Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Keeper Secrets Manager and Commander platform overview
Keeper Secrets Manager provides your DevOps, IT Security and software development teams with a fully cloud-based, Zero-Knowledge platform for managing all of your infrastructure secrets.
Get Started with Secrets Manager
Keeper Commander is Keeper's feature rich CLI interface to Keeper® Password Manager. Useful for power users, system admins and various automation tasks.
Keeper Security is the leading password security platform to protect your enterprise from password-related data breaches and cyberthreats.
Protects Your Organization Against Ransomware Attacks Keeper protects your organization against ransomware attacks using robust administration, controls and visibility over strong password security and real-time dark web monitoring. Mitigates Risk of Data Breaches Keeper uses a proprietary, zero-knowledge security architecture that supports on-prem, cloud and hybrid-cloud environments for client-side encryption key management.
Bolsters Security and Privacy Each employee gets a private, encrypted vault for storing and managing their passwords, credentials, files and private client data.
Boosts Employee Productivity Reduces help desk costs, saves employees time, reduces frustration and eliminates the need for employees to reuse and remember passwords.
Enables Secure Sharing of Credentials and Secrets Keeper allows IT Admins to enable secure, granular and controlled sharing of credentials, secrets and vaults among employees and teams.
Robust Compliance and Reporting Supports role-based access controls, 2FA, auditing, event reporting and industry compliance with NIST, PCI DSS, SOC 2, ISO 27001, HIPAA, DPA, FINRA and GDPR.
Keeper also helps organizations meet and satisfy Sarbanes-Oxley (SOX) compliance requirements by enforcing internal controls and security safeguards to protect an organization's financial data and digital assets.
Keeper's end-user applications on the Web Vault, Desktop App, Browser Extension and Mobile Apps are built for more than just secrets.
The Keeper Admin Console provides advanced user provisioning, role enforcement policies, SSO integration, SIEM reporting, security scoring and dark web monitoring of secrets.
In addition to protecting all of your DevOps secrets, Keeper protects all of your end-users as a world class Enterprise Password Manager. Keeper can be deployed alongside any Single Sign-On solution such as Microsoft Azure, Okta, Ping, Duo or any other SAML 2.0 compatible identity provider.
Keeper's Security Audit provides insights into the password and secret strength across your infrastructure and end-users.
Keeper supports integration into any 3rd party SIEM solution like Splunk, Azure Sentinel or any other Syslog-compatible solution.
Common terminology that will be referenced throughout this documentation
In order to organize and maintain access to Secrets, Keeper Secrets Manager uses structures called Applications and Clients.
Read below about how each of these items function in Secrets Manager.
Secrets are stored as records in the Keeper Vault and are typically stored as attachments or fields in these records.
Any record or shared folder from the vault can be shared with an Application.
Keeper Secrets Manager Applications are assigned to specific secrets or shared folders. The application is a container of permissions, client devices, audit trail, and history. An application can only decrypt the records assigned.
Keeper recommends implementing the principle of least privilege, ensuring client devices only have access to the records they need. Although the user of the Vault can have unlimited secrets, Keeper recommends sharing up to 500 records per application for optimal performance.
An example of an Application would be a Production Github Actions pipeline or Jenkins server.
A Client device is any endpoint that needs to access secrets associated with an Application. This can be a physical device, virtual device, or cloud-based device. A client device can also be identified by any software application running in the cloud or CI/CD tool.
Each Client device has a unique key to read and access the secrets.
Clients adhere to the following:
One Time Access Tokens used for initialization that expire after 24 hours
IP Address lock (optional)
Access expiration (optional)
An example of a Client Device would be a development machine, Terraform script or a Github Actions instance. At least one client device is required to access secrets that are associated with an Application. Multiple client devices can be associated with the same Application.
A Secrets Manager "Configuration" is a set of tokens that includes encryption keys, client identifiers and destination server information used to authenticate and decrypt data from the Keeper Secrets Manager APIs.
Secrets Manager configurations are created from One Time Access Tokens and have a one to one relationship with client devices.
A configuration can be stored as a text file with JSON, or it can be encoded into a single line string.