Keeper Security
盈利型身份安全平台,ARR 规模真实,但估值支撑仍受价格敏感性约束
Keeper 的平台价值具备数十亿美元级可信基础,在监管市场也站住了脚;但公开证据目前只支持“观察 / 继续研究”,因为价格证据仍落后于公司基本面。
封面要素
公司概况
Keeper Security 是一家总部位于 Chicago 的私营网络安全公司,由 Darren Guccione 和 Craig Lurey 于 2011 年共同创立。公司起步于密码管理器,如今扩展成更宽的身份安全平台,覆盖 KeeperPAM、机密管理、连接管理、远程浏览器隔离和公共部门产品。公开证据证实它在受监管市场已有实质进展,包括 FedRAMP Certified 与 GovRAMP High 资质;2026 年 7 月披露进一步拉高了财务画像:$225M ARR、盈利、无债务,并管理层开始讲述具备 IPO 选择权的叙事。公开资料仍缺少精确估值和股权条款,因此应把 Keeper 视作一家已具规模的后期私营资产:平台能力真实,但价格透明度仍不完整。
- 成立时间
- 2011-01-01
- 创始人
- Darren Guccione, Craig Lurey
- 创立地点
- Chicago, Illinois, USA
- 总部
- Chicago, Illinois, USA
- 产品
- Keeper 提供企业和消费者密码管理、KeeperPAM、Keeper Secrets Manager、Keeper Connection Manager、暗网监测,以及面向受监管政府云的身份安全能力。
- 客户
- 目标客户包括需要零知识凭据与特权访问控制的企业 IT 和安全团队、公共部门机构、SMB、MSP,以及消费者 / 家庭用户。
- 商业模式
- 订阅软件模式,包含分层商业和企业计划、定制报价的 PAM 与公共部门部署,并通过机密管理和高级控制的附加或打包销售扩张。
- 阶段
- late-stage private / growth-equity-backed
- 融资情况
- 公司仍为私营;公开证据确认 Insight Partners 在 2020 年领投一笔 $60M 少数股权投资,Summit Partners 随后也完成一笔重要少数股权投资,但经济条款未披露。到 2026 年 7 月,管理层把公司定位为盈利、无债务、IPO 选择权增强,而不是资本受限。
执行摘要
主要优势
- 2026 年公开披露已经证明 Keeper 有真实规模:$225M 年经常性收入(ARR)、盈利、无债务,新 Logo 增长也强。
- 产品边界不止密码管理,已经延伸到 PAM、Secrets、远程访问和受监管政府工作负载。
- FedRAMP Certified 与 GovRAMP High 资质帮助 Keeper 区别于更简单的密码工具。
- 客户与评价证据支持其企业级相关性,不只是消费安全故事。
主要风险
- 公开证据仍缺 NRR、GRR、毛利率、现金生成、客户集中度和股权结构条款。
- 身份与特权访问都是信任敏感位置,一次重大安全或合规事故就可能迅速压缩估值。
- 高端定价和附加模块复杂度,在独立评价渠道里仍是可见摩擦。
- 通行密钥、云端 Secret 存储和大型身份平台的捆绑替代方案,会封住低端估值倍数扩张空间。
未决问题
- 当前 ARR 桥、产品组合以及各细分市场的模块附加率仍未披露。
- 留存质量、Logo 流失和队列扩张不公开。
- 优先股堆叠、老股交易价格以及清晰的当前投后估值仍不明确。
- 毛利率、自由现金流、客户集中度和公共部门 ARR 占比,仍没有达到可决策质量的披露。
目录
01公司概况
1.1 身份、产品范围与当前公开规模
Keeper Security 现在把自己呈现为身份安全平台,而不只是保险库应用。官网把 Keeper 描述为统一控制平面,覆盖特权访问、机密、远程连接、端点和数据库;核心产品页面显示,这把伞已经延伸到 KeeperPAM、Keeper Secrets Manager、安全远程访问、政府云和通行密钥能力。公司在这些页面反复用零信任、零知识架构和端到端加密锚定差异化,并强调只有客户才能解密已存储数据。公开规模说法有分量,但并不完全同步:官网称 Keeper 服务超过 93,000 家企业客户、保护 400 万人、业务遍及 150 多个国家;而 2025 年 12 月 FedRAMP High 公告称 Keeper 保护超过 85,000 家组织。这种差异更像页面更新节奏问题,不足以严重动摇平台叙事,但后续章节仍不能在不注明页面日期的情况下假设一个精确数量。产品广度也明显超出人工密码存储。KeeperPAM 统一密码、机密、连接管理、零信任网络访问和远程浏览器隔离;Keeper Secrets Manager 聚焦 API 密钥、CI/CD 凭据、容器和其他非人类身份。因此,公开材料支持这样一个判断:Keeper 已从密码管理入口扩展为更宽的身份安全厂商,扩张路径是特权访问和机器机密控制。[CO001, CO002, CO003, CO020, CO021, CO022]
