Pricing designed for every organization

Business Starter
Password Manager

Protects sole proprietors and small teams

 
user / month billed annually
*zzgl MwSt *Includes GST

Includes:

  • Encrypted vault and admin console
  • Credential sharing and autofill
  • Protection for 5–10 users
Business
Password Manager

Company-wide security, visibility and administration

  user / month billed annually
*zzgl MwSt *Includes GST

All Business Starter features, plus:

  • Shared team folders
  • Delegated administration
  • Advanced organizational structure and integrations
  • Free Family Plan for every user
Enterprise
Password Manager

Advanced provisioning, RBAC, governance and reporting

  user / month billed annually
*zzgl MwSt *Includes GST

All Business features, plus:

  • Advanced provisioning (SCIM, AD/LDAP, SSO/SAML)
  • SIEM integration
  • Advanced two-factor authentication
  • Role-based access control
  • Developer APIs
Recommended
Privileged Access
Management Platform

Modern control plane for humans, machines, NHIs and AI agents

  user / month billed annually
*zzgl MwSt *Includes GST

All Enterprise features, plus:

  • Agentic AI threat detection and response
  • Secrets management for CI/CD, IaC, ITSM and MCP for AI agents
  • Session management, tunneling and remote browser isolation
  • Database management
  • Endpoint privilege management
  • Automated credential rotation
  • Over 100 technology integrations
  • Dark Web Monitoring
  • Advanced reporting and alerts
  • Compliance Reporting

KeeperMSP®


Manage passwords, infrastructure secrets, endpoints and privileged access for your customers.

Explore all features

 
Business Starter
Password Manager
Business
Password Manager
Enterprise
Password Manager
Privileged Access
Manager
Credential management
Encrypted vault

Securely store passwords, passkeys, files, photos, infrastructure secrets and resources with zero-knowledge encryption

Learn More
Password and passkey sharing

Securely share records and folders containing passwords, passkeys, files, photos or any other secrets with individuals or teams on a persistent or time-limited basis

Learn More
Autofill across all devices

Autofill passwords, passkeys, payment cards and 2FA codes across apps and browsers

Learn More
Bidirectional One-Time Share

Securely share credentials with anyone even if they don't have a Keeper account using end-to-end encryption and bidirectional editing capabilities

Learn More
Time-limited access and self-destructing records

Share records with users outside of Keeper, while automatically deleting the record from your vault and disabling the share link at specified time

Folders and subfolders

Organize your vault records into folders and nested subfolders

Shared team folders

Manage and organize credentials, files and protected resources in shared folders with team and user permissions

Password and passphrase generator

Create strong, unique passwords and passphrases instantly with customizable character set selection

Browser extension and native desktop app

Access Keeper on any web browser or with our native desktop applications for Mac, Windows or Linux

Learn More
iOS and Android apps

Access Keeper on iOS and Android with instant vault syncing across all your devices

Vault Transfer

Securely transfer an employee's vault when they leave the organization

Free Family Plan for every user

All users can create a free, Keeper Family Plan for up to 5 family members with unlimited devices

Administration and provisioning
Admin Console

Provides a centralized platform for admins to manage users, teams, machines, and AI agents with full compliance monitoring and security reporting

Policy engine and enforcements

Enforce security policies for the organization – by user, role or team

Team management

Easily share privileged account credentials and assign role policies to pre-defined user groups

Basic two-factor authentication

Two-factor support for SMS, authenticator apps, smartwatch and security keys, providing an extra layer of security for your vault

Instant account switching

Seamlessly switch between your personal and business vaults without having to log out of your current session

Biometric login with passkeys

Allows you to authenticate using a device-bound passkey that replaces all traditional login methods – including master password, SSO, and 2FA.

Delegated administration

Allows admins to delegate management permissions (e.g. user onboarding, policy enforcement) to sub-administrators based on organizational nodes (e.g. department or subsidiary)

Advanced Organizational Structure

Keeper's scalable architecture addresses the unique needs of all organization types, from small offices to complex government agencies

Advanced integrations

Extend Keeper across your enterprise technology stack, enabling AI assistants and agents to securely access vault credentials through standardized protocols

Advanced admin controls

Granular administrative controls support least-privilege permissions and policies

SCIM provisioning

Support provided for direct SCIM API user and team provisioning for any 3rd party identity provider

CLI and TUI applications for terminal access

Access your Keeper Vault, perform administrative functions, manage privileged access, run reports and create custom automations from a command line or text user interface

Share admin role for elevated permissions

Provides elevated access rights over shared records and folders

Active Directory and LDAP sync

Automatically provision and deprovision users from AD and LDAP using Keeper Bridge

Entra ID, Okta, Ping and other IdP integrations

Integrate with leading identity providers to enable automated provisioning

Learn More
Single Sign-On (SAML 2.0) authentication

Federate login to Keeper with any SAML 2.0 compatible identity provider

Learn More
DUO and RSA two-factor authentication

Support provided for advanced two-factor authentication methods

Developer SDKs and REST API

SDKs and secrets management tools for DevOps, IT Security and software development teams to access Keeper

Slack, Jira, ServiceNow and Teams apps for workflow

Enable secure sharing and approval workflows within popular collaboration tools

Add-onAdd-on
Secrets management
Automated credential rotation

Automate credential rotation for SSH keys, database passwords, API tokens and service accounts across cloud and on-prem environments

Learn More
Add-onAdd-on
Secrets manager CLI and SDKs

Enable core Secrets Manager Vault interaction from a terminal, shell script or any software that can be launched from a shell

