Source
Encryption model & independent audits — found from sitemap — Keeper
Checked for Keeper on 1 Oct 2026
- Page
- https://www.keepersecurity.com/security.html
- Checked
- 1 Oct 2026, 17:51 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:3f3b2132444840bb931cbf92fe3f43465fa7d623c2832830cd22ec4e603b046f
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Encryption algorithms Report an error
“Keeper safeguards your passwords, secrets and personal information with AES 256-bit encryption and Elliptic-Curve cryptography (ECC)”
-
Zero knowledge Report an error
“Keeper is a zero-knowledge security provider. Zero knowledge is a system architecture that guarantees the highest levels of security and privacy. Encryption and decryption of data always occur locally on the user's device.”
-
Bug bounty Report an error
“we have partnered with Bugcrowd to manage our Vulnerability Disclosure Program (VDP) and bug bounty program.”
-
Fips 140 3 Report an error
“Keeper is certified by the NIST Cryptographic Module Verification Program (CMVP) to meet the FIPS 140-3 standard.”
-
Penetration testing Report an error
“Keeper partners with third-party experts such as NCC Group, CyberTest and independent security researchers to perform quarterly pen testing against all solutions and systems.”
-
Provider regions Report an error
“Keeper utilizes AWS in several regions – including the US, US GovCloud, EU, AU, CA and JP – to host and operate the Keeper platform and architecture.”
-
Availability Report an error
“The Keeper global infrastructure is hosted in multiple high-availability AWS data centers. These data centers are distributed across multiple AWS regions to ensure service availability in the event of a regional internet outage.”
-
MFA methods Report an error
“Keeper supports multi-factor authentication (MFA), SSO authentication, conditional access policies (CAP), FIDO2 WebAuthn hardware security keys, passkeys, biometric login (such as Face ID, Touch ID and Windows Hello), and Keeper DNA®, which uses smartwatch devices to confirm identity.”
-
Record level encryption Report an error
“End-user data is encrypted and decrypted at the device level and record level – never in the cloud or on Keeper's servers.”
-
Vault record encryption Report an error
“256-bit AES record-level keys and folder-level keys are generated on the client device, which encrypt each stored vault record. The vault records and all of its contents are fully encrypted, including logins, file attachments, TOTP codes, payment information, URLs and custom fields.”
-
Pbkdf2 iterations Report an error
“the password-based key variation function (PBKDF2), with 1,000,000 iterations.”
-
SSO ecc key Report an error
“A local ECC-256 (secp256r1) private key is used to decrypt the data key.”
-
Record versioning Report an error
“Keeper maintains a full encrypted version history of every record stored in the user's vault, providing confidence that no critical data is ever lost.”
-
Business admin console Report an error
“Keeper administrators are provided access to a cloud-based administrative console which allows full control over user on-boarding, off-boarding, role-based permissions, delegated administration, teams, Active Directory/LDAP integration, Two-Factor Authentication, Single Sign-On and security enforcement policies.”
-
Hsm super encryption Report an error
“In addition to storing only device-encrypted ciphertext in the AWS infrastructure, Keeper also performs super-encryption with multi-region hardware security modules (HSM) using non-exportable keys.”
-
Backup recovery Report an error
“Keeper's Support Team can assist in a recovery to any point in time (up to the minute) within 30 days. For a fee, Keeper support can assist in any recovery, such as user restore, vault restore or full Enterprise restore.”
-
Account recovery phrase Report an error
“A 24-word recovery phrase enables Keeper customers to regain access to their Keeper Vault if they lose or forget their master password.”
-
Device verification Report an error
“Before a user can even attempt to log into an account, they must pass a device approval and verification step first. Device verification prevents enumeration of accounts, and protects against brute force attacks.”
-
GDPR Report an error
“Keeper is GDPR compliant and committed to ensuring our processes and products maintain GDPR compliance for our customers in the European Union and across the world.”
-
Data privacy frameworks Report an error
“We comply with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, the German Federal Data Protection Act (BDSG) and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") as set forth by the U.S. Department of Commerce.”
