Password Management
Keeper
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Keeper Security, Inc. · www.keepersecurity.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Keeper is an enterprise password manager whose strongest area in the judges' scoring is identity integration, at 8-9: single sign-on over SAML 2.0 with SCIM provisioning and deprovisioning, identity-provider group mapping, conditional access, FIDO2 hardware keys and passkey unlock, built on a published, patented zero-knowledge key model that needs no master password. Sharing and access control follows at 7-8, with over 80 permissions across 14 categories, persistent, time-limited and self-destructing shares, and offboarding that transfers vault ownership under zero knowledge. Pricing transparency scores a flat 2: the captured pages contain no per-user, tier or seat price — only a 14-day free trial, a demo request and the note that SSO Connect is included with Keeper Enterprise. Sovereignty sits at 4-5: European customers contract with the Irish entity and may select an EU AWS region, but the parent is a US company, the regions list begins with the United States, and transfers rest on the EU-US data privacy framework with standard contractual clauses. The bench flagged no disagreements; its one-point spreads track named gaps such as penetration-testing firms cited without published reports.
Speaks for it
- Identity integration scores 8-9, with any SAML 2.0 identity provider, SCIM provisioning and deprovisioning, and a published, patented zero-knowledge unlock model that removes the master password.
- Sharing is governed in depth, with over 80 permissions across 14 categories, persistent, time-limited and self-destructing shares, and one-time shares to people without a Keeper account.
- The encryption architecture is published in specifics: AES-256, PBKDF2 with 1,000,000 iterations, client-generated record and folder keys, and an encrypted-field list covering URLs, custom fields, attachments and TOTP codes.
- Audit logs cover authentication, credential access, sharing and administrative events, exportable as PDF, JSON or CSV, with SIEM integration and an ISO 27001 control mapping.
- Offline vault access works without internet or identity provider, with admin-controlled durations and per-role toggles.
Held against it
- Pricing transparency scores a flat 2 — no per-user, tier or seat price appears in the captured pages, only a 14-day free trial, a demo request and the note that SSO Connect is included with Keeper Enterprise.
- Sovereignty scores 4-5: the parent is a US company, the captured regions list begins with the United States with no stated default region, and transfers rest on the EU-US data privacy framework with standard contractual clauses.
- We found no public information on published penetration-test reports, incident history or reviewable client code, which holds security architecture at 6-7.
- SIEM export is described without a single named destination system, and we found no public information on log retention periods or tamper-evidence.
- Hosting is Keeper's AWS cloud — the components documented as on-premises are the single sign-on connector and gateway, not the vault — and we found no public information on export fidelity for attachments or folders.
Best for
- You run Okta, Microsoft Entra ID or another SAML 2.0 identity provider and want vault unlock without a master password under a zero-knowledge key model.
- You need an audit trail mapped to SOC 2, HIPAA, NIST 800-53 or ISO 27001, with exportable and schedulable reports.
- You need governed team sharing — delegated administration scoped to a node, time-limited and one-time shares, and offboarding that locks a leaver's vault and transfers ownership.
Avoid if
- You must compute an annual cost from public pages before talking to a vendor — ask the vendor: the public pages we read do not show it
- You require a provider without a US parent or US-headquartered infrastructure company in the chain — the parent is Keeper Security, Inc. of Chicago and AWS is US-headquartered regardless of the server region.
- You need to self-host the vault itself — the hosting described is Keeper's AWS cloud, with only the single sign-on connector and gateway components documented as on-premises.
The scores
Encryption model & independent audits
Show reasoningHide reasoning
How this is scored
What the vendor can prove about its security design: end-to-end encryption with named algorithms and key derivation, which fields are encrypted on the device and which are not, independent audits and penetration tests with published results, a bug bounty, and incident history disclosed.
0 — Security described in adjectives ("bank-grade", "military encryption") with no architecture, no audit and no statement of what the vendor can read.
3 — Encryption algorithms named and "zero knowledge" claimed, but no whitepaper, no statement of which fields stay unencrypted, and audits mentioned without dates, auditors or results.
