whats-best.ai

Password Management

Keeper

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 3 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Keeper Security, Inc. · www.keepersecurity.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Compliance Auditor

Weighted verdict

Prepares the ISO 27001 and NIS2 evidence and has to show who could see the firewall admin password last March. Wants event logs that cover views and copies, export to the SIEM, enforceable policies, and the contracting entity, hosting and subprocessors named.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Compliance Auditor

Encryption model & independent audits

How this is scored

What the vendor can prove about its security design: end-to-end encryption with named algorithms and key derivation, which fields are encrypted on the device and which are not, independent audits and penetration tests with published results, a bug bounty, and incident history disclosed.

0 — Security described in adjectives ("bank-grade", "military encryption") with no architecture, no audit and no statement of what the vendor can read.

3 — Encryption algorithms named and "zero knowledge" claimed, but no whitepaper, no statement of which fields stay unencrypted, and audits mentioned without dates, auditors or results.

5 — A published security whitepaper naming algorithms, key derivation and the client-side encryption model, a stated list of what is and is not encrypted (including URLs and metadata), and a named independent audit or certification (ISO 27001, SOC 2) with its date.

8 — Recurring independent penetration tests or code audits with reports or summaries published, a public bug bounty or vulnerability disclosure policy, past security incidents documented with their impact, and open-source clients or cryptography that can be reviewed.

10 — The design is verifiable end to end: full source or cryptographic design public, every field encrypted client-side including metadata, audits by named firms repeated yearly with full reports, a threat model that states what a compromise of the vendor's servers would expose, and incident post-mortems published.

Report an error

The Compliance Auditor

The security pages go beyond adjectives: AES-256 and elliptic-curve cryptography are named, key derivation is stated as PBKDF2 with 1,000,000 iterations, and the encrypted-field list explicitly covers URLs, custom fields, file attachments and TOTP codes. Periodic penetration tests by named firms, a Bugcrowd-managed bounty, a public disclosure programme and annual ISO 27001 audits are all on the record — but we found no public information on published test reports or summaries, on past security incidents and their impact, or on open-source clients or cryptography for review. 5 6 12 1 3

Report an error

Sharing, roles & recovery

How this is scored

How credentials are shared and governed across a company: shared vaults or collections, role-based permissions, view-only and time-limited access, admin account recovery, emergency access, and what happens to shared items when an employee leaves.

0 — Personal vaults only, or sharing by sending a password to another user with no permissions and no record.

3 — Shared folders with all-or-nothing access, no roles, and no stated process for recovering an account or reclaiming credentials from a departing employee.

5 — Shared vaults or collections with read, edit and manage permissions, groups and admin roles, an admin recovery mechanism documented with its key model, and offboarding that transfers a leaver's shared items.

8 — Granular permissions down to hiding the password while allowing autofill, time-limited and one-time sharing with external parties, emergency access with a waiting period, delegated administration per team or location, and approval workflows for sensitive items.

10 — Access is governed and provable: least-privilege defaults, recovery and emergency access designed so the vendor never holds a key and stated so, periodic access reviews supported in the product, and every grant, change and revocation attributable to a person.

Report an error

The Compliance Auditor

Sharing is governed rather than merely possible: persistent, time-limited and self-destructing shares, one-time shares to people without a Keeper account, delegated administration scoped to a node, approval workflows for eligible-team access, over eighty permissions across fourteen categories, and offboarding that locks the vault and transfers ownership while keeping zero knowledge, with the most restrictive policy applied by default. A 24-word BIP39 recovery phrase with 2FA and email verification, which companies can disable by policy, covers recovery. We found no public information on emergency access with a waiting period or on hiding the password while still allowing autofill. 7 8 6 5

Report an error

SSO, directory sync & provisioning

How this is scored

How the vault fits into the company's identity stack: SSO with Entra ID, Okta or Google, and the key model behind an SSO unlock; SCIM or directory sync for joiners and leavers; MFA options including hardware keys; and passkey support for users and the vault itself.

0 — Each user creates an account by email; no SSO, no directory sync and no MFA beyond an app code.

3 — SSO available only to sign in to the admin console or on the top tier with no description of how the vault is then decrypted, and users provisioned by CSV invite.

