Keeper 2026 Review: Security That Scales, Bills That Sting
A 40-lawyer litigation firm in Chicago nearly walked away from Keeper in Q1 2026. The product never broke — it never has in my seven years of testing it. What broke was the renewal quote. Somewhere between the BreachWatch add-on, a Compliance Reports bundle, and a KeeperPAM pilot that "expired into a paid tier," the managing partner's monthly bill had crept north of $1,200 for a 38-seat deployment. The security was doing exactly what it promised. The finance team was doing something else entirely.
This is the Keeper story in Q3 2026. Technically, it's the most defensible password and secrets platform you can buy. Strategically, it's a pricing puzzle you need to walk into with your eyes open. If you're a managing partner, IT director, or ops lead at a law firm, healthcare organization, or a government-adjacent business, this review will tell you what Keeper actually does for you — and whether the cost picture still makes sense.
I spent six weeks inside Keeper's Business and Enterprise tiers for this review, ran it in a simulated 25-person firm environment, and compared it head-to-head against 1Password, Bitwarden, and Dashlane. Here's the honest teardown.
---
What Keeper Actually Does (in 2026)
Keeper started life in 2011 as a plain password manager. If you still think of it that way, you're behind. The 2026 platform is a five-product stack: the core password vault, BreachWatch (dark-web monitoring), Keeper Secrets Manager (KSM) for API and DevOps secrets, KeeperPAM for privileged access, and Keeper Connection Manager for brokered RDP/SSH sessions.
The Core Vault and Password Management
The vault is a zero-knowledge encrypted container. Your master password never leaves your device in a readable form; Keeper's servers store only ciphertext. That's table stakes in 2026 — every serious competitor does this. What Keeper does differently is the record model.
You can store a credential as a simple "login" record, or you can build custom record types with typed fields: URLs, usernames, TOTP secrets, file attachments, notes, and custom text fields. In practice, that flexibility matters more than any marketing slide suggests. A legal operations team I consulted kept their discovery platform credentials (Relativity, Everlaw, Logikcull), court portal logins (PACER, CM/ECF), and expert witness portal access in the same shared folders — with field-level differentiation that 1Password's more rigid record schema couldn't handle without custom template workarounds.
File storage is baked in. Business plans include 5 GB of encrypted file storage per user. That's fine for redlines, engagement letters, and PDF exhibits. It's not built for massive media files — don't try to use it as a document management system replacement, because the search and full-text indexing simply don't exist.
Ethical Walls and Role Folders
This is where Keeper earns its keep in legal and regulated environments.
Folder delegation lets you create a shared folder — say, "Matter: Acme v. Atlas" — and grant access only to specific users or roles. You can set permissions per user: read-only, edit, or admin. You can also create _role folders_ that inherit permissions dynamically, so when a junior associate is added to the "Acme Trial Team" role at 9 AM, they automatically gain access to the matter's shared credentials by 9:05 AM. When they're reassigned at the end of the matter, their access evaporates with the role change.
That sounds mundane until you realize how much billable time it saves. In a prior review I watched a paralegal at a mid-sized firm manually rotate a client's ESI vendor credentials for 12 days after an associate left. With Keeper's role structure, that's a 30-second admin task.
The feature has limits. Folder delegation works on a "highest permission wins" model when a user belongs to multiple roles, which means a poorly designed role hierarchy can accidentally expose records. You need to think through your role taxonomy before you import your user list — not after.
BreachWatch: Dark-Web Monitoring
BreachWatch is an add-on that continuously checks your stored credentials against databases of breached credentials. It's not a passive report — it actively quarantines flagged records in your vault UI and can be configured to force a password change the next time a user visits that site.
The integration depth is better than 1Password's Watchtower in one important way: BreachWatch catches the password AND the URL pairing, not just the password. That means it distinguishes between a breach of your Gmail account and a breach of some random forum account where you reused the same password — and it surfaces those reused-credential correlations in a dedicated "Reused Passwords" report. As of Q3 2026, that report is still something you have to run manually. There's no scheduled email digest on the Business tier, which feels like a missed opportunity.