| 指标 | 数值 | 日期 / 期间 | 置信度 | 备注 |
|---|---|---|---|---|
| 法定实体 | Keeper Security, Inc. | 当前 | 高 | 公开条款页写明 Keeper Security, Inc.,并列出芝加哥地址。 |
| 全球总部 | 美国伊利诺伊州芝加哥 | 当前 | 高 | 关于页面和条款页都把主要总部放在芝加哥。 |
| 产品起源 | 最初的 Keeper 应用可追溯至 2009 年 | 历史 | 中 | 历史公司资料来源把应用起源与后来公司成立区分开。 |
| 正式联合创立 | 2011 | 历史 | 中 | Crunchbase News、Summit 材料和 Wikipedia 将 2011 年描述为公司成立年份。 |
| 创始人 | Darren Guccione 和 Craig Lurey | 当前 | 高 | 两位创始人仍在当前领导层页面担任 CEO / CTO。 |
| 当前阶段 | 私有、获成长股权支持的公司 | 当前 | 高 | 公开记录显示 Insight 和 Summit 支持,但没有 IPO 或公开上市证据。 |
| 服务国家 | 150+ | 当前 | 中 | 首页和公司标准简介提到在超过 150 个国家提供服务。 |
| 企业客户 | 93,000+ | 当前 | 中 | 首页当前快照;其他官方页面引用 85,000+ 家组织,因此页面日期很重要。 |
| 受保护人数 | 4 million | 当前 | 中 | 首页公司指标。 |
| 已披露主要股权轮 | Insight 少数股权投资 US$60M | 2020-08 | 高 | 据 Crunchbase News 和 Insight Partners,这是首次披露的股权融资。 |
| 后续披露成长轮 | Summit Partners 的重大少数股权投资(金额未披露) | 2023-2024 公开来源集 | 中 | Summit 公告披露少数股权投资,但未披露价格或支票规模。 |
| 政府授权 | FedRAMP High 和 GovRAMP High | 当前 | 高 | 政府云以及 2025-2026 年授权发布支持这一点。 |
| 核心平台定位 | 覆盖 PAM、机密凭证、远程访问、端点和数据库的统一控制平面 | 当前 | 高 | 首页和 KeeperPAM 页面在这一定位上保持一致。 |
| 当前精确员工数 | 已审阅的可访问来源没有公开锁定 | 2026 报告运行日 | 低 | 招聘增长信号存在,但可访问官方页面没有披露确切员工数。 |
快照混合了当前官方指标和历史融资里程碑。客户数受页面日期影响,员工数仍是证据缺口,而不是已验证 KPI。
[CO001, CO003, CO004, CO008, CO010, CO011]把创始人延续、平台扩张、客户规模、资本伙伴和公共部门授权串起来,构成 Keeper 当下的公司层叙事。
[CO001, CO004, CO010, CO013, CO016, CO020]突出后续章节可复用的概览指标,同时明确员工数和未披露交易条款的不确定性。
客户和国家数字是公司声称的最低值,不是经审计披露;投资者数量只包括公开具名的机构成长股权支持方。
[CO003, CO007, CO013, CO016, CO022, CO038]1.2 领导层、治理、法律身份与运营版图
公开领导层页面显示,Keeper 的创始人连续性异常强。Darren Guccione 仍任 CEO 和联合创始人,Craig Lurey 仍任 CTO 和联合创始人,高管团队还列出 CFO Amy Lindenmeyer、CRO Tim Strickland、CHRO Tracy Dale-Baker、CISO Shane Barney 和总法律顾问 David Oskin。治理层也体现外部成长股权资本的影响:Keeper 董事会页面列出 Insight Partners 董事总经理 Thomas Krane 和 Summit Partners 董事总经理 Len Ferrington,与 Guccione 及独立成员同席,说明两家主要资本伙伴如今都有可见董事会席位。