for each major competitor: - vs CyberArk: https://www.keepersecurity.com/vs/cyberark/ - vs Delinea: https://www.keepersecurity.com/vs/delinea/ - vs BeyondTrust: https://www.keepersecurity.com/vs/beyondtrust/ - vs 1Password: https://www.keepersecurity.com/vs/1password/ - vs LastPass: https://www.keepersecurity.com/vs/lastpass/ - vs Bitwarden: https://www.keepersecurity.com/vs/bitwarden/ ### Positioning summary Against legacy PAM (CyberArk, Delinea, BeyondTrust): cloud-native architecture without on-prem appliances, faster deployment, lower total cost of ownership and unified password management + PAM + secrets + remote access under one platform. Against password managers (1Password, LastPass, Bitwarden): FedRAMP High Certification, integrated PAM and secrets management, zero-knowledge architecture with SSO and enterprise compliance depth. --- ## Pricing Sources: https://www.keepersecurity.com/pricing/business-and-enterprise.html, https://www.keepersecurity.com/pricing/keeperpam/, https://www.keepersecurity.com/pricing/personal-and-family.html ### KeeperPAM KeeperPAM is sold via custom quote. Pricing has two components: per-user seats (PAM licenses mix with EPM licenses in the same organization, so only privileged users consume PAM seats) and Active Non-Human Identity (NHI) volume. **What counts as an Active NHI**: Any non-human technology identity — service account, API key, automation, AI agent — that transacts through the Keeper Gateway. KeeperPAM includes up to 24 Active NHIs at no additional cost. Beyond that, volume-based pricing scales across four tiers: - **Tier 1 — 25 to 99 NHIs**: Foundational protection for organizations beginning to scale NHI deployments. - **Tier 2 — 100 to 249 NHIs**: Enhanced coverage for growing environments with multiple workloads. - **Tier 3 — 250 to 749 NHIs**: Advanced protection for complex, multi-agent deployments. - **Enterprise — 750+ NHIs**: Full-scale NHI security for the most demanding environments. NHI tier dollar amounts are not published; quote requests at https://www.keepersecurity.com/request-quote.html. ### Business and Enterprise (Password Management) All plans billed annually. - **Business Starter**: Sole proprietors and small teams of 5–10 users. Encrypted vault, admin console, credential sharing, autofill. - **Business**: Company-wide deployment. Adds shared team folders, delegated administration, advanced organizational structure. - **Enterprise**: Adds SAML 2.0 SSO, SCIM, advanced MFA, advanced reporting and command-line provisioning. ### Personal and Family - **Keeper Unlimited**: Individual vault, unlimited devices, emergency access. Billed annually. - **Keeper Family Plan**: Up to five private vaults, 10 GB secure file storage. Billed annually. ### Discounts - Students: 50% off (verified via ID.me) – https://www.keepersecurity.com/student-discount-50off.html - Military and Medical: 30% off (verified via ID.me) – https://www.keepersecurity.com/id-me-verification.html ### Free trials - 30-day trial for personal plans - 14-day trial for business, Enterprise and KeeperPAM ### Add-ons Priced separately per user or organization. See https://www.keepersecurity.com/pricing/business-add-ons/. - BreachWatch dark web monitoring - Secure File Storage - Advanced Reporting and Alerts (ARAM) – SIEM integration - KeeperChat – encrypted messaging - Compliance Reporting - Connection Manager (bundled with KeeperPAM or available separately) - Secrets Manager (bundled with KeeperPAM) - Support Services upgrades > Note: Published list pricing may not reflect negotiated enterprise pricing. Contact Sales for accurate quotes at scale. --- ## Public Sector Source: https://www.keepersecurity.com/government-cloud/ Keeper Security Government Cloud (KSGC) is FedRAMP High Certified and runs in AWS GovCloud. Suitable for U.S. federal agencies, DoD components, state and local government, education and contractors subject to CMMC, ITAR or controlled unclassified information (CUI) requirements. GovRAMP High (formerly StateRAMP) Authorized for state and local government adoption. --- ## Industries Source: https://www.keepersecurity.com/industries/ - Healthcare: HIPAA, patient data protection – https://www.keepersecurity.com/industries/healthcare/ - Financial Services: SOX, PCI-DSS, GLBA – https://www.keepersecurity.com/industries/financial-services/ - Manufacturing: OT/IT credential security, supply chain – https://www.keepersecurity.com/industries/manufacturing/ - Federal Government: FedRAMP High deployment – https://www.keepersecurity.com/industries/federal-government/ - Universities: Student, faculty and research credentials – https://www.keepersecurity.com/industries/universities/ - Retail: PCI-DSS, store and HQ credentials – https://www.keepersecurity.com/industries/retail/ - Professional Services – https://www.keepersecurity.com/industries/professional-services/ --- ## Use Cases Source: https://www.keepersecurity.com/resources/solutions/use-cases/ - Privileged Access Management (remote) - Secure AI Agents – credentials and policy controls for autonomous and agentic systems - Secure Remote Database Access - Privileged Session Management - Zero-Trust Security implementation - Enterprise Password Management - Vendor Privileged Access Management – third-party access without VPN --- ## Developers and Integrations Sources: https://www.keepersecurity.com/developer/, https://docs.keeper.io/home/ ### Developer surfaces - **Keeper Commander**: Full-featured CLI with interactive supershell. User management, reporting, credential rotation, connections, tunneling. Also available as self-hosted