5 — A published security whitepaper naming algorithms, key derivation and the client-side encryption model, a stated list of what is and is not encrypted (including URLs and metadata), and a named independent audit or certification (ISO 27001, SOC 2) with its date.
8 — Recurring independent penetration tests or code audits with reports or summaries published, a public bug bounty or vulnerability disclosure policy, past security incidents documented with their impact, and open-source clients or cryptography that can be reviewed.
10 — The design is verifiable end to end: full source or cryptographic design public, every field encrypted client-side including metadata, audits by named firms repeated yearly with full reports, a threat model that states what a compromise of the vendor's servers would expose, and incident post-mortems published.
The CISO
The security pages name the algorithms, the one-million-iteration PBKDF2 key derivation, client-generated record keys, and state that URLs and custom fields are encrypted, with penetration testers named (NCC Group, CyberTest), a Bugcrowd bug bounty, FIPS 140-3 validation and an annual ISO 27001 audit. We found no public information on published test reports or summaries, a named assessor or dated certificate, incident history, a threat model for a server compromise, or a reviewable client, which holds it below the top band. 1 3 5 6 12
The Identity Engineer
The security pages name algorithms down to PBKDF2 with 1,000,000 iterations, client-generated 256-bit AES record and folder keys, and a field-level list of what is encrypted including URLs, attachments and TOTP codes, with ISO 27001 audited annually and cryptographic modules validated to FIPS 140-3. Recurring penetration tests by NCC Group and CyberTest and a Bugcrowd-run bug bounty are public. We found no public information on published test reports, past incident disclosures, or open-source clients that could be independently reviewed. 5 6 12 1
The Compliance Auditor
The security pages go beyond adjectives: AES-256 and elliptic-curve cryptography are named, key derivation is stated as PBKDF2 with 1,000,000 iterations, and the encrypted-field list explicitly covers URLs, custom fields, file attachments and TOTP codes. Periodic penetration tests by named firms, a Bugcrowd-managed bounty, a public disclosure programme and annual ISO 27001 audits are all on the record — but we found no public information on published test reports or summaries, on past security incidents and their impact, or on open-source clients or cryptography for review. 5 6 12 1 3
The SME Owner
The encryption model is specific, not adjectives: AES-256 with elliptic-curve keys and PBKDF2 at one million iterations, record-level keys generated on the client, and a stated list of encrypted contents including URLs, custom fields and attachments, backed by annually audited ISO 27001 certification, FIPS 140-3 validated crypto modules, named penetration-testing firms and a public bug bounty on Bugcrowd. We found no public information on published audit report summaries, a documented incident history, or reviewable source code. 6 12 3
The DevOps Engineer
The security page reads like engineering, not adjectives: named algorithms, PBKDF2 with 1,000,000 iterations, client-generated record and folder keys, an explicit list of encrypted fields including URLs and attachments, annual ISO 27001 audits, FIPS 140-3 validated modules and recurring penetration tests naming NCC Group and CyberTest alongside a public Bugcrowd bounty. What holds it back for me is that I found no public information on published test summaries, on incident history, or on open-source code I could review myself. 3 5 6 12
The Skeptic
AES-256 with a million PBKDF2 iterations, client-generated record and folder keys, and an encrypted-field list that explicitly includes URLs and custom fields — this is a stated architecture, not adjectives. The captured pages also name penetration testers (NCC Group, CyberTest) and a Bugcrowd-run bounty, but give no audit or test reports, no certification dates, and I found no public information on incident history or on client code that could be independently reviewed. Named firms without published results is exactly the pattern I refuse to round up on. 5 6 12 1
Sharing, roles & recovery
Show reasoningHide reasoning
How this is scored
How credentials are shared and governed across a company: shared vaults or collections, role-based permissions, view-only and time-limited access, admin account recovery, emergency access, and what happens to shared items when an employee leaves.
