Keeper (password Manager)
   HOME

TheInfoList



OR:

Keeper Security, Inc. (Keeper) is a leading provider of zero-knowledge security and
encryption software Encryption software is software that uses cryptography to prevent unauthorized access to digital information. Cryptography is used to protect digital information on computers as well as the digital information that is sent to other computers over t ...
covering
password management There are several forms of software used to help users or organizations better manage passwords: * Intended for use by a single user: ** Password manager software is used by individuals to organize and encrypt many personal passwords using a singl ...
, secrets management, connection management,
dark web The dark web is the World Wide Web content that exists on ''darknets'': overlay networks that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communi ...
monitoring, digital file storage, encrypted messaging and more.   Keeper holds SOC 2 type 2 and ISO27001 certifications in the industry, and is
FIPS 140-2 The Federal Information Processing Standard Publication 140-2, (FIPS PUB 140-2), is a U.S. government computer security standard used to approve cryptographic modules. The title is ''Security Requirements for Cryptographic Modules''. Initial publ ...
,
FedRAMP The Federal Risk and Authorization Management Program (FedRAMP) is a United States federal government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and servi ...
and StateRAMP Authorized.


Keeper Password Manager

Keeper
password manager A password manager is a computer program that allows users to store and manage their passwords for local applications and online services. In many cases software used to manage passwords allow also generate strong passwords and fill forms. Pas ...
uses a
freemium Freemium, a portmanteau of the words "free" and "premium," is a pricing strategy by which a basic product or service is provided free of charge, but money (a premium) is charged for additional features, services, or virtual (online) or physical (o ...
pricing model for individual consumers and a subscription-based model for households and businesses. The free individual version of Keeper offers storage for passwords, identity data, and financial information, and includes a password generator and two-factor authentication (2FA) on a single mobile device. The subscription-based model for individual consumers offers additional features, such as unlimited password, identity data, and financial data storage across an unlimited number of devices, cross-device syncing, and record-sharing capabilities. Keeper’s “Family” plans extend these features to up to five people in a household. Keeper also offers a variety of add-ons at additional cost, including: * BreachWatch, a tool that monitors the
Dark Web The dark web is the World Wide Web content that exists on ''darknets'': overlay networks that use the Internet but require specific software, configurations, or authorization to access. Through the dark web, private computer networks can communi ...
for stolen passwords and notifies users if their credentials are found. * KeeperChat, a secure messaging application. KeeperChat is free for individuals and sold on a subscription basis to businesses. * Keeper Secure File Storage, which enables users to store confidential files, photos, and videos in their Keeper Vaults. Keeper is available as a mobile app for Android and
iOS iOS (formerly iPhone OS) is a mobile operating system created and developed by Apple Inc. exclusively for its hardware. It is the operating system that powers many of the company's mobile devices, including the iPhone; the term also includes ...
, as well as a desktop application for
Windows Windows is a group of several proprietary graphical operating system families developed and marketed by Microsoft. Each family caters to a certain sector of the computing industry. For example, Windows NT for consumers, Windows Server for serv ...
,
Linux Linux ( or ) is a family of open-source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically packaged as a Linux distribution, which ...
, and
