
Keeper
Unified zero-trust identity security platform for passwords, secrets, privileged access and endpoints
By Keeper Security, Inc. · HQ Chicago, US · 4.3/5 Value-Position score (estimate)
Positioning guardrails
Best for
- Security and IT teams replacing standing admin rights with just-in-time privileged access across servers, databases and endpoints
- Regulated enterprises that need a zero-knowledge vault for credentials, secrets and service accounts with strong audit trails
- DevOps and platform teams injecting vaulted secrets into CI/CD, IaC, containers and IDE workflows
- Admins who must govern secrets consumed by AI agents and assistants under RBAC and audit logging
- Organizations consolidating password management, secrets management and remote session control in one cloud platform
Ideal size: 50-5,000+ seats people · Mid-market to enterprise with a dedicated security or IT operations function
Not for
- Teams that need an open-source, fully self-hosted credential store with no vendor cloud dependency
- Buyers with no privileged-access or compliance requirement who only need basic shared password storage
- Organizations wanting fully published, self-serve rates for PAM, secrets and endpoint add-ons
- Companies looking for a SIEM or endpoint detection platform; Keeper governs credentials and sessions, not threat telemetry
Value metrics scorecard
Time-to-Value
2-4 weeks
~14 days to first production value
Total Cost of Ownership
$6,000/yr
Starts at $24 · Per user, per month, billed annually across Business Starter, Business and Enterprise tiers; KeeperPAM and most PAM, secrets and endpoint add-ons are quoted through sales.
Implementation Friction
2/5
Engineering + admin effort required
Value-Position score
out of 5 · model estimate
Full cost breakdown
Mandatory implementation fee
None
Seat tiers
Business Starter is scoped to small teams (about 5-10 users); Business and Enterprise scale per user; KeeperPAM priced by organisation size and infrastructure.
Add-on costs
- KeeperPAM privileged access management (quote-based)
- Secrets Manager and automated credential rotation
- Endpoint Privilege Manager for Windows, macOS and Linux
- Remote Browser Isolation, KeeperDB and passwordless database access
- KeeperAI agentic threat detection and response
- Advanced Reporting & Alerts (ARAM) and compliance reporting
Company & support
Who is behind Keeper, and how your team gets help once it is live.
Company
- Founded
- Not recorded
- Headquarters
- Chicago, US
How you get support
- PhonePaid plans
- EmailPaid plans
- Live chatPaid plans
- Support portal / ticketsPaid plans
- Community forumAll plans
- Help centre / docsAll plans
- Dedicated account managerPlan not stated
- In person / on-siteNot listed
- Hours
- 24/7
- Response time
- Not stated
Keeper states support is available 24/7 and that options and response times vary by plan. Business and Enterprise get priority email, live chat, phone support and onboarding help; MSP partners get a dedicated partner team.
“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.
Market position
Where Keeper sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.
Quadrant view
Typical annual cost × Time-to-value
The lines cross at the median of the solutions shown, so about half sit on each side of each line.
Companies on the chart 6 / 10
- Keeper
- Snyk
- Duo
- HYCU
- Tenable
- Josys
Add or change companies
Up to 10 companies including Keeper. Listed closest first.
Stack fit signal
Compatibility with standard B2B ecosystems.
A community or partner MCP server covers this. Usable today, though not maintained by the vendor.
AI & MCP readiness
What Keeper ships in AI, and what it asks of your ecosystem.
AI features shipped
KeeperAI analyses privileged activity and classifies risk in real time, automatically terminating high-risk sessions and producing encrypted, forensic-ready summaries. AI-driven session recording analysis is an add-on, and Keeper publishes an AI agent integration with MCP so agents can reach vault secrets under RBAC and audit logging.
Your data & models
- Trains on your data
- Not recorded — ask the vendor
- Runs on
- Not recorded
- AI pricing
- Paid add-on
In your ecosystem
- AI connection
- Community MCP server
- Model key
- Not recorded
- AI usage audit
- Basic visibility
Compliance attestations
* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.
Bottom line
Keeper Security is a zero-trust identity security platform combining enterprise password management, privileged access management (KeeperPAM), secrets management, remote access and endpoint privilege management. It is built on a zero-knowledge, end-to-end encrypted architecture with tenant data isolated in AWS regions including US GovCloud, and reports 93,000+ business customers. Core password management deploys quickly; PAM, secrets and endpoint capabilities are quote-based add-ons, KeeperAI adds agentic threat detection for privileged sessions, and support is stated as 24/7.
Frequently asked questions
How is Keeper licensed and priced?
Keeper Business Starter, Business and Enterprise are licensed per user, per month, billed annually and sold in three password-management tiers. Keeper's public pricing page presents the tiers but not the exact rates, and KeeperPAM plus most secrets, endpoint and remote-access capabilities are quote-only through sales. Add-ons such as KeeperAI, Advanced Reporting & Alerts and Secrets Manager are bought on top of a plan, so total cost scales with seats and the number of add-ons enabled.
Is privileged access management included in the base plans?
No. KeeperPAM extends the platform with just-in-time access, privileged session management, credential rotation and infrastructure discovery, and is available through sales with custom pricing tailored to organisation size and infrastructure. Secrets Manager, Endpoint Privilege Manager, Remote Browser Isolation and KeeperDB are also add-ons rather than part of the password-management tiers. Customers on Business or Enterprise can trial KeeperPAM before committing.
How long does deployment take?
Keeper describes its privileged access management solution as deploying in minutes, and it is a cloud-first service with minimal infrastructure to stand up. In practice enterprise timelines are driven by SSO, SCIM and directory provisioning, gateway deployment for remote access, and role and enforcement policy design. Budget a few weeks for a governed production rollout, with password management usable by end users much sooner.
Can Keeper secure AI agents and MCP-based workflows?
Yes. Keeper documents an AI agent integration with the Model Context Protocol that lets agents access and manage secrets, plus integrations with Claude Code, OpenAI Codex, Cursor and GitHub Copilot through the Keeper Agent Kit. Credentials are kept out of chat and source control, and access is governed by Keeper's role-based policies and standard audit logging. The MCP agent integration is sold as an add-on.
What security and compliance assurances does Keeper publish?
Keeper publishes a security page covering its AES-256 and elliptic-curve encryption model, zero-knowledge and zero-trust architecture, FIPS 140-3 validated cryptography, quarterly third-party penetration testing, a bug bounty programme and GDPR compliance, plus a Trust Center. Tenants can be hosted in isolated AWS regions including the US, US GovCloud, EU, Australia, Canada and Japan. Confirm current certification scope with Keeper during procurement.
Is there a free trial and how do we get support?
Keeper offers free trials for Keeper Business, Keeper Enterprise and KeeperPAM, and a free Family Plan for every business user. Paid plans include email, live chat and phone support plus a business support ticket portal and enterprise onboarding help; MSP partners get a dedicated partner team. Keeper states support is available around the clock, with options and response times varying by plan.