Security Stack Logo
KeeperPAM logo

Identity & Access Management

KeeperPAM

Cloud-native zero-knowledge PAM unifying password, secrets, connection and privilege management.

Privileged Access Management (PAM)

KeeperPAM Overview

What it does

KeeperPAM is a cloud-native Privileged Access Management (PAM) platform that secures access to servers, web applications, databases and workloads for human, machine and AI-agent identities. Its distinctive mechanism is a zero-knowledge, zero-trust architecture: encryption and decryption happen at the device and record level, so Keeper's cloud never holds decryption keys. The platform combines enterprise password management, secrets management, connection management, zero-trust network access and remote browser isolation in a single vault interface.

How it works

The Keeper Gateway service deploys into each cloud or on-premises environment and brokers end-to-end encrypted sessions and tunnels to target infrastructure. Keeper Discovery catalogs privileged accounts, machines, databases and identities across local, AWS and Azure environments, and vaulted credentials rotate automatically. Just-in-time access uses ephemeral account provisioning and dynamic role or group elevation, while the Endpoint Privilege Manager agent removes standing admin rights on Windows, macOS and Linux. Sessions are recorded across SSH, RDP, VNC, database and web protocols, KeeperAI monitors privileged activity in real time, terminating suspicious sessions, and events log to Security Information and Event Management (SIEM) platforms.

Credentials and traction

Keeper holds SOC 2 Type II, ISO 27001, ISO 27017 and ISO 27018 certifications, is FedRAMP High and GovRAMP High authorized, PCI DSS certified and uses FIPS 140-3 validated encryption (NIST CMVP certificate #4743). KeeperPAM was recognized in the 2025 Gartner Magic Quadrant for Privileged Access Management. The platform serves more than 93,000 business customers in over 150 countries, spanning enterprises, managed service providers and government agencies.

Key Capabilities

mapped to solution categories
Privileged Access Management (PAM)

Secure storage, automated rotation, and auditing of privileged account credentials in a vault.

Time-bound, on-demand granting of privileged access that removes standing privilege.

Creates net-new permissions per need and removes them after a time-bound session, eliminating standing privileged accounts.

Brokering, monitoring, and recording of privileged sessions with the ability to audit and terminate them in real time.

Automated discovery and onboarding of privileged accounts across on-premises and cloud environments.

Analyzes privilege patterns, misconfigurations and access anomalies to detect and respond to privileged threats.

Provides role-based administration and centralized policy management for controlling access to privileged credentials and actions.

Management and rotation of machine and application secrets such as API keys, tokens, and certificates for non-human identities.

Granular elevation of privileges on endpoints and servers based on policy, without granting standing administrative rights.

Brokers secure remote privileged access for third-party and external IT staff such as vendors and service providers.

Compliance

certifications
CCPAFedRAMP HighFIPS 140-3GDPRGovRAMPHIPAAISO 27001ISO 27017ISO 27018PCI DSSSOC 2 Type IITX-RAMP

Integrations

compatible tools
AnsibleAWSAzure DevOpsConductorOneDuoGitHub ActionsGitLabGoogle WorkspaceJenkinsJiraJumpCloudLumosMicrosoft AzureMicrosoft Entra IDOktaOneLoginPing IdentitySailPointSaviyntServiceNowSplunkTenableTerraformWizYubiKey

Implementation & support

Deployment model
Browser ExtensionEndpoint AgentOn-PremisesSaaS
Pricing structure
Custom / EnterpriseFree TrialSubscription
Support channels
24/7 SupportDocumentationLive ChatPhone SupportTicketing PortalTraining / Academy

Info last updated on July 26, 2026

Vendors

Is this your product?

Claim your profile to connect with the teams looking for your solutions.

Security Stack Logo

The curated research platform for enterprise cybersecurity solutions.

All product and company names, logos, and brands are property of their respective owners and are used on this website for identification purposes only. Security Stack does not endorse any vendor, product, or service listed, and makes no warranties, express or implied, as to the accuracy or completeness of this content, including any warranties of merchantability or fitness for a particular purpose.

© 2026 Security Stack. All rights reserved.