5 — SSO with named identity providers (Entra ID, Okta, Google) documented with how the vault key is derived or released, SCIM or directory sync for provisioning and deprovisioning, and MFA including FIDO2 or hardware keys.

8 — SSO unlock designed so the vendor cannot derive the vault key and stated so, group sync driving vault permissions, automated suspension on deprovisioning, conditional access or device policies, and passkeys stored and used across platforms.

10 — Identity is integrated without trust shortcuts: the SSO key model published and independently reviewed, deprovisioning that revokes vault access and shared items immediately with a log entry, passwordless vault unlock with passkeys, and support for the customer's own key-management or trusted-device approval.

Report an error

The Compliance Auditor

The SSO story is documented down to the key model: SAML 2.0 with a long list of named providers, the data key decrypted with a device private key and an ECC-256 key after identity-provider authentication, SCIM provisioning and deprovisioning, directory mapping driving vault access, conditional-access compatibility, and FIDO2 hardware keys alongside passkeys stored and autofilled across platforms. Biometric passkey login that replaces both master password and SSO is even claimed. We found no public information on an independent review of the SSO key model or on deprovisioning that revokes shared items immediately with a log entry. 9 6 5 10 12

Report an error

Audit logs, policies & reporting

How this is scored

What an administrator and an auditor can see and enforce: event logs of access and changes, password health and breach reports, enforceable policies (master password, MFA, sharing, export), SIEM integration, and reports an ISO 27001 or NIS2 audit can use.

0 — No audit log and no admin policies; the administrator sees a user list.

3 — A basic activity list and a password-strength score, but no exportable log, no enforceable policies, and no record of who viewed or copied a shared credential.

5 — Event logs covering logins, item access, sharing and admin changes, exportable or available through an API, enforceable policies for master password and MFA, and password health and breach-monitoring reports.

8 — Native SIEM integration with named targets (Splunk, Microsoft Sentinel, Elastic or syslog), policies for sharing, export and browser-extension behaviour, log retention stated, and compliance reports aligned to ISO 27001, NIS2 or BSI IT-Grundschutz.

10 — Auditability is complete: every view, copy, autofill and permission change logged with user and device, logs tamper-evident and retained for a configurable period, alerting on anomalous access, and an auditor role that can read logs without access to secrets.

Report an error

The Compliance Auditor

For my ISO 27001 file this is the strongest page set: audit logs for authentication events, credential access, sharing actions and administrative changes, exportable in PDF, JSON or CSV or via a scriptable CLI into SIEM platforms, role policies enforcing 2FA plus sharing and export rules, a dedicated ISO 27001 control mapping, anomaly flagging, and segregation of duties so security administrators see policies without vault contents. But the captured pages give no named SIEM targets such as Splunk or Sentinel, no stated log retention period, and we found no public information that copies or autofill events are individually logged or that logs are tamper-evident — so who copied the firewall password last March stays partly unanswered. 12 8 11 7

Report an error

Hosting choice, offline access & export

How this is scored

Where and how the vault runs and how the data leaves it: cloud region choice, a self-hosted or on-premises option, offline access during a vendor outage, client coverage across operating systems and browsers, and a complete, documented export and import path.

0 — Cloud only in an unstated region, no offline access, and no export or an export that drops attachments and shared items.

3 — Cloud with a region named, apps for common platforms, and an export in CSV only that leaves out attachments, folders, TOTP seeds or custom fields.

5 — An EU region or self-hosted option, offline read access on desktop and mobile, clients for Windows, macOS, Linux, iOS, Android and the major browsers, and an export that covers all item types including attachments.

8 — Both EU cloud and self-hosted or on-premises deployment documented, a status page with incident history, encrypted full-fidelity export and import from named competitors, and vault access continuing during an outage of the vendor's service.

10 — The customer can run and leave the vault on their own terms: self-hosting with documented high availability and backup, an open or documented export format that preserves structure, permissions and history, and a stated procedure for continued access if the vendor ends the service.

