Keeper Security
Profitable identity-security platform with real ARR scale but still price-sensitive valuation support
Keeper has credible multibillion-dollar platform value and real regulated-market strength, but public evidence still supports only a track / research-more call because price proof lags company proof.
Cover facts
Company profile
Keeper Security is a private Chicago-based cybersecurity company co-founded in 2011 by Darren Guccione and Craig Lurey. What began as a password manager has expanded into a broader identity-security platform that now includes KeeperPAM, secrets management, connection management, remote browser isolation and public-sector offerings. Public evidence confirms meaningful regulated-market traction, including FedRAMP Certified and GovRAMP High posture, while July 2026 disclosures established a stronger financial profile with $225M ARR, profitability, debt-free status and a stated IPO-optional narrative. The open-source record is still incomplete on exact valuation and equity terms, so Keeper should be treated as a scaled late-stage private asset with real platform strength but still incomplete price transparency.
- Website
- www.keepersecurity.com
- Founded
- 2011-01-01
- Founders
- Darren Guccione, Craig Lurey
- Founding location
- Chicago, Illinois, USA
- Headquarters
- Chicago, Illinois, USA
- Product
- Keeper offers enterprise and consumer password management, KeeperPAM, Keeper Secrets Manager, Keeper Connection Manager, dark-web monitoring and regulated government-cloud identity security.
- Customers
- Enterprise IT and security teams, public-sector agencies, SMBs, MSPs and consumer/family users that need zero-knowledge credential and privileged-access controls.
- Business model
- Subscription software with tiered business and enterprise plans, custom-priced PAM and public-sector deployments, and add-on or bundled expansion into secrets and advanced controls.
- Stage
- late-stage private / growth-equity-backed
- Funding status
- Privately held; public evidence confirms Insight Partners led a $60M minority investment in 2020 and Summit Partners later made a significant minority investment with undisclosed economics. By July 2026, management framed the company as profitable, debt-free and increasingly IPO-optional rather than capital-constrained.
Executive summary
Top strengths
- Public 2026 disclosure now supports real scale with $225M ARR, profitability, debt-free status and strong new-logo momentum.
- Product breadth extends beyond password management into PAM, secrets, remote access and regulated government workloads.
- FedRAMP Certified and GovRAMP High posture help differentiate Keeper from simpler password-only tools.
- Customer and review evidence supports genuine enterprise relevance rather than a purely consumer-security story.
Top risks
- Public evidence is still thin on NRR, GRR, gross margin, cash generation, concentration and cap-table terms.
- Trust-sensitive identity and privileged-access positioning means one material security or compliance failure could compress valuation quickly.
- Premium pricing and add-on complexity remain visible friction points in independent review channels.
- Bundled substitutes from passkeys, cloud-secret stores and larger identity platforms cap low-end multiple expansion.
Open gaps
- Current ARR bridge, product mix and module attach by segment remain undisclosed.
- Retention quality, logo churn and cohort expansion are not public.
- Preference stack, secondary marks and any clean current post-money valuation remain unclear.
- Gross margin, free cash flow, concentration and public-sector ARR mix are still not available in decision-grade form.
Contents
01Company Overview
1.1 Identity, product scope, and current public scale
Keeper Security currently presents itself as an identity-security platform, not merely a vault app. The homepage describes Keeper as a unified control plane for privileged access, secrets, remote connections, endpoints and databases, while the core product pages show that this umbrella now spans KeeperPAM, Keeper Secrets Manager, secure remote access, government cloud and passkey capabilities. Across these surfaces, the company repeatedly anchors differentiation on zero-trust and zero-knowledge architecture with end-to-end encryption, arguing that only the customer can decrypt stored data. Public scale claims are meaningful but not perfectly synchronized: the homepage says Keeper serves more than 93,000 business customers, protects 4 million people and operates in more than 150 countries, while the December 2025 FedRAMP High announcement says Keeper protects more than 85,000 organizations. The discrepancy looks more like page-refresh cadence than a contradiction severe enough to discredit the platform narrative, but it is still important because later chapters should not assume one exact count without citing the page date. Product breadth also clearly extends beyond human-password storage. KeeperPAM unifies password, secrets, connection management, zero-trust network access and remote browser isolation, while Keeper Secrets Manager focuses on API keys, CI/CD credentials, containers and other non-human identities. The company’s public materials therefore support a view of Keeper as a broadened identity-security vendor with password management as the entry wedge and privileged access plus machine-secret control as the expansion path.[CO001, CO002, CO003, CO020, CO021, CO022]
| Metric | Value | Date / Period | Confidence | Notes |
|---|---|---|---|---|
| Legal entity | Keeper Security, Inc. | Current | high | Public terms page names Keeper Security, Inc. and lists the Chicago address. |
| Global headquarters | Chicago, Illinois, USA | Current | high | About page and terms page both place the primary headquarters in Chicago. |
| Product origin | Original Keeper app dates to 2009 | Historical | medium | Historical company-profile sources separate the app origin from later corporate founding. |
| Formal co-founding | 2011 | Historical | medium | Crunchbase News, Summit materials and Wikipedia describe 2011 as the corporate founding year. |
| Founders | Darren Guccione and Craig Lurey | Current | high | Both founders remain in CEO/CTO roles on the current leadership page. |
| Current stage | Private growth-equity-backed company | Current | high | Public record shows Insight and Summit backing, but no IPO or public-listing evidence. |
| Countries served | 150+ | Current | medium | Homepage and company boilerplate reference service in over 150 countries. |
| Business customers | 93,000+ | Current | medium | Homepage current snapshot; other official pages cite 85,000+ organizations, so page date matters. |
| People secured | 4 million | Current | medium | Homepage company metric. |
| Major disclosed equity round | US$60M Insight minority investment | 2020-08 | high | First disclosed equity raise per Crunchbase News and Insight Partners. |
| Later disclosed growth round | Significant minority investment from Summit Partners (amount undisclosed) | 2023-2024 public source set | medium | Summit announcement discloses minority investment but not price or check size. |
| Government authorizations | FedRAMP High and GovRAMP High | Current | high | Government cloud and 2025-2026 authorization releases support this. |
| Core platform positioning | Unified control plane across PAM, secrets, remote access, endpoints and databases | Current | high | Homepage and KeeperPAM page align on this positioning. |
| Current precise headcount | Not publicly pinned in reviewed accessible sources | 2026 run date | low | Hiring growth signals exist, but no exact employee figure is disclosed on accessible official pages. |
Snapshot mixes current official metrics with historical financing milestones. Customer counts are page-date sensitive and headcount remains an evidence gap rather than a verified KPI.
[CO001, CO003, CO004, CO008, CO010, CO011]Maps how founder continuity, platform expansion, customer scale, capital partners and public-sector authorizations fit together in Keeper’s current company-level story.
[CO001, CO004, CO010, CO013, CO016, CO020]Highlights the overview metrics that later chapters can reuse while making uncertainty around headcount and undisclosed transaction terms explicit.
Customer and country figures are minimum company claims rather than audited disclosures, and the investor count only includes publicly named institutional growth-equity backers.
[CO003, CO007, CO013, CO016, CO022, CO038]1.2 Leadership, governance, legal identity, and operating footprint
Public leadership pages show unusually strong founder continuity. Darren Guccione remains CEO and co-founder, Craig Lurey remains CTO and co-founder, and the executive bench names Amy Lindenmeyer as CFO, Tim Strickland as CRO, Tracy Dale-Baker as CHRO, Shane Barney as CISO and David Oskin as General Counsel. Governance also reflects external growth-equity influence: Keeper’s board page lists both Insight Partners managing director Thomas Krane and Summit Partners managing director Len Ferrington alongside Guccione and independent members, indicating that both major capital partners now have visible board representation. The about page and terms also make Keeper’s operating footprint concrete. The company lists Chicago as global headquarters, El Dorado Hills as product development, Cork as EMEA business sales and Tokyo as APAC business sales, while the terms page identifies the legal entity as Keeper Security, Inc. at 311 W. Monroe Street, Suite 406, Chicago, Illinois. One chronology nuance matters for later chapters: public sources distinguish between a 2009 product origin and a 2011 formal co-founding of Keeper Security, Inc. That distinction reconciles the seemingly conflicting dates visible across Chicago Innovation, Crunchbase News, Wikipedia and Summit’s company materials. What remains opaque is current headcount and cap-table control. Reviewed sources show that Keeper added 120 employees around the 2020 Insight round and several hundred more employees by the time of the Summit announcement, but none of the accessible official pages provides a precise current employee count or a detailed cap table.[CO004, CO005, CO006, CO007, CO008, CO009]
| Person | Role | As of | Background / functional coverage | Key-person or diligence note |
|---|---|---|---|---|
| Darren Guccione | CEO & Co-Founder | 2026-08-13 | Founder-CEO and external face of Keeper’s capital raises, federal positioning and product narrative. | High founder dependence; strategic direction remains closely identified with Guccione. |
| Craig Lurey | CTO & Co-Founder | 2026-08-13 | Founder-CTO with continuity from product origin through current platform expansion. | Core technical continuity; central to product and architecture diligence. |
| Amy Lindenmeyer | CFO | 2026-08-13 | Owns finance and likely fundraising / reporting interface. | No accessible public financial disclosures despite named CFO bench strength. |
| Tim Strickland | CRO | 2026-08-13 | Commercial lead for enterprise and channel scaling. | Relevant to go-to-market and partner-economics diligence. |
| Tracy Dale-Baker | CHRO | 2026-08-13 | Human-resources lead as team scales globally. | Useful counterweight to founder-led culture questions. |
| Shane Barney | CISO | 2026-08-13 | Security leader supporting trust, compliance and federal posture. | Important for breach response and secure-development-process diligence. |
| David Oskin | General Counsel | 2026-08-13 | Legal/compliance executive on the public bench. | Key owner for privacy, contracts and regulatory matters. |
This is a public-facing subset of the leadership bench rather than a complete org chart; founder continuity is the most important overview finding.
[CO004, CO005, CO036]| Stakeholder | Role | Control / economic importance | Evidence today | Diligence ask |
|---|---|---|---|---|
| Darren Guccione | CEO, co-founder, board member | Management control and strategic narrative anchor | Current about page and board list. | Clarify voting control, option pool influence and liquidity history. |
| Craig Lurey | CTO, co-founder | Technical co-founder continuity and product influence | Current leadership page plus historical profiles. | Clarify product ownership split and succession depth below the founder level. |
| Insight Partners | Growth-equity investor | First disclosed institutional equity backer from 2020; board representation via Thomas Krane | Crunchbase News, Insight article and board list. | Request ownership %, liquidation preferences and governance rights. |
| Thomas Krane | Insight board representative | Board-level influence over growth strategy and software GTM discipline | Named in 2020 funding coverage and current board list. | Confirm committee roles and current board tenure. |
| Summit Partners | Growth-equity investor | Second major growth-equity backer; minority investment with undisclosed terms | Summit announcement, retrospective and board list. | Request check size, valuation, ownership %, pro-rata and protective provisions. |
| Len Ferrington | Summit board representative | Board-level capital partner with cybersecurity investing background | Named in Summit announcement and current board list. | Confirm whether Summit holds observer or full director rights and any vetoes. |
Private-company ownership remains incomplete in the public record; the map focuses on visible control and governance nodes that matter for diligence.
[CO006, CO010, CO013, CO014, CO016, CO017]1.3 Capital formation, chronology, and public adverse record
Keeper’s publicly visible financing chronology begins with the August 2020 Insight Partners transaction, which Crunchbase News described as the company’s first equity raise and which Insight framed as a $60M growth round supporting a successful shift toward B2B enterprise password management. The later Summit Partners transaction is strategically important but financially incomplete in public record: Summit says it completed a significant minority investment and joined the board, while explicitly noting that no other terms of the private transaction were disclosed. Even without the missing check size or valuation, the company’s own and partner materials show a meaningful milestone chain after 2020: Glyptodon was acquired in late 2021 and reworked into Keeper Connection Manager in 2022, FedRAMP Moderate was achieved in August 2022, Tokyo opened as APAC headquarters in 2023, Keeper’s retrospective flagged both Summit’s investment and the KeeperPAM platform launch as defining moments of that year, mobile passkey support shipped in March 2024, FedRAMP High arrived in December 2025 and GovRAMP High followed in February 2026. The public adverse record is more about attack-surface scrutiny than a famous catastrophic breach. Keeper’s own documentation publishes vulnerability advisories for Keeper Connection Manager, including one high-severity SAML-response issue, OpenCVE tracks additional Keeper-related CVEs such as disputed plaintext-memory exposure and a KeeperChat biometric issue, and Built In’s AI-generated employer profile surfaces founder-led pressure and burnout commentary as a low-confidence culture signal. Those issues do not on their own negate Keeper’s platform quality, but they do show that diligence should price technical scrutiny and key-person dependence rather than assume a spotless record.[CO013, CO015, CO016, CO018, CO019, CO023]
| Date | Event | Type | Amount / valuation / status | Participants | Implication |
|---|---|---|---|---|---|
| 2009-01-01 | Original Keeper app developed / product origin | founding | Product origin established | Darren Guccione; Craig Lurey | Explains why some sources cite 2009 even though corporate founding is later. |
| 2011-01-01 | Keeper Security, Inc. formally co-founded | founding | Corporate founding year in multiple public sources | Darren Guccione; Craig Lurey | Canonical corporate start date for later funding and stage analysis. |
| 2020-08-17 | Insight Partners minority growth round | financing | US$60M disclosed; first equity raise | Insight Partners; Thomas Krane | Introduced institutional capital and board oversight. |
| 2021-12-01 | Glyptodon acquired | product | Acquisition integrated later into KCM | Keeper; Glyptodon | Expanded remote-access and browser-based session capabilities. |
| 2022-05-04 | Keeper Connection Manager announced | product | Zero-trust remote infrastructure access layer launched | Keeper | Brought privileged remote access closer to full PAM coverage. |
| 2022-08-01 | FedRAMP Moderate achieved | regulatory | Moderate baseline authorization | Keeper Security Government Cloud | Opened the path into U.S. federal workloads. |
| 2023-05-01 | Tokyo APAC headquarters opened | scale | Regional office launch | Keeper leadership; board; local partners | Signals international sales investment and regionalization. |
| 2023-12-18 | Retrospective highlights Summit investment and KeeperPAM launch as defining 2023 events | partnership | Year-end summary of growth and platform expansion | Keeper; Summit Partners | Shows 2023 as the transition year from password manager toward broader PAM identity platform. |
| 2024-03-25 | Passkey management added to iOS and Android | product | Mobile passkey support live | Keeper product team | Extends passwordless narrative beyond browser extensions. |
| 2025-12-23 | FedRAMP High authorization announced | regulatory | High baseline authorization | Keeper Security Government Cloud | Strengthens federal-market credibility for high-impact workloads. |
| 2026-02-11 | GovRAMP High authorization announced | regulatory | High impact SLED authorization | Keeper Security Government Cloud | Expands regulated public-sector reach beyond federal buyers. |
Year-only and month-only milestones are normalized to the first day of the period when the exact day was not recoverable from accessible public evidence.
[CO011, CO012, CO013, CO016, CO023, CO024]Keeper’s public chronology runs from a 2009 product origin and 2011 corporate founding through 2020/2023 growth-equity backing, 2022-2024 product broadening and 2025-2026 federal and SLED authorization upgrades.
Exact days are used only where a dated public announcement was recoverable; year-only or month-only milestones are pinned to the first day of that period.
[CO003, CO011, CO012, CO013, CO016, CO023]1.4 Exhibits
02Market Analysis
2.1 Market boundary, adjacencies, and status-quo substitutes
Keeper participates in a layered market, not just the classic consumer-password-manager category. Its current product pages span workforce password management, privileged access management, secrets management, remote browser and remote infrastructure access, passkey management and public-sector identity security. That means the relevant market boundary is broader than “store passwords in a vault” but narrower than the entire identity stack. Keeper is not trying to be an all-purpose directory, full customer-identity platform or broad SIEM; instead it sits where organizations need secure credential storage, least-privilege session control, machine-secret workflows and phishing-resistant authentication without stitching together multiple point tools. The substitute set is therefore structurally important. At the low end, Google Password Manager and Apple’s Passwords app already give consumers and lightly managed workforces built-in password and passkey storage at a zero-price point. On the machine-identity side, AWS Secrets Manager and Azure Key Vault cover cloud-secret storage inside their own ecosystems. In adjacent enterprise-security budgets, BeyondTrust and other PAM incumbents already sell just-in-time and least-privilege controls. Keeper’s wedge is the unification of these jobs in one zero-knowledge control plane, especially for buyers who want one system to bridge human credentials, secrets, privileged sessions and passwordless migration rather than separate vendor silos.[CM001, CM002, CM003, CM004, CM005, CM025]
| Segment / Category | Included spend | Excluded spend | Buyer / payer | Relevance to Keeper |
|---|---|---|---|---|
| Workforce password management | Paid vault subscriptions, credential sharing, policy controls, audit logs and recovery workflows | Unmanaged spreadsheets, browser memory, and zero-price unmanaged storage | Individual, IT admin, CISO / user or employer | Core revenue wedge and historical brand anchor |
| Privileged access management | Least-privilege access, credential rotation, session monitoring, remote access and endpoint privilege controls | Broad IAM directory spend or full network-security platforms | Security, IAM, infrastructure and compliance teams / security or IT budget | Fastest-growing adjacent market that KeeperPAM is explicitly targeting |
| Secrets management / NHI security | API keys, service credentials, CI/CD secrets, cloud rotation and machine-to-machine access control | General cloud infrastructure spend not tied to credentials | DevSecOps and platform engineering / engineering or security budget | Important expansion path beyond human vaulting |
| Passwordless / passkey orchestration | Passkey storage, sharing, autofill, workforce rollout and phishing-resistant login policy | Biometric hardware itself and consumer device OS lock-in | Identity, security and end-user IT / security or productivity budget | Strategic growth layer and retention defense as passwords decline |
| Government / regulated identity security | FedRAMP/GovRAMP compliant access control, auditability and zero-trust privileged access | Broader public-sector ERP or case-management software | Agency security teams, procurement and compliance / public-sector IT budget | Where Keeper’s authorization stack expands TAM beyond commercial SMB |
| Built-in / ecosystem substitutes | n/a — competitive context rather than Keeper revenue pool | Google Password Manager, Apple Passwords, CSP-native secrets stores | End user or existing cloud account owner / often no separate payer | Defines the zero-price or already-bundled baseline Keeper must exceed |
This table defines the market by jobs-to-be-done rather than treating all identity spending as Keeper’s addressable opportunity.
[CM001, CM002, CM003, CM004, CM005, CM025]Keeper’s market connects consumer, enterprise-security, engineering and public-sector buying centers to one integrated credential-control platform.
[CM001, CM003, CM014, CM015, CM016, CM027]2.2 Sizing lenses, geography, and segment economics
Published 2026 market sizing is directionally bullish but numerically inconsistent, which is exactly why Keeper’s market should be framed as a range. Mordor Intelligence and Research and Markets both project the password-management market at US$2.94B in 2026 growing to US$8.07B by 2031 at a 22.39% CAGR, while Fortune Business Insights puts the same category at US$3.79B in 2026 and US$10.63B by 2034 at a 13.77% CAGR. The spread is not trivial: using the high versus low 2026 figure changes any implied share or revenue discussion by nearly US$850M. The segment and regional direction is more useful than the single-point totals. North America remains the largest region at roughly one-third to almost two-fifths of spend, while Asia Pacific is the fastest grower. Cloud is the dominant deployment mode today, but hybrid models are growing quickly under data-residency and regulated-workload pressure. Large organizations remain the revenue anchor, while SMEs are the fastest-growing cohort as subscription pricing and lower-complexity SaaS deployment widen access. Vertical concentration in BFSI and rising growth in healthcare align well with Keeper’s compliance-heavy positioning. The most defensible SAM for Keeper is therefore not “all password management” but the paid, multi-user, compliance-sensitive slice where buyers value least privilege, auditability, identity-provider integration, passkeys and machine-secret control enough to budget for a specialist platform.[CM006, CM007, CM008, CM009, CM010, CM011]
| Publisher / lens | Year | Geography | Value | CAGR | Methodology / interpretation | Confidence | Limitation |
|---|---|---|---|---|---|---|---|
| Mordor Intelligence | 2026 | Global | US$2.94B in 2026; US$8.07B by 2031 | 22.39% | Password-management market model with solution, deployment and region splits | medium | Syndicated analyst methodology is proprietary and broader than Keeper’s paid wedge |
| Research and Markets | 2026 | Global | US$2.94B in 2026; US$8.07B by 2031 | 22.39% | Distributor summary that aligns closely with the Mordor framing | medium | Appears to mirror the same market frame rather than provide a wholly independent build |
| Fortune Business Insights | 2026 | Global | US$3.79B in 2026; US$10.63B by 2034 | 13.77% | Alternative syndicated estimate with different base, terminal year and segment shares | medium | Different time horizon and category definitions complicate direct comparison |
| Published regional concentration lens | 2025-2026 | North America / APAC | North America 33.17%-38.93% share; APAC fastest growth | 24.13% APAC in Mordor/R&M | Cross-publisher view on where current spend is concentrated and where growth is fastest | medium | Regional shares differ by publisher and are not a Keeper share proxy |
| Published segment-mix lens | 2025-2031 | Global | Large orgs 63.4% of 2025 spend; SMEs fastest 24.3% CAGR; BFSI 29.1% share | 24.3% SME CAGR; 25.9% healthcare CAGR | Segment and vertical mix from analyst models | medium | Useful for direction but still category-level, not company-specific |
| Keeper practical SAM lens | 2026 | Regulated SMB to enterprise plus public sector | Evidence-constrained subset of headline TAM rather than a precise dollar point | n/a | Paid multi-user slice where least privilege, auditability, secrets and passkeys matter enough to budget for a specialist platform | low | No public disclosure of Keeper’s actual paid-seat mix, geo mix or share |
Conflicting publisher estimates are preserved instead of averaged. Keeper’s practical SAM is a capability-defined lens rather than a management-disclosed number.