0 — Personal vaults only, or sharing by sending a password to another user with no permissions and no record.
3 — Shared folders with all-or-nothing access, no roles, and no stated process for recovering an account or reclaiming credentials from a departing employee.
5 — Shared vaults or collections with read, edit and manage permissions, groups and admin roles, an admin recovery mechanism documented with its key model, and offboarding that transfers a leaver's shared items.
8 — Granular permissions down to hiding the password while allowing autofill, time-limited and one-time sharing with external parties, emergency access with a waiting period, delegated administration per team or location, and approval workflows for sensitive items.
10 — Access is governed and provable: least-privilege defaults, recovery and emergency access designed so the vendor never holds a key and stated so, periodic access reviews supported in the product, and every grant, change and revocation attributable to a person.
The CISO
Over eighty permissions across fourteen categories, time-limited and one-time shares to people without an account, node-scoped delegated administration, approval-based workflows, and offboarding that locks a leaver's vault and transfers ownership while keeping zero knowledge. Recovery rests on a user-held 24-word phrase confirmed by email and a second factor, with companies able to disable it by policy; we found no public information on emergency access with a waiting period or on hiding a password while still allowing autofill, which keeps this short of the top. 5 6 7 8 10
The Identity Engineer
Sharing covers persistent, time-limited and self-destructing forms including one-time links to people without a Keeper account, with over eighty permissions across fourteen categories, node-scoped delegated administration, request-based approval workflows, and offboarding that locks a leaver's vault and transfers ownership without breaking zero-knowledge. A 24-word BIP39 recovery phrase restores access under email and 2FA verification, and the most restrictive policy wins for users in multiple roles. We found no public information on emergency access with a waiting period or on hiding a password while still allowing autofill. 7 8 6 5
The Compliance Auditor
Sharing is governed rather than merely possible: persistent, time-limited and self-destructing shares, one-time shares to people without a Keeper account, delegated administration scoped to a node, approval workflows for eligible-team access, over eighty permissions across fourteen categories, and offboarding that locks the vault and transfers ownership while keeping zero knowledge, with the most restrictive policy applied by default. A 24-word BIP39 recovery phrase with 2FA and email verification, which companies can disable by policy, covers recovery. We found no public information on emergency access with a waiting period or on hiding the password while still allowing autofill. 7 8 6 5
The SME Owner
This is what my Excel file needs to become: shared folders and records with persistent, time-limited and self-destructing sharing, one-time shares to people without a Keeper account, over eighty permissions across fourteen categories, node-based delegated admins, and offboarding that locks a leaver's vault and transfers ownership while keeping zero knowledge. Recovery from a forgotten master password is documented as a 24-word phrase with email and two-factor verification — we found no public information on emergency access with a waiting period or on hiding a password while still allowing autofill. 7 8 6
The DevOps Engineer
Sharing is genuinely governed: over 80 permissions across 14 categories, node-scoped delegated administration, one-time and time-limited shares to people without an account, approval workflows, most-restrictive-policy defaults and an offboarding transfer that locks the vault and hands over ownership while keeping zero-knowledge. Recovery is a 24-word BIP39 phrase with 2FA and email verification that admins can disable and that the vendor states it cannot decrypt, but I found no public information on emergency access with a waiting period. 5 6 7 8
The Skeptic
Sharing is documented in real depth: over eighty permissions across fourteen categories, node-scoped delegated administration, persistent, time-limited and self-destructing shares, one-time shares to people without an account, and offboarding that locks a leaver's vault and transfers ownership without breaking zero-knowledge. Approval workflows exist for privileged access, and the most restrictive policy wins when a user holds several roles. I found no public information on emergency access with a waiting period, or on hiding a password while still allowing autofill, and those gaps hold this short of the top band. 7 8 6
SSO, directory sync & provisioning
Show reasoningHide reasoning
How this is scored
How the vault fits into the company's identity stack: SSO with Entra ID, Okta or Google, and the key model behind an SSO unlock; SCIM or directory sync for joiners and leavers; MFA options including hardware keys; and passkey support for users and the vault itself.
