Keeper Security
Primary category: secrets-management. Also listed in identity-access.
One-liner — A zero-knowledge password manager that grew upward into privileged access management and machine secrets — the cheapest credible path from “we use a shared password vault” to something an examiner will accept.
What it does — Three layers on one zero-knowledge vault. Password management for humans (the original business, browser extension and apps). Secrets management for applications and CI/CD, competing with doppler, infisical and the cloud-native stores. KeeperPAM adds the privileged-access layer: session monitoring and recording, access provisioning, remote connection brokering and behavioural analytics — moving it onto cyberark, delinea and beyondtrust ground. In 2026 it extended agentic AI governance into its Endpoint Privilege Manager, i.e. applying privilege policy to AI agents acting on endpoints rather than only to humans.
Naming / provenance — Founded 2011 in Chicago by Darren Guccione and Craig Lurey, both still in place. Single brand throughout.
Ownership & viability — independent and, unusually for this category, still founder-led. Growth equity rather than control: Insight Partners earlier, then a significant minority investment from Summit Partners in 2023 with Len Ferrington joining the board. Summit reports Keeper added ~250 staff since and compounded ARR at roughly 73% over five years. Note this is the investor’s published figure, not an audited one. The practical implication for a buyer: no PE control means less of the renewal-pricing pressure that delinea and beyondtrust carry, but a minority-invested company at this growth rate is an obvious future control-transaction candidate.
Positioning & differentiators —
- Zero-knowledge architecture. Keeper cannot decrypt customer vaults — encryption and decryption happen on the device. For a firm placing every credential it owns with a vendor, this is the single most important architectural property, and it is the right thing to verify rather than assume.
- Price and time-to-value versus the PAM incumbents. A full cyberark deployment is a project; Keeper is a purchase. For a manager with 50–500 staff that needs credential control it can actually finish deploying, this is the practical trade.
- One product spanning human passwords, machine secrets and privileged sessions. Most competitors do one of the three well. The flip side is that KeeperPAM is materially shallower than cyberark on privileged-session control and lacks the depth hashicorp-vault has on dynamic secrets.
- Agentic-AI privilege is a real and early move. Applying privilege policy to non-human agents overlaps non-human-identity; how substantive it is versus a feature announcement is unverified.
Who should choose them / anti-fit — Fits a small-to-mid firm that needs credential hygiene, some privileged-access control, and a defensible answer to a due-diligence questionnaire, without a PAM implementation project. Anti-fit: a large firm with complex privileged-session, jump-host and vaulting requirements (buy cyberark); a platform-engineering team wanting dynamic short-lived secrets and encryption-as-a-service (buy hashicorp-vault).
Known weaknesses / gotchas — PAM depth is well below the incumbents despite the KeeperPAM branding — do not assume feature parity from the category label. Concentration risk is inherent: one vendor holding every credential in the firm is a single point of catastrophic failure regardless of architecture, so the zero-knowledge claim, the breach history, and the recovery process all deserve real diligence.
Deployment & data handling — SaaS (with on-prem options). Encrypted vault data resides with Keeper, but under the zero-knowledge model the vendor holds no key. Confirm the key-management model, the recovery path, and what metadata (vault structure, access times, record titles) is visible to Keeper — that last one is where zero-knowledge claims usually have caveats.
Integrations & partnerships — IdP/SSO (SAML, SCIM), CI/CD secrets injection, SIEM export, MSP tooling. MCP support unverified.
Compliance & FS traction — Unverified in specifics, though Keeper markets FedRAMP and StateRAMP authorisation and SOC 2 / ISO 27001; none independently confirmed here and all should be checked directly given the product’s role.
Commercial — Published per-seat tiers for business plans; enterprise and PAM pricing negotiated. Among the cheapest options in this category.
Open questions
- Confirm certifications directly (FedRAMP, SOC 2 Type II, ISO 27001) — marketed but not verified here.
- What metadata is visible to Keeper under the zero-knowledge model.
- KeeperPAM’s actual session-control depth versus cyberark — feature-by-feature.
- Substance of the agentic-AI privilege governance beyond the announcement.
- Named financial-services customers; breach history.
Sources
- Keeper Security Announces Minority Growth Equity Investment from Summit Partners — fetched 2026-08-26 — supports: ownership structure, board, growth figures; confidence: high (primary, investor)
- Keeper Security Extends Agentic AI Governance to Endpoint Privilege Manager (PR Newswire) — fetched 2026-08-26 — supports: KeeperPAM scope, 2026 agentic-AI direction; confidence: medium (vendor release)
- Cached:
raw/sources/2026-08-26--keeper--ownership-and-pam-expansion.md
History
- [2026-08-26] Page created via wiki-create + researched same day. Found by diffing the live SurveyMonkey instrument against the wiki.