About 页面和条款页也把运营版图讲清楚:全球总部在 Chicago,产品开发在 El Dorado Hills,EMEA 业务销售在 Cork,APAC 业务销售在 Tokyo;条款页将法律实体标识为 Keeper Security, Inc.,地址为 311 W. Monroe Street, Suite 406, Chicago, Illinois。一个时间线细节会影响后续章节:公开来源区分 2009 年的产品起源和 2011 年 Keeper Security, Inc. 的正式共同创立。这个区分调和了 Chicago Innovation、Crunchbase News、Wikipedia 和 Summit 公司材料中看似冲突的日期。仍然不透明的是当前员工数和股权结构控制权。已审阅来源显示,Keeper 在 2020 年 Insight 轮前后增加了 120 名员工,到 Summit 公告时又增加了数百名员工,但可访问的官方页面没有给出精确当前员工数或详细股权结构表。[CO004, CO005, CO006, CO007, CO008, CO009]
| 人物 | 职务 | 截至 | 背景 / 职能覆盖 | 关键人物或尽调备注 |
|---|---|---|---|---|
| Darren Guccione | CEO 兼联合创始人 | 2026-08-13 | 创始人 CEO,也是 Keeper 融资、联邦定位和产品叙事的外部代表。 | 创始人依赖度高;战略方向仍与 Guccione 紧密绑定。 |
| Craig Lurey | CTO 兼联合创始人 | 2026-08-13 | 创始人 CTO,从产品起源到当前平台扩张保持连续性。 | 核心技术连续性;产品和架构尽调的中心人物。 |
| Amy Lindenmeyer | CFO | 2026-08-13 | 负责财务,也很可能负责融资 / 报告接口。 | 尽管有具名 CFO 阵容,仍没有可访问的公开财务披露。 |
| Tim Strickland | CRO | 2026-08-13 | 负责企业客户和渠道扩张的商业负责人。 | 与进入市场和合作伙伴经济性尽调相关。 |
| Tracy Dale-Baker | CHRO | 2026-08-13 | 团队全球扩张时的人力资源负责人。 | 可用于平衡创始人主导文化相关问题。 |
| Shane Barney | CISO | 2026-08-13 | 支撑信任、合规和联邦姿态的安全负责人。 | 对事件响应和安全开发流程尽调很重要。 |
| David Oskin | 总法律顾问 | 2026-08-13 | 公开领导层中的法律 / 合规高管。 | 隐私、合同和监管事项的关键负责人。 |
这是面向公众的领导层子集,不是完整组织图;创始人连续性是最重要的概览发现。
[CO004, CO005, CO036]| 利益相关方 | 角色 | 控制权 / 经济重要性 | 当前证据 | 尽调问题 |
|---|---|---|---|---|
| Darren Guccione | CEO、联合创始人、董事会成员 | 管理控制权和战略叙事锚点 | 当前关于页面和董事会名单。 | 澄清投票控制权、期权池影响和流动性历史。 |
| Craig Lurey | CTO、联合创始人 | 技术联合创始人连续性和产品影响力 | 当前领导层页面加历史资料。 | 澄清创始人层级以下的产品归属拆分和继任深度。 |
| Insight Partners | 成长股权投资人 | 2020 年以来首次披露的机构股权支持方;通过 Thomas Krane 拥有董事会代表 | Crunchbase News、Insight 文章和董事会名单。 | 索取持股比例、清算优先权和治理权利。 |
| Thomas Krane | Insight 董事会代表 | 对增长战略和软件进入市场纪律有董事会层面影响 | 在 2020 年融资报道和当前董事会名单中具名。 | 确认委员会角色和当前董事任期。 |
| Summit Partners | 成长股权投资人 | 第二个主要成长股权支持方;少数股权投资,条款未披露 | Summit 公告、回顾文章和董事会名单。 | 索取支票规模、估值、持股比例、按比例跟投权和保护性条款。 |
| Len Ferrington | Summit 董事会代表 | 具有网络安全投资背景的董事会层面资本伙伴 | 在 Summit 公告和当前董事会名单中具名。 | 确认 Summit 是否拥有观察员或完整董事权利,以及是否有任何否决权。 |
私有公司所有权在公开记录中仍不完整;图谱聚焦于对尽调重要的可见控制和治理节点。