0 — Each user creates an account by email; no SSO, no directory sync and no MFA beyond an app code.
3 — SSO available only to sign in to the admin console or on the top tier with no description of how the vault is then decrypted, and users provisioned by CSV invite.
5 — SSO with named identity providers (Entra ID, Okta, Google) documented with how the vault key is derived or released, SCIM or directory sync for provisioning and deprovisioning, and MFA including FIDO2 or hardware keys.
8 — SSO unlock designed so the vendor cannot derive the vault key and stated so, group sync driving vault permissions, automated suspension on deprovisioning, conditional access or device policies, and passkeys stored and used across platforms.
10 — Identity is integrated without trust shortcuts: the SSO key model published and independently reviewed, deprovisioning that revokes vault access and shared items immediately with a log entry, passwordless vault unlock with passkeys, and support for the customer's own key-management or trusted-device approval.
The CISO
Single sign-on works with named providers over SAML 2.0 and the unlock model is published — a device private key (ECC-256) releases the user's data key after identity-provider authentication, patented and in production since 2015 — with SCIM provisioning and deprovisioning, identity-provider group mapping, conditional access, FIDO2 hardware keys and passwordless passkey unlock. We found no public information on an independent review of that key model or support for the customer's own key-management approval, so it is not the full ten. 5 6 9 10 12
The Identity Engineer
Entra ID is a named SAML provider, the unlock key model is published in detail — the user's data key is decrypted with a device private ECC-256 key after identity-provider authentication, with no master password, under two public US patents — and SCIM handles provisioning and deprovisioning alongside IdP group mapping and conditional access compatibility. FIDO2 WebAuthn hardware keys are supported and passkeys unlock the vault itself across platforms. To reach the top I would want an independent review of that key model and an explicit statement that deprovisioning revokes vault and shared-item access immediately with a log entry. 9 6 10 12
The Compliance Auditor
The SSO story is documented down to the key model: SAML 2.0 with a long list of named providers, the data key decrypted with a device private key and an ECC-256 key after identity-provider authentication, SCIM provisioning and deprovisioning, directory mapping driving vault access, conditional-access compatibility, and FIDO2 hardware keys alongside passkeys stored and autofilled across platforms. Biometric passkey login that replaces both master password and SSO is even claimed. We found no public information on an independent review of the SSO key model or on deprovisioning that revokes shared items immediately with a log entry. 9 6 5 10 12
The SME Owner
Everything I would ask about the identity stack is documented: SSO Connect with Entra ID, Okta, Google Workspace and any SAML 2.0 provider, a published key model where a local ECC-256 key unlocks the data key and no master password is needed in that mode, SCIM provisioning and deprovisioning, identity-provider group mapping with conditional access, FIDO2 hardware keys, and passkey-based passwordless unlock of the vault itself. The catch for a company my size is that SSO Connect is stated as included with Keeper Enterprise — we found no public information on independent review of the SSO key model. 9 6 10 12
The DevOps Engineer
SSO is the best-documented part of the product: any SAML 2.0 provider, SCIM provisioning and deprovisioning, IdP group mapping with conditional access, and a key model where the data key is only decrypted with the device private key after identity-provider authentication in a zero-knowledge design with patents behind it. Passkey unlock across platforms and a self-hosted SSO Connect On-Prem with load balancing and HSM support meet my bar; I found no public information on an independent review of that key model, or on deprovisioning revoking vault access immediately with a log entry. 5 6 9 10
The Skeptic
The SSO unlock is documented at the key level — the data key is decrypted with a device private key after identity-provider authentication, in a zero-knowledge model that removes the master password — plus SCIM provisioning and deprovisioning, directory-to-role mapping, conditional access and FIDO2 hardware keys. Passkey-based passwordless unlock of the vault itself is described, and the SSO broker can run on-premises. But the key model is published and patented, and I found no public information on any independent review of it, nor any statement that deprovisioning revokes shared items immediately with a log entry. 9 6 10 12
Audit logs, policies & reporting
Show reasoningHide reasoning
How this is scored
What an administrator and an auditor can see and enforce: event logs of access and changes, password health and breach reports, enforceable policies (master password, MFA, sharing, export), SIEM integration, and reports an ISO 27001 or NIS2 audit can use.