MacOS macOS (; previously OS X and originally Mac OS X) is a Unix operating system developed and marketed by Apple Inc. since 2001. It is the primary operating system for Apple's Mac computers. Within the market of desktop and lapt ...
. It also offers a desktop browser extension for
Safari A safari (; ) is an overland journey to observe wild animals, especially in eastern or southern Africa. The so-called "Big Five" game animals of Africa – lion, leopard, rhinoceros, elephant, and Cape buffalo – particularly form an importa ...
, Chrome,
Firefox Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation. It uses the Gecko rendering engine to display web pages, which implements current and ...
,
Edge Edge or EDGE may refer to: Technology Computing * Edge computing, a network load-balancing system * Edge device, an entry point to a computer network * Adobe Edge, a graphical development application * Microsoft Edge, a web browser developed by ...
,
Internet Explorer Internet Explorer (formerly Microsoft Internet Explorer and Windows Internet Explorer, commonly abbreviated IE or MSIE) is a series of graphical user interface, graphical web browsers developed by Microsoft which was used in the Microsoft Wind ...
,
Opera Opera is a form of theatre in which music is a fundamental component and dramatic roles are taken by singers. Such a "work" (the literal translation of the Italian word "opera") is typically a collaboration between a composer and a librett ...
, and Brave. The mobile app, desktop app, and browser extension can generate random passwords for new website and app accounts and fill in existing apps and accounts automatically. Users secure their Keeper vaults with a “master password.” Users can further protect their Keeper vaults via a variety of
multi-factor authentication Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
methods, including
Google Authenticator Google Authenticator is a software-based authenticator by Google that implements two-step verification services using the Time-based One-time Password Algorithm (TOTP; specified in RFC 6238) and HMAC-based One-time Password algorithm (HOTP; spec ...
, Duo Security, FIDO U2F, and
biometrics Biometrics are body measurements and calculations related to human characteristics. Biometric authentication (or realistic authentication) is used in computer science as a form of identification and access control. It is also used to identify in ...
. Keeper utilizes a zero-knowledge and zero-trust security architecture, where encryption of user passwords and other data is performed locally on the user’s device. Customer vaults are secured using an AES-256 key, which is derived from the user’s master password using
PBKDF2 In cryptography, PBKDF1 and PBKDF2 (Password-Based Key Derivation Function 1 and 2) are key derivation functions with a sliding computational cost, used to reduce vulnerabilities of brute-force attacks. PBKDF2 is part of RSA Laboratories' Publ ...
. Only encrypted
ciphertext In cryptography, ciphertext or cyphertext is the result of encryption performed on plaintext using an algorithm, called a cipher. Ciphertext is also known as encrypted or encoded information because it contains a form of the original plaintext ...
is stored on Keeper’s servers, and Keeper has no way of decrypting the data its customers store in their digital vaults, nor can it retrieve their master passwords. Keeper users can directly share passwords, files, and other information “vault to vault” with other Keeper users; all shared content is secured with PKI encryption. Additionally, Keeper's One-Time Share feature enables its users to securely share passwords and other confidential information with anyone on a time-limited basis, even if the recipient does not have a Keeper account. All One-Time Shares are secured using zero-knowledge encryption; record data is decrypted locally, on the recipient's device, using 256-bit AES, and all server requests are signed with
elliptic-curve cryptography Elliptic-curve cryptography (ECC) is an approach to public-key cryptography based on the algebraic structure of elliptic curves over finite fields. ECC allows smaller keys compared to non-EC cryptography (based on plain Galois fields) to provide e ...
(ECDSA).