[CO006, CO010, CO013, CO014, CO016, CO017]1.3 资本形成、时间线与公开负面记录
Keeper 公开可见的融资时间线从 2020 年 8 月 Insight Partners 交易开始;Crunchbase News 将其描述为公司首次股权融资,Insight 则将其定位为 $60M 成长轮,用来支持公司成功转向 B2B 企业密码管理。后续 Summit Partners 交易在战略上重要,但公开记录中的财务信息不完整:Summit 称其完成一笔重要少数股权投资并加入董事会,同时明确指出私下交易的其他条款未披露。即使缺少支票金额或估值,公司及合作伙伴材料仍显示 2020 年后有一串重要里程碑:2021 年底收购 Glyptodon,并在 2022 年改造为 Keeper Connection Manager;2022 年 8 月取得 FedRAMP Moderate;2023 年开设 Tokyo 作为 APAC 总部;Keeper 回顾材料把 Summit 投资和 KeeperPAM 平台发布都列为当年关键节点;2024 年 3 月推出移动端通行密钥支持;2025 年 12 月获得 FedRAMP High,2026 年 2 月获得 GovRAMP High。公开负面记录更多指向攻击面审查,而不是广为人知的灾难性泄露。Keeper 自有文档发布 Keeper Connection Manager 的漏洞公告,其中包括一个高严重级别 SAML 响应问题;OpenCVE 追踪更多 Keeper 相关 CVE,例如有争议的明文内存暴露和 KeeperChat 生物识别问题;Built In 的 AI 生成雇主画像还浮现了创始人主导压力和倦怠评论,属于低置信度文化信号。这些问题本身不会否定 Keeper 的平台质量,但说明尽调应计入技术审查和关键人物依赖,而不能假设记录完全无瑕。[CO013, CO015, CO016, CO018, CO019, CO023]
| 日期 | 事件 | 类型 | 金额 / 估值 / 状态 | 参与方 | 含义 |
|---|---|---|---|---|---|
| 2009-01-01 | 最初的 Keeper 应用开发 / 产品起源 | 创立 | 产品起源确立 | Darren Guccione;Craig Lurey | 解释为什么有些来源引用 2009 年,尽管公司成立更晚。 |
| 2011-01-01 | Keeper Security, Inc. 正式联合创立 | 创立 | 多个公开来源中的公司成立年份 | Darren Guccione;Craig Lurey | 后续融资和阶段分析的规范公司起点。 |
| 2020-08-17 | Insight Partners 少数股权成长轮 | 融资 | US$60M 已披露;首次股权融资 | Insight Partners;Thomas Krane | 引入机构资本和董事会监督。 |
| 2021-12-01 | 收购 Glyptodon | 产品 | 收购后来整合进 KCM | Keeper;Glyptodon | 扩展远程访问和基于浏览器的会话能力。 |
| 2022-05-04 | Keeper Connection Manager 发布 | 产品 | 零信任远程基础设施访问层上线 | Keeper | 将特权远程访问更推近完整 PAM 覆盖。 |
| 2022-08-01 | 达成 FedRAMP Moderate | 监管 | Moderate 基线授权 | Keeper Security Government Cloud | 打开进入美国联邦工作负载的路径。 |
| 2023-05-01 | 东京 APAC 总部开设 | 规模 | 区域办公室启动 | Keeper 领导层;董事会;本地伙伴 | 释放国际销售投入和区域化信号。 |
| 2023-12-18 | 回顾文章将 Summit 投资和 KeeperPAM 发布列为 2023 年标志性事件 | 合作 | 年终增长和平台扩张总结 | Keeper;Summit Partners | 显示 2023 年是从密码管理器转向更广义 PAM 身份平台的过渡年。 |
| 2024-03-25 | iOS 和 Android 新增通行密钥管理 | 产品 | 移动端通行密钥支持已上线 | Keeper 产品团队 | 把无密码叙事扩展到浏览器扩展之外。 |
| 2025-12-23 | 宣布 FedRAMP High 授权 | 监管 | High 基线授权 | Keeper Security Government Cloud | 强化面向高影响工作负载的联邦市场可信度。 |