[CM006, CM007, CM008, CM009, CM010, CM011]Published password-management market estimates support a bounded 2026 TAM range rather than a single definitive number.
[CM006, CM007, CM008, CM013]Keeper’s practical market narrows from all credential demand to the subset where governed, multi-user identity control is worth paying for.
Only the published TAM layer is numeric because lower layers are defined by capability and control requirements rather than by disclosed market totals.
[CM005, CM008, CM014, CM025, CM035, CM037]2.3 Buyers, adoption path, growth drivers, and constraints
Buyer and payer roles vary materially by segment. Individuals and families self-procure; SMBs often buy through an owner or IT generalist; larger private enterprises route decisions through a CISO, IAM lead or security architect; DevSecOps or platform-engineering teams join when secrets, automation or multi-cloud rotation matter; and federal or SLED agencies layer procurement and compliance stakeholders on top. That buyer complexity can slow deals, but the demand drivers are durable. Verizon’s 2026 DBIR continues to tie breach causation to the human element, phishing and stolen credentials, while IBM’s 2026 report puts the average cost of a breach at US$4.99M and emphasizes the rising identity-control demands of AI systems. NIST SP 800-207 and CISA’s zero-trust maturity model both reinforce least-privilege, per-request access and data-centric security controls, and NIST SP 800-63B now requires phishing-resistant options at AAL2 while mandating them for federal personnel. Microsoft’s 2026 Entra update pushes the market further by making passkeys the default path and retiring Microsoft-provided native SMS/voice delivery in 2027. Those are strong category tailwinds for Keeper. The counterweights are equally important: free built-in password/passkey tools compress willingness to pay in the consumer and light-admin segments; PAM budgets are contested by entrenched incumbents; cloud-secret managers satisfy some machine-identity needs without a separate vendor; and organizations often underestimate the change-management work required to migrate shared credentials, integrate IdPs, and enforce new least-privilege workflows. Keeper’s market attractiveness therefore depends less on the existence of cyber risk—which is obvious—and more on whether it can keep winning the integrated, higher-control slice where the operational burden of fragmented tools is already painful enough to justify consolidation.[CM015, CM016, CM017, CM018, CM019, CM020]
| Segment | Buyer | User | Payer | Workflow | Budget owner | Adoption trigger |
|---|---|---|---|---|---|---|
| Individuals / families | Individual consumer or household lead | Same person or family group | Same person or household | Store passwords, passkeys, verification codes and share credentials | Personal discretionary spend | Need cross-device security beyond memory or notes |
| SMB / business starter | Owner or IT generalist | Employees and contractors | Business owner or IT budget | Shared credentials, admin console, team folders, basic policies | IT or general admin budget | Password sprawl and onboarding/offboarding pain |
| Mid-market / enterprise workforce | CISO, IAM lead or security architect | Workforce users and admins | Security or enterprise IT budget | SSO/SCIM integration, RBAC, audit logs, privileged workflows | Security / IAM budget | Need for governed credential sharing and compliance evidence |
| DevSecOps / platform engineering | Platform lead or DevSecOps manager | Developers, SREs, automation and workloads | Engineering or shared security budget | Secure API keys, service accounts, CI/CD secrets and rotation | Engineering platform budget | Hard-coded secret sprawl and multi-cloud automation |
| Public sector / regulated agencies | Agency security leadership plus procurement | Federal, state, local and contractor staff | Public-sector IT / security budget | Phishing-resistant access, privileged session control, compliance logging | Agency CIO/CISO budget | FedRAMP/GovRAMP, least privilege and audit mandates |
| MSP / partner-led deployments | MSP practice lead or reseller security team | Partner admins plus downstream customers | Channel / downstream customer budget | Multi-tenant credential and privileged-access administration | Partner security practice budget | Need to operationalize security services across many customer estates |
Buyer, user and payer roles fragment meaningfully across Keeper’s end markets; that fragmentation explains both cross-sell upside and sales-cycle complexity.
[CM001, CM014, CM015, CM016, CM027, CM028]| Driver / constraint | Direction | Timing | Implication for Keeper | Diligence ask |
|---|---|---|---|---|
| Phishing, stolen credentials and the human element remain major breach drivers | up | Current / structural | Sustains demand for password, passkey and privileged-control platforms | Test whether Keeper converts macro threat urgency into budgeted paid seats |
| Record US$4.99M average breach cost raises willingness to fund identity controls | up | Current | Strengthens ROI case for credential and least-privilege tooling | Ask customers which cost-avoidance arguments actually win deals |
| Zero-trust policy and federal guidance require least-privilege and phishing-resistant access | up | Current / structural | Benefits Keeper’s PAM and government-cloud positioning | Measure what portion of pipeline is compliance-led versus convenience-led |
| Microsoft default-passkey rollout accelerates passwordless migration | up and down | 2026-2027 | Tailwind for Keeper passkey orchestration but also a signal that standalone password demand will evolve | Quantify whether Keeper wins orchestration even when Microsoft drives the policy change |
| Built-in Google and Apple password/passkey stacks compress the low end | down | Current / structural | Raises customer-acquisition risk in consumer and light-admin segments | Focus SAM on managed and regulated buyers rather than all users |
| Cloud-native secrets stores from AWS and Azure satisfy some machine-identity jobs inside existing CSP budgets | down | Current | Limits Keeper’s machine-secret wedge where buyers prefer single-cloud native tools | Identify multi-cloud and audit-driven use cases where unification beats native stores |
| Legacy on-prem PAM tools are often complex and staff-intensive to deploy | up for Keeper | Current | Cloud-native ease-of-deployment can be a real wedge if buyer proof holds | Validate EMA and SoftwareReviews findings with reference customers |
| Category overlap across password, PAM, secrets and endpoint budgets can slow buying committees | down | Current | Sales cycles may lengthen because multiple teams must agree on scope | Map which budget owner signs first in successful Keeper expansions |
Several factors are double-edged: passkeys help category urgency but can also commoditize the low end; PAM complexity creates opportunity but also raises proof burdens.
[CM018, CM019, CM020, CM021, CM022, CM023]Enterprise adoption is a staged process from evaluation through identity integration, migration, monitoring and expansion into PAM, passkeys or secrets.
[CM017, CM028, CM029, CM030, CM031]2.4 Exhibits
03Competitors
3.1 Landscape, substitutes, and competitor classes
Keeper’s competitive set is best understood as four overlapping classes. First are direct workforce-password and credential-control peers: 1Password, Bitwarden, Dashlane and LastPass, all of which market secure vaulting, sharing, admin controls and passwordless or passkey support to business buyers. Second are adjacent privileged-access and identity-security suites such as CyberArk, Delinea and BeyondTrust, which approach the same buyer from least-privilege, session-control and zero-standing-privilege workflows rather than from a classic password-vault starting point. Third are secrets-centric tools and cloud-native substitutes such as HashiCorp Vault, AWS Secrets Manager and Azure Key Vault, which solve the machine-identity side of the problem and can absorb budget that might otherwise flow to a unified platform. Fourth are the zero-price built-ins and the status quo: Google Password Manager, Apple Passwords, and unmanaged habits like browser autofill, hard-coded secrets and ad hoc credential sharing. This matters because Keeper is squeezed from both ends. Google and Apple compress the low-end willingness to pay, while CyberArk or Delinea can pull larger enterprises toward broader identity-security suites. Keeper’s addressable win zone therefore is not “everyone with passwords” but the slice of buyers who value unified control across passwords, passkeys, secrets, privileged access and compliance enough to prefer a specialist platform over piecemeal or bundled substitutes.[CP001, CP002, CP010, CP011, CP012, CP013]
| Competitor | Category | Scale / funding signal | Target segment | Differentiation | Limitation |
|---|---|---|---|---|---|
| Keeper Security | Direct enterprise credential-security platform | Thousands of organizations; millions of users; public-sector compliance posture emphasized | SMB, enterprise, public sector, MSPs | Zero-knowledge vaulting plus passkeys, secrets, KeeperPAM and compliance depth in one platform | Private company with limited public pricing realization and win/loss disclosure |
| 1Password | Direct premium access platform | 200,000+ businesses trust 1Password | SMB to enterprise | Broader access story spanning passwords, secrets, apps, devices and AI/SaaS discovery | Public business pricing visibility was weak in fetched pages; less public-sector compliance emphasis than Keeper |
| Bitwarden | Direct value/transparency peer | 80,000+ businesses worldwide | SMB, enterprise, regulated buyers, developers | Open-source transparency, self-host option, rapid deployment and ROI claims | Public-sector and compliance posture less foregrounded than Keeper’s |
| Dashlane | Direct credential-security peer | Business scale not cleanly disclosed on fetched pages | Business and enterprise | Omnix repositioning, credential protection, admin controls, SSO/SCIM and least-privilege sharing | Pricing detail is largely custom/opaque in fetched pages and direct public scale signals are thinner |
| LastPass | Direct incumbent password-manager peer | Recognized consumer and business brand; scale claims on current fetched pages are qualitative | Individuals, SMB, business | Cross-platform zero-knowledge vault plus SSO/MFA adjacency and broad install familiarity | Trust posture still shaped by disclosed 2022 incident and ongoing remediation messaging |
| CyberArk | Adjacent identity-security / PAM suite | Large enterprise identity-security brand | Enterprise, cloud and security buyers | Zero-standing-privilege, every-identity control, agentic identity and secure remote access | Broader platform can be heavier than a pure workforce-vault deployment |
| Delinea | Adjacent PAM / identity-security suite | Established enterprise PAM platform with Secret Server and remote access modules | Enterprise and regulated buyers | Dynamic authorization, AI-driven auditing, session monitoring, password rotation and remote privileged access | May be over-scoped for buyers who only need a workforce vault or lightweight sharing |
| BeyondTrust | Adjacent endpoint / privilege management | Mature endpoint and privilege-management footprint | Enterprise security and endpoint buyers | Just-in-time / just-enough privilege with endpoint coverage and compliance framing | Less centered on consumer/workforce password UX than direct vault peers |
| HashiCorp Vault | Adjacent developer secrets platform | Developer and platform-engineering standard for secret engines and dynamic credentials | Platform engineering, DevSecOps, multi-cloud teams | Strong API/CLI, dynamic credentials and encryption-as-a-service motion | Not a natural workforce password-sharing product |
| Native and bundled substitutes | Substitute / status quo | Preinstalled at ecosystem scale or bundled with existing cloud spend | Consumers, lightly managed teams, single-cloud engineering teams | Zero incremental software purchase, familiarity, tight platform integration | Weak org-wide governance for mixed human-plus-machine identity control |
The table covers the primary ways a buyer can solve the same credential-control job: direct peers, broader PAM suites, developer-secret platforms and bundled substitutes.
[CP001, CP002, CP003, CP005, CP007, CP009]Positions major competitors on governance/compliance depth versus breadth of identity-control scope using evidence-backed ordinal scores.
Scores are ordinal synthesis from fetched official pages, not audited market-share or benchmark metrics.
[CP001, CP010, CP011, CP014, CP015, CP016]3.2 Peer profiles, capability trade-offs, and pricing posture
Among direct peers, 1Password is the strongest premium benchmark in disclosed business scale: its business page says more than 200,000 businesses trust the platform, and the company now positions around passwords, secrets, devices, apps outside SSO, AI discovery and broader access governance rather than only vaulting. Bitwarden attacks from the opposite direction with 80,000+ businesses, open-source transparency, cloud or self-host deployment, and quantified ease-of-setup and ROI claims. Dashlane is reframing itself from password manager to Omnix credential-security platform, pairing secure vaulting with credential-protection and risk-detection modules. LastPass remains a recognizable cross-platform zero-knowledge brand with SSO and MFA adjacency, but its own current site still spends meaningful real estate explaining post-2022 remediation and security transformation, which signals persistent trust drag. Keeper’s own pitch combines zero-knowledge architecture, secure sharing, SCIM/SSO, passkeys, secrets, KeeperPAM, MSP support, AI-agent secret access and public-sector compliance. In adjacent enterprise buyers, CyberArk and Delinea now market dynamic authorization, AI-driven auditing, secure remote access, machine identities and zero-standing-privilege models that can subsume simpler vault point-solutions. Public pricing transparency is mixed: most fetched pages show per-user annual packaging or custom-sales motions, but public numeric comparability is weaker than category buyers might expect, especially once enterprise bundles, ELAs and custom quotes enter the picture.[CP003, CP004, CP005, CP006, CP007, CP008]
| Buying criterion | Keeper | 1Password | Bitwarden | Dashlane | LastPass | CyberArk / Delinea | HashiCorp Vault | Native built-ins |
|---|---|---|---|---|---|---|---|---|
| Workforce password vault + sharing | High | High | High | High | High | Medium | Low | Medium |
| SCIM / SSO / admin policy depth | High | High | High | High | Medium | High | Low | Low |
| Passkey / passwordless readiness | High | Medium | High | Medium | Medium | Low-Medium | Low | High |
| Machine secrets / DevOps workflows | High | Medium | High | Low | Low | High | High | Low |
| Privileged access / session control | High | Low-Medium | Low | Low | Low | High | Low | Low |
| Compliance / public-sector posture | High | Medium | Medium | Medium | Medium | High | Medium | Low |
| Deployment control / self-host or deep platform control | Medium | Medium | High | Low | Low | High | High | Low |
Scores are ordinal synthesis from fetched official pages. “High” means the capability is explicitly foregrounded on the current fetched surface, not that the vendor is universally best-in-class.
[CP012, CP013, CP014, CP015, CP016, CP017]| Vendor | Price / unit / contract model | Included capabilities | Discount / unknowns | Implication |
|---|---|---|---|---|
| Keeper | Per-user annual packaging plus custom quote paths for higher-end modules | Business, enterprise, family-benefit, secrets, PAM and MSP adjacencies on the pricing surface | Exact numeric list prices were not cleanly recoverable from fetched text; custom quote applies for KeeperPAM | Cross-sell breadth is attractive, but realized pricing power is opaque |
| 1Password | Pricing page fetched successfully but business-specific public numeric pricing was not clearly exposed in extracted text | Business positioning, strong support and broader access-platform scope | Opaque business price in current fetched extraction | Signals premium positioning but makes direct list-price comparison harder |
| Bitwarden | Annual subscription model with Teams and Enterprise packages | Vaulting, sharing, business support, health reporting, optional secrets expansion | Exact numeric values were not present in current extracted pricing text | Value story remains strong even when public numeric list-price extraction is imperfect |
| Dashlane | Per-user/month billed annually plus custom enterprise packaging | Password management, credential protection, SSO/SCIM and account management | Public pricing page emphasizes packaging structure more than clean numeric comparison | Suggests sales-led enterprise motion rather than pure self-serve comparison |
| LastPass | Paid plans layered above a limited free tier | Zero-knowledge vaulting and broader password-manager functionality | Business pricing pages fetched as 404 at this run date | Current public packaging clarity appears weaker than peers |
| CyberArk / Delinea | Enterprise sales motion | Broader PAM, dynamic authorization, sessions, secrets and AI-driven auditing | Public pages emphasize capability rather than transparent list pricing | These vendors compete as broader suites, not as low-friction self-serve tools |
| HashiCorp Vault | Product-led docs plus enterprise deployment paths | Secrets engines, dynamic credentials, encryption and API/CLI workflows | Public pricing not central on fetched docs surfaces | Engineering-led secret buyers may compare architecture before price |
| Native / bundled substitutes | Zero incremental or pre-bundled | Password/passkey storage or cloud secrets inside existing ecosystems | Cost is hidden inside platform or cloud relationship rather than separate SKU | Creates severe low-end and single-cloud substitute pressure |
Where current fetched pages did not expose clean public numeric pricing, the row preserves the unknown explicitly rather than importing unstated list prices.
[CP015, CP017, CP019, CP022, CP023, CP029]Shows how direct password peers and adjacent suites differ less on basic vaulting than on control depth, machine identity and privileged access breadth.
[CP012, CP013, CP014, CP015, CP016, CP017]3.3 Switching costs, distribution power, and moat durability
Keeper has a real but conditional moat. Switching costs are meaningful once a buyer has configured folders, roles, SCIM provisioning, SSO, session controls and onboarding workflows, but they are not absolute because competitors actively advertise migration, import and rapid rollout. That keeps feature parity pressure high. Distribution power increasingly sits with ecosystem breadth and buyer trust rather than with password storage alone: 1Password stretches into SaaS governance and AI discovery, CyberArk and Delinea stretch into every-identity privilege control, and cloud-native secret stores can win by simply being “already there” inside AWS or Azure. Keeper’s strongest moat signals from fetched pages are its compliance-heavy posture, public-sector readiness, unified passwords-plus-secrets-plus-PAM story, and the ability to sell operational simplicity alongside security. Its biggest displacement risk is commoditization of basic vaulting and passkeys by Apple, Google and platform vendors, plus higher-end suite competition from broader identity-security players. The most important open question is therefore not whether Keeper is feature-complete—it broadly is—but whether it can consistently win the integrated control-heavy slice fast enough to offset bundled-native substitutes below and broader suite consolidation above. Without current win/loss data, realized pricing and product attach rates, moat durability should be viewed as promising but not yet fully underwritten.[CP022, CP024, CP025, CP026, CP027, CP028]
| Moat claim | Threat | Severity | Mitigation / current signal | Diligence ask |
|---|---|---|---|---|
| Compliance-led differentiation | Broader vendors replicate enough controls for commercial buyers that only public-sector and regulated accounts remain clearly differentiated | High | Keeper foregrounds FedRAMP/GovRAMP and zero-knowledge architecture | Quantify public-sector ARR, renewal rates and win rates versus 1Password and CyberArk |
| Unified human + machine identity story | AWS, Azure and HashiCorp can absorb the machine-secret slice while Apple/Google absorb simple user storage | High | Keeper pricing and product pages show secrets, AI-agent access and PAM in one platform | Measure attach rate of secrets and PAM in new logo wins |
| Operational simplicity | Bitwarden and Dashlane both market fast deployment or admin-efficiency benefits | Medium | Keeper business page says deployment happens in minutes with 24x7 support | Validate implementation time and admin effort with recent customer references |
| Trust and security architecture | Any major incident could rapidly reshape vendor selection, as LastPass shows | High | Keeper emphasizes zero-knowledge, audits and compliance posture | Request incident history, insurance impacts and large-account security questionnaires |
| Pricing power | Opaque custom contracts may erase list-price or bundle advantages | Medium | Keeper can package family plans, MSP, secrets and PAM to expand value | Collect competitive quotes and discount bands by segment before underwriting pricing durability |
| Suite consolidation defense | 1Password, CyberArk and Delinea all broaden the identity-control story beyond vaulting | High | Keeper already spans passkeys, secrets and privileged access | Assess whether buyers see Keeper as a true platform shortlist or as a vault plus add-ons |
Severity reflects likely strategic pressure over the next 12-36 months rather than certainty of share loss.