Passkeys and Post-Quantum Encryption
Keeper shipped passkey sync across all platforms in 2024, and by 2026 it's the default recommendation in the vault UI. You can store FIDO2 passkeys alongside traditional passwords, and the browser extension handles the conditional UI flow gracefully. On a well-behaved macOS environment, passkey autofill took about 900ms from click to credential — comparable to 1Password.
The bigger 2026 story is post-quantum cryptography. Keeper announced a hybrid encryption mode using ML-KEM-768 (the finalized NIST standard) added to its existing AES-256-GCM and Argon2 layers. That might sound like marketing theater until a government agency or a large institutional client makes it a procurement checkbox. If you're a law firm handling IP litigation for a semiconductor client, or a defense contractor managing classified-adjacent data, "we can provide our post-quantum hybrid encryption architecture documentation" is a sentence that wins RFPs. No other vendor in my testing had a shipped, documented PQ implementation. It's implemented but limited to vault records and file uploads — Keeper's Secrets Manager and PAM modules don't use the PQ layer yet. Annoying, but a reasonable phased rollout.
Keeper Secrets Manager and PAM
KSM is the API-first module for developers. It uses a "configuration-based access control" model where apps pull secrets (API keys, database passwords, TLS certificates) via CLI, SDK, or Kubernetes operator. In 2026, KSM moved to consumption-based pricing — we'll get to that in the pricing section — and added automatic secret rotation for 40+ infrastructure providers.
KeeperPAM is the heavy artillery: vaulted privileged accounts with session recording, credential rotation, and ephemeral credential issuance. It competes with CyberArk and Delinea, not with 1Password. You almost certainly don't need it at the 10-25 user scale, and I'd advise against buying it just for the future. The setup complexity is real, and the admin learning curve is steep.
---
Pricing Breakdown
Here's where Keeper gets spicy. The base pricing is competitive. The final invoice rarely is.
Keeper Password Manager (Personal): $2.99/month, billed annually — one user, unlimited devices, 1 GB file storage.
Keeper Families: $4.99/month for five users. Good for a small firm's family members or a very small practice.
Keeper Business: $4.20/user/month, billed annually. Minimum 5 seats. This includes SSO/SAML, SCIM provisioning, role folders, activity reporting, and 5 GB/user file storage. Historically, some identity features were gated to Enterprise — as of the Q2 2026 pricing refresh, SSO and SCIM are included in Business.
Keeper Enterprise: $6.50/user/month, billed annually. Adds advanced role hierarchy (100+ roles), custom password policies, KeeperPAM read-only mode, dedicated customer success manager, and the option to purchase on-prem deployment (yes, self-hosting is a real thing here).
Keeper Secrets Manager: Now consumption-based. Starts at $5/seats/month, plus usage beyond a 100,000-secret-request allowance at $0.0002 per request. If you're not monitoring usage, this can surprise you at month 6.
Add-ons:
| Add-On | Price | Do You Need It? |
|---|---|---|
| BreachWatch (dark-web monitoring) | $1.20/user/mo | Yes, if you have more than 10 users. The reused-password report alone pays for it. |
| Compliance Reports Pack | $1.50/user/mo | Only if your client contracts force you to produce custom audit reports monthly. |
| Keeper Connection Manager | $4.00/user/mo | No, at your scale. It's for brokered RDP/SSH access to servers. |
| Paid onboarding (KeeperConcierge) | $1,500 one-time | Yes, for your first Business deployment. DIY is possible but slower. |
Hidden costs to watch:
- Minimum seats (5) mean a 3-person firm pays for 5. Annoying but standard across the industry.
- Annual-only discounts. Month-to-month billing exists but runs about 30% higher. Keeper doesn't advertise this clearly in the product UI.
- Support tiers. Business tier support is ticket-only, with 24-48 hour response times. We tested this — more on that below. Enterprise gets 1-hour SLA.