0 — No audit log and no admin policies; the administrator sees a user list.
3 — A basic activity list and a password-strength score, but no exportable log, no enforceable policies, and no record of who viewed or copied a shared credential.
5 — Event logs covering logins, item access, sharing and admin changes, exportable or available through an API, enforceable policies for master password and MFA, and password health and breach-monitoring reports.
8 — Native SIEM integration with named targets (Splunk, Microsoft Sentinel, Elastic or syslog), policies for sharing, export and browser-extension behaviour, log retention stated, and compliance reports aligned to ISO 27001, NIS2 or BSI IT-Grundschutz.
10 — Auditability is complete: every view, copy, autofill and permission change logged with user and device, logs tamper-evident and retained for a configurable period, alerting on anomalous access, and an auditor role that can read logs without access to secrets.
The CISO
Every role assignment, policy change and vault action is logged and reportable, covering authentication, credential access, sharing and admin events, with exports to PDF, JSON or CSV, scripted recurring reports, SIEM integration and anomaly and behavioural flagging — much of what an ISO 27001 or SOC 2 auditor will ask for. Roles enforce two-factor, platform, vault, sharing and export rules, and administrators can manage policies without access to vault contents. We found no public information on named SIEM targets, stated log retention, or tamper-evidence of the logs, which is where the last points sit. 7 8 11 12
The Identity Engineer
Audit logs cover authentication events, credential access, sharing actions and administrative changes, exportable as PDF, JSON or CSV and schedulable through a command-line tool, with SIEM integration, anomaly flagging and role policies governing 2FA, platform restrictions, sharing and export. Reports are aligned to SOC 2, HIPAA, NIST 800-53, ISO 27001, SOX and PCI. We found no public information on named SIEM targets, log retention periods, or breach-monitoring reports. 12 8 11 7
The Compliance Auditor
For my ISO 27001 file this is the strongest page set: audit logs for authentication events, credential access, sharing actions and administrative changes, exportable in PDF, JSON or CSV or via a scriptable CLI into SIEM platforms, role policies enforcing 2FA plus sharing and export rules, a dedicated ISO 27001 control mapping, anomaly flagging, and segregation of duties so security administrators see policies without vault contents. But the captured pages give no named SIEM targets such as Splunk or Sentinel, no stated log retention period, and we found no public information that copies or autofill events are individually logged or that logs are tamper-evident — so who copied the firewall password last March stays partly unanswered. 12 8 11 7
The SME Owner
The admin-side logging looks genuinely usable: every role assignment, policy change and vault action logged and reportable, a report builder with PDF, JSON and CSV export, scheduled recurring reports through the Commander CLI, password-hygiene reporting, and anomalous-session flagging by KeeperAI. We found no public information on named SIEM destinations, a stated log retention period, or a master-password enforcement policy, which is what separates good from complete here. 8 11 12
The DevOps Engineer
Every role assignment, policy change and vault action is logged and reportable, roles enforce MFA plus sharing and export rules, reports export as PDF, JSON or CSV, and a CLI lets me script and schedule recurring audits — exactly what my pipelines want, with anomaly flagging on top. The captured pages state SIEM export but name no target systems, and I found no public information on log retention or tamper-evidence, so an external auditor still has open questions. 7 8 11 12
The Skeptic
Authentication, credential access, sharing and administrative changes are all logged and reportable, exportable as PDF, JSON or CSV or into a SIEM, with password-hygiene reporting and control-by-control ISO 27001 mapping an auditor can actually work with; anomaly flagging and a role separation that keeps policy admins out of vault contents are also evidenced. The SIEM integration is described without naming a single target system, and I found no public information on log retention periods, breach-monitoring reports or tamper-evidence of the logs — the difference between audit logs and auditability. 12 8 11 7
Hosting choice, offline access & export
Show reasoningHide reasoning
How this is scored
Where and how the vault runs and how the data leaves it: cloud region choice, a self-hosted or on-premises option, offline access during a vendor outage, client coverage across operating systems and browsers, and a complete, documented export and import path.