[CP008, CP010, CP011, CP016, CP017, CP024]Summarizes the most important competitive durability indicators for Keeper relative to direct and adjacent peers.
[CP003, CP005, CP016, CP017, CP025, CP031]3.4 Exhibits
04Financials
4.1 Revenue model, pricing, and monetization architecture
Keeper’s revenue mechanism is much clearer than its audited results. Official pricing and product pages show a seat-based subscription business with layered monetization rather than a one-product consumer app. At the entry end, Keeper sells Business Starter for small teams; it then expands to Business and Enterprise tiers with broader administration, identity-provider integration, SCIM, RBAC and developer APIs. The company also sells or packages higher-value adjacencies: Secrets Manager is an add-on to business plans and included with KeeperPAM; KeeperPAM itself is sold through custom pricing; MSP packaging exposes a channel-oriented revenue surface; and a free Keeper Family Plan for every business user functions as an adoption and retention enhancer even if it is not itself a direct incremental ARR stream. The important financial reading is that Keeper is monetizing access control by account tier, governance depth and adjacent-module attach, not by transaction volume or services-heavy implementation. That generally improves revenue quality because seat subscriptions, enterprise governance features and module expansion are typically recurring and sticky. But public monetization clarity is still not the same as public monetization depth. The pages identify what Keeper can charge for; they do not disclose how much ARR comes from SMB password management versus enterprise contracts, public sector, MSP, secrets or PAM. They also do not expose realized ASP after discounting. So the business model is understandable, but revenue mix remains private.[CI001, CI002, CI003, CI004, CI005, CI006]
| Stream | Mechanism | Unit | Current value / status | Quality | Diligence ask |
|---|---|---|---|---|---|
| Business Starter password manager | Seat-based recurring SaaS for small teams | Per user / month billed annually | Officially marketed and positioned for 5–10 users | high | What percent of new logo volume lands here versus standard Business or Enterprise? |
| Business password manager | Seat-based recurring SaaS | Per user / month billed annually | Officially marketed as company-wide security and administration tier | high | What is realized ASP after seat discounts and what share of ARR comes from this tier? |
| Enterprise password manager | Seat-based recurring SaaS with deeper governance | Per user / month billed annually plus negotiated enterprise packaging | Officially marketed with SCIM, SSO, RBAC and APIs | high | What percent of ARR comes from enterprise contracts and what is gross retention in this cohort? |
| Secrets Manager add-on | Module add-on for business plans; included with KeeperPAM | Per user / year or bundled | Officially described as add-on to all business plans and included with PAM | high | What attach rate does Secrets Manager have and what is its standalone ASP? |
| KeeperPAM | Sales-led recurring platform expansion | Custom quote | Officially sold through Sales only with organization-specific pricing | medium | How much ARR and gross margin does KeeperPAM contribute today? |
| MSP / channel packaging | Partner-mediated recurring software packaging | Customer or partner contract | Official MSP surface is present on pricing pages | medium | How much ARR is channel-sourced and what is the partner margin structure? |
| Consumer / family adjacency | Free family plan for each business user plus consumer-facing vault experience | Household plan / consumer plan | Visible as adoption/retention enhancer rather than clearly incremental business ARR | medium | What percent of workforce users convert or retain because of the family-plan benefit? |
Revenue streams are visible from public pages, but public revenue mix is not. The pages reveal monetization architecture rather than segment-level ARR composition.
[CI001, CI002, CI003, CI004, CI005, CI006]| Price / unit / contract | List vs realized pricing | Discounts / unknowns | Source | Implication |
|---|---|---|---|---|
| Business Starter / Business / Enterprise user-based annual packaging | List structure public; numeric values were not consistently recoverable in fetched text | Realized ASP, discounting and seat minimums undisclosed | Official Keeper pricing | Confirms recurring seat-based monetization without revealing revenue density |
| KeeperPAM custom pricing | Negotiated pricing only | Quote-led structure obscures realized module economics | Official Keeper pricing and PAM FAQ | Higher-value module likely carries stronger ASP but weaker public transparency |
| Secrets Manager add-on to business plans | Partially public structure | Exact add-on ASP and bundle penetration undisclosed | Official Secrets Manager page | Suggests modular ARPU expansion beyond core vaulting |
| Free family plan for every business user | Not a direct business-price line item | Economic impact on retention, adoption and support cost is unknown | Official Keeper pricing and business pages | May improve adoption while reducing apparent ARPU |
| MSP packaging | Sales- and partner-led packaging | Reseller margin and end-customer pricing undisclosed | Official Keeper pricing | Channel can scale distribution but blurs realized economics |
| Enterprise bundles, curated pricing and ELAs | Negotiated enterprise economics | No public discount bands or support-bundle pricing | Official Keeper enterprise and pricing pages | Large-account unit economics cannot be inferred from list pages alone |
Official public pricing is structural, not sufficient for realized revenue analysis. Private-company diligence must bridge from list architecture to actual contract economics.
[CI002, CI003, CI005, CI006, CI029, CI036]Shows how Keeper converts account adoption into recurring revenue through tier upgrades and add-on attach.
[CI001, CI002, CI003, CI004, CI025, CI036]Public 2024-2026 estimates span wide ranges because private-company databases and company disclosures measure different things.
[CI007, CI008, CI012, CI013]4.2 GTM motion, public traction, and unit-economics proxies
Keeper’s July 2026 disclosure materially changes the traction baseline for this report. The company now claims US$225M in ARR, more than 3x ARR growth since 2021, more than 95,000 organizations protected, average new-logo additions of 850 organizations per month, and 10x year-over-year revenue growth for KeeperPAM since its February 2025 launch. A separate 2026 PR release tied to SoftwareReviews says Keeper’s 2025 global revenue growth rate was 53.42%, or 3.45x the overall market average cited in that release. Those are company-originated figures and should not be mistaken for audited filings, but they are directionally important because they imply Keeper is no longer a subscale password-vault vendor. The go-to-market motion also appears blended rather than purely enterprise-sales driven. Business and enterprise pages emphasize deploy-in-minutes onboarding, user adoption, 24x7 support and out-of-the-box identity integrations, which suggests product-led or product-assisted entry for smaller accounts. At the same time, custom pricing for KeeperPAM, compliance-heavy public-sector positioning and broader module attach imply a classic sales-assisted motion for larger enterprise and government deals. The unit-economics picture remains incomplete. Third-party databases disagree sharply on headcount and estimated revenue, which reinforces how noisy private-company data feeds can be. Publicly, that means the strongest underwriting inputs are the company’s own recent ARR/growth claims and product pricing architecture, while the weakest are precisely the metrics investors care about most: churn, net retention, CAC, payback, segment mix and realized expansion rates.[CI007, CI008, CI009, CI010, CI011, CI012]
| Metric | Value / null | Confidence | Why it matters | Diligence ask |
|---|---|---|---|---|
| ARR milestone | US$225M ARR (company-claimed, July 2026) | medium | Provides the first strong public anchor for scale | Request auditor-reviewed ARR bridge by product family and segment |
| ARR growth since 2021 | Over 3x | medium | Supports growth durability narrative | Provide annual ARR by year-end from 2021 to 2026 with net new and expansion splits |
| New-logo velocity | 850 new organizations per month average | medium | Signals funnel strength and sales capacity | Show logo adds by segment, average first-year ARR, and conversion to paid tiers |
| KeeperPAM growth | 10x year-over-year revenue growth since February 2025 launch | medium | Suggests high-ARPU expansion path inside the platform | Show absolute ARR, gross margin and attach rate for KeeperPAM |
| 2025 global revenue growth proxy | 53.42% year-over-year in 2025 per company-cited SoftwareReviews PR | medium | Supports momentum prior to the 2026 ARR disclosure | Provide reconciled GAAP/management revenue definition behind this figure |
| Gross margin | null | low | Core margin quality remains publicly undisclosed | Provide GAAP gross margin overall and by core vaulting vs PAM vs secrets |
| CAC | null | low | Needed to test growth efficiency and compare land motions by segment | Provide blended and segmented CAC including channel-sourced deals |
| CAC payback | null | low | Critical for underwriting sales-led module expansion | Provide payback by SMB, enterprise, public sector and partner-channel cohorts |
| Net revenue retention | null | low | Required to value seat expansion and module attach within installed accounts | Provide NRR and gross retention by cohort and product family |
| Churn | null | low | Low-end password categories can hide weak paid durability | Provide logo churn and gross-dollar churn by segment |
| Headcount | Third-party estimates conflict: 506 employees (Growjo) versus 795 (Tracxn) | low | Conflicting headcount undermines outside cost and productivity modeling | Provide current FTEs by function and geography |
| Working capital burden | Likely light, but undisclosed | medium | Software model should be less working-capital intensive than hardware or transaction businesses | Provide deferred revenue, billing cadence, DSO/DPO and collections metrics |
The nulls are the real blockers. Public growth signals are useful, but they do not replace retention, margin or cash-efficiency disclosure.
[CI007, CI008, CI010, CI011, CI012, CI013]Public evidence supports growth and attach-rate proxies, but the core SaaS efficiency metrics remain undisclosed.
[CI007, CI008, CI009, CI010, CI028, CI040]4.3 Cost structure, capital adequacy, and financial verdict
The most defensible inference about Keeper’s cost structure is what it is not. This is not a hardware, payments or inventory business. Its products are cloud software, client apps, identity integrations, secrets workflows and privileged-session controls, so the likely primary cost buckets are engineering, cloud infrastructure, security operations, compliance, customer success and go-to-market. Public identity-software comparables help bound the shape of those economics even if they do not prove Keeper’s own margins. Okta’s fiscal 2026 results show approximately 77% GAAP gross margin, sales and marketing expense equal to roughly 35% of revenue, R&D at roughly 22% of revenue, and free-cash-flow margin around 30%. That is a useful benchmark for what scaled identity SaaS can look like: high gross margins, heavy but manageable sales investment, and strong cash generation once scale is reached. Keeper’s own July 2026 PR says the company combines profitability with a debt-free capital structure, which is directionally positive for capital adequacy. Insight’s 2020 US$60M growth investment and Summit Partners’ 2024 minority investment also suggest Keeper has not obviously needed distressed financing to reach its current stage. But none of that substitutes for current cash, burn or runway disclosure. The financial verdict is therefore favorable on revenue quality and likely margin shape, cautiously positive on capital adequacy direction, and still blocked on the most decision-critical private metrics. Put simply: Keeper now looks like a growthy, subscription-heavy identity platform with credible enterprise scale, but the public record is still too thin to underwrite efficiency or downside protection with confidence.[CI016, CI020, CI021, CI022, CI026, CI028]
| Cash on hand | Monthly burn | Runway months | Planned use of funds | Next-round trigger | Debt / project-finance obligations |
|---|---|---|---|---|---|
| Undisclosed publicly | Undisclosed publicly | Undisclosed publicly | Historically: 2020 growth capital for expansion; 2024 minority investment; 2026 emphasis on AI-native identity, PAM and platform expansion | Not publicly disclosed; company frames optionality for a public offering rather than emergency financing | July 2026 PR says debt-free capital structure; no public project-finance obligations identified |
Capital direction is better than capital proof. Public sources suggest no obvious near-term distress, but current cash, burn and runway are still private.
[CI021, CI022, CI023, CI024, CI030]| Missing private metric | Impact | Exact diligence path |
|---|---|---|
| ARR decomposition by product and segment | Without it, the sustainability of the 2026 ARR milestone cannot be separated into core vaulting, PAM, secrets, MSP and public-sector contributions | Request ARR by segment, product family, geography and customer-size cohort for 2024-2026 |
| GAAP gross margin and hosting/support cost structure | Prevents direct judgment on software margin quality and scalability | Request audited gross margin overall and by core vaulting, secrets and PAM |
| CAC, payback and channel economics | Blocks any credible view of growth efficiency and partner leverage | Request CAC/payback by acquisition channel and contract band, including reseller economics |
| NRR, churn and expansion by cohort | Makes cross-sell durability and downside risk unknowable | Request retention cohorts for SMB, enterprise, public sector and MSP accounts |
| Cash balance, burn and runway | Leaves solvency and financing dependency unproven despite positive directionality | Request monthly burn, unrestricted cash, debt facilities and minimum liquidity targets |
| Public-sector revenue share | Keeps compliance-led moat financially unquantified | Request ARR, bookings and retention for government and regulated verticals |
These are ordinary private-company disclosures, but they remain decisive for investor-grade underwriting.
[CI015, CI021, CI024, CI028, CI030, CI040]Keeper appears to have software-like capital intensity, but the public record leaves the cash position and efficiency bridge incomplete.
[CI016, CI019, CI020, CI021, CI022, CI030]4.4 Exhibits
05Product & Technology
5.1 Product surface and operator workflow
Keeper’s public product map now spans three layers. The base layer remains employee and consumer vaulting: secure password, passkey, file and confidential-data storage with policy controls, browser/mobile coverage, and enterprise administration. The second layer is machine and privileged access: KeeperPAM, Keeper Secrets Manager, and Keeper Connection Manager together cover secrets, credential rotation, discovery, browser-based remote access, tunnels, session recording and zero-trust access workflows. The third layer is regulated and specialized packaging: Government Cloud for public-sector buyers, BreachWatch for compromised-credential monitoring, and a rapidly growing integration catalog that now includes AI-agent environments, CI/CD tools, major identity providers and cloud services. The most important product conclusion is architectural, not just categorical: Keeper is trying to make the vault the shared control plane for both human and machine identity workflows. That gives the company a coherent cross-sell story because passkeys, secrets, remote sessions and policy enforcement all inherit the same admin and encryption posture. It also means later products are judged against the trust standard of the core vault, which raises the bar for operations, detection quality and release discipline. Packaging breadth matters here because Keeper can now sell the same trust story into workforce, developer, privileged-admin and public-sector contexts.[CE001, CE002, CE003, CE004, CE005, CE006]
| Module | Primary user / workload | Delivery model | What it does | Current diligence read |
|---|---|---|---|---|
| Business / Enterprise vault | Workforce users and IT admins | SaaS vault plus browser, desktop and mobile clients | Passwords, passkeys, files, sharing, admin policy, SSO/SCIM/RBAC | Mature core platform and the base layer for adjacent modules |
| KeeperPAM | Security, IT, DevOps and infrastructure teams | Cloud-native access control plane with gateway pattern | JIT access, session brokering, discovery, rotation, session monitoring and privileged workflows | Expansion engine and the clearest product-scope shift beyond vaulting |
| Keeper Connection Manager | Sovereignty-sensitive, self-hosted or air-gapped deployments | Self-hosted Docker-based remote access gateway | Browser-based RDP, SSH, VNC, K8s, database and internal web access with recording | Differentiated deployment option but operationally heavier |
| Keeper Secrets Manager | DevOps, software engineering and machine identity workflows | Fully managed cloud service with SDKs, CLI and integrations | Infrastructure secrets, API keys, certificates, service-account rotation and CI/CD injection | Strong machine-identity adjacency to the core vault |
| BreachWatch | End users and admins monitoring compromised credentials | Add-on feature inside Keeper clients | Local scans and dark-web / breach monitoring for records in vault | Mature adjunct security feature, not a standalone platform |
| Government Cloud (KSGC) | Federal, state, local and contractor workloads | AWS GovCloud-based regulated offering | Passwords, secrets, session monitoring, secure remote access and compliance framing | Important regulated wrapper around broader Keeper stack |
| Passkey management | Consumers, workforce users and admins | Native vault capability across clients | Save, sync, autofill and share passkeys with biometric unlock support | Extends vault relevance into passwordless workflows |
Rows enumerate the public Keeper modules and packaging layers most material to product diligence as of 2026-08-13.
[CE001, CE002, CE003, CE004, CE005, CE006]| User segment | Job to be done | Keeper workflow | Control benefit | Limitation / diligence ask |
|---|---|---|---|---|
| Workforce employee | Store credentials and sign in safely | Vault + browser/mobile autofill + MFA/passkeys | Reduces reuse and centralizes org policy | Need actual adoption and daily-active usage by tier |
| Infrastructure admin | Reach sensitive servers and databases without sharing credentials | KeeperPAM or KCM launches browser-based sessions, tunnels or native-tool access | Supports JIT, session recording and credential-free access | Need session scale, latency and uptime metrics |
| DevOps / platform engineer | Inject secrets into automation and apps | KSM CLI / SDK / CI-CD integrations pull secrets into pipelines | Removes hard-coded secrets and centralizes audit trails | Need attach rates and rotation coverage by environment |
| Government operator | Meet zero-trust and federal compliance controls | KSGC in AWS GovCloud with PIV/CAC, SIEM and regulated packaging | Improves sovereignty and compliance fit | Need current ATO package depth and deployment references |
| Security team | Detect weak or compromised credentials | BreachWatch scans locally and alerts on breached passwords | Adds monitoring without moving plaintext passwords to Keeper servers | Need measured remediation rates and alert efficacy |
| Developer using AI tools | Give agents secure access to credentials without pasting secrets into chat | Keeper Agent Kit / integrations connect secrets workflows into Claude Code, Copilot, Codex and MCP contexts | Extends Keeper into agentic workflows with RBAC and audit logging | Need production adoption and guardrail-performance data |
The table captures the main human, machine and regulated workflows visible from official pages and docs.
[CE002, CE003, CE004, CE006, CE008, CE020]The privileged workflow centers on policy-controlled access from the Keeper vault into target systems without exposing standing credentials to end users.
[CE020, CE021, CE023, CE033]5.2 Architecture, encryption, deployment and trust controls
The technical core is unusually explicit for a private software company. Keeper’s security architecture page describes client-side record and folder keys, PBKDF2 with one million iterations for master-password flows, ECC-based device approval for SSO and passwordless flows, AES-256 GCM for stored data, TLS 1.3 plus payload wrapping in transit, and a Q1 2026 rollout of an additional quantum-resistant wrapper on transmission keys. That same source, the user guides, and the enterprise guide all reinforce the central claim that Keeper employees cannot decrypt customer data because encryption and decryption occur locally on approved devices. On deployment, KeeperPAM uses a cloud access control plane with lightweight outbound gateway patterns, while Keeper Connection Manager exists for customers that need a fully self-hosted, in-network or air-gapped browser-based gateway. That flexibility is strategically valuable: it widens Keeper’s fit across commercial cloud, hybrid and regulated-government environments. But it also creates more operating modes to secure. Self-hosted KCM introduces Docker, SSL, database and patch-management obligations for customers, while cloud-hosted flows still depend on device trust, browser extension behavior and identity-provider integrity. The architecture looks strong and differentiated; the attack surface is broader than a simple vault product.[CE009, CE010, CE011, CE012, CE013, CE014]
| Layer | Components / design | Evidence | Strength | Risk / unknown |
|---|---|---|---|---|
| Client crypto | Record keys, folder keys, user data key, local cache key, device-local encryption/decryption | Security architecture page | Strong least-privilege and blast-radius reduction story | Need independent architecture review and key-handling audit |
| Authentication and device approval | PBKDF2 for master-password flow; ECC-256 device keys and DEDK for SSO/passwordless | Security architecture page | Clear separation between login modes with explicit device trust model | Endpoint compromise or extension compromise remains critical |
| Hosted access plane | Cloud-native KeeperPAM plus outbound gateway model and no ingress requirement | KeeperPAM page and docs | Easier deployment than bastion-heavy legacy approaches | Public reliability and scale data absent |
| Self-hosted access gateway | KCM Docker deployment with Guacamole, NGINX, Tomcat and supported DBs | KCM overview and security docs | Useful for air-gapped and in-network control needs | Customer owns more patching, SSL and DB posture |
| Machine secrets layer | KSM SDKs, CLI, REST and CI/CD integrations | Secrets pages and developer docs | Broad automation surface for machine identity | Need attach and rotation-depth data by customer segment |
| Trust and recovery layer | Record versioning, backups, recovery phrase, admin policy controls | Security page and guides | Strong data-resilience posture on paper | Recovery operations and support-driven restores are not quantified publicly |
| Government packaging | AWS GovCloud deployment with regulated identity and compliance claims | Government page plus AWS GovCloud context | Extends fit into high-control public-sector workloads | Exact authorization package and workload reference depth not public |
Public sources are detailed enough to map Keeper’s major operating layers, but not enough to test them empirically.