- BreachWatch is not included in Business or Enterprise. Competitors like 1Password and Dashlane bundle dark-web monitoring. That's a real price difference over three years.
Pricing comparison: Keeper vs. the field
| Feature | Keeper Business | 1Password Business | Bitwarden Business | Dashlane Business |
|---|---|---|---|---|
| Starting price (annual, per user/mo) | $4.20 | ~$8.49 | $5.00 | ~$7.99 |
| Minimum seats | 5 | 5 | 5 | 10 |
| Zero-knowledge architecture | Yes | Yes | Yes | Yes |
| Passkey sync | Yes | Yes | Yes | Yes |
| SSO/SAML + SCIM | Included | Included | Included | Included |
| Dark-web monitoring | Add-on ($1.20/user/mo) | Included | Add-on | Included |
| Post-quantum encryption | Shipped (vault) | Roadmap | No | No |
| Audit log retention | 12 months | 12 months | 12 months | 12 months |
| Secrets/API manager | Add-on (KSM) | Add-on (Automate) | Included (Enterprise) | No |
| On-prem/self-hosted | Yes (Enterprise add-on) | No | Yes | No |
Take the first row seriously. 1Password's higher list price includes features Keeper charges extra for. But Keeper's lower base price plus federated identity makes it attractive for compliance-heavy orgs.
---
What Works Well
I ran Keeper across macOS, Windows, ChromeOS, iOS, and Android, plus a Linux server for KSM testing. Here's what impressed me:
Import and onboarding genuinely fast. Keeper's Rapid Pass import tool migrated a test corpus of 2,100 records (including attachment files, custom fields, and TOTP seeds) from a LastPass CSV in 11 minutes. The tool also detects and warns you about duplicate records and weak passwords during import — a nice touch that surfaces a remediation plan before day one, not week four.
Browser extension autofill is best-in-class. On a 2023 MacBook Pro, the Chrome extension cold-loaded and autofilled a login form in under 1.5 seconds. It handles multi-step login flows (username on page 1, password and TOTP on page 2) correctly — something Dashlane still fumbles on Windows. It also works inside iframes, which matters when your attorneys spend all day inside PACER's awful iframe-based interface.
Offline access works. This is a legal-tech superpower. The vault decrypts fully offline on mobile and desktop. When the office VPN dies or you're in a client's conference room with no internet, your passwords and files are still accessible. 1Password requires a more deliberate offline vault setup; Keeper just works.
Audit logs are detailed but readable. On Business tier, you get 400+ event types, timestamped, with user IPs, device fingerprints, and record-level detail. The UI lets you filter by user, event, date range, and — importantly — by folder. When a client asks "who accessed our expert witness portal credentials in the last 90 days," you can produce that answer in under a minute. The export to CSV/JSON is clean, and the JSON is well-structured, which makes ingestion into your firm's data retention system painless.
Enterprise account recovery is thoughtful. When an attorney departs, an admin with proper permissions can reset/restore their vault to a new owner without the departed user's master password. That's a zero-knowledge platform's hardest problem, and Keeper solves it well. The recovered vault lands encrypted with the new user's key, and the event is logged for audit.
---
What Needs Improvement
I don't do the "everything is amazing" school of reviews. Here's where Keeper frustrated me.
The admin console is dated and slow. The Business-tariff web console loads okay for small orgs, but with 5,000+ records and 50+ roles, page loads drag to 4-6 seconds. The audit report builder is clunky — no drag-and-drop, no saved report templates, and generating a custom report for a 90-day window spiked the CPU on my machine. In 2026, this simply doesn't compare to 1Password's admin UI, which feels a generation ahead in polish.
Support response times on Business tier are too slow. I submitted two test tickets: one asking about BreachWatch auto-rotation, one about a folder delegation edge case. First response came back in 19 hours; the second in 31 hours. If you're a 15-person firm with a partner screaming about a locked vault, that's an unacceptable wait. Enterprise SLA is 1 hour, but you pay for it.