| 2026-02-11 | 宣布 GovRAMP High 授权 | 监管 | 高影响 SLED 授权 | Keeper Security Government Cloud | 将受监管公共部门触达扩展到联邦买家之外。 |
若无法从可访问公开证据恢复精确日期,只到年份或月份的里程碑统一归一到该期间第一天。
[CO011, CO012, CO013, CO016, CO023, CO024]Keeper 的公开时间线从 2009 年产品起源和 2011 年公司成立开始,经过 2020/2023 年成长股权资金支持、2022-2024 年产品扩展, 直到 2025-2026 年联邦和 SLED 授权升级。
只有能找到带日期的公开公告时才使用具体日期;仅有年份或月份的里程碑固定到该期间第一天。
[CO003, CO011, CO012, CO013, CO016, CO023]1.4 展示材料
02市场分析
2.1 市场边界、相邻领域与现状替代品
Keeper 所在的是分层市场,而不只是传统消费者密码管理器品类。当前产品页面覆盖员工密码管理、特权访问管理、机密管理、远程浏览器和远程基础设施访问、通行密钥管理以及公共部门身份安全。这意味着相关市场边界比“把密码存在保险库里”更宽,但又窄于完整身份栈。Keeper 并不想成为通用目录、完整客户身份平台或广义 SIEM;它切入的是组织需要安全凭据存储、最小权限会话控制、机器机密工作流和抗钓鱼认证,但又不想拼接多个点状工具的场景。因此,替代品集合具有结构性重要性。低端市场里,Google Password Manager 和 Apple 的 Passwords 应用已经为消费者和轻管理团队提供零价格的内置密码与通行密钥存储。机器身份侧,AWS Secrets Manager 和 Azure Key Vault 覆盖各自生态内的云机密存储。相邻企业安全预算中,BeyondTrust 等 PAM 老牌厂商已经销售即时授权和最小权限控制。Keeper 的楔子在于把这些任务统一进一个零知识控制平面,尤其适合那些希望用一个系统横跨人工凭据、机密、特权会话和无密码迁移,而不是拆成多个供应商孤岛的买家。[CM001, CM002, CM003, CM004, CM005, CM025]
| 分部 / 品类 | 纳入支出 | 排除支出 | 买方 / 付款方 | 与 Keeper 的相关性 |
|---|---|---|---|---|
| 员工密码管理 | 付费密码库订阅、凭证共享、策略控制、审计日志和恢复工作流 | 未管理的电子表格、浏览器记忆,以及零价格的未管理存储 | 个人、IT 管理员、CISO / 用户或雇主 | 核心收入楔子和历史品牌锚点 |
| 特权访问管理 | 最小权限访问、凭证轮换、会话监控、远程访问和端点权限控制 | 广义 IAM 目录支出或完整网络安全平台 | 安全、IAM、基础设施和合规团队 / 安全或 IT 预算 | KeeperPAM 明确瞄准的增长最快相邻市场 |
| 机密凭证管理 / NHI 安全 | API 密钥、服务凭证、CI/CD 机密凭证、云端轮换和机器到机器访问控制 | 未与凭证绑定的一般云基础设施支出 | DevSecOps 和平台工程 / 工程或安全预算 | 人类密码库之外的重要扩张路径 |
| 无密码 / 通行密钥编排 | 通行密钥存储、共享、自动填充、员工推广和抗钓鱼登录策略 | 生物识别硬件本身和消费者设备操作系统锁定 | 身份、安全和终端用户 IT / 安全或生产力预算 | 密码衰退时的战略增长层和留存防线 |
| 政府 / 受监管身份安全 | 符合 FedRAMP / GovRAMP 的访问控制、可审计性和零信任特权访问 | 更广义公共部门 ERP 或案件管理软件 | 机构安全团队、采购和合规 / 公共部门 IT 预算 | Keeper 的授权栈把 TAM 扩展到商业 SMB 之外的地方 |
| 内置 / 生态替代品 | n/a — 竞争语境,而不是 Keeper 收入池 | Google Password Manager、Apple Passwords、CSP 原生机密凭证存储 | 终端用户或现有云账户所有者 / 通常没有单独付款方 | 定义 Keeper 必须超越的零价格或已打包基线 |
这张表按待完成任务定义市场,而不是把所有身份支出都当作 Keeper 的可服务机会。
[CM001, CM002, CM003, CM004, CM005, CM025]Keeper 的市场把消费者、企业安全、工程和公共部门采购中心连接到一个集成式凭证控制平台。
[CM001, CM003, CM014, CM015, CM016, CM027]2.2 规模测算视角、地域与分段经济性
