
Identity & Access Management
KeeperPAM
Cloud-native zero-knowledge PAM unifying password, secrets, connection and privilege management.
KeeperPAM Overview
What it does
KeeperPAM is a cloud-native Privileged Access Management (PAM) platform that secures access to servers, web applications, databases and workloads for human, machine and AI-agent identities. Its distinctive mechanism is a zero-knowledge, zero-trust architecture: encryption and decryption happen at the device and record level, so Keeper's cloud never holds decryption keys. The platform combines enterprise password management, secrets management, connection management, zero-trust network access and remote browser isolation in a single vault interface.
How it works
The Keeper Gateway service deploys into each cloud or on-premises environment and brokers end-to-end encrypted sessions and tunnels to target infrastructure. Keeper Discovery catalogs privileged accounts, machines, databases and identities across local, AWS and Azure environments, and vaulted credentials rotate automatically. Just-in-time access uses ephemeral account provisioning and dynamic role or group elevation, while the Endpoint Privilege Manager agent removes standing admin rights on Windows, macOS and Linux. Sessions are recorded across SSH, RDP, VNC, database and web protocols, KeeperAI monitors privileged activity in real time, terminating suspicious sessions, and events log to Security Information and Event Management (SIEM) platforms.
Credentials and traction
Keeper holds SOC 2 Type II, ISO 27001, ISO 27017 and ISO 27018 certifications, is FedRAMP High and GovRAMP High authorized, PCI DSS certified and uses FIPS 140-3 validated encryption (NIST CMVP certificate #4743). KeeperPAM was recognized in the 2025 Gartner Magic Quadrant for Privileged Access Management. The platform serves more than 93,000 business customers in over 150 countries, spanning enterprises, managed service providers and government agencies.
Key Capabilities
mapped to solution categoriesSecure storage, automated rotation, and auditing of privileged account credentials in a vault.
Time-bound, on-demand granting of privileged access that removes standing privilege.
Creates net-new permissions per need and removes them after a time-bound session, eliminating standing privileged accounts.
Brokering, monitoring, and recording of privileged sessions with the ability to audit and terminate them in real time.
Automated discovery and onboarding of privileged accounts across on-premises and cloud environments.
Analyzes privilege patterns, misconfigurations and access anomalies to detect and respond to privileged threats.
Provides role-based administration and centralized policy management for controlling access to privileged credentials and actions.
Management and rotation of machine and application secrets such as API keys, tokens, and certificates for non-human identities.
Granular elevation of privileges on endpoints and servers based on policy, without granting standing administrative rights.
Brokers secure remote privileged access for third-party and external IT staff such as vendors and service providers.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 26, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.