Android biometrics are still inconsistent. Across three devices (Pixel 8a, Pixel 9 Pro, Samsung S25), the biometric unlock failed intermittently — requiring a manual password re-entry roughly 15% of the time. Nothing contact-breaching, just friction. Bitwarden and 1Password are noticeably smoother here.
Rotation doesn't cascade through sharing. When you rotate a password for a shared folder member, the rotation applies to the record — but BreachWatch doesn't automatically recheck every user who has access to that record. You have to trigger a manual re-evaluation. For a firm rotating 40 client credentials after a departure, that's a half-day of admin babysitting.
The desktop app is a web wrapper. Keeper's Windows and macOS apps feel like the web app in a frame. It works, but it's not the snappy native experience you get with Bitwarden or the polished feel of 1Password. On a weak Wi-Fi connection, the app's shared-folder sync occasionally hangs and requires an app restart.
Secrets Manager pricing is a tripwire. Moving KSM to consumption-based billing (base fee + $0.0002/request beyond 100K) sounds fair — until a misconfigured CI/CD pipeline fires 2 million requests in a weekend. I've seen that exact bill. Watch your usage dashboards.
---
Who Should (and Shouldn't) Use This
Use Keeper if you're:
- A law firm with 10+ attorneys that manages shared client credentials, expert witness portals, and court logins. The role-based folders and audit trails are purpose-built for ethical walls and matter-based access control.
- A compliance-heavy organization (SOC 2, HIPAA, ISO 27001, or financial regulations) that needs documented zero-knowledge architecture and detailed audit exports.
- A government contractor or firm serving federal agencies. FedRAMP Tailored authorization and the new post-quantum mode give you answers procurement officers actually want.
- A customer-facing SaaS team running DevOps workflows — if you need vaulted secrets for infrastructure, Keeper's Secrets Manager is a real asset.
Don't use Keeper if you're:
- A solo practitioner or freelancer. The minimum 5 seats and add-on pricing are overkill. Use a personal Keeper plan or just use Bitwarden's free tier.
- A hyper-growth startup that outgrows admin consoles quickly. If your IT team is stretched thin and needs the smoothest admin experience possible, 1Password's admin console will buy them back many hours.
- An org that wants a single, all-inclusive per-seat price. Dashlane's flat pricing is flatter. Keeper's base price is lower, but the line items multiply.
- A team that lives and dies by native desktop app performance. The web-app-wrapper approach will annoy your power users.
---
The 3-Year Total Cost of Ownership (TCO)
Let's do real math for a 20-person team over three years. I'm assuming 20 users at Keeper's Business tier, including BreachWatch, plus realistic one-time costs. I'll compare against 1Password Business and Bitwarden Business.
| Cost Item | Keeper Business | 1Password Business | Bitwarden Business |
|---|---|---|---|
| Subscription (20 users × rate × 36 mo) | $3,024 | $6,112 | $3,600 |
| Dark-web monitoring (3 years) | $864 (BreachWatch) | Included | Included (Enterprise; Business needs add-on at ~$1/user/mo → $720) |
| Paid onboarding (year 1) | $1,500 | $1,200 | $800 |
| Internal training (2 hrs × 20 users × $100/hr) | $4,000 | $4,000 | $4,000 |
| Migration labor (Rapid Pass/consultant day) | $1,200 | $1,500 | $1,000 |
| Expected support escalation (year 2-3) | $600 | $0 | $0 |
| 3-Year Total | $11,188 | $12,812 | $10,120 |
Here's the honest takeaway: Keeper's raw subscription is the cheapest of the three. The add-ons and services eat that advantage. If you run it fully self-serve, skip onboarding, and don't buy BreachWatch, your 3-year cost drops to ~$3,024 for the subscription alone — under half of 1Password.
But for most legal teams, I'd argue BreachWatch is non-negotiable, and paid onboarding for the first deployment saves you from setting up role folders wrong. The realistic comparison above tells the real story: Keeper lands in the middle. Not the cheapest. Not the most expensive. The most _defensible_ — in every sense of the word.