0 — Cloud only in an unstated region, no offline access, and no export or an export that drops attachments and shared items.
3 — Cloud with a region named, apps for common platforms, and an export in CSV only that leaves out attachments, folders, TOTP seeds or custom fields.
5 — An EU region or self-hosted option, offline read access on desktop and mobile, clients for Windows, macOS, Linux, iOS, Android and the major browsers, and an export that covers all item types including attachments.
8 — Both EU cloud and self-hosted or on-premises deployment documented, a status page with incident history, encrypted full-fidelity export and import from named competitors, and vault access continuing during an outage of the vendor's service.
10 — The customer can run and leave the vault on their own terms: self-hosting with documented high availability and backup, an open or documented export format that preserves structure, permissions and history, and a stated procedure for continued access if the vendor ends the service.
The CISO
Hosting is selectable across six AWS regions including Europe with isolation at rest and in transit, and offline mode is genuinely documented: an encrypted device-local vault usable without internet or identity provider, with per-role admin control, expiry windows and sync on reconnect. Export exists and the vendor states it cannot decrypt the data, but we found no public information on export fidelity such as attachments, folders or two-factor seeds, on import from named competitors, on a status page with incident history, or on a self-hosted vault — the self-hosted piece we did find covers the single sign-on connector only. 3 5 6 9 14
The Identity Engineer
An EU AWS region is selectable with isolation at rest and in transit, offline access is documented in depth — encrypted local copy, master password or biometric unlock, admin-set durations and per-role toggles — and export is available with Keeper unable to decrypt the data. We found no public information on a self-hosted vault option (the on-prem pieces cover the SSO bridge and a connection gateway), on export fidelity for attachments and custom fields, or on a status page with incident history. 6 14 3 5
The Compliance Auditor
The EU is one of six selectable AWS regions with isolation at rest and in transit, and offline mode is unusually well evidenced: an encrypted device-local vault copy, access without internet or identity provider, admin-controlled durations, per-role toggles and resync on reconnect. Export exists and Keeper states it cannot decrypt the data, but we found no public information on which item types and attachments the export covers, on import from named competitors, or on self-hosting of the vault itself beyond on-premises SSO and gateway components; client coverage is claimed generically with no enumerated platform list. 6 14 3 5 4
The SME Owner
Offline access is well covered — the vault stays encrypted and device-local, unlocks with the master password or biometrics, and admins control who gets it and for how many days — and I can select an EU AWS region, but the hosting choices end there. We found no public information on a self-hosted vault option, on export fidelity beyond the statement that I can export at any time and Keeper cannot decrypt the data, or on import from other password managers. 14 6 3
The DevOps Engineer
I can select an EU AWS region and the offline mode is thoroughly documented — encrypted local vault, admin-controlled durations, device priming, self-destruct — but the hosting described is Keeper's AWS cloud; the self-hosted components I found are the SSO bridge and a secrets-manager gateway, not the platform itself. Export exists and Keeper states it cannot decrypt the data for you, yet I found no public information on export fidelity for attachments and folders, on import from named competitors, or on a documented exit path if the service ends. 3 5 6 14
The Skeptic
Offline vault access without internet or identity provider is documented down to session expiry, self-destruct and per-role toggles, so access during a vendor outage is genuinely covered, and customers select among six AWS regions including an EU one. But that region is an opt-in on US-headquartered AWS with no stated default, the on-premises pieces are the SSO broker and a secrets gateway rather than the vault, and export is confirmed only alongside a statement that Keeper cannot decrypt the data — I found no public information on whether attachments, folders or TOTP seeds survive export, on an enumerated client list, or on incident history behind the status link. 14 6 5 3 4
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Who the contracting entity and the parent company are, where vault data and metadata are hosted, and who the subprocessors are. Independently sourced by the sovereignty pipeline; end-to-end encryption narrows what a foreign authority could compel, but metadata, logs and the update channel for the client software remain in the vendor's hands, so the chain still counts.