2026 年已发布市场规模测算方向上偏乐观,但数字彼此不一致,这正是 Keeper 市场应以区间呈现的原因。Mordor Intelligence 和 Research and Markets 都预计密码管理市场 2026 年为 US$2.94B,并以 22.39% CAGR 增至 2031 年 US$8.07B;Fortune Business Insights 则把同一品类定为 2026 年 US$3.79B、2034 年 US$10.63B,CAGR 为 13.77%。差距并不小:采用高位还是低位 2026 年数字,会让任何隐含份额或收入讨论相差近 US$850M。比单点总量更有用的是分段和区域方向。北美仍是最大区域,占支出约三分之一到接近五分之二;亚太增长最快。云部署今天占主导,但在数据驻留和受监管工作负载压力下,混合模式增长很快。大型组织仍是收入锚点,SME 则是增长最快的队列,因为订阅定价和低复杂度 SaaS 部署降低了准入门槛。BFSI 的垂直集中度和医疗健康的上升增长,与 Keeper 偏合规的定位相匹配。因此,Keeper 最站得住脚的 SAM 不是“所有密码管理”,而是付费、多用户、合规敏感的那一片:买家足够看重最小权限、可审计性、身份提供商集成、通行密钥和机器机密控制,愿意为专业平台列预算。[CM006, CM007, CM008, CM009, CM010, CM011]
| 发布方 / 视角 | 年份 | 地理范围 | 数值 | CAGR | 方法 / 解读 | 置信度 | 局限 |
|---|---|---|---|---|---|---|---|
| Mordor Intelligence | 2026 | 全球 | 2026 年 US$2.94B;2031 年达 US$8.07B | 22.39% | 密码管理市场模型,按解决方案、部署和地区拆分 | 中 | 综合分析机构方法论为自有,且比 Keeper 的付费楔子更宽 |
| Research and Markets 市场研究 | 2026 | 全球 | 2026 年 US$2.94B;2031 年达 US$8.07B | 22.39% | 分销商摘要,与 Mordor 框架高度一致 | 中 | 看起来复用了同一市场框架,而不是给出完全独立的构建 |
| Fortune Business Insights | 2026 | 全球 | 2026 年 US$3.79B;2034 年达 US$10.63B | 13.77% | 另一组综合分析机构估计,基数、终止年份和分部份额不同 | 中 | 时间跨度和品类定义不同,直接比较更复杂 |
| 已发布区域集中度视角 | 2025-2026 | 北美 / APAC | 北美占比 33.17%-38.93%;APAC 增长最快 | Mordor/R&M 中 APAC 为 24.13% | 跨发布方观察当前支出集中在哪里、增长最快在哪里 | 中 | 区域份额因发布方而异,不能代理 Keeper 份额 |
| 已发布分部组合视角 | 2025-2031 | 全球 | 大型组织占 2025 年支出的 63.4%;SME 最快,CAGR 24.3%;BFSI 占比 29.1% | SME CAGR 24.3%;医疗健康 CAGR 25.9% | 分部和垂直组合来自分析机构模型 | 中 | 可用于判断方向,但仍是品类层面,不是公司特定数据 |
| Keeper 实际 SAM 视角 | 2026 | 受监管 SMB 到企业及公共部门 | 受证据约束的名义 TAM 子集,而非精确美元点位 | n/a | 付费多用户切片:最小权限、可审计性、机密和通行密钥重要到足以为专业平台列预算 | 低 | Keeper 未公开实际付费席位结构、地域结构或市场份额 |
保留相互冲突的发布方估计,不做平均。Keeper 的实际可服务市场(SAM)是一种按能力界定的视角,而不是管理层披露的数字。
[CM006, CM007, CM008, CM009, CM010, CM011]公开发表的密码管理市场估算支持一个有边界的 2026 年 TAM 区间,而不是单一确定数字。
[CM006, CM007, CM008, CM013]Keeper 的实际市场从全部凭证需求,收窄到愿意为受治理、多用户身份控制付费的部分。
只有已发布 TAM 层是数字化的;更低层由能力和控制要求定义,而不是由已披露市场总量定义。
[CM005, CM008, CM014, CM025, CM035, CM037]2.3 买家、采用路径、增长驱动与约束