Keeper's Solutions for Business and Enterprise

Keeper offers a suite of
cybersecurity Computer security, cybersecurity (cyber security), or information technology security (IT security) is the protection of computer systems and networks from attack by malicious actors that may result in unauthorized information disclosure, the ...
products for commercial use, all of which integrate with each other, including: * Keeper's enterprise password manager, which offers the same features as Keeper's consumer product, plus additional tools that are specific to organizations, including
multi-tenant Software multitenancy is a software architecture in which a single instance of software runs on a server and serves multiple tenants. Systems designed in such manner are "shared" (rather than "dedicated" or "isolated"). A tenant is a group of us ...
password management, user
provisioning In telecommunication, provisioning involves the process of preparing and equipping a network to allow it to provide new services to its users. In National Security/Emergency Preparedness telecommunications services, ''"provisioning"'' equates to ...
, auditing, reporting,
Active Directory Active Directory (AD) is a directory service developed by Microsoft for Windows domain networks. It is included in most Windows Server operating systems as a set of processes and services. Initially, Active Directory was used only for centralize ...
integration, and delegated administration, all of which are accessed through a centralized administration console. * Keeper Secrets Manager, which stores confidential data related to
IT infrastructure Information technology infrastructure is defined broadly as a set of information technology (IT) components that are the foundation of an IT service; typically physical components (computer and networking hardware and facilities), but also variou ...
, such as API keys, certificates, database passwords, privileged credentials, and access keys. * Keeper Connection Manager, an agentless remote desktop gateway that enables IT Admins and DevOps teams to securely access RDP, SSH, MySQL and Kubernetes endpoints through a web browser. Keeper Connection Manager is built on top of the
open-source Open source is source code that is made freely available for possible modification and redistribution. Products include permission to use the source code, design documents, or content of the product. The open-source model is a decentralized sof ...
gateway
Apache Guacamole Apache Guacamole is a free and open-source, cross-platform, clientless remote desktop gateway maintained by the Apache Software Foundation. It allows users to control remote computers or virtual machines via a web browser, and allows administra ...
. Business customers can also access a variety of add-on products, including: * Commercial-grade versions of BreachWatch, KeeperChat, and Secure File Storage. * Keeper Compliance Reports, which gives Keeper Administrators visibility into access permissions of records and credentials across their organizations. Administrators can also run reports on-demand and forward them to automated compliance systems, or send them directly to external auditors. * Keeper's Advanced Reporting and Alerts Module (ARAM), which provides advanced event logging to meet compliance requirements. ARAM can track over 100 event types, generate custom reports, send alert notifications via email and SMS, and feed alert data into security information and event management (SIEM) systems. * Keeper SSO Connect, a
SAML 2.0 Security Assertion Markup Language 2.0 (SAML 2.0) is a version of the SAML standard for exchanging authentication and authorization identities between security domains. SAML 2.0 is an XML-based protocol that uses security tokens conta ...
SaaS Software as a service (SaaS ) is a software licensing and delivery model in which software is licensed on a subscription basis and is centrally hosted. SaaS is also known as "on-demand software" and Web-based/Web-hosted software. SaaS is cons ...
solution that enables businesses to integrate their existing single sign-on (SSO) deployments with Keeper’s password management platform.


Keeper Security Government Cloud

Keeper Security is listed as Authorized on the FedRAMP Marketplace at the Moderate impact level, with an authorization date of 8/23/2022. Keeper Security Government Cloud (KSGC) is designed specifically for U.S. federal, state, and municipal government agencies and supports compliance with the United States International Traffic in Arms Regulations (ITAR). Keeper Security Government Cloud obtained StateRAMP Authorization at the Moderate Impact Level with an authorization date of 11/30/2022. The nationwide StateRAMP cybersecurity verification program promotes the adoption of secure cloud services across state and local governments by providing a standardized approach to security and risk assessment for cloud technologies.


History

In 2009, Craig Lurey developed the original Keeper app while on a long business flight to China with Darren Guccione. In 2011, Lurey and Guccione officially co-founded Keeper Security, Inc. As of March 2022, Keeper had offices located in Chicago (Headquarters), California (Software Development), Ireland (EMEA Business Sales) and the Philippines (International Customer Support). In October 2019, Keeper launched KeeperMSP, a password management platform designed specifically for managed service providers (MSPs), managed security service providers (MSSPs), and their customers. In August 2020, Keeper received a $60 million minority investment from
venture capital Venture capital (often abbreviated as VC) is a form of private equity financing that is provided by venture capital firms or funds to startups, early-stage, and emerging companies that have been deemed to have high growth potential or which ha ...
firm
Insight Partners Insight Partners (previously Insight Venture Partners) is an American venture capital and private equity firm based in New York City. The firm invests in growth-stage technology, software and Internet businesses. History Insight Partners was fo ...
. In March 2021, Keeper launched Keeper SSO Connect. In May 2021, Keeper was listed on the U.S. federal government’s FedRAMP Marketplace as a “CSP in Process.” In January 2022, Keeper announced the launch of Keeper Secrets Manager. In February 2022, Keeper acquired remote access gateway company Glyptodon Inc., creator of Glyptodon Enterprise and Apache Guacamole, and commenced integrating Glyptodon Enterprise into its product suite. In May 2022, Keeper launched Keeper Connection Manager, a rebranding and revamping of Glyptodon Enterprise into a commercial-grade remote desktop gateway with expanded capabilities, advanced integrations, and ongoing feature development. In August 2022, Keeper Security became Authorized on the FedRAMP Marketplace at the Moderate impact level, with an authorization date of 8/23/2022. In November 2022, Keeper Security Government Cloud obtained StateRAMP Authorization at the Moderate Impact Level with an authorization date of 11/30/2022.