[CE009, CE010, CE011, CE012, CE013, CE014]| Control area | Current public evidence | Confidence | Why it matters | Gap |
|---|---|---|---|---|
| Zero-knowledge design | Device-local encryption/decryption and no employee decryption access claims | high | Core differentiator versus simpler cloud credential stores | Need current third-party validation under NDA |
| Cryptographic controls | AES-256, ECC, PBKDF2 1,000,000 iterations, TLS 1.3, payload wrapping, QRC rollout claim | medium | Establishes concrete technical trust model | Need module-boundary mapping and implementation review |
| Compliance certifications | SOC 2 Type 2, ISO 27001/27017/27018, FedRAMP High messaging, GovRAMP High messaging | medium | Supports enterprise and government procurement | Need certification reports and scope boundaries |
| FIPS evidence | Security page cites FIPS 140-3 cert | medium | Important for federal and regulated buyers | Need product-to-module mapping and current certificate applicability |
| Security testing and disclosure | Quarterly pen tests, Bugcrowd-managed VDP, historical advisories | high | Shows active vulnerability-management process | Need most recent test summaries and remediation SLAs |
| Logging and auditability | Session recording, SIEM integration and admin event reporting across PAM flows | high | Critical for privileged-access governance | Need retention defaults, storage costs and investigation workflow detail |
Trust posture is one of Keeper’s stronger public product assets, but some claims still depend on company-authored materials rather than independently inspectable reports.
[CE009, CE013, CE016, CE017, CE018, CE019]Keeper’s public architecture now stacks a zero-knowledge vault, privileged-access control plane, secrets tooling, and optional self-hosted gateway modes on top of shared admin and compliance controls.
[CE001, CE002, CE004, CE009, CE015, CE021]Keeper’s flexibility comes from mixing cloud-native control with self-hosted components and endpoint trust anchors, which broadens fit but widens operational dependencies.
[CE015, CE027, CE028, CE033, CE034, CE035]5.3 Engineering signal, release velocity and technical-risk verdict
Public engineering signal is solid, though not fully open. Keeper’s documentation portal shows frequent mid-2026 updates across backend APIs, web vault, mobile clients, browser extensions, Commander, SDKs, gateway components, admin console and database-management modules. The GitHub organization exposes meaningful but selective developer surfaces: Commander, Secrets Manager, PowerCommander, a GitHub Action and a Terraform provider all point to real programmability and ecosystem reach, but they do not imply the full platform is open. This is a healthy pattern for a commercial security vendor: enough public code and SDK evidence to validate automation depth, not enough to assume product transparency everywhere. The main technical-risk signals are also public. Keeper Connection Manager carries a visible historical advisory list, and OpenCVE still indexes client-edge issues affecting adjacent products such as KeeperChat and KeeperFill. That does not negate the platform’s maturity; it simply shows Keeper is a real security software company with a broad estate and therefore a normal vulnerability-management burden. The release stream also matters commercially: frequent updates across user clients, gateways and developer tooling suggest Keeper is funding platform upkeep rather than simply harvesting a legacy vault franchise. The product-tech verdict is favorable. Keeper appears technically ahead of the “password manager” label, with credible infrastructure for secrets and privileged access, but diligence should still demand live reliability data, independent current test results and usage adoption by module before underwriting the newest AI and government-control surfaces.[CE024, CE025, CE026, CE029, CE030, CE031]
| Surface | Public signal | 2026 maturity read | Why it matters | Missing proof |
|---|---|---|---|---|
| Web Vault / Desktop / Browser / Mobile | Frequent 2026 releases across client surfaces | Mature | Core UX and password/passkey footprint is actively maintained | Need crash, retention and upgrade-friction metrics |
| Keeper Gateway / KCM / KeeperDB | Multiple summer-2026 releases in gateway and DB-related components | Mature to expansion | Signals operational investment in privileged workflows | Need deployment counts and incident rates |
| Commander / SDKs / CLI | Release notes plus public GitHub repos and docs | Mature | Strong programmability and admin automation signal | Need usage by enterprise segment and support burden |
| Secrets Manager ecosystem | SDK docs, integrations catalog, GitHub repo and Terraform / Actions references | Mature to expansion | Important machine-identity wedge | Need paid adoption, rotation coverage and NHI growth |
| AI/agent integrations | Integrations page now lists Claude Code, Codex, Cursor, Copilot and MCP workflows | Early expansion | Extends Keeper into new developer workflow budgets | Need production references, abuse controls and detection efficacy |
| Government Cloud packaging | Strong marketing and compliance framing | Expansion | Potentially high-value regulated segment | Need live customer references and authorization-package detail |
Release activity and public repos show engineering motion, but adoption and reliability remain private.
[CE024, CE025, CE026, CE032, CE037]Keeper’s public product surfaces look most mature in vaulting, session access and automation, with newer expansion areas in AI-agent and some regulated-use workflows.
[CE024, CE025, CE032, CE037]5.4 Exhibits
06Customers
6.1 Customer segments, scale and named-customer coverage
Keeper’s visible customer map spans at least seven meaningful segments. At one end are consumer individuals and families using the cross-device vault, secure sharing and BreachWatch surfaces; app-store ratings, family-plan packaging and repeated references to “millions of people” support a large long-tail user base. In the middle are SMB and mid-market business customers using the core enterprise password platform with SSO, SCIM, reporting and secure sharing. At the upper end are enterprise and highly regulated buyers that care about privileged access, secrets, session monitoring and audit controls. Public-sector, higher-education and nonprofit users are clearly real subsegments rather than marketing abstractions: New Mexico’s Taxation and Revenue Department, Illinois College, Oregon State University and Alzheimer’s Association all appear in Keeper’s case-study inventory, and Government Cloud messaging reinforces dedicated public-sector positioning. MSP/channel demand is also visible through the Lucidica and KeeperMSP materials, where the buyer is the service provider and the downstream users are both the MSP staff and managed clients. Finally, a technical operator segment now sits on top of the base vault business: Asite, Williams and Nokia highlight buyers who need privileged sessions, secrets, credential brokering or remote-access infrastructure rather than only employee password storage. The important conclusion is that Keeper is not dependent on one mono-segment customer story. Its reference set spans commercial, education, finance, public sector, telecom, legal and managed services, which argues for broad utility and low obvious single-vertical concentration.[CU001, CU002, CU003, CU004, CU005, CU006]
| Segment | Buyer / user / payer | Use case | Public scale signal | Strategic value | Gap |
|---|---|---|---|---|---|
| Consumer individual | Individual = buyer / user / payer | Passwords, passkeys, private vault, secure files, dark-web monitoring | Millions of people; 229K iOS ratings; 111K Android ratings | Brand, funnel and broad data set for product direction | Paid conversion and churn are private |
| Families / household | Household organizer = payer; family members = users | Shared household credentials and emergency access | Publicly bundled and linked to business-family benefit | Retention enhancer and consumer expansion path | Family attach and renewal rates are private |
| SMB / mid-market business | IT/admin = buyer; employees = users; company = payer | Shared vaults, admin controls, SSO, compliance and reporting | Material subset of 95,000+ orgs | Core land motion and seat-expansion engine | Segment mix and realized ASP are private |
| Enterprise / regulated commercial | Security / IT / compliance = buyer; workforce = users | SSO/SCIM, audit, secrets, privileged access, policy enforcement | Many Fortune 500 enterprises cited by company | Premium contract and module-attach opportunity | Top-account concentration and retention are private |
| Public sector / education / nonprofit | Agency/CIO/IT leadership = buyer; staff and students = users | Government Cloud, credential management, remote access, compliance | New Mexico, Illinois College, Oregon State, Alzheimer’s Association | Strong trust/compliance wedge | Current contracted ARR by public sector is private |
| MSP / channel | MSP leadership = buyer / payer; MSP staff + managed clients = users | Multi-tenant password governance and client credential sharing | Lucidica and KeeperMSP references | Can multiply seats downstream across customer portfolios | Channel revenue share and partner concentration are private |
| Privileged-access / developer / ops buyers | Security/platform/infra team = buyer; admins and developers = users | PAM, secrets, tunnels, secure remote access, session recording | Williams, Asite, Nokia and New Mexico KCM use cases | Higher-value expansion beyond core vaulting | Attach rate and renewal depth are private |
Customer segments compiled from Keeper’s 2025-2026 product, review and case-study surfaces.
[CU001, CU002, CU003, CU006, CU007, CU009]| Customer | Segment | Deployment / use case | Production vs pilot | Outcome / proof point | Limitation |
|---|---|---|---|---|---|
| Atlassian Williams F1 Team | Enterprise / technical ops | KeeperPAM for privileged access across global workforce and race operations | Production | Workforce operating in 20+ countries; security + usability quote from former head of security | No contract value or seat count disclosed |
| Asite | Global SaaS / enterprise | Passwords, secrets and PAM unification | Production | 500+ employees, 9 data centers, replaced costly/complex legacy tools | Case study is company-authored |
| Lucidica | MSP / channel | KeeperMSP plus BreachWatch for employees and managed client users | Production | Supports dozens of organizations and hundreds of managed users; sync and sharing issues eliminated | No downstream customer revenue disclosed |
| Illinois College | Higher education | Enterprise password manager with SSO, provisioning and MFA | Production | Significant decrease in help-desk tickets and growing student adoption | No renewal or active-user percentage disclosed |
| Peak Trust | Financial services / trust company | Shared folders, compliance reporting and board-level use | Production | FFIEC reporting support, sister-company and board-user expansion | Case dates to 2022 |
| Oregon State University | Higher education | Shared password vault for consolidated IT teams | Production | 4,500+ employees; improved security scorecard and high adoption among non-technical staff | Current 2026 usage not public |
| NokiaEDU | Telecom / training | KCM for remote training labs | Production | Thousands of students monthly; clientless remote access and geo-redundancy benefits | KCM case is older and product lineage evolved |
| New Mexico Taxation and Revenue Department | State government | KCM for mass secure remote desktops | Production | 700+ employees enabled in under a week with secure browser-based access | Case originates from pandemic-era remote-work need |
| Alzheimer’s Association | Nonprofit / healthcare-adjacent | Credential management modernization | Production | Named nonprofit proof expands vertical diversity | Extracted outcome detail is thinner than newer cases |
| Global UK technology services provider | Large enterprise | Unified password management across 11,000+ employees | Production | Smooth implementation, high user adoption and stronger compliance visibility | Customer name withheld, reducing reference quality |
Named proof is broader than typical for a private cyber vendor and spans both legacy vaulting and newer PAM / KCM use cases.
[CU007, CU014, CU015, CU016, CU017, CU018]The dominant Keeper journey runs from insecure or fragmented credential habits into centralized vault adoption, then expands into higher-control features such as SSO, secrets, PAM, family spillover or public-sector deployment.
[CU001, CU011, CU012, CU028, CU031, CU038]Named customer proof is strong across segment diversity and production evidence, but freshness and financial depth vary materially by reference.
[CU014, CU015, CU016, CU017, CU018, CU019]6.2 Adoption trajectory, deployment patterns and satisfaction proxies
Public adoption evidence is imperfect but directionally strong. Keeper’s July 2026 PR says the company protects more than 95,000 organizations and is adding roughly 850 new organizations per month, while the December 2025 G2 blog cites 1,172 total reviews, 94% satisfaction on meeting requirements and a 92% recommendation rate. A later company blog tied to G2 states that over 100,000 organizations choose Keeper, which should be read as a newer publication point rather than a clean contradiction to the 95,000+ figure. External review platforms broadly echo this positive picture. GetApp shows 507 verified reviews and 82% positive retention sentiment; G2 review excerpts emphasize fast rollout, SSO/SCIM automation, cross-device sync and admin usability; TrustRadius- and SourceForge-style listings surface high overall ratings and recurring praise for secure sharing, auditability and ease of use. The named case studies also show real deployment depth rather than shallow logo lending. New Mexico moved 700+ employees to secure remote desktops in less than a week. Nokia uses KCM for thousands of students per month. Illinois College reports a significant decrease in help-desk tickets and growing student adoption. Asite standardized passwords, secrets and PAM across a 500+ employee global SaaS workforce and nine data-center locations. These are production deployments with explicit outcomes, not abstract testimonials. The limits are also visible. None of these sources discloses active daily users, seat penetration per account, deployment success rates across the full base or renewal curves by cohort. So adoption strength is evident, but precision is not.[CU003, CU005, CU006, CU011, CU012, CU013]
| Metric | Value | Date | Source | Confidence | Implication | Missing denominator |
|---|---|---|---|---|---|---|
| Organizations protected | 95,000+ | Jul 2026 | ARR PR | medium | Strong installed-base anchor | Active seats per organization |
| Public company count on later surface | 100,000+ organizations choose Keeper | Dec 2025 blog snapshot | G2 Winter 2026 blog | medium | Suggests scale at least high-five-figure and rising | Exact count methodology and update lag |
| New organizations added monthly | 850 average per month | Jul 2026 | ARR PR | medium | Signals continued new-logo momentum | Conversion to meaningful ARR and retention |
| G2 review count | 1,172 total reviews | Dec 2025 | Keeper G2 blog | medium | Large social-proof base for password product | Segment and geography skew |
| iOS rating base | 229K ratings, 4.9/5 | Aug 2026 store snapshot | Apple App Store | medium | Strong consumer/mobile engagement proxy | Paid-vs-free and business-user overlap |
| Android rating base | 111K ratings, 4.7/5 | Aug 2026 store snapshot | Google Play | medium | Large Android footprint and ongoing consumer usage | Paid-vs-free and business-user overlap |
| GetApp verified reviews | 507 | Jul 2026 | GetApp | medium | Broad SMB/mid-market review evidence | Review self-selection bias |
| Nokia training throughput | Thousands of students each month | 2022 case study | Nokia KCM case | medium | Confirms repeat-use remote-access deployment at scale | Current 2026 volume not public |
| New Mexico rollout | 700+ remote desktops in less than a week | 2020 case; still cited in 2022 PDF | New Mexico case | medium | Shows rapid deployment in public sector | Long-term seat retention not public |
| Illinois College footprint | 300 employees and growing student adoption | 2026 case study | Illinois College case | medium | Evidence of campus-wide land-and-expand | Active-student adoption percentage |
| Asite workforce footprint | 500+ employees across 9 data-center locations | 2026 case study | Asite case | medium | Confirms global mid-market / enterprise fit | Deployed-seat depth and modules in use |
Public adoption evidence is strongest on gross customer count, review volume and selected deployment stories; seat depth and retention remain private.
[CU003, CU005, CU006, CU012, CU013, CU016]| Metric | Value / null | Segment | Confidence | Diligence ask |
|---|---|---|---|---|
| G2 recommendation rate | 92% | Password-manager users | medium | Break out by SMB vs enterprise and disclose sample size trend in 2026 |
| G2 requirement satisfaction | 94% | Password-manager users | medium | Provide cohorted admin vs end-user satisfaction and net change since 2025 |
| SoftwareReviews likelihood to recommend | 93% | KeeperPAM users | medium | Provide raw respondent count and enterprise-size mix |
| SoftwareReviews fair cost-to-value | 87% | KeeperPAM users | medium | Show win/loss and renewal pricing sensitivity by segment |
| GetApp positive retention sentiment | 82% | Mixed customer base | medium | Reconcile sentiment with actual logo and dollar retention |
| NRR | not disclosed | All business segments | low | Provide NRR by SMB, enterprise, public sector and MSP |
| GRR | not disclosed | All business segments | low | Provide GRR by product family and cohort |
| Logo churn | not disclosed | All segments | low | Provide annual logo churn and top drivers |
| Contract length / renewal mix | not fully disclosed | Business and enterprise | low | Provide monthly vs annual vs multi-year mix by segment |
| Active-seat utilization | not disclosed | Business and enterprise | low | Provide deployed seats, MAU/DAU and admin engagement by customer size |
| Consumer repeat usage | inferred from large app-store rating bases | Consumer | low | Provide monthly active consumer vaults and paid conversion |
Satisfaction is public; retention economics are not.
[CU022, CU023, CU024, CU026, CU027, CU031]Illustrative funnel showing how Keeper can move from awareness into vault rollout and then into higher-value module adoption. Absolute conversion rates are private; values below are directional analyst placeholders.
[CU011, CU012, CU028, CU038]6.3 Retention, expansion, concentration and customer verdict
Keeper’s customer quality looks promising, but the public record still stops short of investor-grade retention proof. Expansion vectors are easy to see: per-seat growth inside business and enterprise accounts, business-to-family spillover, Secrets Manager and KeeperPAM attach, public-sector upsell through Government Cloud, and MSP-style downstream seat multiplication through service-provider customers. Review sources and case studies also hint that easy implementation matters commercially because low-friction rollout improves both adoption and renewal odds. At the same time, public adverse signals are real and should not be ignored. G2, GetApp and Slashdot-style reviews repeatedly mention high or confusing pricing, price increases, add-on fatigue, autofill inconsistency, reporting gaps and some admin-console or standalone-app limitations. Those complaints are not severe enough to suggest a trust crisis, but they do point to the practical areas where churn or procurement friction can accumulate, especially in smaller or cost-sensitive accounts. Concentration risk is still mostly unknowable publicly. The reference set is diverse across verticals and geographies, which argues against extreme dependence on any one sector, but top-10 customer revenue, top-customer seat counts and module-specific renewal performance are all private. Freshness is mixed too: some KCM references date back to 2022, while many password-manager and KeeperPAM references are 2025-2026. The overall customer verdict is therefore favorable but incomplete: Keeper appears to have a diversified installed base with real production references and good customer sentiment, yet the key durability metrics — NRR, GRR, churn, renewal pricing behavior and concentration — remain unverified in public evidence.[CU025, CU026, CU027, CU028, CU029, CU030]
| Expansion driver | Concentration / friction risk | Impact | Diligence path |
|---|---|---|---|
| Per-seat expansion inside business and enterprise | Seat penetration and seat contraction rates are private | Core ARR growth driver likely meaningful but unverified | Request seat cohorts by initial deal size and annual expansion |
| PAM and Secrets Manager attach | Module attach rates not public | High-value cross-sell may materially raise ARPU | Request attach by segment, product family ARR and renewal rates |
| Business-to-family spillover | Unknown true conversion or retention lift | May increase adoption and reduce employee resistance | Request usage, conversion and retention delta for family-plan users |
| Public-sector and education growth | Procurement cycles and contract concentration are private | Could improve durability but lengthen sales cycles | Request win rates, cycle length and ARR share by regulated buyers |
| MSP/channel expansion | Downstream client concentration and partner dependence private | Can multiply distribution efficiently, but partner churn could bite | Request top-partner revenue share and downstream seat distribution |
| Pricing and add-on friction | Repeated review complaints about pricing changes, add-ons and reporting extras | Can slow expansion or complicate renewal | Request renewal uplift, discount history and loss reasons by segment |
| Vertical concentration | Public references are diverse, but top-customer revenue is unknown | Diversification appears favorable yet cannot be proven financially | Request top-10 customer revenue concentration and contract terms |
The visible customer story supports expansion potential, but public concentration evidence is qualitative rather than financial.
[CU025, CU028, CU029, CU030, CU032, CU036]Estimated retention cohorts for Keeper segments over 24 months. Keeper does not publish actual NRR/GRR or cohort curves; these values are directional estimates based on deployment stickiness, review sentiment and segment behavior.
[CU026, CU027, CU035, CU036]6.4 Exhibits
07Risks
7.1 Regulatory, legal and trust risk
The defining legal and regulatory risk is trust failure under a compliance-heavy go-to-market. Keeper markets into FedRAMP High, GovRAMP High, FIPS, SOC 2, ISO and NIST-aligned buying contexts, and it explicitly positions itself as the control plane for privileged identities, secrets and AI agents. That raises the consequence of any certification lapse, disclosure error or security incident. The company’s public materials correctly frame many of these controls as differentiators, but the same positioning means they can become downside multipliers. A vulnerability in a remote-access component, a failure in device approval, or a disputed data-handling issue can quickly turn into procurement friction, delayed renewals or legal scrutiny because buyers are not purchasing a low-stakes consumer utility — they are buying a trust and compliance system. Public evidence already shows that Keeper is not risk-free. The Connection Manager advisories page lists historical CVEs, including a high-severity SAML validation issue, and OpenCVE tracks additional Keeper-related client or adjacent-product issues. None of this proves a current platform weakness, but it does prove the normal reality of a large attack surface. The mitigating counterweight is substantial: zero-knowledge design, quarterly testing, Bugcrowd disclosure, region isolation and explicit cryptographic controls. The legal/regulatory verdict is not that Keeper is unusually fragile; it is that the business has chosen regulated, high-control customer segments where the penalty for any trust miss is disproportionately large.[CR001, CR002, CR003, CR004, CR005, CR006]
| Rule / case / obligation | Jurisdiction | Status | Likelihood | Severity | Mitigation | Residual exposure | Diligence path |
|---|---|---|---|---|---|---|---|
| FedRAMP / GovRAMP / FIPS / regulated-control claims | US federal and SLED | Active strategic differentiator | Medium | High | Dedicated compliance posture, Government Cloud packaging, published control claims | Any certification lapse or scope mismatch could impair public-sector pipeline | Request current authorization packages, scope docs and renewal calendar |
| Vulnerability disclosure and incident response | Global | Ongoing operational requirement | High | High | Bugcrowd program, quarterly testing, advisories page, published security model | A severe trust incident would quickly hit procurement, renewals and valuation | Request latest incident metrics, response SLAs and pentest summaries |
| Privacy / identity / audit obligations | US, EU and global enterprise buyers | Ongoing | Medium | High | Zero-knowledge design and audit controls reduce plaintext exposure | Misstated control boundaries or customer misuse could still trigger scrutiny | Request DPA templates, retention defaults and privacy incident history |
| Export / public-sector handling obligations | US and global | Ongoing | Low-Medium | Medium | Published compliance posture and export references in security docs | Breach or control error in sensitive workloads raises consequence severity | Review export-classification and sensitive-workload governance processes |
Rows ordered by residual severity rather than by existence of current enforcement actions.