买方和付款方角色会随分段显著变化。个人和家庭自行购买;SMB 往往由业主或 IT 通才采购;更大的私营企业会让 CISO、IAM 负责人或安全架构师参与决策;当机密、自动化或多云轮换重要时,DevSecOps 或平台工程团队会加入;联邦或 SLED 机构还会叠加采购和合规利益相关方。买方复杂度会拖慢交易,但需求驱动很持久。Verizon 2026 DBIR 继续把泄露成因与人为因素、钓鱼和被盗凭据绑定;IBM 2026 报告把平均泄露成本定为 US$4.99M,并强调 AI 系统对身份控制的需求正在上升。NIST SP 800-207 和 CISA 零信任成熟度模型都强化了最小权限、逐请求访问和以数据为中心的安全控制;NIST SP 800-63B 现在要求 AAL2 提供抗钓鱼选项,并对联邦人员强制要求。Microsoft 2026 Entra 更新进一步推动市场:让通行密钥成为默认路径,并将在 2027 年停用 Microsoft 提供的原生 SMS / 语音投递。这些都是 Keeper 所在品类的强顺风。反向力量同样重要:免费的内置密码 / 通行密钥工具压缩消费者和轻管理分段的支付意愿;PAM 预算要与根深蒂固的老牌厂商竞争;云机密管理器能满足部分机器身份需求,无需另买供应商;组织也常低估迁移共享凭据、集成 IdP 和执行新最小权限工作流所需的变更管理工作。因此,Keeper 的市场吸引力并不主要取决于网络风险是否存在——这很明显——而取决于它能否持续赢下整合度更高、控制要求更强的那一片市场,那里碎片化工具带来的运营负担已经痛到足以支撑整合采购。[CM015, CM016, CM017, CM018, CM019, CM020]
| 细分市场 | 买方 | 用户 | 付款方 | 工作流 | 预算负责人 | 采用触发因素 |
|---|---|---|---|---|---|---|
| 个人 / 家庭 | 个人消费者或家庭负责人 | 同一人或家庭群组 | 同一人或家庭 | 存储密码、通行密钥、验证码,并共享凭据 | 个人可支配支出 | 需要跨设备安全,不能只靠记忆或备忘录 |
| SMB / 商业起步 | 业主或 IT 通才 | 员工和承包商 | 企业主或 IT 预算 | 共享凭据、管理控制台、团队文件夹、基础策略 | IT 或一般管理预算 | 密码蔓延和入职 / 离职流程疼痛 |
| 中端市场 / 企业员工 | CISO、IAM 负责人或安全架构师 | 员工用户和管理员 | 安全或企业 IT 预算 | SSO/SCIM 集成、RBAC、审计日志、特权工作流 | 安全 / IAM 预算 | 需要受治理的凭据共享和合规证据 |
| DevSecOps / 平台工程 | 平台负责人或 DevSecOps 经理 | 开发者、SRE、自动化和工作负载 | 工程或共享安全预算 | 保护 API key、服务账号、CI/CD 机密并轮换 | 工程平台预算 | 硬编码机密蔓延和多云自动化 |
| 公共部门 / 受监管机构 | 机构安全领导层加采购 | 联邦、州、地方和承包商员工 | 公共部门 IT / 安全预算 | 抗钓鱼访问、特权会话控制、合规日志 | 机构 CIO/CISO 预算 | FedRAMP/GovRAMP、最小权限和审计要求 |
| MSP / 合作伙伴主导部署 | MSP 业务负责人或经销商安全团队 | 合作伙伴管理员加下游客户 | 渠道 / 下游客户预算 | 多租户凭据和特权访问管理 | 合作伙伴安全业务预算 | 需要把安全服务运营到大量客户环境中 |
Keeper 终端市场中,买方、用户和付款方角色明显分裂;这种分裂既解释了交叉销售空间,也解释了销售周期复杂度。
[CM001, CM014, CM015, CM016, CM027, CM028]| 驱动因素 / 约束 | 方向 | 时间 | Keeper 含义 | 尽调问题 |
|---|---|---|---|---|
| 钓鱼攻击、被盗凭据和人为因素仍是重大泄露驱动因素 | 上行 | 当前 / 结构性 | 支撑对密码、通行密钥和特权控制平台的需求 | 测试 Keeper 能否把宏观威胁紧迫性转化为有预算的付费席位 |
| 平均泄露成本创纪录达到 US$4.99M,提高了企业为身份控制付费的意愿 | 上行 | 当前 | 强化凭据和最小权限工具的 ROI 逻辑 | 询问客户哪些成本规避论点真正能赢单 |
| 零信任政策和联邦指引要求最小权限和抗钓鱼访问 | 上行 | 当前 / 结构性 | 利好 Keeper 的 PAM 和政府云定位 | 衡量管线中有多少由合规驱动,而不是便利性驱动 |
| Microsoft 默认推出通行密钥,加速无密码迁移 | 上行和下行 | 2026-2027 | 给 Keeper 通行密钥编排带来顺风,但也表明独立密码需求会演进 | 量化即使 Microsoft 推动政策变化,Keeper 是否仍能赢下编排层 |