Reception

PC World ''PC World'' (stylized as PCWorld) is a global computer magazine published monthly by IDG. Since 2013, it has been an online only publication. It offers advice on various aspects of PCs and related items, the Internet, and other personal tech ...
named Keeper an Editor's Choice in 2019 and Most Security-Minded Password Manager in 2022.
PCMag ''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and have continued to the present d ...
named Keeper “Best Password Manager for Businesses" (2022), as well as Best Password Manager and Editors' Choice for the previous three consecutive years. Tom’s Guide named Keeper one of the best password managers of 2022. U.S. News & World Report’s 360 Reviews team named Keeper Best Overall Password Manager of 2021. Keeper is the recipient of multiple InfoSec Awards, which are sponsored by Cyber Defense Magazine and handed out annually at the
RSA Conference The RSA Conference is a series of IT security conferences. Approximately 45,000 people attend one of the conferences each year. It was founded in 1991 as a small cryptography conference. RSA conferences take place in the United States, Europe, Asia ...
:


Patents

Keeper holds the following patents through the
United States Patent & Trademark Office The United States Patent and Trademark Office (USPTO) is an agency in the U.S. Department of Commerce that serves as the national patent office and trademark registration authority for the United States. The USPTO's headquarters are in Alexa ...
:


Incidents

In December 2017, Keeper was bundled with Windows 10 by Microsoft. Google security researcher
Tavis Ormandy Tavis Ormandy is an English computer security white hat hacker. He is currently employed by Google as part of their Project Zero team. Notable discoveries Ormandy is credited with discovering severe vulnerabilities in LibTIFF, Sophos' antiviru ...
disclosed that the software recommended installing a browser addon which contained a vulnerability allowing any malicious website to steal any password. A nearly identical vulnerability was already previously discovered and disclosed to Keeper in 2016. Within 24 hours, the company issued a patch. Days later, the company that makes Keeper sued
Ars Technica ''Ars Technica'' is a website covering news and opinions in technology, science, politics, and society, created by Ken Fisher and Jon Stokes in 1998. It publishes news, reviews, and guides on issues such as computer hardware and software, sci ...
, claiming their article was defamatory and misleading. The lawsuit was dismissed on March 30, 2018, and Ars Technica added further clarifications to the article. Following the lawsuit, Keeper launched a public vulnerability disclosure program in partnership with
Bugcrowd Bugcrowd is a crowdsourced security platform. It was founded in 2011 and in 2019 it was one of the largest bug bounty and vulnerability disclosure companies on the internet. In March 2018 it secured $26 million in a Series C funding round le ...
.


See also

*
List of password managers The list below includes the names of notable password managers with dedicated Wikipedia articles. Summary information Features See also * Password manager * Password fatigue Password fatigue is the feeling experienced by many people who ...
*
Cryptography Cryptography, or cryptology (from grc, , translit=kryptós "hidden, secret"; and ''graphein'', "to write", or ''-logia'', "study", respectively), is the practice and study of techniques for secure communication in the presence of adver ...


References


External links


Official website
{{Password managers Password managers