
KeeperPAM Explained: What It Is and How It Works
KeeperPAM is the privileged access management platform from Keeper Security. It is cloud-native, built on a zero-knowledge and zero-trust architecture, and it consolidates enterprise password management, secrets management, connection management, database management, endpoint privilege management, zero-trust network access (ZTNA), and remote browser isolation (RBI) in a single interface — with no agents, no VPN, and no firewall changes required.
What Problems KeeperPAM Is Designed to Solve
KeeperPAM addresses the two most common failure modes in privileged access programs:
- Standing privilege — privileged accounts that exist permanently, far beyond any legitimate use window.
- Credential exposure — users, administrators, and automated processes handling raw credentials that can be stolen, reused, or hard-coded into source files.
KeeperPAM removes the need for users to ever see underlying credentials during a session and supports zero standing privilege through time-limited access, ephemeral account creation, and temporary role elevation.
How the Keeper Gateway Works
Deployment centers on the Keeper Gateway, a lightweight component installed inside your environment. It creates an outbound-only connection — no open inbound ports, no VPN tunnel, no firewall rule changes. From the administrator’s perspective, there is nothing to put in a DMZ and no agent to deploy on each target system.
Once the gateway is in place:
- Users launch browser-based privileged sessions (SSH, RDP, VNC, HTTPS) or TCP tunnels directly from the Keeper Vault.
- Connections reach servers, databases, and cloud workloads without exposing raw credentials to the end user.
- Session recording is available, and KeeperAI monitors privileged activity in real time, automatically terminating high-risk sessions and generating encrypted, forensic-ready session summaries.
KeeperPAM’s engineers are the original creators of Apache Guacamole, and the platform natively supports MySQL, PostgreSQL, and SQL Server alongside the standard server protocols.
Discovery, Secrets Management, and Least Privilege
Keeper Discovery automatically finds and catalogs machines, databases, directories, accounts, and credentials across local infrastructure, AWS, and Azure, importing them into the Keeper Vault as managed resources. This closes the visibility gap that makes least-privilege enforcement difficult in practice.
For non-human identities and infrastructure secrets, Keeper Secrets Manager (KSM) — a fully cloud-based, zero-knowledge component of KeeperPAM — removes hard-coded credentials from source code and config files, and delivers secrets to CI/CD pipelines (Jenkins, GitHub Actions, Terraform, and others). It also powers automated credential rotation for Active Directory users, machines, and databases, so that access revocation actually means the credential is no longer valid.
Access governance is enforced through:
- Role-based access control (RBAC) and delegated administration
- Just-in-time (JIT) access provisioning
- Time-limited sessions with automatic credential rotation after access is revoked
Zero-Knowledge Architecture
All encryption and decryption happen locally on the user’s device. Keeper’s infrastructure never has the ability to decrypt stored vault data. Each vault record is encrypted with a unique, client-side-generated 256-bit AES key (GCM mode), with layered keys at the record, shared-folder, and data-key levels. Data is encrypted in transit over TLS and at rest with AES-256.
This architecture matters for regulated industries: it means even a compromise of Keeper’s cloud infrastructure would not expose plaintext credentials.
Compliance Posture
KeeperPAM carries credentials that matter in regulated environments:
- Over ten years of SOC 2 compliance — Keeper states this is the longest-standing attestation in the password-management industry
- ISO 27001, ISO 27017, and ISO 27018 certifications
- FedRAMP High Authorization
- Cloud infrastructure certified to more than 325 security controls aligned with NIST guidelines
Administrators also get a Risk Management Dashboard with security benchmarks and customizable compliance reports suitable for frameworks such as SOX.
Identity Integration
KeeperPAM integrates out of the box with Entra ID, Okta, Google Workspace, Ping, and AD FS. Keeper SSO Connect enables federated login through your existing identity provider, and automated SCIM provisioning supports joiner-mover-leaver lifecycle management without manual intervention.
From an applied IAM standpoint, this means KeeperPAM can sit behind the identity governance layer you already operate, extending least-privilege controls to privileged accounts and service accounts without replacing your existing IdP or directory infrastructure.
Ready to close the credential gap?
As a Keeper partner, AppliedIAM deploys and runs Keeper across password management, dark web monitoring, secrets, and privileged access.
Talk to us about Keeper →