0 — Non-EU vendor and contracting entity, hosting unstated, and subprocessors unnamed.
3 — An EU data region offered while the contracting entity and parent are non-EU without a stated safeguard, or the subprocessor list is absent.
5 — EU hosting as standard or selectable and an EU contracting entity, but the parent company or parts of the chain (support, analytics, email, client distribution) are non-EU.
8 — EU hosting on named infrastructure, EU contracting entity, subprocessor list published with locations, a DPA covering vault metadata and logs, and a self-hosted option that removes the vendor from the data path.
10 — Sovereign end to end and evidenced: European ownership, entity, hosting and every subprocessor, certifications published (ISO 27001, BSI C5 or equivalent), and source code or builds verifiable so the client update channel is not a blind trust in the vendor.
The CISO
European customers contract with Keeper Security EMEA Limited in Cork under Irish law with the Irish data protection authority named, and vault data can be isolated to a chosen AWS region — but the parent is a US company, the United States appears first in the region list, AWS is US-headquartered regardless of server region, and we found no public information on a published subprocessor list with locations. Legal disclosure is described as limited to general account information, which narrows but does not remove the foreign-authority exposure on metadata and the update channel. 3 4 5 6
The Identity Engineer
European customers contract with the Irish entity Keeper Security EMEA Limited under Irish law and may select an EU hosting region, but the parent is a US company, the infrastructure provider is US-headquartered regardless of server region, and transfers rely on the EU-US Data Privacy Framework and standard contractual clauses. We found no public information on a published subprocessor list with locations or on a data-processing agreement covering vault metadata and logs. 4 6 3 5
The Compliance Auditor
European customers contract with Keeper Security EMEA Limited in Cork under Irish law with the Irish Data Protection Commission as supervisory authority, and can select an EU AWS region — but the parent is the Chicago company, the security pages leave a default region unstated with the regions list beginning with the United States, and transfers rest primarily on the EU-US data privacy framework rather than European safeguards. We found no public subprocessor list naming locations; only AWS appears as hosting provider, and it is US-headquartered regardless of server region. 4 3 5 1 6
The SME Owner
My company would contract with Keeper Security EMEA Limited in Cork under Irish law with the Irish data protection authority named as supervisor, and could select an EU AWS region — but the parent is Keeper Security, Inc. of Chicago and the infrastructure is US-headquartered AWS. We found no public information on a published subprocessor list with locations or on the ownership structure. 4 6 3
The DevOps Engineer
European customers contract with Keeper Security EMEA Limited in Cork under Irish law and can select an EU AWS region, but the parent is a US company, ownership is not stated, and AWS sits in the chain regardless of server region. Transfers rest on the EU-US framework with standard contractual clauses as fallback; I found no published subprocessor list with locations, and no self-hosted option that removes the vendor from the data path. 3 4 5 6
The Skeptic
European customers contract with the Irish entity and can select an EU AWS region, but the parent is a Chicago company, the security page states no default region and lists the United States first, and transfers out of the EEA rest on the EU-US data privacy framework and standard contractual clauses. I found no public information on a subprocessor list with locations — only a statement that data processing agreements exist with unnamed vendors — and no evidence of a self-hosting option that removes the vendor from the vault's data path. 4 5 3 6
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real annual cost from public pages alone: price per user and tier, which features (SSO, SCIM, SIEM, self-hosting) sit in which tier, minimum seats, add-ons, and the minimum term.
0 — No public prices at all; every tier is a sales conversation.
3 — A starting price exists, but which business features (SSO, SCIM, audit logs) sit in which tier is unclear — the invoice is unknowable.