[CR001, CR002, CR003, CR004, CR005, CR006]7.2 Operational, dependency and people risk
Operationally, Keeper has broadened beyond the simpler failure modes of a classic password manager. The platform now spans cloud-hosted vaulting, outbound gateway patterns, self-hosted Connection Manager, secrets tooling, privileged sessions, AI monitoring and public-sector variants. That breadth is strategic, but it widens execution exposure. The most visible dependency risks sit with AWS and GovCloud infrastructure, enterprise IdPs, browsers, mobile operating systems, app stores and the Apache Guacamole lineage underneath KCM. For self-hosted customers, Keeper also inherits a subtle brand risk from environments it does not fully control: if a customer misconfigures SSL, lags database patches or mishandles upgrades in KCM, the operational incident can still be emotionally attributed to Keeper. Review sources add another operational signal: customers repeatedly praise ease of deployment but also mention pricing complexity, reporting gaps, autofill inconsistency and some admin-console friction. These are not existential problems, yet they are exactly the kind of annoyances that can compound at scale if new-logo velocity remains high. The people dimension is similarly important. Founder continuity is a strength, but it also means key-person dependence remains meaningful in the company’s external narrative and product direction. Rapid platform expansion requires deep benches in security engineering, support, compliance, public-sector operations and product management; public sources do not prove those benches are weak, but they also do not prove succession depth or organizational redundancy. The main operational read is therefore a classic scaling risk: Keeper’s product breadth is becoming a strategic asset and a coordination burden at the same time.[CR014, CR015, CR016, CR017, CR018, CR019]
| Failure mode | Likelihood | Severity | Mitigation maturity | Residual exposure | Unresolved gap |
|---|---|---|---|---|---|
| Material breach of vault, secrets or privileged-session trust | Medium | Very High | High | Trust contagion across entire platform | Need current independent test evidence and incident history |
| KCM / self-host misconfiguration or unpatched deployment | Medium | High | Medium | Customer-managed environments can still damage Keeper’s reputation | Need install-base mix, upgrade adherence and support burden data |
| Client / extension / device-approval edge-case vulnerability | Medium | High | Medium | Zero knowledge does not eliminate endpoint or extension risk | Need endpoint incident patterns and patch latency data |
| AI monitoring false positives / false negatives | Medium | Medium-High | Low-Medium | Could reduce trust in new premium surfaces | Need benchmark accuracy and production adoption data |
| Release-velocity regression or quality slip from platform sprawl | Medium | Medium-High | Medium | Many products now ship quickly across multiple surfaces | Need defect escape rates and rollback metrics |
| Support / onboarding strain at current growth rate | Medium | Medium | Medium | 850 new organizations per month can pressure CS, support and training | Need support ratios, implementation times and backlog data |
Residual ratings are directional and synthesize public evidence rather than disclosed incident frequencies.
[CR009, CR010, CR011, CR014, CR015, CR020]| Dependency | Counterparty | Role | Concentration | Failure scenario | Severity | Mitigation | Residual exposure |
|---|---|---|---|---|---|---|---|
| Cloud hosting and sovereign regions | AWS / AWS GovCloud | Core hosting substrate and regulated deployment environment | High | Outage, regional issue or commercial change affects availability or public-sector positioning | High | Multi-region posture and GovCloud specialization | Material availability and procurement dependence remains |
| Enterprise authentication layer | Customer IdPs / SSO / SCIM ecosystems | Access and provisioning dependency | High | SAML/OIDC issue, SCIM drift or IdP outage blocks access or provisioning | High | Device approval, admin controls and integration breadth | Upstream identity dependency remains structurally important |
| Browser / OS / app-store distribution | Apple, Google, browser vendors | Client delivery, autofill, passkeys and mobile reach | High | Platform-policy or API changes degrade UX or consumer/business adoption | Medium-High | Cross-platform support and multiple clients | Native substitutes and policy changes remain a durable threat |
| Open-source remote access base | Apache Guacamole | Underlying KCM session stack | Medium | Upstream vulnerability or integration issue creates urgent patch burden | Medium-High | Keeper stewardship and monitoring of upstream issues | Open-source dependency still creates patch urgency |
| Review / analyst / reputation ecosystem | G2, GetApp, SoftwareReviews and word-of-mouth | Discovery and social proof | Medium | Sentiment deterioration slows new-logo motion | Medium | Strong current customer proof and review volume | Reputation remains path-dependent in security categories |
Concentration reflects functional criticality rather than disclosed spend share or contractual exclusivity.
[CR016, CR017, CR018, CR019, CR022, CR023]| Role / function | Dependency or gap | Likelihood | Severity | Mitigation | Diligence path |
|---|---|---|---|---|---|
| Founder leadership | CEO/CTO continuity is strategic strength but also key-person risk | Medium | High | Visible executive bench and investor-backed board | Request succession planning and delegated product / GTM ownership |
| Compliance and public-sector operations | Expanding regulated surface requires specialist process depth | Medium | High | Government Cloud, FedRAMP/GovRAMP posture and audit tooling | Request org chart and certification staffing coverage |
| Security engineering and incident response | Fast product expansion raises coordination and response demands | Medium | High | Quarterly testing, disclosure program and frequent releases | Request staffing ratios, pager model and remediation SLAs |
| Support / customer success / training | High new-logo pace may overwhelm implementation resources | Medium | Medium | Reviews currently praise support and onboarding | Request CSM coverage, support queue data and onboarding cycle times |
| Cross-product product management | Vault + PAM + KSM + AI + gov surfaces increase prioritization complexity | Medium | Medium-High | Unified control-plane narrative helps product coherence | Request roadmap governance and release-quality metrics |
Public sources show founder prominence and platform breadth, but not internal org charts or succession coverage.
[CR020, CR024, CR025, CR030, CR031]Critical dependencies sit across cloud infrastructure, upstream identity systems, client platforms and the open-source KCM stack.
[CR016, CR017, CR018, CR019, CR023]7.3 Financial/model risk, mitigations and thesis-breakers
The biggest model risk is the gap between growth narrative and underwritten durability. Keeper now has a much better public scale story than it did even a year earlier: more than 95,000 organizations protected, 850 new organizations per month, strong satisfaction metrics and a stated path toward US$1B ARR. But investors still lack the metrics that determine how resilient that growth is: NRR, GRR, logo churn, seat depth, top-customer concentration, public-sector ARR mix, CAC payback and current cash generation beyond company-claimed profitability. That missing data matters because several identified risks can transmit directly into valuation. Competitive pressure from native platform managers can compress low-end pricing. Higher-end competitors such as BeyondTrust and AWS Secrets Manager can erode attach rates or win control-heavy workloads. A security event or certification problem could slow public-sector growth and damage sales efficiency. Support strain or pricing backlash could reduce conversion or renewal quality. The good news is that Keeper also has visible mitigations: a differentiated zero-knowledge trust model, broad customer proof, regulated-market fit, review-backed usability and growing module breadth beyond pure vaulting. The core thesis-break triggers are therefore monitorable. If new-logo growth slows sharply, if PAM/Secrets attach stalls, if public review sentiment deteriorates, if a major security incident lands, or if management cannot evidence durable retention and diversified revenue during diligence, the bullish case weakens quickly. Risk here is not abstract; it is a set of identifiable transmission paths into customer growth, margin quality and exit multiple support.[CR026, CR027, CR028, CR029, CR030, CR031]
| Risk | Monitorable trigger | Threshold / event | Action implication |
|---|---|---|---|
| Security incident / trust failure | Public disclosure, major CVE or certification incident | One material breach affecting core vault / PAM trust | Recut downside case; customer and valuation risk becomes first-order |
| Growth durability | New-logo pace and module attach | Clear falloff from 850 orgs/month with weak PAM/Secrets attach | Reassess premium-growth multiple and IPO timing assumptions |
| Retention / pricing quality | Renewal friction and review sentiment | Broadening complaints on price increases, add-ons or value mismatch | Pressure test gross retention and ASP assumptions |
| Regulated-market execution | FedRAMP/GovRAMP scope or renewal slippage | Delayed or impaired public-sector authorization posture | Lower confidence in high-value government expansion |
| Operational scaling | Support backlog, implementation times, defect escape rate | Sustained deterioration despite high release cadence | Increase execution discount and margin-risk assumptions |
| Dependency shock | AWS/IdP/browser policy or outage event | Repeat availability or compatibility issue across critical surfaces | Increase platform-dependency discount and business-continuity scrutiny |
Trigger thresholds are diligence heuristics derived from public signals rather than company-guided KPI guardrails.
[CR033, CR034, CR035, CR036, CR037, CR038]Highest residual risks cluster where security incidents, compliance posture and execution quality can transmit into customer trust and valuation simultaneously.
[CR001, CR009, CR014, CR026, CR028, CR033]Keeper’s main risks propagate through trust first, then into conversion, retention, margin quality and valuation.
[CR004, CR015, CR026, CR033, CR035, CR038]7.4 Exhibits
08Valuation
8.1 Recommendation should remain track because platform proof exceeds price proof
Keeper’s product and customer proof is now strong enough that a subscale or distressed framing no longer fits the facts. The company publicly disclosed $225 million of ARR in July 2026, more than 95,000 organizations protected, 850 new organizations added per month, more than threefold growth since 2021, profitability and a debt-free balance sheet. Customer and market evidence from prior chapters also shows meaningful enterprise, public-sector and PAM adoption rather than a purely consumer password-manager story. Those are valuation-supportive facts. The problem is not company quality but underwriting depth. Public sources still do not disclose net revenue retention, gross retention, gross margin, free cash flow, top-customer concentration, public-sector ARR mix, or the cap-table and preference terms that determine whether a headline enterprise value is actually attractive to new money. Open-source funding databases also remain frustratingly incomplete, showing a limited funding history but not a clean current post-money mark. The right recommendation is therefore track / research-more, not buy: Keeper appears to be a strong private cybersecurity asset, but the public evidence does not yet support price-insensitive conviction, especially if the seller’s expectation sits materially above the low-$3B range implied by current disclosed ARR and public comps.[CV001, CV002, CV003, CV004, CV005, CV006]
| Dimension | Assessment | Why | Decision implication |
|---|---|---|---|
| Recommendation | track / research-more | Strong company-quality evidence, incomplete price support | Keep diligence active; do not underwrite on public evidence alone |
| Confidence | medium | Scale and comp evidence are decent, economics disclosure is incomplete | Use ranges and diligence gates rather than point precision |
| Risk rating | medium | Trust-sensitive category plus real competitive and disclosure risk | Size conservatively and tie work to monitorable triggers |
| Valuation stance | fair-to-full | Unicorn support is plausible, but public math struggles to support a mid-$4B ask today | Seek price discipline or richer disclosure before upgrading |
| Decision threshold | evidence-sensitive | Call should move mainly with retention, margin and cap-table disclosure | Upgrade only if durability and equity economics are proven |
| Likely exit lens | IPO or strategic optionality | Scale, profitability and category relevance are visible, timing is not | Model multiple exit paths rather than one dated outcome |
This is a price-sensitive recommendation rather than a generic view that Keeper is a high-quality company.
[CV001, CV002, CV004, CV007, CV025, CV029]| Argument | Evidence today | What would change the view |
|---|---|---|
| Thesis: Keeper is now a real scaled identity-security platform | Disclosed $225M ARR, 95k+ organizations, 850 orgs/month, profitability and broad product surface | Evidence that ARR quality or module attach is materially weaker than top-line growth implies |
| Thesis: Regulated-market and PAM exposure can justify a premium to commodity password tools | FedRAMP Certified government posture, GovRAMP High, KeeperPAM growth and enterprise proof | Loss of trust, weaker public-sector traction or weak enterprise attach economics |
| Anti-thesis: Public valuation support is incomplete | No public NRR, GRR, gross margin, concentration, cash flow or preference-stack disclosure | Management disclosure that proves durable ARR quality and clean equity economics |
| Anti-thesis: Trust and pricing issues can compress multiples quickly | Security incidents, status/uptime complexity and review-site pricing friction all matter in this category | A long clean operating record plus stronger retention and pricing-quality data |
Separates company-quality arguments from price-support arguments so the recommendation remains disciplined.
[CV001, CV003, CV004, CV005, CV006, CV007]The call turns on whether disclosed scale can overcome the still-large transparency gap around durability and equity economics.
[CV001, CV004, CV007, CV012, CV019, CV045]Keeper scores well on market, product and customer proof, but only middling on valuation support and disclosure quality.
[CV001, CV004, CV005, CV006, CV007, CV029]8.2 Comparable math supports a unicorn outcome but not automatic support for a mid-$4B price
The cleanest public framing for Keeper is to anchor on disclosed scale and then pressure-test that scale against public identity/security software multiples. The most decision-useful reference set in this run is Okta, SailPoint and CyberArk. StockAnalysis and CompaniesMarketCap imply roughly 8.5x sales for Okta, about 9.5x for SailPoint and about 15x for CyberArk using August 2026 market caps and latest disclosed trailing revenue. These are imperfect comparables: Okta is broader identity, SailPoint is an identity-governance specialist with full public-company disclosure, and CyberArk is the premium PAM comp with stronger enterprise control depth. But the set is still useful because all three operate in trust-sensitive identity/security categories and disclose far more than Keeper does. Applying the low end of that band to Keeper’s disclosed $225M ARR produces roughly $1.9B to $2.1B of enterprise value; a 12x multiple implies about $2.7B; a CyberArk-like 15x premium implies about $3.4B; and even 20x only gets to roughly $4.5B. That does not mean Keeper is overvalued at any price above $3B, because ARR is not identical to revenue and private scarcity can matter. It does mean that any valuation at or above the mid-$4B level needs management to prove materially stronger ARR, retention, margin quality or strategic scarcity than the public record currently reveals.[CV009, CV010, CV011, CV012, CV013, CV014]
| Scenario | Assumptions | Illustrative valuation logic (USD M) | Probability signal | What would support it |
|---|---|---|---|---|
| Bull | ARR rises to about 275-325, profitability holds, PAM/secrets attach strengthens and no trust shock occurs | 13x-15x => about 3,575-4,875 | Possible but not yet proven | Show NRR durability, high attach economics and clean governance/cap-table terms |
| Base | ARR stays around 225-260, growth moderates but remains healthy, margins are solid and risk posture stays stable | 9x-12x => about 2,025-3,120 | Most evidence-supported range | Verify retention, concentration and margin quality in diligence |
| Bear | ARR slips toward 180-220, pricing pressure rises or a trust/compliance issue slows growth | 5x-8x => about 900-1,760 | Real downside if disclosure or risk posture disappoints | Evidence of weaker monetization quality or renewed trust damage |
Ranges are scenario heuristics built from disclosed ARR because Keeper does not publish the revenue, retention or margin detail needed for a tighter model.
[CV013, CV014, CV015, CV016, CV017, CV018]| Comparable | Current metric set | Valuation / multiple / status | Relevance | Limitation |
|---|---|---|---|---|
| Okta | TTM revenue about $3.00B; public sec-filings infrastructure and market data support current disclosure depth | About $25.82B market cap; about 8.5x sales | Large public identity platform provides a mature-category multiple floor | Broader product scope, different margins and much richer disclosure than Keeper |
| SailPoint | TTM revenue about $1.12B; public 10-K and market data show full disclosure discipline | About $10.62B market cap; about 9.5x sales | Useful identity-security comp with current public filing support | Different product focus and stronger disclosure than Keeper |
| CyberArk | 2025 revenue about $1.36B; premium PAM leader with strategic scarcity | About $20.63B market cap; about 15x sales | Best premium control-oriented comp for KeeperPAM and regulated workloads | Larger enterprise control depth and premium strategic positioning |
| Keeper public context | Disclosed ARR $225M, profitability, debt-free status and strong customer-growth narrative, but no public NRR / GRR / margin detail | Supports unicorn plausibility, but direct support for a mid-$4B price is incomplete | Closest business-model fit because it is the target asset | Private-company opacity makes exact multiple selection fragile |
Uses the most decision-useful public identity/security references in this run instead of pretending there is a perfect Keeper public comp.
[CV003, CV009, CV010, CV011, CV012, CV013]On the disclosed $225M ARR base, multiple selection is the biggest driver of public-value support.
[CV013, CV014, CV015, CV016, CV017, CV018]The public evidence supports a wide range, with the base case centered well below a mid-$4B outcome.
[CV026, CV027, CV028, CV041]8.3 The upgrade path is simple: prove durable ARR quality and clean equity economics
Keeper’s next-step diligence asks are straightforward because the main blocker is not category ambiguity but private company opacity. Public evidence now supports real exit optionality: Keeper looks large enough, profitable enough and strategically relevant enough to reach either IPO preparation or credible strategic interest from identity, PAM or broader security incumbents. But no serious investment committee should convert that observation into a buy call without first seeing the numbers that determine durability and common-equity outcomes. Management needs to provide a current ARR bridge by product and segment, NRR, GRR, logo churn, gross margin, operating margin, cash generation, top-customer concentration, public-sector mix, module attach for PAM and secrets, and the actual preference stack or secondary marks tied to prior rounds. The risk chapter also has to stay wired directly into valuation. Another material trust incident, a pronounced slowdown in new-logo additions, or evidence that pricing friction is growing faster than product expansion would re-rate the company quickly toward the low end of the comp range. Until those questions are answered, the disciplined stance is fair-to-full, medium-confidence and track rather than buy. In other words, the diligence bottleneck is solvable, but it is still real enough to dominate price discipline today.[CV026, CV027, CV028, CV029, CV030, CV032]
| Trigger | Threshold / event | Transmission to thesis | Action implication |
|---|---|---|---|
| Security or trust shock | One material incident affecting core vault, PAM or regulated-control credibility | Premium trust narrative weakens and multiple compresses quickly | Move to downside case and reprice |
| Growth durability miss | New-logo pace and module attach deteriorate materially from current trajectory | High-growth narrative weakens and comp set shifts lower | Reassess scenario range and reduce acceptable entry price |
| Pricing / retention deterioration | Broadening complaints plus weak renewals or smaller expansions | Premium pricing power looks less durable | Demand cohort metrics before proceeding |
| Disclosure disappointment | Management cannot evidence healthy NRR, GRR, margins or clean cap table | Public valuation opacity remains unresolved | Maintain track / no-buy stance |
| Public-sector or compliance slippage | FedRAMP/GovRAMP scope or renewal posture weakens | Government premium and control-story credibility deteriorate | Lower multiple assumptions and extension value |
Thresholds are diligence heuristics grounded in public evidence, not company-guided KPI guardrails.
[CV006, CV007, CV024, CV029, CV030, CV037]| Topic | Missing evidence | Why it matters | Owner or diligence path |
|---|---|---|---|
| ARR quality | Current ARR bridge by product, geography and customer segment | Determines whether disclosed scale is concentrated, durable and mix-shift supportive | Request CFO package and board-level KPI deck |
| Retention | NRR, GRR, logo churn and cohort expansion by enterprise / SMB / public sector | Most important input for premium-multiple support | Request monthly recurring revenue cohort analyses |
| Margins and cash | Gross margin, contribution margin, opex structure, free cash flow and cash balance | Determines whether profitability claim is structurally strong or lightly defined | Request audited or board-reviewed financial statements |
| Concentration | Top-10 customers, public-sector mix and channel concentration | Bounds downside from delayed renewals or customer loss | Request ARR concentration and renewal calendar |
| Module economics | KeeperPAM and Secrets attach, win rate and implementation burden | Decides whether platform expansion deserves a premium vs password-only peers | Request product attach and win/loss by segment |
| Cap table and preferences | Liquidation preferences, protective provisions, secondaries and any 2023+ marks | Enterprise value alone does not determine common-equity attractiveness | Request legal cap-table pack and transaction history |
Each diligence ask is selected because it would materially move recommendation, multiple or downside calibration.
