Keeper Security

United States · keepersecurity.com · 32 vendors

Keeper Security, Inc. is a global cybersecurity company that provides zero-knowledge security and encryption software. It offers solutions for password and passkey management, secrets management, privileged access management, and secure remote access for individuals and organizations. The company's platform is built on a foundation of zero-trust and zero-knowledge security to protect users and devices from cyber threats.

Resilience scores

Technology vendors

Insights

Last updated 2026-05-05 · revision 8

32 direct vendors, 308 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

Keeper Security's migration readiness is assessed as medium. A significant challenge for migration is the company's extensive and stringent data residency requirements, with operations across multiple global data centers (US, EU, AU, JP, CA) and strict data localization policies. Migrating such an architecture while maintaining compliance with regulations like GDPR (EU data stays in EU) and ensuring geographic isolation would be a highly complex and costly undertaking. The company's robust regulatory compliance (GDPR, HIPAA, SOC2, ISO 27001) is a double-edged sword; while it demonstrates maturity in managing compliance, it also means any migration must meticulously ensure continued adherence to these diverse and demanding standards, adding complexity. A major impediment to a higher migration readiness score is the complete lack of information regarding Keeper Security's internal tech stack (e.g., cloud-native adoption, containerization, microservices architecture). Without this data, it is difficult to assess the inherent flexibility and ease with which their systems could be moved or refactored. Financially, the company's consistent growth and stable revenue indicate a strong position to fund a significant migration effort if required. Regarding vendor relationships, similar to resilience, the 'Total Vendors: 0' is an anomaly. However, with 'Total Services: 38' and 'Vendor Geographic Diversity' across 7 unique countries, it suggests a moderately diverse vendor ecosystem. While the 'Vendor Lock-in Risk' is unknown, a diverse geographic vendor base generally reduces the risk of heavy vendor lock-in compared to a concentrated vendor landscape, offering some flexibility for migration. Overall, while financially capable and possessing a mature compliance framework, the complexity introduced by data residency and the unknown tech stack significantly temper migration readiness.

Compliance

4 in-scope frameworks identified; showing 3.

SOC 2 (source) — Compliant

Keeper has maintained SOC 2 Type 2 compliance for over ten years, demonstrating long-standing commitment to security controls. This is a critical certification for cloud service providers and cybersecurity companies, with regular audits ensuring ongoing compliance.

Evidence: https://www.keepersecurity.com/security.html

HIPAA (source) — Compliant

Keeper explicitly states HIPAA compliance and serves healthcare industry customers. Their zero-knowledge architecture provides strong protection for ePHI. However, they note they are not a Business Associate under HIPAA due to their inability to decrypt customer data, which reduces compliance burden and risk.

Evidence: https://www.keepersecurity.com/security.html, https://www.keepersecurity.com/industries/healthcare/

ISO 27001 (source) — Compliant

Keeper holds ISO 27001, 27017, and 27018 certifications covering information security management, cloud security controls, and data privacy controls. These are internationally recognized standards with regular third-party audits, indicating strong security posture and low compliance risk.

Evidence: https://www.keepersecurity.com/security.html

Financials

Three-year financials

Financial Resilience Score: 7/10

Keeper Security is a mid-stage, Insight Partners-backed private US cybersecurity company with a strong product franchise in password management and a credible, certification-heavy expansion into PAM and federal markets. Qualitative indicators (85,000+ business customers, ~4 million end users, FedRAMP High Authorization, ISO 27001/27017/27018, SOC 2, PCI DSS L1, HIPAA certifications, analyst recognition in Gartner Magic Quadrant for PAM 2025, capital backing from Insight Partners and Summit Partners, multiple international offices) point to a financially healthy and growing business with recurring SaaS subscription revenue across consumer, SMB, enterprise, MSP and federal segments. The company received a majority growth investment of more than US$60 million from Insight Partners in August 2020, and press coverage has historically described Keeper as profitable/cash-generative prior to that investment, although the company has not published audited confirmation. Strategic shift over five years from a consumer/SMB password-manager vendor to an enterprise/public-sector identity & PAM platform is typically associated with rising ACV and revenue. However, no audited revenue, EBIT or equity figures are publicly available, limiting external verifiability. The company faces well-funded competitors including 1Password, Bitwarden, LastPass, Dashlane in passwords and CyberArk, BeyondTrust, Delinea in PAM. Consumer password-manager commoditization from browsers and OS vendors pressures consumer pricing, and cybersecurity event risk remains a material concern for any password-vault product.

Key strengths: Recurring SaaS subscription revenue across consumer, SMB, enterprise, MSP and federal segments, Diversified customer base of 85,000+ business customers and ~4 million end users, Strong investor backing from Insight Partners (>US$30B AUM) and Summit Partners, Government/regulated-market validation with FedRAMP High, GovRAMP High, FIPS 140-3, ISO 27001/27017/27018, SOC 2, PCI DSS L1, HIPAA certifications, Product breadth expansion from password management into higher-ACV PAM and Secrets Management market, Recognized in 2025 Gartner Magic Quadrant for PAM and EMA Overall Leader 2025, Historically described as profitable/cash-generative prior to 2020 Insight investment, 2020 Insight Partners majority growth investment of >US$60M

Risk factors: Opaque financial reporting with no public audited statements, Competitive intensity from 1Password, Bitwarden, LastPass, Dashlane in passwords and CyberArk, BeyondTrust, Delinea in PAM, Consumer password-manager commoditization from browsers (Chrome/Safari/Edge) and OS vendors (Apple iCloud Keychain, Google Password Manager, Microsoft Authenticator), Cybersecurity event risk - breach or vulnerability disclosure could be existentially damaging, Single-investor concentration with Insight Partners as controlling shareholder, FX and regional exposure across EUR/JPY/USD

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report