For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cloud Security

Closed-loop remediation for CNAPP findings with KeeperPAM.

Overview

Keeper Cloud Security turns cloud security findings into privileged access remediation. It helps teams move from detection to action with credential rotation, JIT access, and managed onboarding. It is built on Keeper's zero-knowledge model.

Why Keeper built it

CNAPP platforms are strong at finding risk. They do not remediate identity exposure by themselves. Teams still need to rotate credentials, restrict access, and bring unmanaged resources under control.

Keeper Cloud Security closes that gap. It brings findings into Keeper, maps them to identities and infrastructure, and turns them into remediations you can track.

Why the integration matters

  • Send findings from your CNAPP directly into Keeper.

  • Resolve issues with rotation, JIT access, or managed onboarding.

  • Keep remediation status aligned between both systems.

How Keeper Encrypter fits

Keeper does not decrypt customer data in the cloud. Cloud Security integrations still need a secure way to receive findings and return status updates. Keeper Encrypter provides that bridge.

Keeper Encrypter is a self-hosted Docker service. It runs in your environment. It receives CNAPP webhooks and encrypts integration traffic between Keeper and the provider. The encryption key stays under your control in your vault.

The service uses Keeper Secrets Manager device configuration and the CNAPP configuration record to authenticate and retrieve the settings it needs. This keeps the integration aligned with Keeper's zero-knowledge architecture.

For deployment details, see Keeper Encrypter.

Available Integrations

  • Wiz

  • More providers are coming soon.

Prerequisites

Keeper Cloud Security is part of the KeeperPAM platform for customers with an active KeeperPAM subscription.

To enable it:

  • Create or select a PAM Configuration.

  • Choose your CNAPP provider in Secrets Manager → PAM Configuration.

  • Deploy Keeper Encrypter for the provider workflow.

What you can do with a finding

  • Rotate exposed or stale credentials.

  • Apply Just-In-Time (JIT) access and approval workflows.

  • Onboard users, machines, and databases as managed KeeperPAM resources.

You can also standardize access after onboarding with Connections and Tunnels.

Vault Interface

After you select a CNAPP provider, Cloud Security appears in the Keeper Vault. From this screen, an admin can review a finding, open it in the provider, ignore it, delete it, or start remediation.

Cloud Security with CNAPP Provider Integration

Resolve a finding

1

Review the finding

Open the finding from the Cloud Security dashboard. Use the provider link if you need more context before remediation.

2

Map the affected resource

To remediate the finding, onboard the identity or machine as a KeeperPAM resource. You can also map the finding to an existing KeeperPAM resource.

3

Run remediation

Choose the best control for the issue:

4

Return status to the provider

After remediation, Keeper updates the finding status back to the CNAPP provider. The provider clears the issue after its next validation cycle.

Last updated