Updated Jun 2026

Keeper Security Review

4.3 / 5Best For: Enterprise and security professionals
Get Now

The short version

Enterprise-focused password manager with secure file storage, BreachWatch dark-web monitoring, and SCIM/SSO for teams.

What we liked

  • FedRAMP High, SOC 2 Type II, ISO 27001 and FIPS 140-3 audits all in place.
  • Admin Console supports SAML SSO, SCIM 2.0 and just-in-time provisioning.
  • Role-based policies, MFA enforcement and full audit logging map to NIST and HIPAA.
  • Offline mode keeps an encrypted local copy of the vault for use without internet.

Could be better

  • BreachWatch dark-web monitoring is a paid add-on, not bundled with subscriptions.
  • Trustpilot reviewers repeatedly flag aggressive auto-renewal practices.
  • The 2017 Project Zero flaw and lawsuit against Ars Technica still colour community trust.
  • Family plan at $84.99 a year sits well above 1Password and Bitwarden equivalents.

Overview

Keeper Security leans hardest on its audit footprint, and the case for it largely lives or dies on that ground. The platform holds FedRAMP High Authorization (December 2025) on top of long-standing FedRAMP Moderate, SOC 2 Type II for more than a decade, SOC 3, ISO 27001, 27017 and 27018, plus FIPS 140-3 validation.

For password managers, that is an unusually deep certification stack, and it is the reason Keeper turns up so often in federal, healthcare and finance procurement shortlists where the buyer has to evidence controls rather than describe them. The administrative model is built around the same audience.

The Admin Console supports SAML SSO with any identity provider, SCIM 2.0 provisioning, Active Directory integration and Just-In-Time user creation with automatic role and node assignment. Role-based access control is granular, MFA enforcement and export restrictions are configurable per role, and the audit log can be aligned with NIST 800-53, HIPAA and SOC 2 reporting needs.

G2's 4.6 out of 5 score across roughly 960 reviews reflects that the controls land in practice, not only on the data sheet. Tom's Guide highlights the offline mode, which stores an encrypted local copy of the vault and keeps the product usable without network access. The trade-offs are mostly commercial.

BreachWatch, Keeper's dark-web monitoring feature, is a paid add-on at $26.99 a year for personal accounts and $53.99 for family, where RoboForm and several others fold breach scanning into the base subscription. The Family plan at $84.99 a year is also steep against 1Password Families at $60 and Bitwarden Families at $40 for six users, and How-To Geek notes there is no clear feature in the bundle that justifies the gap.

Trustpilot reviewers repeatedly flag auto-renewal charges arriving up to three weeks before the renewal date with no obvious in-app toggle, which is the sort of detail that erodes goodwill quickly. The other shadow over Keeper is older but still surfaces in community discussion. In 2017 Tavis Ormandy at Google Project Zero disclosed a browser-extension flaw, and Keeper sued Ars Technica over its coverage before later dropping the case and launching a Bugcrowd disclosure programme.

The technical issue was fixed, but the response to security press damaged trust in some communities in a way the company is still working through. Our read is that Keeper is built for buyers who need an auditable platform with strong administrative controls and are willing to pay for it. Individuals and families optimising for price, or those who want breach monitoring included by default, will find the bundle harder to justify.

Security & Privacy

Password Encryption

Encryption standard for stored passwords

AES-256
Zero-Knowledge Architecture

Provider cannot access your master password

Available
Two-Factor Authentication

Support for 2FA/MFA security

Available
Biometric Login

Support for fingerprint and face recognition

Available
Security Audits

Regular third-party security audits

Available
Dark Web Monitoring

Monitors for compromised passwords

Available
Security Breach Alerts

Notifications when accounts are compromised

Available

Core Functionality

File Attachments

Store encrypted files and documents

Available
Password Generator

Built-in strong password generator

Available
Secure Sharing

Ability to securely share passwords with others

Available
Emergency Access

Grant emergency access to trusted contacts

Available
Password Audit

Checks for weak or reused passwords

Available
Secure Notes

Store encrypted notes and documents

Available
Form Autofill

Auto-fills credit cards and personal info

Available
Password Sharing Permissions

Granular control over shared items

Available
Offline Access

Access passwords without internet

Available
Travel Mode

Temporarily remove sensitive data

Not Available

Platform Compatibility

Cross-Platform Sync

Syncs passwords across all devices

Available
Browser Extensions

Supported web browsers

Chrome,Firefox,Safari,Edge,Brave

Business Model

Customer Support

Available support channels

Email,Live Chat,Phone,Knowledge Base
Free Tier Available

Offers a free tier with basic features

Not Available

Expert Ratings

Related Content

Related Articles

Related Content

Recommended Password Managers

Dashlane

Best for: Security-conscious users
  • Password Encryption
  • Dark Web Monitoring
  • Free Tier Available

Password manager that bundles a VPN, dark-web monitoring, and a passwordless login flow. AES-256, zero-knowledge architecture.

£3.33/month

RoboForm

Best for: Power users and businesses
  • Password Encryption
  • Form Autofill
  • Free Tier Available

Password manager known for handling complex form-filling — long-running product, AES-256, supports unlimited passwords.

£2.50/month
Save up to 33% off