-
No trackers Report an error
“None of Keeper's applications contain trackers or 3rd party libraries that perform tracking.”
-
Available regions Report an error
“United States (US) United States Government Cloud (US_GOV) Europe (EU) Australia (AU) Japan (JP) Canada (CA)”
-
Encryption in transit Report an error
“Vault data at rest is encrypted on the user's device locally using AES-256 GCM, and encrypted data in transit is encrypted with TLS 1.3 with an additional layer of encryption in the payload.”
-
Quantum resistant Report an error
“Starting in Q1 2026, Keeper has started the rollout of Quantum-Resistant Cryptography (QRC) as an additional encryption wrapper on the transmission key.”
-
Memory protection Report an error
“Keeper Forcefield extends Keeper’s Zero-Knowledge security model by providing real-time memory protection for sensitive applications on Windows endpoints.”
-
SAML providers Report an error
“Keeper integrates with all SAML 2.0-compatible identity providers, including Okta, Microsoft Entra ID (Azure), AD FS, Google Workspace, Centrify, OneLogin, Ping Identity, JumpCloud, Duo, Auth0 and more.”
-
SSO types Report an error
“Our products offer two different SSO types: SSO Connect Cloud and SSO Connect On-Prem.”
-
SSO automator Report an error
“Keeper Automator is an optional service which performs instant team approvals, device approvals and team user assignments upon a successful login from the SSO identity provider.”
-
One time share Report an error
“Keeper One-Time Share provides limited-time, secure sharing of a record – such as a password, credential, secret, connection, document or other confidential information – with anyone, even if they don't have a Keeper account.”
-
Share admin Report an error
“Keeper's Share Admin feature is a role-based access control (RBAC) permission that gives admins elevated privileges over an organization's shared folders and records.”
-
Secrets manager Report an error
“Keeper Secrets Manager is a zero-knowledge platform for IT and DevOps professionals that allows teams to manage secrets throughout the software development and deployment lifecycle.”
-
Privileged access manager Report an error
“Zero-Trust KeeperPAM® provides the capability to establish cloud and on-prem privileged sessions, create tunnels, establish direct infrastructure access and secure remote database access without a VPN.”
-
Remote browser isolation Report an error
“Keeper Remote Browser Isolation technology protects access to internal web applications or any other web-based asset through the Keeper Connection Manager Docker container or through the Keeper Gateway.”
-
Ad ldap bridge Report an error
“The Keeper Bridge integrates with Active Directory and LDAP servers for provisioning and onboarding of users.”
-
Ksm gateway rotation Report an error
“A unique Keeper Secrets Manager (KSM) client, called a gateway, is installed in the customer's environment.”
-
Keeper connection manager Report an error
“Keeper Connection Manager (KCM) is a remote desktop gateway that provides DevOps and IT teams with effortless, Zero-Trust Network Access (ZTNA) to RDP, SSH, databases, internal web applications and Kubernetes endpoints through a web browser – no agent required.”
Scores citing this record
- The CISO Encryption model & independent audits
- The CISO Sharing, roles & recovery
- The CISO SSO, directory sync & provisioning
- The CISO Hosting choice, offline access & export
- The CISO European sovereignty
- The Compliance Auditor Encryption model & independent audits
- The Compliance Auditor Sharing, roles & recovery
- The Compliance Auditor SSO, directory sync & provisioning
- The Compliance Auditor Hosting choice, offline access & export
- The Compliance Auditor European sovereignty
- The DevOps Engineer Encryption model & independent audits
- The DevOps Engineer Sharing, roles & recovery
- The DevOps Engineer SSO, directory sync & provisioning
- The DevOps Engineer Hosting choice, offline access & export
- The DevOps Engineer European sovereignty
- The Identity Engineer Encryption model & independent audits
- The Identity Engineer Sharing, roles & recovery
- The Identity Engineer Hosting choice, offline access & export
- The Identity Engineer European sovereignty
- The Skeptic Encryption model & independent audits
- The Skeptic Hosting choice, offline access & export
- The Skeptic European sovereignty