Add-onAdd-on
AI agent integration with MCP

Allow AI agents to securely access and manage secrets

Add-onAdd-on
CI/CD, IaC, ITSM and DevOps integrations

Protect secrets in automation pipelines

Add-onAdd-on
VSCode, Cursor and JetBrains plugins

Access secrets directly in IDEs

Add-onAdd-on
Developer SDKs for all popular languages

Integrate secrets into any application

Add-onAdd-on
Remote access
Privileged Session Management

Securely manage privileged sessions for all your systems, applications, containers and databases with no credential exposure

Learn More
Add-onAdd-on
Session recording and playback with AI summary

Capture and store graphical and text-based session recordings complete with AI-driven analysis of user activity

Add-onAdd-on
Database management

Enable passwordless database access directly in the Keeper Vault

Add-onAdd-on
Passwordless database proxy

Access databases without using stored passwords

Add-onAdd-on
Native tools access with TCP tunneling

Create a secure, encrypted TCP/IP connection between the Keeper Vault and the target endpoint

Add-onAdd-on
Remote browser isolation with multi-tab and file transfer support

Enable secure access to web-based applications through an isolated browser

Learn More
Add-onAdd-on
Zero-trust brokered access via Keeper Gateway

Provide secure access without network exposure

Add-onAdd-on
Ephemeral accounts and JIT elevation

Grant temporary privileged access through one-time-use accounts

Add-onAdd-on
Automated discovery in-cloud and on-prem

Discover machines, databases, accounts and services across your on-prem and cloud infrastructure with Keeper Discovery

Add-onAdd-on
Vendor Privileged Access Management

Enforce zero-trust vendor privileged access to internal resources

Learn More
Add-onAdd-on
Endpoint privilege management
Remove local admin rights for Zero-Standing Privilege (ZSP)

Eliminate the risk associated with compromised privileged accounts due to standing admin rights

Add-onAdd-on
Just-in-Time (JIT) access and elevation requests with approval workflow

Replace standing privileges with time-bound approvals and escalation workflows

Add-onAdd-on
Agents for Windows, macOS and Linux devices

Cross-platform protection across all major operating systems

Add-onAdd-on
MFA and justification controls

Add an additional layer of security with MFA and justification requirements

Add-onAdd-on
Sudo policies for macOS and Linux

Control sudo usage on Unix systems

Add-onAdd-on
File access policies

Restrict access to sensitive files

Add-onAdd-on
Approvals in ServiceNow, Jira, Slack and Teams

Approve or deny access within the workflow tools you already use daily

Add-onAdd-on
Monitoring and reporting
Risk Management Dashboard

Gain full visibility into your organization’s security posture with key insights into end-user deployment, utilization, cloud configuration, and event monitoring

Learn More
Security Audit

Monitor password strength and reuse across your organization

Activity reporting

Provides an overview of high level data on your user activity and overall security status

KeeperAI® agentic threat detection and response

Enable automated high-risk session termination based on custom rules

Learn More
Add-onAdd-onAdd-on
Advanced Reporting & Alerts (ARAM)

Delivers real-time event monitoring, customizable reports and compliance-ready audit trails

Add-onAdd-onAdd-on
ITSM integrations with ServiceNow, Jira and Salesforce

Centrally manage and respond to Keeper-generated security alerts in your preferred ITSM solution

Add-onAdd-onAdd-on
Compliance Reporting

Provide on-demand visibility to permissions asssociated with your records to support regulatory compliance requirements

Add-onAdd-onAdd-on
SIEM integration

Automatically feed live event data into external SIEM products

ARAM requiredARAM requiredARAM required
Security
Zero-knowledge encryption

Keeper's system architecture garantees the highest levels of security and privacy with encryption and decryption of data always occur locally on the user's device

Learn More
SOC 2 Type 2 and SOC 3 certified

Independently audited and certified for security, availability and confidentiality controls that protect customer data

ISO 27001, 27017 and 27018 certified

Certified to international security and privacy standards for information security management, cloud services and personal data protection

FedRAMP High and GovRAMP Authorized

Keeper is approved to protect the U.S. federal government’s most sensitive data and workloads

Learn More
Forcefield™ memory attack protection

Protect Windows machines against memory-based attacks

Learn More

Frequently asked questions

Is KeeperPAM® a separate product from Keeper?

KeeperPAM is part of the broader Keeper Security platform and extends Keeper's capabilities with a full-featured, cloud-based Privileged Access Management (PAM) solution. It integrates seamlessly with Keeper's vault and identity infrastructure, combining enterprise password management, secrets management, remote access, session recording and zero-trust network access in one unified interface. Customers do not need to manage separate deployments. KeeperPAM is delivered via the Keeper Vault with minimal infrastructure requirements.

How does purchasing KeeperPAM work?

To utilize KeeperPAM, your organization must have a Keeper Business or Keeper Enterprise subscription. Additionally, KeeperPAM requires a minimum of five licenses. KeeperPAM is available for direct self-service purchase or you have the option of contacting Sales to receive a custom quote based on your organization’s size, infrastructure and privileged access requirements. If you're not currently a Keeper customer, you can start a free enterprise trial, which includes KeeperPAM.

Does Keeper offer a free trial?

Yes, Keeper offers free trials for Keeper Business, Keeper Enterprise and KeeperPAM.

How much does Keeper charge?

Keeper offers flexible, user-based pricing to meet the needs of businesses and enterprises:

  • Keeper Business - Starts at per user per month, billed annually. Includes encrypted vaults, shared team folders, role-based policies and basic two-factor authentication.
  • Keeper Enterprise - Starts at per user per month, billed annually. Adds advanced features like Single Sign-On (SAML 2.0), SCIM provisioning and advanced MFA options.
  • KeeperPAM - per user per month, with a minimum of 5 users. Available to customers on Keeper Business or Enterprise plans.

Keeper also offers add-ons that can be aggregated to these plans based on your organization's needs.

Buy Now