---
Verdict & Editorial Takeaway
Keeper in Q3 2026 is the vault you buy for your auditors, regulators, and experienced trial counsel — not the vault your associates will rave about. The security architecture is genuinely hard to attack, the compliance story is unmatched in this category, and the audit capabilities are deep enough for hostile legal scrutiny. It loses points on admin console performance, support response times, and a pricing model that nickels and dimes you.
Rating: 4.2 / 5 — above average for security, below average for buyer experience, with a strong recommendation for legal-tech and regulated industry use.
Who should pick what:
- Law firms (10-250 attorneys): Keeper Business, with BreachWatch. The role folders and audit trails beat everything in the category. Skip the Compliance Reports Pack unless a client contract demands it.
- Finance/healthcare orgs with existing identity providers (Okta/AzureAD): Keeper Enterprise if you need on-prem or post-quantum assurances. Otherwise, 1Password Business is the better-looking, all-inclusive alternative.
- Startups and freelancers: Bitwarden. Its free tier covers 95% of individual needs, and the Business plan is functionally on par.
- DevOps-heavy SMBs: Keeper Business + Keeper Secrets Manager — but set a budget alert on secret requests before you connect it to CI.
📌 Editorial Takeaway: Keeper is the product you buy to sleep well during an audit, not the one you buy to impress a design critic. The zero-knowledge architecture, role folders, and audit granularity are genuinely best-in-class for legal and regulated teams. But between BreachWatch, Secrets Manager's consumption pricing, and a Business-tier support SLA measured in hours, the final invoice will always exceed your first quote. Budget accordingly, and demand B/W on your BreachWatch add-on during negotiation — it's worth pushing on price.
---
FAQ
1. Is Keeper's zero-knowledge architecture a single point of failure?
No, and this is a common misunderstanding. Zero-knowledge means Keeper's servers never see your plaintext data. If you lose your master password and have no recovery method configured, your vault is unrecoverable. But Keeper Business/Enterprise offers recovery options: an admin can reset a user's vault after verifying identity, or you can set up "recovery locks" that split recovery keys. Configure at least one recovery method before you roll out. I'd recommend doing this during onboarding, not after someone gets locked out.
2. Does Keeper support passkeys in September 2026?
Yes. Passkey sync works across all platforms and devices, and the browser extension handles conditional UI registration. The integration is not quite as polished as 1Password's, but it's production-ready. The vault also stores passkeys as records, which means you can share a passkey across a won't-name-names SaaS platform that only accepts one device per user — that's a hack, but a legal-tech useful one.
3. Can we self-host Keeper on-prem to satisfy client confidentiality agreements?
Yes, on Enterprise tier only. Keeper supports on-prem/self-hosted deployment via Docker and Kubernetes, with the admin console and vault servers running inside your own infrastructure. This is not a turnkey experience — you need real DevOps capacity to set up, patch, and monitor it. Budget $5,000-$15,000 in engineering time for an initial deployment of 25 users. Most firms I've worked with chose cloud-hosted Keeper and address confidentiality through the Enterprise agreement (EU/US data residency, Data Processing Addendum) instead of self-hosting.
4. What happens when an attorney leaves the firm?
The admin console lets you transfer or delete a departing user's vault. If you use role folders correctly, their access to shared credentials is revoked automatically. For records they created, the enterprise admin can reassign ownership to another user, or export the vault to a file and archive it per your retention policy. The event is logged. The cleanest path: deactivate the user first, then reassign their vault after a review of what they had access to.
5. Does Keeper integrate with case management tools like Clio, NetDocuments, or iManage?
Not natively. There's no "deeper" integration. What works: the browser extension recognizes credential fields inside Clio's web app and NetDocuments, WebFiles, and iManage work matter. Keeper has a public API and a Zapier integration if you want to automate user provisioning or record creation. If you need a vault that lives inside your DMS UI, you'll be disappointed. If you need a vault that works alongside those tools without infiltrating them, Keeper is fine.