[CV004, CV026, CV030, CV031, CV032, CV033]Disclaimer
This report is based on publicly available information as of 2026-08-13. Keeper Security is a private company, and the valuation stance relies on disclosed ARR, scenario analysis and public comparables rather than audited internal financial statements.
Evidence index
| ID | Statement | Confidence | Sources |
|---|---|---|---|
| CO001 | Keeper’s homepage positions the company as a unified control plane for privileged access, secrets, remote connections, endpoints and databases. | Medium | SO001 |
| CO002 | Keeper publicly markets a zero-trust and zero-knowledge architecture with end-to-end encryption in which only the customer can decrypt stored data. | High | SO001, SO006 |
| CO003 | Keeper’s homepage claims the company serves more than 150 countries, more than 93,000 business customers and 4 million people. | Medium | SO001 |
| CO004 | Darren Guccione is publicly listed as CEO & Co-Founder and Craig Lurey is publicly listed as CTO & Co-Founder as of the run date. | High | SO002, SO017 |
| CO005 | Keeper’s current public executive bench includes Amy Lindenmeyer as CFO, Tim Strickland as CRO, Tracy Dale-Baker as CHRO and Shane Barney as CISO. | High | SO002, SO015 |
| CO006 | Keeper’s current board list includes Darren Guccione, Thomas Krane of Insight Partners and Len Ferrington of Summit Partners. | High | SO002, SO013 |
| CO007 | Keeper publicly lists Chicago, El Dorado Hills, Cork and Tokyo as its office locations for global headquarters, product development, EMEA sales and APAC sales respectively. | High | SO002, SO018 |
| CO008 | Keeper’s public terms page identifies the company as Keeper Security, Inc. and lists 311 W. Monroe Street, Suite 406, Chicago, Illinois as an address. | High | SO003, SO002 |
| CO009 | Keeper’s terms state that the governing law and venue for the applicable U.S. Keeper entity are Delaware, United States. | Medium | SO003 |
| CO010 | Reviewed public materials support treating Keeper as a private growth-equity-backed company rather than a public issuer. | High | SO002, SO013, SO014 |
| CO011 | Historical public sources trace the original Keeper product back to 2009. | Medium | SO017, SO018 |
| CO012 | Multiple accessible public sources describe Keeper Security, Inc. as being co-founded in 2011 by Darren Guccione and Craig Lurey. | Medium | SO011, SO013, SO018 |
| CO013 | Keeper disclosed a US$60 million minority investment from Insight Partners in August 2020, and Crunchbase News described it as the company’s first equity raise. | Medium | SO011, SO012 |
| CO014 | Insight Partners principal Thomas Krane joined Keeper’s board as part of the 2020 investment. | High | SO011, SO002 |
| CO015 | Insight Partners said Keeper’s B2B business was growing at triple-digit rates in 2020 and posted its best month in company history in July 2020. | Medium | SO012 |
| CO016 | Summit Partners announced that it completed a significant minority investment in Keeper, but did not disclose the size or valuation of the transaction. | Medium | SO013, SO014 |
| CO017 | Len Ferrington of Summit Partners joined Keeper’s board in connection with Summit’s investment. | High | SO013, SO002 |
| CO018 | Summit said Keeper had added several hundred employees, doubled revenue while maintaining strong gross margins and recorded its strongest quarter on record in Q1 2023. | Medium | SO013 |
| CO019 | Summit attributed Keeper’s post-2020 progress to the Glyptodon acquisition, FedRAMP and StateRAMP authorizations, new data centers in Australia, Canada and Japan, and broader partner expansion across NorAm, EMEA and APAC. | Medium | SO013 |
| CO020 | KeeperPAM combines enterprise password management, secrets management, connection management, zero-trust network access and remote browser isolation in a single cloud-native platform. | High | SO006, SO029 |
| CO021 | Keeper Secrets Manager is marketed as a cloud-based system for API keys, certificates, service credentials, CI/CD pipelines, containers, automation scripts and other non-human identities. | Medium | SO007 |
| CO022 | Keeper Security Government Cloud is publicly described as a FedRAMP High and GovRAMP High authorized zero-trust PAM solution hosted in AWS GovCloud. | High | SO008, SO009, SO010 |
| CO023 | Keeper’s December 2025 FedRAMP High announcement says FedRAMP Moderate authorization had been achieved in August 2022. | Medium | SO009 |
| CO024 | Keeper’s February 2026 GovRAMP High announcement says Keeper Security Government Cloud has maintained GovRAMP authorization since 2022. | Medium | SO010 |
| CO025 | Keeper’s current public materials advertise FedRAMP High, GovRAMP High, FIPS 140-3, ISO 27001/27017/27018, PCI DSS and TrustArc-related privacy certifications. | High | SO001, SO008, SO010 |
| CO026 | Keeper began integrating Glyptodon after acquiring it in December 2021 and announced Keeper Connection Manager on 2022-05-04 as the reworked zero-trust remote-access layer. | Medium | SO026 |
| CO027 | Keeper’s 2023 retrospective says the company opened its Asia-Pacific headquarters in Tokyo in May 2023. | Medium | SO027 |
| CO028 | Keeper’s 2023 retrospective characterizes Summit’s investment and the KeeperPAM platform launch as defining milestones of 2023. | Medium | SO027 |
| CO029 | Keeper’s retrospective says the company introduced passkey support in its browser extension during 2023. | Medium | SO027, SO018 |
| CO030 | Keeper extended passkey management and autofill to iOS and Android on 2024-03-25. | High | SO028, SO030 |
| CO031 | Keeper’s April 2025 product update reiterates that KeeperPAM is the unifying control plane for password management, secrets management, connection management, zero-trust network access and remote browser isolation. | High | SO029, SO006 |
| CO032 | Keeper’s Connection Manager advisories page documents multiple disclosed vulnerabilities from 2020-2021, including CVE-2021-43999 rated High 8.7, and points researchers to a Bugcrowd-managed disclosure program. | Medium | SO020 |
| CO033 | OpenCVE currently lists Keeper-related vulnerabilities including a disputed 2023 plaintext-memory exposure and a 2025 KeeperChat biometric-authentication issue. | Medium | SO019 |
| CO034 | Built In’s AI-generated employer profile describes Keeper as founder-led and execution-first, but warns of top-down pressure, shifting priorities, transparency concerns and burnout risk. | Low | SO021 |
| CO035 | The reviewed source set did not surface a public report of a catastrophic Keeper vault breach; the accessible adverse record is centered on disclosed vulnerabilities and culture critique instead. | Low | SO019, SO020, SO021, SO025 |
| CO036 | Keeper’s about page names cryptographer Adam Everspaugh and former CISA CIO David Epperson among its public advisors. | Medium | SO002 |
| CO037 | Keeper’s FedRAMP High announcement names the Departments of Justice, Energy, Transportation and the Interior, FEMA and NASA as major federal agencies using Keeper. | Medium | SO009 |
| CO038 | Keeper’s accessible official pages are not perfectly synchronized on scale, with the homepage claiming 93,000+ business customers while the December 2025 FedRAMP post claims 85,000+ organizations. | High | SO001, SO009 |
| CO039 | Craft describes Keeper as an AI-enabled cybersecurity platform serving enterprise, medical and military sectors. | Medium | SO016 |
| CO040 | The accessible public record does not disclose Summit’s exact check size, Keeper’s latest valuation, or a detailed current cap table. | Medium | SO013, SO014 |
| CO041 | Accessible public sources do not pin a precise current headcount; they only show that Keeper added 120 employees around 2020 and several hundred employees after the 2020 funding round. | Medium | SO011, SO013 |
| CO042 | Keeper’s government-cloud materials say the platform supports CAC and PIV smart-card authentication and aligns with FIPS 201 and NIST SP 800-63 identity requirements. | Medium | SO009 |
| CO043 | Keeper’s partner page describes the Keeper Partner Network as a global community of expert partners. | Medium | SO023 |
| CO044 | Keeper’s integrations directory shows direct integrations with Okta, Entra ID, Google Workspace, AWS, Azure, Splunk, Chronicle and major cloud secret stores. | Medium | SO031 |
| CO045 | Keeper’s terms include a 99.9% monthly uptime-availability commitment for the Keeper Services API, excluding emergency maintenance and force-majeure events. | Medium | SO003 |
| CM001 | Keeper’s current product surface spans workforce password management, privileged access management, secrets management, remote connections, passkeys and government identity security rather than a single-purpose consumer vault. | High | SM001, SM002, SM003, SM004 |
| CM002 | Google Password Manager and Apple’s Passwords app provide built-in password and passkey management, creating a zero-price substitute for consumers and lightly managed users. | High | SM015, SM016 |
| CM003 | AWS Secrets Manager and Azure Key Vault already cover centralized machine-secret storage and rotation inside their own cloud ecosystems. | High | SM021, SM022 |
| CM004 | BeyondTrust’s endpoint privilege offering shows that least-privilege elevation and just-in-time access are contested by established adjacent incumbents, not only by password-vault vendors. | Medium | SM020 |
| CM005 | Keeper’s practical category is narrower than full IAM and broader than a personal password vault: it is the governed credential-control layer linking passwords, passkeys, secrets and privileged access. | High | SM001, SM002, SM004 |
| CM006 | Mordor Intelligence and Research and Markets both estimate the password-management market at US$2.94B in 2026 and US$8.07B by 2031, implying a 22.39% CAGR from 2026 to 2031. | Medium | SM006, SM008 |
| CM007 | Fortune Business Insights estimates the password-management market at US$3.79B in 2026 and US$10.63B by 2034, implying a 13.77% CAGR from 2026 to 2034. | Medium | SM007 |
| CM008 | Published password-management TAM estimates disagree enough that Keeper’s market should be treated as a bounded range rather than a single point estimate. | Medium | SM006, SM007, SM008 |
| CM009 | Cloud deployment dominates current category spend, with publishers citing either 64.4% share in 2025 or 79.1% share in 2026 depending definition and sample. | Medium | SM006, SM007 |
| CM010 | Hybrid deployment is a major growth area, with Mordor / Research and Markets projecting a 23.9% CAGR as data-residency and regulated-workload needs persist. | Medium | SM006, SM008 |
| CM011 | Large organizations represented 63.4% of 2025 password-management spending in Mordor / Research and Markets, while SMEs are projected to grow fastest at 24.3% CAGR through 2031. | Medium | SM006, SM008 |
| CM012 | BFSI accounted for 29.1% of 2025 revenue in Mordor-style market work, while healthcare and life sciences were projected to grow fastest at 25.9% CAGR. | Medium | SM006 |
| CM013 | North America remains the largest regional pool for password-management spend, with published 2025 share estimates ranging from 33.17% to 38.93%, while Asia Pacific is the fastest-growing region. | Medium | SM006, SM007, SM008 |
| CM014 | Keeper’s most defensible practical SAM is the paid, multi-user slice where buyers need policy control, least privilege, secrets, passkeys and regulated deployment support. | High | SM001, SM002, SM004, SM006 |
| CM015 | Keeper’s buyer map spans consumers, SMB IT generalists, enterprise CISOs or IAM leads, platform-engineering teams and public-sector security buyers. | High | SM001, SM002, SM004, SM005 |
| CM016 | The paying budget for Keeper shifts by segment from personal discretionary spend to enterprise security, IT, engineering and public-sector compliance budgets. | High | SM001, SM002, SM004 |
| CM017 | A plausible Keeper enterprise adoption path runs from admin evaluation into IdP/MFA integration, credential migration, least-privilege policy rollout, monitoring and expansion into broader PAM or secrets use cases. | High | SM001, SM005, SM023, SM024 |
| CM018 | An EMA survey summarized by Keeper and DRJ found that 69% of organizations adopt PAM primarily to prevent credential theft and mitigate cyber threats. | Medium | SM023, SM025 |
| CM019 | Verizon’s 2026 DBIR says the most frequent breach causes continue to heavily involve the human element, phishing and stolen credentials. | Medium | SM009 |
| CM020 | IBM’s 2026 report says the global average cost of a data breach reached US$4.99M, a 12% year-over-year increase and a record high. | Medium | SM010 |
| CM021 | NIST SP 800-207 and CISA’s Zero Trust Maturity Model both define zero trust around least-privilege, granular access decisions rather than network location-based trust. | High | SM011, SM012 |
| CM022 | NIST SP 800-63B requires a phishing-resistant option at AAL2 and requires federal staff, contractors and partners to use phishing-resistant authentication for federal information systems. | Medium | SM013 |
| CM023 | Microsoft will start making passkeys the default authentication experience in Entra ID on 2026-09-01 and will retire Microsoft-provided native SMS and voice delivery on 2027-02-01. | Medium | SM014 |
| CM024 | FIDO describes passkeys as phishing-resistant cryptographic credentials that reduce phishing, credential stuffing and authentication-service costs. | High | SM018, SM019 |
| CM025 | Built-in consumer stacks from Apple and Google intensify substitute pressure on independent password vendors at the low end of the market. | High | SM015, SM016, SM019 |
| CM026 | Keeper argues that its passkey value comes from cross-platform sync, centralized vault control and secure sharing rather than device-bound storage alone. | High | SM003, SM019 |
| CM027 | Keeper’s government-cloud materials align the company with public-sector and regulated buyers by emphasizing least privilege, auditability and FedRAMP/GovRAMP authorization. | Medium | SM004 |
| CM028 | Keeper’s integrations directory shows material connectors to IdPs, SIEMs, CI/CD workflows and cloud providers, supporting cross-functional buyer involvement in deals. | Medium | SM005 |
| CM029 | Keeper’s EMA summary says 60% of KeeperPAM users described deployment as very easy versus 22% of users of competing PAM tools, and only 15% required dedicated staff versus nearly 40% for others. | Medium | SM023, SM025 |
| CM030 | Keeper’s SoftwareReviews release says the platform led implementation-related metrics with 85% ease of implementation and 85% ease of IT administration. | Medium | SM024 |
| CM031 | Legacy PAM complexity and staffing burden remain a real market constraint, which is why cloud-native ease-of-deployment is a material wedge in current PAM evaluations. | High | SM020, SM023, SM025 |
| CM032 | Passkeys are simultaneously a tailwind and a threat for Keeper: they validate the move toward phishing-resistant authentication while making native platform managers more capable. | High | SM014, SM015, SM016, SM019 |
| CM033 | IBM’s 2026 breach report argues that organizations need stronger identity access and control to secure AI agents and machine identities as AI threats grow. | Medium | SM010 |
| CM034 | Market-growth drivers for Keeper cluster around zero trust, public-sector mandates, phishing-resistant authentication, cyber-insurance pressure and the need to reduce credential sprawl across humans and machines. | High | SM006, SM011, SM012, SM013, SM018 |
| CM035 | Keeper competes across multiple overlapping budgets because cloud secret stores, built-in password managers and privilege vendors each solve part of the same job. | High | SM003, SM020, SM021, SM022 |
| CM036 | Public-sector buyer journeys are more procurement- and compliance-heavy than commercial buyers, which makes FedRAMP/GovRAMP readiness part of the adoption path rather than just a product feature. | High | SM004, SM012, SM013 |
| CM037 | Category-wide market reports disagree enough on absolute size and scope that Keeper-specific SAM and share must be evidence-constrained rather than extrapolated from one headline TAM number. | Medium | SM006, SM007, SM008 |
| CM038 | Mobile and cross-device usability are important demand drivers because market reports and platform documentation both emphasize smartphones, browser sync and device-spanning credential access. | High | SM006, SM015, SM016 |
| CM039 | Self-service and low-friction password-management functions are a large current revenue pool, but that portion of the market is more vulnerable to commoditization than privileged and regulated workflows. | Medium | SM006, SM007 |
| CP001 | Keeper’s competitor set spans direct password peers, adjacent PAM/identity suites, developer-secret tools, native built-ins and cloud-native substitutes rather than one simple list of vault apps. | High | SP001, SP014, SP019, SP021, SP023 |
| CP002 | Keeper’s clearest direct paid peers in workforce credential management are 1Password, Bitwarden, Dashlane and LastPass, each of which markets business password management and administrative control. | High | SP004, SP006, SP009, SP011 |
| CP003 | 1Password says more than 200,000 businesses trust the platform. | Medium | SP004 |
| CP004 | 1Password positions itself beyond basic vaulting by emphasizing passwords, secrets, apps, devices, apps outside SSO and AI/SaaS discovery on its business surface. | Medium | SP004 |
| CP005 | Bitwarden says it is trusted by 80,000+ businesses worldwide. | Medium | SP006 |
| CP006 | Bitwarden markets open-source transparency, optional self-hosting, rapid deployment and 24x7 business support as core competitive advantages. | Medium | SP006 |
| CP007 | LastPass still markets a cross-platform zero-knowledge vault with SSO and MFA adjacency and a paid-versus-free tier distinction. | Medium | SP009 |
| CP008 | LastPass’s current official surface still devotes significant space to post-2022 remediation and security transformation, indicating that trust recovery remains part of its competitive posture. | High | SP009, SP010 |
| CP009 | Dashlane is explicitly repositioning from password manager toward Omnix credential security and Credential Protection, pairing vaulting with risk detection and domain protection. | High | SP011, SP012, SP013 |
| CP010 | CyberArk’s current pages market a broader identity-security platform centered on privileged access, zero-standing privileges, machine identities and agentic AI security. | High | SP014, SP015 |
| CP011 | Delinea’s current pages position the company around dynamic authorization, remote privileged access, session monitoring, password rotation and Secret Server vaulting rather than simple workforce password sharing. | High | SP016, SP017 |
| CP012 | BeyondTrust, CyberArk and Delinea show that Keeper competes in enterprise deals against broader privilege-control suites, not just other password managers. | High | SP014, SP016, SP018 |
| CP013 | HashiCorp Vault competes most directly on machine secrets, dynamic credentials and API/CLI-led workflows rather than on workforce vault UX. | High | SP019, SP020 |
| CP014 | Google Password Manager and Apple Passwords provide built-in password and passkey storage, making low-end credential management available at zero incremental software price. | High | SP021, SP022 |
| CP015 | AWS Secrets Manager and Azure Key Vault are credible substitutes for Keeper’s machine-secret wedge in single-cloud environments. | High | SP023, SP024 |
| CP016 | Keeper differentiates itself by combining zero-knowledge vaulting with passkeys, secrets, PAM and a public-sector compliance posture across its business, enterprise and pricing pages. | High | SP001, SP002, SP003 |
| CP017 | Keeper’s pricing and product surfaces show cross-sell breadth into family plans, MSP, secrets, AI-agent access and KeeperPAM rather than a single-SKU vault offer. | High | SP002, SP003 |
| CP018 | 1Password’s competitive direction is broader access governance, not only password storage, because it foregrounds apps outside SSO, trusted devices and AI/SaaS discovery. | Medium | SP004 |
| CP019 | Bitwarden’s direct competitive wedge is operational simplicity plus control: go-live-in-days claims, self-host flexibility, admin oversight and priority support. | High | SP006, SP007 |
| CP020 | Dashlane markets role-based access, encrypted audit logs, SAML login, automated provisioning and admin vault policies for enterprise teams. | High | SP011, SP012 |
| CP021 | LastPass still competes on cross-platform coverage, zero-knowledge vaulting and SSO/MFA breadth, but its current free tier is constrained relative to paid usage. | Medium | SP009 |
| CP022 | Public pricing transparency is uneven across the field: several vendors show annual per-user or custom-sales motions, but fetched public pages often do not expose clean business list prices in comparable form. | High | SP003, SP005, SP007, SP012 |
| CP023 | Keeper’s current fetched pricing text makes higher-end modules like KeeperPAM appear quote-led rather than transparently self-serve. | Medium | SP003 |
| CP024 | Operational simplicity is a key competitive battleground because Keeper, Bitwarden and Delinea each highlight fast deployment or reduced implementation burden. | High | SP001, SP006, SP017 |
| CP025 | CyberArk and Delinea compete for high-value enterprise deals by extending privilege control across human, machine and remote-access workflows that go well beyond shared passwords. | High | SP014, SP015, SP016, SP017 |
| CP026 | HashiCorp Vault, AWS Secrets Manager and Azure Key Vault can each absorb part of the machine-secret budget that Keeper would otherwise target. | High | SP019, SP020, SP023, SP024 |
| CP027 | Native passkey momentum from Google, Apple and Microsoft increases substitute pressure on simple vault use cases even as it validates passwordless demand. | High | SP021, SP022, SP027 |
| CP028 | The LastPass incident shows that trust shocks can re-rank category winners even when core password-manager functionality remains comparable. | High | SP009, SP010 |
| CP029 | Switching costs are meaningful but not absolute because major vendors market migration, import or fast onboarding rather than proprietary lock-in alone. | High | SP001, SP006, SP011 |