5 — Per-user tier prices public with the main features per tier, but at least one commonly needed piece (SSO, SIEM integration, self-hosting, minimum seats) is unpriced or "on request".
8 — Every tier priced publicly with its feature set and seat minimum, add-on prices listed, self-hosted licensing stated, minimum term and VAT treatment given.
10 — Complete price computability: annual invoice derivable for a given number of users, with every add-on, self-hosting licence, support level and renewal condition published.
The CISO
We found no public information on any price per user, tier price, seat minimum, term, add-on or self-hosting licence in the captured pages, so an annual invoice is not computable from what is published. The only pricing-adjacent facts are a 14-day free trial and a note that the single sign-on connector is included with the Enterprise plan. 2 9 11
The Identity Engineer
The public information shows a 14-day free trial, that SSO Connect is included with the Enterprise tier, and that offline admin controls come with the business and enterprise plans, but no per-user prices, seat minimums, add-on prices or minimum terms appear anywhere we reviewed. An annual invoice for a given headcount cannot be computed from the published pages alone. 2 9 14
The Compliance Auditor
A pricing page was captured, yet no per-user price, tier price, seat minimum, minimum term or VAT treatment appears in any of the captured pages — the only public commercial facts are a 14-day free trial, a demo request and a note that SSO Connect is included with Keeper Enterprise. Without figures I cannot compute an annual invoice from public pages, and we found no public information on where SCIM or SIEM integration sit priced. 2 9 8 11
The SME Owner
I cannot price forty seats from the public pages: we found no per-user price figure for any tier, only a 14-day free trial and a request-a-demo button, and the one tier signal that did surface puts SSO Connect with Keeper Enterprise rather than a starter business plan. We found no public information on seat minimums, add-on prices, minimum term or VAT treatment, so my annual invoice is unknowable from what is published. 2 9 8
The DevOps Engineer
I found no public price information anywhere in the captured pages — no per-user tier prices, seat minimums, add-ons or minimum terms — only a 14-day free trial, a demo request and the note that SSO Connect is included with the Enterprise tier. A buyer cannot begin to compute an annual invoice from this. 8 9 11
The Skeptic
Not one price figure is captured anywhere: no per-user rate, no tier boundaries, no seat minimum, no add-on — only a 14-day free trial, a demo request and a note that SSO Connect is included with Keeper Enterprise. A buyer cannot compute any annual cost from the public pages we were given, and that makes the invoice a sales conversation. 2 9 8
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in US ⚠ unverified | 0/3 pts | 4 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU optional ⚠ unverified | 1/3 pts | 5 Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 1 Oct 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The terms of use list regional contracting entities, so European customers contract with the Irish entity Keeper Security EMEA Limited and Japanese customers with Keeper Security APAC KK rather than the US parent.
- Weak sourcing — Data residency. The security page frames hosting as a customer choice ('preferred AWS region') and never states a default region, and the truncated 'Available regions' list begins with 'United States (US)', suggesting US hosting unless the EU region is selected.
- Weak sourcing — Subprocessors. AWS is US-headquartered regardless of the server region, though customers may select an EU AWS region and vault contents are zero-knowledge encrypted so Keeper holds only ciphertext.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 30 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (14)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.keepersecurity.com Checked 1 Oct 2026 Details →
- 2 Pricing page www.keepersecurity.com Checked 1 Oct 2026 Details →
- 3 Privacy policy www.keepersecurity.com Checked 1 Oct 2026 Details →
- 4 Terms of service www.keepersecurity.com Checked 1 Oct 2026 Details →
- 5 Encryption model & independent audits — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 6 Encryption model & independent audits — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 7 Sharing, roles & recovery — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 8 Sharing, roles & recovery — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 9 SSO, directory sync & provisioning — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 10 SSO, directory sync & provisioning — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 11 Audit logs, policies & reporting — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 12 Audit logs, policies & reporting — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 13 Hosting choice, offline access & export — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
- 14 Hosting choice, offline access & export — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →