PrivacyPick
Keeper logo

Keeper

AES-256-GCM, PBKDF2 1M

7.1
out of 10
Visit Keeper →
EncryptionAES-256-GCM, PBKDF2 1M
HostingCloud
Free TierLimited free tier
OwnerKeeper Security, Inc.
Vault 2FAhardware
Passkeysboth
Telemetryopt-out
Open SourceNoSecond-Secret ModelNoBuilt-In Email AliasesNoPast Data BreachNo
WindowsmacOSLinuxAndroidiOSBrowser extensionCLI
Keeper Unlimited (individual, 1-year)
$3.58/mo
Keeper Family (5 users, 1-year)
$7.67/mo

Published September 8, 2026By Juan Martinez

In This Article

Keeper is one of the most heavily marketed password managers, a regular in “best of” roundups, and the rare consumer product with FedRAMP High authorization for its government edition. The cryptographic core is strong — native authenticated encryption, a million PBKDF2 iterations, every field encrypted — and it runs native apps on more platforms than most rivals. What holds it back is trust that has to be taken on the company’s word: the code is closed, no independent cryptography audit has ever been published, and in 2017 Keeper sued a reporter for accurately covering a bug in its software.

Security

Keeper encrypts each vault record on your device with its own 256-bit AES key in GCM mode — a native authenticated cipher, not the older AES-CBC-plus-HMAC that some competitors still ship. Those record keys are wrapped by a per-user Data Key, and the Data Key is wrapped by a key derived from your master password with PBKDF2-HMAC-SHA256 at 1,000,000 iterations — the highest iteration count of any manager in this section. Your master password never leaves the device. Every field is encrypted, not just the password: URLs, titles, notes, custom fields, TOTP secrets and file attachments, so the server cannot see which services you hold accounts with. The offline cache is protected separately with a randomly generated Client Key.

Vault-unlock 2FA is genuinely strong: TOTP apps, plus FIDO2 hardware keys (YubiKey, Google Titan) and passkeys, plus biometric unlock through the platform secure enclave. A passkey can both be stored for websites and used to unlock Keeper itself. In November 2025 Keeper began rolling a hybrid Kyber key-encapsulation layer into its clients, ahead of most of the category on post-quantum work.

Two caveats. There is no “second secret” — no equivalent of the account-level secret key that some managers mix into the vault key, so the security of your vault rests entirely on the strength of your master password against that million-iteration PBKDF2. And PBKDF2, even at a high iteration count, is not memory-hard the way Argon2 is; a well-funded attacker with custom hardware gets more leverage against it than against a memory-hard function. Keeper’s own history also includes a browser-extension flaw that Tavis Ormandy found twice — once in 2016 and again in December 2017 — that let a malicious page pull stored passwords. Both times Keeper patched within 24 hours, and the desktop app was never affected, but a password-disclosure bug reappearing in the same component points to a real process failure.

Privacy & Trust

This is where Keeper costs itself points. The clients are closed source — only the Commander CLI and the Secrets Manager SDK are public — so the encryption model can be read in Keeper’s documentation but not verified against shipping code by anyone outside the company.

More to the point, there is no published independent security audit. Keeper holds a long list of certifications — SOC 2 Type II for over a decade, SOC 3, ISO 27001/27017/27018, FedRAMP High, FIPS 140-3 validated modules — and says third parties including NCC Group run quarterly penetration tests. But certifications attest to process controls, and no pen-test report or cryptography review is published, gated or otherwise. No named cryptographer has put Keeper’s design on the record the way one has for the open and audited managers.

Then there is 2017. After Ars Technica reported on the Ormandy browser-extension bug — a report based on coordinated disclosure, published after Keeper had patched — Keeper sued the publication and its reporter for defamation, seeking removal of the article and damages. The suit was dismissed in March 2018 after an anti-SLAPP response and widespread criticism from the security community, and Keeper subsequently opened a Bugcrowd disclosure program. It is old, and the company’s posture toward researchers has visibly changed since. But suing a journalist over accurate vulnerability reporting is a data point about institutional instincts that the other managers in this section do not carry.

On ownership Keeper is clean: founder-led since 2011 (Darren Guccione and Craig Lurey still run it), headquartered in Chicago, with two minority growth-equity investments — Insight Partners in 2020 and Summit Partners in 2023 — and no majority-stake acquisition. Account recovery is zero-knowledge: a 24-word recovery phrase generated at setup is the only way back into a vault after a lost master password, and Keeper cannot reset it for you. The clients collect adjustable analytics; Keeper does not publish a precise breakdown of what they send, so the reading here is telemetry that is on by default and can be turned off.

Features

The paid product is well stocked. Passkeys are stored, autofilled and shareable. BreachWatch monitors your credentials against dark-web dumps. There is a built-in TOTP generator, one-time time-limited record sharing to non-users, emergency access for family plans, offline access, a password-health dashboard, secure file storage, and KeeperFill for autofill across apps and sites. Native apps cover Windows, macOS and Linux, plus iOS and Android, plus six browser extensions and a CLI.

The gap is email aliasing — Keeper has no built-in alias generator and no integration with an alias service, a privacy feature several competitors now ship. And on the personal plan, BreachWatch is a paid add-on ($26.99/year) rather than an included feature, which is how some rivals bundle equivalent monitoring.

Usability & Platforms

Platform coverage is a real strength: native desktop clients on all three major operating systems — including Linux, which not every manager offers — alongside both mobile platforms and every mainstream browser. Onboarding is straightforward and autofill is generally competent.

Reputation is the soft spot. Keeper’s Trustpilot score sits at 3.2 across several thousand reviews, with persistent complaints about auto-renewal billing that is hard to find or cancel, support that users describe as unresponsive, occasional autofill flakiness, and — the one that matters most for a password manager — difficulty exporting your data after a subscription lapses without paying to renew first. The vault works well day to day; the friction users report clusters around the subscription and the exit.

Price & Value

Keeper Unlimited is $42.99 a year ($3.58/month) and Keeper Family is $91.99 a year ($7.67/month) for five users. That is mid-to-high for an individual plan, and the value proposition is thin for the money: the free tier is capped at one device and ten records, so it functions as a demo rather than a usable option; BreachWatch costs extra on the personal plan; there is no bundled VPN or email aliasing to pad the package. Reviewers consistently land on “expensive for what you get.” The 30-day trial is generous, but once you are paying, Keeper asks a fair amount for a feature set that open and audited alternatives match or beat for less.

Pros

  • AES-256 in GCM mode with per-record keys, and PBKDF2 at 1,000,000 iterations — the highest iteration count in this section
  • Every vault field is encrypted, including URLs, titles, notes and attachments
  • Strong vault-unlock 2FA: FIDO2 hardware keys and passkeys, not just TOTP
  • Native desktop apps on Windows, macOS and Linux, plus iOS, Android, six browser extensions and a CLI
  • Hybrid post-quantum (Kyber) encryption rolling out across clients since late 2025
  • FedRAMP High authorization and long-standing SOC 2 Type II and ISO 27001 certifications
  • Founder-led with a clear ownership history and minority-only outside investment

Cons

  • Closed source, and no independent cryptography audit has ever been published — only certifications and unpublished pen tests
  • In 2017 Keeper sued a publication and reporter for defamation over accurate, coordinated-disclosure vulnerability reporting; the suit was dismissed in 2018
  • A browser-extension password-disclosure bug was found by the same researcher twice, in 2016 and 2017
  • No account-level second secret — vault security rests entirely on the master password against PBKDF2, which is not memory-hard
  • Free tier is capped at one device and ten records; BreachWatch is a paid add-on on the personal plan
  • No built-in email aliasing
  • Trustpilot reviews flag auto-renewal billing friction and difficulty exporting data after a subscription lapses

Our Rating

Category Score Notes
Security 8.0/10 Native AES-256-GCM with per-record keys, PBKDF2 at a million iterations, every field encrypted, and FIDO2 hardware-key vault unlock. Held back by no account-level second secret, a KDF that is not memory-hard, and a browser-extension flaw that recurred in the same component in 2016 and 2017
Privacy & Trust 5.5/10 Zero-knowledge recovery and a clean founder-led ownership history, but the code is closed, no independent cryptography audit has ever been published — only certifications and unpublished pen tests — and Keeper sued a reporter for defamation over accurate vulnerability reporting in 2017
Features 8.5/10 Passkey storage and sharing, BreachWatch dark-web monitoring, built-in TOTP, one-time share, emergency access, secure file storage and broad autofill — a complete paid set, minus email aliasing, with BreachWatch a paid add-on on the personal plan
Usability & Platforms 7.5/10 Native apps on Windows, macOS and Linux plus both mobile platforms and six browser extensions — wider coverage than most rivals — but Trustpilot reviews flag persistent auto-renewal billing friction and difficulty exporting data after a subscription lapses
Price & Value 5.0/10 $42.99/year for the individual plan is mid-to-high, the free tier is a one-device ten-record demo rather than a usable option, and BreachWatch costs extra on the personal plan. The 30-day trial is generous
Overall 7.1/10 Security 30% · Privacy & Trust 25% · Features 20% · Usability 15% · Price 10%

Keeper is a technically sound manager with a strong cryptographic core, unusually broad platform support, and government-grade certifications. If you are inside its ecosystem with a strong master password, it protects your vault well. What keeps it out of the top tier is trust you have to extend rather than verify: closed source, no published audit anyone outside the company can read, a thin value proposition at the price, and a 2017 lawsuit against a journalist that the open, audited alternatives give you no reason to overlook.

Rating: 7.1/10

Ready to try Keeper?

Visit Keeper →

Last updated: September 8, 2026By Juan Martinez