| CP030 | Base feature parity among direct peers is high on password vaulting, secure sharing, admin control and provisioning, so differentiation increasingly comes from trust, compliance, scope and ease-of-use. | High | SP001, SP004, SP006, SP011 |
| CP031 | Keeper’s sharpest wedge appears in compliance-heavy, control-heavy and public-sector-friendly deployments rather than in generic consumer or lightly managed team use cases. | High | SP001, SP002, SP003, SP014, SP021 |
| CP032 | 1Password and CyberArk both extend the category toward AI and every-identity security narratives, increasing platform-consolidation pressure around Keeper. | High | SP004, SP015 |
| CP033 | Bitwarden and Dashlane both market quantified or explicit productivity gains from simpler deployment or reduced admin effort, raising the proof burden for Keeper’s similar simplicity claims. | High | SP006, SP011 |
| CP034 | The competitive field is structurally split among direct password peers, broader PAM suites, developer-secret platforms and bundled substitutes. | High | SP004, SP014, SP019, SP021, SP023 |
| CP035 | Status-quo and internal-build alternatives include native browser or device storage, hard-coded secrets and ad hoc sharing, not just named software vendors. | High | SP008, SP021, SP022 |
| CP036 | Multi-homing is likely in enterprise environments because workforce vaulting, privileged access and machine-secret lifecycle needs are increasingly served by overlapping but non-identical tool categories. | High | SP003, SP014, SP019, SP023 |
| CP037 | Opaque discounting and custom contract structure remain a real diligence blocker because public pages do not provide a clean apples-to-apples business price comparison across the field. | High | SP003, SP005, SP012 |
| CP038 | The low end of the market is structurally difficult to monetize because password and passkey storage are increasingly bundled into dominant operating systems, browsers and cloud ecosystems. | High | SP021, SP022, SP023, SP024, SP027 |
| CP039 | Keeper faces visible scale and platform-breadth pressure from 1Password’s 200,000+ business claim, Bitwarden’s 80,000+ business claim and CyberArk’s broader identity-security narrative. | High | SP004, SP006, SP015 |
| CP040 | Without current win/loss data, realized pricing, attach rates for KeeperPAM or secrets, and segment-level renewal evidence, Keeper’s moat durability cannot be fully underwritten from public materials alone. | High | SP003, SP025 |
| CI001 | Keeper’s visible revenue streams are primarily recurring software subscriptions rather than transactions, hardware or labor-heavy services. | High | SI002, SI003, SI004 |
| CI002 | Keeper publicly markets a tiered seat-based ladder from Business Starter to Business to Enterprise, with deeper governance and integration features appearing in higher tiers. | High | SI003, SI004 |
| CI003 | Keeper Secrets Manager is positioned as an add-on to business password-manager plans and is included with KeeperPAM. | High | SI004, SI006 |
| CI004 | KeeperPAM is sold through custom pricing tailored to organization size, infrastructure and privileged-access needs rather than a simple public self-serve SKU. | High | SI004, SI005 |
| CI005 | Keeper’s pricing surfaces reveal the monetization architecture but not realized ASP, discounting or seat-minimum economics. | High | SI003, SI004 |
| CI006 | The free Family Plan for business users functions more like an adoption and retention enhancer than a clearly visible direct ARR stream. | High | SI002, SI003, SI004 |
| CI007 | Keeper announced in July 2026 that it had reached US$225M in ARR. | Medium | SI001 |
| CI008 | Keeper says its ARR has grown more than 3x since 2021. | Medium | SI001 |
| CI009 | Keeper says it protects over 95,000 organizations worldwide. | Medium | SI001 |
| CI010 | Keeper says KeeperPAM revenue has grown 10x year-over-year since its February 2025 launch and that the company adds an average of 850 new organizations per month. | Medium | SI001 |
| CI011 | Keeper’s SoftwareReviews 2026 PR says the company achieved 53.42% year-over-year global revenue growth in 2025, or 3.45x the overall market average cited in that release. | Medium | SI009 |
| CI012 | Third-party private-company databases put Keeper’s 2024 revenue around US$90.6M to US$97.8M, showing how noisy outside estimates remain for a private company. | Medium | SI013, SI014 |
| CI013 | Third-party headcount estimates for Keeper conflict materially, with Growjo showing 506 employees and Tracxn showing 795 employees. | Medium | SI012, SI013 |
| CI014 | Because third-party revenue and headcount estimates conflict so sharply, public database profiles are better used as rough ranges than as underwritten financial facts. | Medium | SI012, SI013, SI014 |
| CI015 | Public sources do not disclose Keeper’s revenue mix across SMB, enterprise, public sector, MSP, secrets and PAM. | High | SI001, SI004 |
| CI016 | Keeper’s likely primary cost buckets are engineering, cloud infrastructure, security operations, compliance, support and go-to-market rather than inventory or manufacturing. | High | SI002, SI003, SI005 |
| CI017 | Okta’s fiscal 2026 results imply roughly 77% GAAP gross margin on US$2.919B of revenue, providing a reasonable benchmark for scaled identity SaaS margin shape. | High | SI016, SI017 |
| CI018 | Okta’s fiscal 2026 results imply sales and marketing expense equal to roughly 35% of revenue and R&D expense equal to roughly 22% of revenue, illustrating that identity SaaS remains sales- and product-investment heavy even at scale. | High | SI016, SI017 |
| CI019 | Okta’s fiscal 2026 free cash flow of US$863M on US$2.919B of revenue implies about a 30% free-cash-flow margin, showing that identity software can become strongly cash generative at scale. | High | SI016, SI017 |
| CI020 | Keeper appears capital-light relative to hardware or payments businesses because its monetization is software-based and there is no visible inventory, manufacturing or project-finance burden in public materials. | High | SI002, SI003, SI004 |
| CI021 | Keeper’s July 2026 ARR release says the company has a debt-free capital structure. | Medium | SI001 |
| CI022 | Keeper’s July 2026 ARR release says the company combines best-in-class growth with profitability, but does not quantify margin or earnings. | Medium | SI001 |
| CI023 | Keeper’s funding chronology—Insight’s 2020 US$60M growth round followed by Summit’s 2024 minority growth-equity investment—suggests the company has had access to expansion capital before the 2026 ARR milestone. | High | SI010, SI011 |
| CI024 | Management now frames future financing in terms of optionality for a public offering rather than immediate capital need, but current cash and runway remain undisclosed. | High | SI001, SI011 |
| CI025 | If KeeperPAM and Secrets Manager continue to attach within the installed base, Keeper’s revenue quality should improve through higher ARPU and deeper workflow lock-in. | High | SI001, SI005, SI006 |
| CI026 | Bundled substitutes from Google, Apple, AWS and Azure create real pricing pressure on the low end of password and secrets management. | High | SI019, SI020, SI021, SI022 |
| CI027 | Keeper’s GTM motion is likely blended: lighter-touch deployment for Business tiers and more sales-assisted motion for Enterprise, PAM and government-led opportunities. | High | SI002, SI003, SI004, SI007 |
| CI028 | The most important public financial blockers are undisclosed gross margin, CAC, payback, NRR, churn, current cash and burn. | High | SI001, SI004 |
| CI029 | Custom pricing for KeeperPAM and opaque enterprise discounts make realized ASP materially harder to underwrite than the pricing architecture alone would suggest. | High | SI004, SI005 |
| CI030 | Public evidence is directionally positive on capital adequacy but insufficient to prove solvency because the company does not disclose current cash, runway or debt covenants. | High | SI001, SI010, SI011 |
| CI031 | Business and enterprise pages emphasize deploy-in-minutes onboarding, identity integrations, training and 24x7 support, suggesting implementation is not unusually services-heavy for the category. | High | SI002, SI003 |
| CI032 | Keeper’s public-sector and compliance positioning likely supports larger contract values or stickier retention, but public evidence does not reveal the actual revenue contribution. | High | SI003, SI007 |
| CI033 | Average additions of 850 organizations per month signal strong top-of-funnel momentum, but do not by themselves reveal average contract value or customer quality. | Medium | SI001 |
| CI034 | The gap between third-party 2024 revenue estimates and Keeper’s 2026 ARR claim could reflect both rapid enterprise growth and the difference between revenue and ARR definitions. | Medium | SI001, SI013, SI014 |
| CI035 | Keeper’s claim of having added over 400 features and products to KeeperPAM in the prior fifteen months implies continued product reinvestment, which likely weighs on opex even if it strengthens enterprise expansion. | Medium | SI001 |
| CI036 | Keeper’s pricing surface is modular, with add-on upsell paths for secrets, PAM and advanced enterprise governance rather than one flat password-manager SKU. | High | SI003, SI004, SI006 |
| CI037 | The free Family Plan and personal/business vault separation indicate Keeper deliberately blends workforce adoption with user-convenience features that may support retention but dilute clean ARPU analysis. | High | SI002, SI003, SI004 |
| CI038 | For a business of Keeper’s type, working-capital and capex burdens are likely lower than the go-to-market and product-investment burdens. | High | SI002, SI017 |
| CI039 | Even scaled identity vendors rely heavily on non-GAAP framing and careful metric normalization, so Keeper’s unquantified profitability claim should be interpreted cautiously until audited detail is available. | High | SI001, SI017 |
| CI040 | The overall financial verdict is that Keeper now shows credible recurring-revenue scale and positive capital-direction signals, but still lacks enough public efficiency and solvency detail for full investor-grade underwriting. | High | SI001, SI004, SI017 |
| CE001 | Keeper now markets a unified identity-security platform spanning password management, privileged sessions, endpoint privilege, secrets, database access, zero-trust access, remote browser isolation, and a shared admin control plane. | Medium | SE002, SE010, SE019 |
| CE002 | KeeperPAM is presented as a cloud-based privileged access platform that unifies password management, secrets management, connection management, database management, endpoint privilege management, zero-trust network access, and remote browser isolation in one product. | Medium | SE002, SE010 |
| CE003 | Keeper Connection Manager is a self-hosted, agentless remote desktop gateway included with KeeperPAM and positioned for buyers that need a fully hosted, in-network or air-gapped deployment they manage themselves. | Medium | SE002, SE011 |
| CE004 | Keeper Secrets Manager is positioned as a fully managed, cloud-based, zero-knowledge service for infrastructure secrets, API keys, certificates, service accounts and other machine-identity credentials. | Medium | SE003, SE015, SE017 |
| CE005 | The Business, Enterprise and Enterprise Guide surfaces show that secure workforce vaulting, policy enforcement, SSO/SCIM and admin controls remain the base layer underneath Keeper’s newer adjacent products. | Medium | SE007, SE008, SE019 |
| CE006 | BreachWatch continuously monitors for compromised credentials tied to records in the vault and performs a local scan of stored passwords on the user’s device after activation. | Medium | SE013 |
| CE007 | Keeper’s passkey feature stores passkeys in the vault, syncs them across devices, supports autofill and biometric unlock, and allows vault-to-vault passkey sharing between Keeper users. | Medium | SE005 |
| CE008 | Keeper’s integrations catalog now spans AI coding agents, identity providers, browser extensions, cloud services, CI/CD platforms and SaaS rotation plugins, indicating a broad ecosystem strategy rather than a closed vault experience. | Medium | SE006, SE014, SE015 |
| CE009 | Keeper’s central technical claim is a zero-knowledge design in which encryption and decryption occur locally on approved devices and company personnel cannot decrypt customer vault data. | Medium | SE001, SE020 |
| CE010 | Keeper publicly describes a layered client-side key model using record keys, folder keys, a user data key and a local cache key to reduce the blast radius of any single shared object. | Medium | SE001 |
| CE011 | For master-password logins, Keeper says the key that unwraps the data key is derived locally from the user’s master password using PBKDF2 with 1,000,000 iterations. | Medium | SE001 |
| CE012 | For SSO and passwordless logins, Keeper says it uses ECC-256 device keys and a device-encrypted data key that is delivered through local device approval workflows rather than a decryptable server-side secret. | Medium | SE001 |
| CE013 | Keeper’s current security page says vault data is encrypted locally with AES-256 GCM, data in transit uses TLS 1.3 plus payload wrapping, and Q1 2026 introduced rollout of an additional quantum-resistant wrapper on the transmission key. | Medium | SE001 |
| CE014 | Keeper says it super-encrypts device-generated ciphertext with multi-region HSMs and keeps encrypted backups replicated across multiple geographies for disaster recovery. | Medium | SE001 |
| CE015 | Keeper’s public hosting model relies on AWS regional infrastructure, preferred-region isolation and multiple high-availability data centers, while Government Cloud adds an AWS GovCloud deployment path for U.S. regulated workloads. | High | SE001, SE004, SE027 |
| CE016 | The Government Cloud product page claims FedRAMP High, GovRAMP High, FIPS 140-3, SIEM support, smart-card authentication and support for NIST-aligned government workflows. | Medium | SE004, SE029, SE031 |
| CE017 | Keeper’s official trust posture includes SOC 2 Type 2, ISO 27001/27017/27018, quarterly third-party penetration testing, and a Bugcrowd-managed vulnerability disclosure and bug bounty program. | High | SE001, SE012, SE026 |
| CE018 | Keeper’s current security page cites FIPS 140-3 certificate | Medium | SE001, SE030 |
| CE019 | Keeper Connection Manager security documentation separately references FIPS 140-2 certificate | Medium | SE012 |
| CE020 | Keeper Connection Manager supports browser-based access to RDP, SSH, VNC, Kubernetes, databases and internal web applications, plus session recording, RBI, MFA, PIV/CAC and IdP integrations. | Medium | SE011 |
| CE021 | KeeperPAM publicly claims just-in-time access, ephemeral account provisioning, dynamic role or group elevation, discovery, credential rotation, encrypted tunnels and a gateway pattern that requires only outbound connectivity to Keeper Cloud. | High | SE002, SE010 |
| CE022 | Keeper’s developer documentation and product pages show SDK and CI/CD coverage across GitHub Actions, Jenkins, Terraform, Kubernetes, Docker and multiple programming languages. | High | SE003, SE014, SE015, SE017 |
| CE023 | Keeper Commander exposes CLI, SDK and REST service mode interfaces for vault access, admin functions, device approvals, PAM automation, session launch and password rotation. | Medium | SE016, SE017, SE022 |
| CE024 | Keeper’s release notes show high-frequency summer-2026 shipping across backend API, web vault, desktop, browser extension, mobile, admin console, Keeper Gateway, Commander, SDKs and KeeperDB. | Medium | SE018 |
| CE025 | The KeeperPAM, BreachWatch, developer-tools, Commander and user-guide pages all show recent update timestamps in 2026, supporting a read of active documentation and product maintenance. | Medium | SE010, SE013, SE014, SE016, SE018 |
| CE026 | Keeper’s public GitHub signal is meaningful but selective: the organization page highlights Commander, Secrets Manager, PowerCommander, a GitHub Action and a Terraform provider rather than the full commercial platform. | Medium | SE021, SE022, SE023 |
| CE027 | Keeper Connection Manager’s security architecture explicitly depends on Apache Guacamole, NGINX, Tomcat and a supported database, which increases operator control but also expands the set of customer-managed components. | High | SE012, SE028 |
| CE028 | The self-hosted and air-gapped positioning of Keeper Connection Manager is a differentiator for sovereignty-sensitive buyers, but it shifts patching, SSL configuration and database posture onto the customer operations team. | Medium | SE011, SE012 |
| CE029 | Keeper’s Connection Manager advisories page records historical vulnerabilities including CVE-2021-43999, a high-severity improper validation of SAML responses issue. | Medium | SE024 |
| CE030 | OpenCVE still indexes client-edge issues tied to Keeper surfaces, including a 2025 KeeperChat iOS biometric-escalation issue and a disputed KeeperFill/Desktop memory-disclosure issue. | Medium | SE025 |
| CE031 | Public product materials do not disclose measured service SLA, historical uptime, latency performance, AI-monitoring false-positive rates or session-detection efficacy metrics. | High | SE002, SE010, SE018 |
| CE032 | Product maturity appears highest in core vaulting, session access, admin policy and secrets workflows, while AI session monitoring and some government-specific packaging look newer and less publicly proven. | High | SE006, SE010, SE018 |
| CE033 | Keeper’s strongest architectural differentiator is deployment flexibility: a cloud-native control plane and outbound gateway model for standard deployments plus optional self-hosted KCM for in-network control. | High | SE002, SE010, SE011 |
| CE034 | Zero-knowledge design reduces provider-side plaintext exposure, but client devices, browser extensions and device-approval workflows remain critical trust anchors and therefore meaningful residual risk points. | High | SE001, SE020, SE025 |
| CE035 | Keeper’s Guacamole lineage gives it an open-source browser-based remote-session foundation with documented APIs and a large external user base, which helps explain the depth of its web-session tooling. | High | SE011, SE028 |
| CE036 | Public product pages tie passkeys, secrets and privileged access back into the same Keeper vault and admin-control posture instead of presenting them as isolated point tools. | High | SE002, SE003, SE005, SE019 |
| CE037 | Keeper’s integrations catalog and developer docs show the company is expanding from workforce password management toward machine and AI-agent identity workflows. | High | SE006, SE014, SE015, SE018 |
| CE038 | As of August 2026, Keeper looks like a broad and technically credible identity-security platform with real engineering motion, but the newest surfaces still require private reliability, adoption and independent security-test evidence before they can be underwritten with the same confidence as the core vault. | High | SE002, SE018, SE021, SE024 |
| CU001 | Keeper’s visible customer base spans consumers, families, SMBs, enterprise, public sector, education/nonprofit, MSP/channel and privileged-access-heavy technical buyers. | Medium | SU004, SU024, SU025, SU026 |
| CU002 | Buyer, user and payer differ materially by segment, with consumer users buying directly, IT/security teams buying for workforce users, and MSPs buying for both their staff and managed clients. | Medium | SU009, SU024, SU025 |
| CU003 | Keeper said in July 2026 that it protects over 95,000 organizations. | Medium | SU001 |
| CU004 | The same July 2026 PR says Keeper’s customer base includes many Fortune 500 enterprises and public-sector agencies. | Medium | SU001 |
| CU005 | Keeper’s current public organization-count messaging varies across fresh company surfaces from 95,000+ organizations to over 100,000 organizations, implying large scale but also publication-timing drift. | Medium | SU001, SU006 |
| CU006 | Consumer adoption appears meaningfully large because Keeper still describes millions of users globally and the mobile apps show 229K iOS ratings and 111K Android ratings as of August 2026. | Medium | SU001, SU021, SU022 |
| CU007 | Named customer proof spans motorsport, global SaaS, MSP services, higher education, finance/trust, telecom training, nonprofit and state government. | Medium | SU004, SU007, SU008, SU009, SU011, SU012, SU014, SU015, SU016 |
| CU008 | The named reference set is geographically broad enough to show UK, US and globally distributed deployments rather than a single-country customer profile. | Medium | SU005, SU007, SU008, SU009, SU014 |
| CU009 | The MSP/channel motion is real and not hypothetical, with Lucidica using KeeperMSP for its own staff and downstream managed client users. | Medium | SU009 |
| CU010 | Public-sector, education and nonprofit demand are substantive visible segments, supported by Government Cloud positioning plus named deployments at New Mexico, Illinois College, Oregon State and Alzheimer’s Association. | Medium | SU011, SU013, SU015, SU016, SU026 |
| CU011 | A recurring pre-Keeper customer pain point is fragmented password handling through spreadsheets, browser tools, text files, printed notes or legacy password managers. | Medium | SU005, SU009, SU011, SU012, SU013 |
| CU012 | Ease of deployment and operational simplicity appear repeatedly in both case studies and reviews as reasons Keeper wins adoption. | Medium | SU002, SU007, SU008, SU011, SU017 |
| CU013 | Keeper says it is adding an average of 850 new organizations every month. | Medium | SU001 |
| CU014 | Keeper has unusually rich named customer proof for a private cybersecurity vendor, with at least ten identifiable reference deployments available publicly. | Medium | SU004, SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015, SU016 |
| CU015 | Atlassian Williams F1 Team uses KeeperPAM to secure privileged access across a globally distributed workforce operating in more than 20 countries each season. | Medium | SU007 |
| CU016 | Asite’s case study shows KeeperPAM in a 500+ employee global SaaS environment with nine data-center locations, replacing separate legacy PAM and secrets tools. | Medium | SU008 |
