Keeper Security review

Zero-knowledge password vault for teams, with privileged access and secrets management sold alongside it.

Visit site →
In short · updated 2026-08-28
The cheapest credible business vault with a genuinely deep compliance record, though the modules that make it a full platform are all separate line items.
Keeper Security website, homepage
Keeper Security homepage, captured 2026-08-28

Pros

  • Per-user pricing sits below most business password managers, which makes company-wide rollout easier to justify
  • Zero-knowledge architecture means encryption and decryption happen on the device and the vendor cannot read stored records
  • The certification list runs to SOC 2, FedRAMP High, ISO 27001, HIPAA, FIPS 140-3 and PCI DSS Level 1, which clears most procurement checklists outright
  • Identity provider coverage is unusually wide, spanning Okta, Entra ID, Google Workspace, Ping, JumpCloud and plain LDAP or SAML
  • Privileged access, secrets management and remote browser isolation come from the same vendor, so a team can grow into them without a second contract

Cons

  • Almost everything past the vault - secrets management, session control, advanced reporting, compliance modules - is a separately priced add-on, and reviewers describe the resulting quotes as confusing
  • Business Starter caps out at ten users, so a growing team migrates tiers early rather than adding seats
  • Directory provisioning through SCIM, Active Directory and single sign-on is held to the Enterprise tier, pushing mid-sized teams to the top per-user rate for what many treat as basic hygiene

Keeper Security pricing

List prices in USD per month, taken from the vendor at review time.

Plan Per month What it covers
Business Starter $2 per user, billed annually, 5-10 users
Business $4 per user, billed annually
Enterprise $6 per user, billed annually, adds SSO and SCIM provisioning

What Keeper Security actually does

Keeper started as a password manager and has grown into an identity security platform, but the foundation is still the vault. Employees store credentials, passkeys, files and secure notes in an encrypted personal vault; administrators manage the whole estate from a console, enforce policy, assign roles, and share credentials through team folders without anyone reading a password aloud in a meeting. Encryption and decryption happen on the user's device under a zero-knowledge model, meaning the company holds ciphertext it cannot open - the structural claim that any credible vault has to make and that Keeper backs with an unusually long certification list, including SOC 2, FedRAMP High, ISO 27001, HIPAA, FIPS 140-3 and PCI DSS Level 1.

Around the vault sit modules aimed at larger and more regulated deployments. KeeperPAM handles privileged access: just-in-time elevation, session control and recorded audit trails for the accounts that actually matter. Secrets Manager stores application and pipeline credentials so they stop living in environment files, with plugins for VS Code and JetBrains editors. Remote browser isolation sandboxes access to sensitive web applications. Connection management brokers access to infrastructure without distributing keys. There is a separate offering for managed service providers. The important structural fact for a buyer is that these are individually licensed rather than bundled: the tier price covers the vault and its administration, and the platform is assembled from there.

Keeper Security, features page screenshot
Keeper Security: features

Key features

The base product is a vault; the platform is what gets added to it.

  • Encrypted vault with autofill across browser, desktop and mobile, plus passkey storage
  • Admin console with role-based access control, delegated administration and enforcement policies
  • Shared team folders with granular per-record permissions
  • Single sign-on plus SCIM, Active Directory and LDAP provisioning on the top tier
  • Privileged access management with just-in-time elevation, session control and audit trails
  • Secrets management for application and CI/CD credentials, with IDE plugins

Who it's for

Keeper suits a small or mid-sized company that has to demonstrate credential control to an auditor, an insurer or an enterprise customer, and does not have the budget for a dedicated security platform. The certification list does a lot of work in procurement, the per-user price is low enough that covering everybody is realistic rather than aspirational, and the growth path into privileged access exists when it becomes necessary. Regulated small operators - clinics, financial advisers, contractors serving government - get particular value from the compliance coverage.

It fits less well for a two-person startup that simply wants a shared vault, where a cheaper or open-source option is adequate and the admin apparatus is overhead. Teams that want everything included in one predictable price will also find the model frustrating, because building the full platform means adding modules one at a time. And the free plan is a single-device personal vault, so there is no free path for a team to trial its way in.

How it compares

1Password remains the better daily experience - cleaner apps, smoother sharing, a developer story that engineers actually enjoy - and it bundles more into its business tiers, at a meaningfully higher price per user. Bitwarden undercuts everyone, is open source and auditable by anyone who cares to look, and covers the vault job well, but its administrative depth and privileged access story are thinner. CyberArk operates in a different weight class entirely for privileged access and is priced accordingly, which is exactly the gap Keeper aims at with a cheaper PAM module attached to a vault a whole company already uses. Keeper wins on price and compliance breadth, and loses to 1Password on polish and to Bitwarden on transparency.

Keeper Security, use cases page screenshot
Keeper Security: use cases

Verdict

This is a serious product at an unserious price, and the reason to choose it is usually compliance: the certification coverage clears procurement questions that force other vendors into lengthy security reviews. The vault works, the admin console is capable, and the identity provider support is broader than most competitors bother with. The caveat is the commercial model. Advanced reporting, secrets management, session control and compliance modules are all separate purchases, provisioning through SCIM and single sign-on sits at the top tier, and reviewers consistently describe the pricing as confusing with upsells arriving over time. Price the actual configuration you need, not the headline per-user rate.

Ready to try Keeper Security?

More founders tools like Keeper Security