Report an error

The Compliance Auditor

The EU is one of six selectable AWS regions with isolation at rest and in transit, and offline mode is unusually well evidenced: an encrypted device-local vault copy, access without internet or identity provider, admin-controlled durations, per-role toggles and resync on reconnect. Export exists and Keeper states it cannot decrypt the data, but we found no public information on which item types and attachments the export covers, on import from named competitors, or on self-hosting of the vault itself beyond on-premises SSO and gateway components; client coverage is claimed generically with no enumerated platform list. 6 14 3 5 4

Report an error

European sovereignty

How this is scored

Who the contracting entity and the parent company are, where vault data and metadata are hosted, and who the subprocessors are. Independently sourced by the sovereignty pipeline; end-to-end encryption narrows what a foreign authority could compel, but metadata, logs and the update channel for the client software remain in the vendor's hands, so the chain still counts.

0 — Non-EU vendor and contracting entity, hosting unstated, and subprocessors unnamed.

3 — An EU data region offered while the contracting entity and parent are non-EU without a stated safeguard, or the subprocessor list is absent.

5 — EU hosting as standard or selectable and an EU contracting entity, but the parent company or parts of the chain (support, analytics, email, client distribution) are non-EU.

8 — EU hosting on named infrastructure, EU contracting entity, subprocessor list published with locations, a DPA covering vault metadata and logs, and a self-hosted option that removes the vendor from the data path.

10 — Sovereign end to end and evidenced: European ownership, entity, hosting and every subprocessor, certifications published (ISO 27001, BSI C5 or equivalent), and source code or builds verifiable so the client update channel is not a blind trust in the vendor.

Report an error

The Compliance Auditor

European customers contract with Keeper Security EMEA Limited in Cork under Irish law with the Irish Data Protection Commission as supervisory authority, and can select an EU AWS region — but the parent is the Chicago company, the security pages leave a default region unstated with the regions list beginning with the United States, and transfers rest primarily on the EU-US data privacy framework rather than European safeguards. We found no public subprocessor list naming locations; only AWS appears as hosting provider, and it is US-headquartered regardless of server region. 4 3 5 1 6

Report an error

Pricing transparency

How this is scored

Whether a buyer can compute the real annual cost from public pages alone: price per user and tier, which features (SSO, SCIM, SIEM, self-hosting) sit in which tier, minimum seats, add-ons, and the minimum term.

0 — No public prices at all; every tier is a sales conversation.

3 — A starting price exists, but which business features (SSO, SCIM, audit logs) sit in which tier is unclear — the invoice is unknowable.

5 — Per-user tier prices public with the main features per tier, but at least one commonly needed piece (SSO, SIEM integration, self-hosting, minimum seats) is unpriced or "on request".

8 — Every tier priced publicly with its feature set and seat minimum, add-on prices listed, self-hosted licensing stated, minimum term and VAT treatment given.

10 — Complete price computability: annual invoice derivable for a given number of users, with every add-on, self-hosting licence, support level and renewal condition published.

Report an error

The Compliance Auditor

A pricing page was captured, yet no per-user price, tier price, seat minimum, minimum term or VAT treatment appears in any of the captured pages — the only public commercial facts are a 14-day free trial, a demo request and a note that SSO Connect is included with Keeper Enterprise. Without figures I cannot compute an annual invoice from public pages, and we found no public information on where SCIM or SIEM integration sit priced. 2 9 8 11

Report an error

European sovereignty — proven facts

3 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency EU optional ⚠ unverified 1/3 pts 5 Report an error
Subprocessors US CLOUD Act reach ⚠ unverified 0/2 pts 3 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.keepersecurity.com Checked 1 Oct 2026 Details →
  2. 2 Pricing page www.keepersecurity.com Checked 1 Oct 2026 Details →
  3. 3 Privacy policy www.keepersecurity.com Checked 1 Oct 2026 Details →
  4. 4 Terms of service www.keepersecurity.com Checked 1 Oct 2026 Details →
  5. 5 Encryption model & independent audits — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  6. 6 Encryption model & independent audits — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  7. 7 Sharing, roles & recovery — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  8. 8 Sharing, roles & recovery — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  9. 9 SSO, directory sync & provisioning — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  10. 10 SSO, directory sync & provisioning — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  11. 11 Audit logs, policies & reporting — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  12. 12 Audit logs, policies & reporting — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  13. 13 Hosting choice, offline access & export — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →
  14. 14 Hosting choice, offline access & export — found from sitemap www.keepersecurity.com Checked 1 Oct 2026 Details →