| CU017 | Lucidica’s case study shows KeeperMSP serving both its internal team and hundreds of managed client users across dozens of customer organizations. | Medium | SU009 |
| CU018 | Illinois College reports growing student adoption and a significant decrease in IT help-desk tickets after deploying Keeper across campus workflows. | Medium | SU011 |
| CU019 | Peak Trust uses Keeper for employees, shared teams, external specialists and regulatory reporting, and later migrated a sister company and outside directors from Dashlane to Keeper. | Medium | SU012 |
| CU020 | NokiaEDU uses Keeper Connection Manager to support remote training for thousands of students each month. | Medium | SU014 |
| CU021 | The New Mexico Taxation and Revenue Department case shows 700+ employees enabled for secure remote desktop access in less than a week. | Medium | SU015 |
| CU022 | Keeper’s December 2025 G2 blog cites 1,172 total reviews, a 4.6/5 rating, 94% satisfaction for meeting requirements and a 92% recommendation rate. | Medium | SU006 |
| CU023 | Keeper’s SoftwareReviews 2026 PR cites 93% likelihood to recommend, 87% fair cost-to-value, 85% ease of implementation and 81% usability for KeeperPAM. | Medium | SU002 |
| CU024 | GetApp shows 507 verified user reviews, 82% positive retention sentiment and password management as the dominant use case for Keeper reviewers. | Medium | SU020 |
| CU025 | Public adverse feedback clusters around pricing, price changes, add-on costs, autofill inconsistency, reporting gaps and occasional app or plugin friction. | Medium | SU017, SU020, SU023 |
| CU026 | Keeper does not publicly disclose NRR, GRR, logo churn, deployed-seat utilization or active-vault cohort curves by segment. | High | SU001, SU024, SU025 |
| CU027 | The best public retention proxies are review sentiment, recurring usage evidence in named deployments and the operational stickiness implied by SSO, shared-folder, reporting and privileged-access workflows, not actual cohort data. | High | SU006, SU020, SU011, SU013 |
| CU028 | Keeper’s main customer expansion levers appear to be seat growth, family-plan spillover, Secrets Manager and KeeperPAM attach, public-sector packaging and MSP downstream client expansion. | High | SU001, SU009, SU024, SU025, SU026 |
| CU029 | Public customer concentration appears diversified by vertical and use case, but top-customer revenue concentration cannot be tested because those figures are private. | Medium | SU004, SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015, SU016 |
| CU030 | Customer-proof freshness is mixed: many password-manager and KeeperPAM stories are 2025-2026, while several KCM references still date to 2022-era deployment narratives. | Medium | SU005, SU007, SU008, SU011, SU014, SU015 |
| CU031 | Review signals consistently praise secure sharing, cross-device sync, SSO/Entra integration, admin usability and customer support as major reasons to adopt or retain Keeper. | Medium | SU017, SU018, SU019, SU020 |
| CU032 | Negative review signals also point to potential procurement and renewal friction around extras-based pricing, reporting limitations, standalone-app performance and autofill behavior. | Medium | SU017, SU020, SU023 |
| CU033 | Keeper’s named public references overwhelmingly describe production use rather than pilot evaluation, because they discuss rollout, active usage, support experience, user adoption or operational outcomes. | Medium | SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015 |
| CU034 | The free family-plan benefit included with business licenses can plausibly accelerate workforce adoption by giving employees a personal-use incentive alongside work deployment. | High | SU005, SU024 |
| CU035 | Customer satisfaction appears materially positive, but review platforms are self-selected and therefore should be treated as sentiment proxies rather than direct retention evidence. | High | SU017, SU020, SU021, SU022 |
| CU036 | The overall customer verdict is favorable on breadth, reference quality and user sentiment, but still blocked on concentration, renewal economics, module-specific retention and active-seat depth. | High | SU001, SU006, SU017, SU020 |
| CU037 | Government Cloud positioning plus public-sector case studies suggest Keeper is winning not only generic enterprise accounts but also higher-control government and education environments. | High | SU015, SU026, SU011, SU013 |
| CU038 | Reviews, case studies and named references likely feed Keeper’s top-of-funnel because satisfied customers create the proof surfaces that future buyers use during discovery. | High | SU003, SU004, SU006, SU017 |
| CR001 | Keeper’s downside is unusually trust-sensitive because the company sells identity, secrets, privileged access and government controls rather than a low-stakes utility product. | High | SR004, SR005, SR006, SR021 |
| CR002 | FedRAMP, GovRAMP, FIPS and NIST-aligned positioning increase the severity of any control failure because they are central to Keeper’s regulated-market pitch. | High | SR005, SR015, SR021, SR022, SR026 |
| CR003 | There is no first-order public evidence of current enforcement or active litigation dominating the risk case today. | High | SR001, SR004, SR005 |
| CR004 | Keeper Connection Manager’s advisories page shows the remote-access surface has had historical vulnerabilities, including a high-severity SAML response validation issue. | Medium | SR010 |
| CR005 | OpenCVE tracks additional Keeper-related client or adjacent-product issues, showing that residual edge-surface vulnerability risk remains even without evidence of a platform-wide catastrophe. | Medium | SR013 |
| CR006 | Keeper’s zero-knowledge design meaningfully reduces provider-side plaintext exposure, but it does not eliminate endpoint, browser-extension or device-approval risk. | High | SR004, SR009, SR013 |
| CR007 | The company’s trust posture is supported by concrete mitigations including published cryptographic detail, quarterly testing, Bugcrowd disclosure and region-isolated hosting. | High | SR004, SR009, SR020 |
| CR008 | Because Keeper positions itself as a unified control plane for privileged access and AI agents, a security incident would likely transmit quickly into procurement friction, customer trust and valuation. | High | SR006, SR014, SR024 |
| CR009 | Self-hosted KCM deployments create operational risk because customers must manage Docker, SSL, database posture and upgrades in environments Keeper does not fully control. | High | SR009, SR025 |
| CR010 | The public materials and release cadence indicate Keeper is now operating a wider and more complex product estate than a classic password manager. | High | SR006, SR007, SR011, SR012 |
| CR011 | Review sources repeatedly surface pricing complexity, add-on fatigue, reporting gaps and autofill inconsistency as practical risks to customer satisfaction. | Medium | SR017, SR018, SR019 |
| CR012 | Review complaints appear operationally irritating rather than existential, but they are precisely the kind of friction that can accumulate in renewal or procurement cycles. | Medium | SR016, SR017, SR018 |
| CR013 | IBM and Verizon both underscore that stolen credentials and identity failures remain economically severe, which increases the downside cost of any Keeper trust event. | High | SR023, SR024 |
| CR014 | Keeper’s risk is broader than a simple vault product because it now spans PAM, secrets, remote access, AI monitoring and government-control surfaces. | High | SR005, SR006, SR007, SR012 |
| CR015 | Rapid shipping across many surfaces raises the chance of quality regressions, support strain or coordination failures even when release velocity is a strength. | Medium | SR011, SR016 |
| CR016 | Keeper has material platform dependence on AWS and AWS GovCloud for core hosting and regulated deployment. | High | SR004, SR005, SR020 |
| CR017 | Enterprise IdPs and provisioning systems are structurally important dependencies because Keeper’s business value often relies on SSO, SCIM and device-approval workflows. | High | SR003, SR006, SR021 |
| CR018 | Browsers, mobile operating systems and app stores remain meaningful external dependencies because they affect autofill, passkeys, distribution and consumer/business usability. | High | SR007, SR017, SR027 |
| CR019 | KCM’s Guacamole lineage creates upstream open-source dependency risk even if it also provides technical depth and commercial differentiation. | High | SR009, SR025 |
| CR020 | Founder continuity under Darren Guccione and Craig Lurey is a strategic strength but also a real key-person and succession risk. | High | SR001, SR014 |
| CR021 | Growing 850 organizations per month can pressure implementation, support and customer-success systems if staffing and process depth lag demand. | Medium | SR014, SR016 |
| CR022 | Native platform defaults and bundled cloud services, including passkeys and AWS Secrets Manager, increase commoditization risk at the low end and can displace point needs. | High | SR027, SR028 |
| CR023 | Dependency risk is not purely technical because review platforms and customer-sentiment surfaces function as discovery infrastructure in security software buying. | Medium | SR008, SR017, SR018 |
| CR024 | Keeper’s public mitigations look more mature than aspirational because they combine detailed architecture pages, active advisories, frequent releases and strong review-backed implementation scores. | Medium | SR009, SR010, SR011, SR016 |
| CR025 | The company’s unified-platform narrative is strategically attractive, but it also increases prioritization and organizational-complexity risk across product, engineering and compliance functions. | Medium | SR006, SR012 |
| CR026 | The biggest financial-model risk is that public growth evidence improved sharply in 2026 while public durability data did not. | Medium | SR014, SR016 |
| CR027 | Strong current satisfaction metrics are a mitigating factor because they suggest customer experience is not presently in obvious distress. | Medium | SR008, SR016 |
| CR028 | Competitive pressure can compress low-end pricing while also forcing Keeper to prove attach-rate value for PAM, secrets and government-control modules. | High | SR017, SR022, SR028 |
| CR029 | Public-sector sales cycles and authorization maintenance likely improve contract quality but can also lengthen revenue timing and create renewal or scope risk. | High | SR005, SR015, SR022 |
| CR030 | Public sources do not prove weak bench depth below the founders, which leaves real but unquantified succession and organizational-redundancy risk. | Medium | SR001 |
| CR031 | High review praise for support and usability is encouraging, but it can become a margin or reputation risk if the company cannot maintain service quality during fast growth. | Medium | SR008, SR016, SR017 |
| CR032 | Keeper has visible mitigating strengths in customer proof, review-backed ease of implementation, regulated-market fit and technical differentiation. | High | SR005, SR008, SR016 |
| CR033 | A material security incident is the clearest thesis-break trigger because it would hit trust, customer conversion, renewals and valuation simultaneously. | High | SR004, SR010, SR024 |
| CR034 | A pronounced slowdown in new-logo growth or module attach would challenge the premium-growth and IPO-optional narrative management is now presenting. | Medium | SR014 |
| CR035 | Broadening complaints about price increases, add-ons or value mismatch would be an important leading indicator of retention and sales-efficiency pressure. | Medium | SR017, SR018 |
| CR036 | Monthly or quarterly monitorable indicators should include new-logo adds, support backlog, implementation time, module attach, review-sentiment drift, release-quality metrics and certification status. | Medium | SR011, SR014, SR016 |
| CR037 | The absence of public NRR, GRR, churn, top-customer concentration, CAC payback and detailed cash data is itself a material risk because it prevents clean downside calibration. | Medium | SR014, SR017, SR018 |
| CR038 | Keeper’s overall risk profile is manageable but meaningfully residual, because several monitorable but non-trivial threats can flow from technical or commercial friction into growth quality and valuation. | Medium | SR014, SR017, SR024 |
| CR039 | The FedRAMP Marketplace lists Keeper ICAM & Identity Security Platform for Government as FedRAMP Certified, Class D (High), with six authorizations and a certified-since date of 2025-12-18, which reduces doubt about authorization existence but raises the importance of continuous compliance maintenance. | High | SR005, SR033 |
| CR040 | Keeper’s public terms and privacy materials explicitly disclaim continuous website availability, incorporate privacy and DPA governance, and place lawful use, export compliance and some security/backup responsibilities on customers or administrators. | High | SR029, SR030 |
| CR041 | Keeper’s public status surface spans multiple geographic data centers plus client apps, on-prem connectors and SCIM/API services, which demonstrates resilience intent but also shows a broad operational surface where localized outages can still affect customer experience. | High | SR031, SR032 |
| CR042 | Independent review coverage still describes Keeper as highly secure but relatively expensive and without a free option, reinforcing that pricing pressure is visible beyond user-review marketplaces. | Medium | SR034, SR035 |
| CV001 | Keeper’s July 2026 disclosure of $225M ARR, 95,000+ organizations protected and 850 new organizations added per month proves the company has real operating scale, not just category buzz. | Medium | SV001 |
| CV002 | Management’s claim that Keeper is profitable and debt-free is valuation-supportive because it reduces immediate financing overhang and downside refinancing pressure. | Medium | SV001 |
| CV003 | Open-source financing data remains opaque: public databases show limited funding history, but not a clean current post-money valuation that investors can underwrite against. | Medium | SV002 |
| CV004 | Because public sources still do not disclose NRR, GRR, gross margin, free cash flow, concentration or preference terms, the recommendation must remain price-sensitive and evidence-sensitive. | Medium | SV001, SV002 |
| CV005 | Keeper’s product breadth, public-sector posture and user-satisfaction signals support the view that this is a strong private cybersecurity asset rather than a narrow consumer vault business. | Medium | SV005, SV006, SV023 |
| CV006 | A material trust incident would likely compress Keeper’s valuation quickly because identity and privileged-access vendors sell assurance first and features second. | High | SV021, SV027, SV028 |
| CV007 | Public evidence supports unicorn plausibility, but public evidence alone does not support a price-insensitive buy call. | Medium | SV001, SV002, SV013, SV018 |
| CV008 | Independent review surfaces praising security while flagging pricing or value friction mean premium pricing power still needs diligence rather than assumption. | Medium | SV007, SV008, SV009, SV029 |
| CV009 | Okta’s August 2026 market cap of about $25.82B against roughly $3.00B of trailing revenue implies a public multiple of about 8.5x sales. | Medium | SV013, SV014 |
| CV010 | SailPoint’s August 2026 market cap of about $10.62B against roughly $1.12B of trailing revenue implies a public multiple of about 9.5x sales. | Medium | SV018, SV019 |
| CV011 | CyberArk’s August 2026 market cap of about $20.63B against 2025 revenue of about $1.36B implies a multiple a little above 15x sales. | Medium | SV015, SV016 |
| CV012 | The most decision-useful public-comp band for Keeper from this run is therefore roughly 8.5x to 15x. | Medium | SV013, SV014, SV015, SV016, SV018, SV019 |
| CV013 | Applying an 8.5x multiple to Keeper’s disclosed $225M ARR yields about $1.9B of enterprise value support. | Medium | SV001, SV013, SV014 |
| CV014 | Applying about 9.5x to Keeper’s disclosed $225M ARR yields about $2.1B of enterprise value support. | Medium | SV001, SV018, SV019 |
| CV015 | Applying a 12x multiple to Keeper’s disclosed $225M ARR yields about $2.7B of enterprise value support. | Medium | SV001, SV013, SV018 |
| CV016 | Applying a 15x multiple to Keeper’s disclosed $225M ARR yields about $3.4B of enterprise value support. | Medium | SV001, SV015, SV016 |
| CV017 | An 18x multiple on Keeper’s disclosed ARR yields about $4.05B, while 20x yields about $4.5B. | Medium | SV001, SV013, SV015 |
| CV018 | A rumored or discussed mid-$4B outcome therefore requires either a very premium multiple on current disclosed ARR or materially higher ARR than Keeper has publicly disclosed. | Medium | SV001, SV013, SV015, SV018 |
| CV019 | Because Keeper disclosed ARR rather than GAAP revenue, direct comparison against public sales multiples is more generous than conservative. | Medium | SV001, SV013, SV018 |
| CV020 | CyberArk’s premium positioning shows what public markets may pay for control-heavy identity assets, but that premium normally comes with richer disclosure and deeper enterprise control depth. | Medium | SV015, SV016, SV021 |
| CV021 | SailPoint’s public 10-K availability underscores the disclosure gap between Keeper and a public identity comp even before any opinion about relative quality. | High | SV017, SV018, SV019 |
| CV022 | Okta’s live SEC-filings infrastructure similarly highlights that public comps provide filing-grade transparency that Keeper does not. | High | SV013, SV030 |
| CV023 | The current cloud/software market is open enough to support healthy multiples, but the BVP cloud index context does not suggest investors should pay any price for growth alone. | Medium | SV020, SV013, SV018 |
| CV024 | Keeper’s FedRAMP Certified and GovRAMP High public-sector posture can justify some premium relative to consumer-only vault vendors because it widens procurement scope and switching relevance. | High | SV004, SV005, SV023 |
| CV025 | Keeper’s public status surface, security posture and legal materials reduce the likelihood of a distress narrative, but they do not close the valuation-opacity gap. | Medium | SV010, SV022, SV025, SV026 |
| CV026 | A reasonable bull case requires ARR moving into roughly the $275M-$325M range, continued profitability, healthy attach for PAM and secrets and no trust shock. | Medium | SV001, SV006, SV023 |
| CV027 | A reasonable base case keeps Keeper around roughly $225M-$260M ARR with 9x-12x support, implying about $2.0B-$3.1B of value. | Medium | SV001, SV013, SV018 |
| CV028 | A reasonable bear case assumes ARR drifting toward about $180M-$220M with weaker growth or trust damage and 5x-8x support, implying about $0.9B-$1.8B of value. | Medium | SV001, SV021, SV027 |
| CV029 | Exit readiness is helped by Keeper’s disclosed scale, profitability, debt-free status and enterprise/public-sector relevance. | Medium | SV001, SV004, SV005 |
| CV030 | Exit readiness is still constrained by missing public data on retention, concentration, margins, cash generation and equity terms. | Medium | SV001, SV002, SV017, SV030 |
| CV031 | Keeper’s 95,000+ organizations and current new-logo pace imply sufficient breadth to support multibillion-dollar outcomes if retention and margins are healthy. | Medium | SV001, SV024 |
| CV032 | Profitability and debt-free status are important mitigants because they reduce the need for value-destructive emergency fundraising. | Medium | SV001, SV002 |
| CV033 | The public-comp set is imperfect because Okta is broader identity, SailPoint is identity governance and CyberArk is a premium PAM leader. | Medium | SV013, SV015, SV017, SV018 |
| CV034 | The same public-comp set remains decision-useful because all three sell trust-sensitive identity or control software into enterprise buyers and public markets. | Medium | SV013, SV015, SV017, SV018 |
| CV035 | Keeper’s open-source funding history and absent public post-money terms prevent clean calculation of common-equity attractiveness even if enterprise value looks plausible. | Medium | SV002 |
| CV036 | Point-in-time public comp multiples can move quickly with market sentiment, so scenario ranges are safer than a single exact fair value. | Medium | SV014, SV016, SV019, SV020 |
| CV037 | Platform-native passkeys and bundled cloud secrets tools cap low-end multiple expansion because they pressure simpler password-only or secrets-only use cases. | Medium | SV011, SV012 |
| CV038 | Strong review-backed usability and satisfaction help offset some commoditization risk and support ongoing relevance. | Medium | SV006, SV007, SV009, SV024 |
| CV039 | Review-site pricing complaints argue against blindly assuming that strong product proof translates into durable premium pricing power. | Medium | SV007, SV008, SV009 |
| CV040 | If a seller’s expectation is closer to the low-$2B to low-$3B range and diligence verifies retention, margins and clean equity terms, Keeper could screen fair; if the ask is materially above $4B, public evidence looks full. | Medium | SV001, SV013, SV015, SV018 |
| CV041 | The final recommendation should be track / research-more rather than buy because company quality currently exceeds price proof. | Medium | SV001, SV002, SV013, SV018, SV021 |
| CV042 | Overall confidence should remain medium because disclosed ARR materially improved the evidence base, but the company is still far less transparent than public comps on durability and equity economics. | Medium | SV001, SV017, SV030 |
| CV043 | Keeper’s July 2026 disclosure materially improved public valuation evidence relative to earlier periods by revealing ARR, profitability and new-logo velocity in one place. | Medium | SV001 |
| CV044 | Even after that improvement, Keeper still discloses less than public comps do on revenue composition, retention and standardized filing detail. | High | SV001, SV017, SV030 |
| CV045 | The evidence-supported valuation stance today is fair-to-full rather than cheap. | Medium | SV001, SV013, SV015, SV018, SV021 |
| CV046 | A stronger buy case would require diligence proof of ARR materially above $300M or unusually strong retention, margin and cap-table quality that public evidence does not yet show. | Medium | SV001, SV002, SV013, SV015 |