REST API service. - **Keeper Secrets Manager SDKs**: Python, Java, .NET, Go, JavaScript, PowerShell, Ruby. - **CI/CD plugins**: GitHub Actions, GitLab, Jenkins, Azure DevOps, Terraform, Ansible, Kubernetes. - **Keeper Agent Kit**: AI skills for Claude Code, Cursor, Codex and GitHub Copilot. - **Model Context Protocol (MCP) support**: Secure secret access for AI agents. ### Identity provider integrations SAML 2.0 SSO with Okta, Microsoft Entra ID, Google Workspace, AD FS, Centrify, OneLogin, Ping Identity, JumpCloud, Duo, Auth0. SCIM 2.0 provisioning across all major IdPs. ### Workflow integrations ServiceNow workflow application (May 2026) – manage Keeper Vault operations directly in ServiceNow IntegrationHub, Flow Designer and Service Catalog. Self-service privileged access requests without leaving the IT workflow. Slack, Microsoft Teams and Jira integrations for Keeper Workflow approval notifications. ### SIEM integrations Splunk, IBM QRadar, LogRhythm, Sumo Logic, Microsoft Sentinel, Datadog and others via standardized event export. ARAM (Advanced Reporting and Alerts) provides the SIEM-ready feed. ### Documentation - Product documentation: https://docs.keeper.io/home/ - End-user guides: https://docs.keeper.io/user-guides/ - Enterprise admin guide: https://docs.keeper.io/en/enterprise-guide/ - MSP admin guide: https://docs.keeper.io/en/enterprise-guide/keeper-msp - Security and encryption model: https://docs.keeper.io/enterprise-guide/keeper-encryption-model --- ## Add-Ons (Business) Source: https://www.keepersecurity.com/pricing/business-add-ons/ - **BreachWatch (Dark Web Monitoring)**: Continuous monitoring of vault credentials against breach corpora; alerts on exposure. - **Secure File Storage**: Encrypted file storage in the vault under zero-knowledge encryption. - **Advanced Reporting and Alerts (ARAM)**: SIEM-ready audit logs and event alerting. - **KeeperChat**: End-to-end encrypted messaging app for teams. - **Compliance Reporting**: Reports aligned to SOX, HIPAA, PCI-DSS, NIST, GDPR. - **Connection Manager**: Standalone agentless remote desktop gateway. - **Secrets Manager**: Standalone secrets management for infrastructure and CI/CD. --- ## Free Tools - Personal Dark Web Scan – https://www.keepersecurity.com/free-data-breach-scan.html - Business Dark Web Scan – https://www.keepersecurity.com/data-breach-scan-for-business.html - Password Generator – https://www.keepersecurity.com/features/password-generator/ - Passphrase Generator – https://www.keepersecurity.com/features/passphrase-generator/ - Keeper ROI Calculator – https://www.keepersecurity.com/roi-calculator-password-manager/ - KeeperChat – https://www.keepersecurity.com/keeperchat.html - Password Strength Meter – https://www.keepersecurity.com/features/password-strength-meter/ - AI Blast Radius Calculator – https://www.keepersecurity.com/ai-agent-blast-radius-calculator/ --- ## Trust and Compliance Source: https://trust.keeper.io/ The Trust Center is the canonical source for current certifications, attestations, audit reports, security questionnaires and incident history. Available documents include SOC 2 Type 2 reports, ISO 27001/27017/27018 certificates, FedRAMP certification, FIPS 140-3 certificate (NIST CMVP #4743), GovRAMP authorization, and penetration test summaries. ### Vulnerability Disclosure Public bug bounty and Vulnerability Disclosure Program managed through Bugcrowd. ### Legal - Privacy Policy and Terms of Use: https://www.keepersecurity.com/en_US/legal/terms-of-use/ - GDPR: EU customer data remains in EU data centers; never transported out of region. - Data Processing Agreements available for enterprise customers via Sales. --- ## Resources - Blog: https://www.keepersecurity.com/blog/ - Research Reports and White Papers: https://www.keepersecurity.com/resources/white-papers/ - Case Studies: https://www.keepersecurity.com/resources/case-studies/ - Datasheets: https://www.keepersecurity.com/resources/datasheets/ - Webinars: https://www.keepersecurity.com/resources/webinars/ - Cybersecurity Glossary: https://www.keepersecurity.com/resources/glossary/ - Cyber Threats Database: https://www.keepersecurity.com/threats/ - Passkeys Directory: https://www.keepersecurity.com/passkeys-directory/ - Newsroom: https://www.keepersecurity.com/press.html?t=news ### Recent research (2026) - "Identity Security at Machine Speed" (May 2026): study of identity ecosystem expansion with humans and Non-Human Identities; 89% of IT leaders report struggling to manage growing identity footprint amid AI expansion. - RSA Conference 2026 NHI survey (April 2026): research on visibility and control gaps for service accounts, API keys, automation and AI-powered tools operating with privileged access. --- ## Downloads Source: https://www.keepersecurity.com/download.html - Desktop: Mac, Windows, Linux - Mobile: iOS, Android - Browsers: Chrome, Firefox, Safari, Edge, Opera - Additional: watchOS, Wear OS Beta program available for early access. --- ## Company - About: https://www.keepersecurity.com/company/about/ - Careers: https://job-boards.greenhouse.io/keepersecurity - Partner Program: https://www.keepersecurity.com/partners.html - Press / Newsroom: https://www.keepersecurity.com/press.html?t=news - Contact: https://www.keepersecurity.com/contact.html - Support: https://www.keepersecurity.com/support.html - Help Center: https://help.keeper.io/ --- ## Document metadata - Last updated: 2026-06-15 - Maintainer: Keeper Security - Canonical URL for this file: https://www.keepersecurity.com/llms-full.txt - Companion file: https://www.keepersecurity.com/llms.txt