| Google 和 Apple 内置密码 / 通行密钥栈挤压低端市场 | 下行 | 当前 / 结构性 | 抬高消费者和轻管理细分市场的获客风险 | 将 SAM 聚焦在托管和受监管买方,而不是所有用户 |
| AWS 和 Azure 的云原生机密存储在现有 CSP 预算里满足一部分机器身份任务 | 下行 | 当前 | 买方偏好单云原生工具时,会限制 Keeper 的机器机密切入点 | 找出多云和审计驱动场景,在这些场景里统一平台胜过原生存储 |
| 传统本地部署 PAM 工具往往复杂,部署也吃人手 | 对 Keeper 上行 | 当前 | 如果买方证据成立,云原生的易部署性可以成为真实切入点 | 用参考客户验证 EMA 和 SoftwareReviews 发现 |
| 密码、PAM、机密和端点预算之间类别重叠,会拖慢采购委员会 | 下行 | 当前 | 多个团队必须先就范围达成一致,销售周期可能拉长 | 梳理 Keeper 扩张成功时,哪个预算负责人最先签字 |
多个因素都是双刃剑:通行密钥能推高类别紧迫性,也可能让低端市场商品化;PAM 复杂度创造机会,也抬高举证门槛。
[CM018, CM019, CM020, CM021, CM022, CM023]企业采用按阶段推进:评估、身份集成、迁移、监控,再扩张到 PAM、通行密钥或机密项。
[CM017, CM028, CM029, CM030, CM031]2.4 展示材料
03竞争格局
3.1 版图、替代品与竞争者类别
Keeper 的竞争集合最好理解为四类重叠玩家。第一类是直接的员工密码和凭据控制同行:1Password、Bitwarden、Dashlane 和 LastPass,它们都向企业买家销售安全保险库、共享、管理员控制以及无密码或通行密钥支持。第二类是相邻的特权访问和身份安全套件,例如 CyberArk、Delinea 和 BeyondTrust;它们不是从传统密码保险库起步,而是从最小权限、会话控制和零常驻特权工作流切入同一买家。第三类是以机密为中心的工具和云原生替代品,例如 HashiCorp Vault、AWS Secrets Manager 和 Azure Key Vault;它们解决问题中的机器身份一侧,并可能吸收本会流向统一平台的预算。第四类是零价格内置工具和现状本身:Google Password Manager、Apple Passwords,以及浏览器自动填充、硬编码机密和临时凭据共享等未治理习惯。关键在于,Keeper 会被两端挤压。Google 和 Apple 压缩低端支付意愿,CyberArk 或 Delinea 则能把大型企业拉向更宽的身份安全套件。因此,Keeper 可赢的可服务市场不是“所有有密码的人”,而是这样一片买家:他们足够看重密码、通行密钥、机密、特权访问和合规上的统一控制,愿意选择专业平台,而不是零散工具或捆绑替代品。[CP001, CP002, CP010, CP011, CP012, CP013]
| 竞争对手 | 类别 | 规模 / 融资信号 | 目标客群 | 差异化 | 局限 |
|---|---|---|---|---|---|
| Keeper Security | 直接竞争:企业凭据安全平台 | 数千家组织;数百万用户;强调公共部门合规姿态 | SMB、企业、公共部门、MSP | 一个平台里整合零知识保险库、通行密钥、机密、KeeperPAM 与合规深度 | 私营公司,公开的实际定价和赢单 / 输单披露有限 |
| 1Password | 直接竞争:高端访问平台 | 200,000+ 家企业信任 1Password | SMB 到企业 | 访问叙事更宽,覆盖密码、机密、应用、设备和 AI/SaaS 发现 | 抓取页面里,公开企业定价可见度弱;公共部门合规强调弱于 Keeper |
| Bitwarden | 直接竞争:价值 / 透明度竞品 | 全球 80,000+ 家企业 | SMB、企业、受监管买方、开发者 | 开源透明度、自托管选项、快速部署和 ROI 主张 | 公共部门和合规姿态没有 Keeper 那么前置 |
| Dashlane | 直接竞争:凭据安全竞品 | 抓取页面未清晰披露业务规模 | 商业客户和企业 | Omnix 重新定位、凭据保护、管理控制、SSO/SCIM 和最小权限共享 | 抓取页面中的定价细节大多为自定义 / 不透明,直接公开规模信号更弱 |
| LastPass | 直接竞争:存量密码管理器竞品 | 公认的消费者和企业品牌;当前抓取页面上的规模主张是定性的 | 个人、SMB、商业客户 | 跨平台零知识保险库,加上 SSO/MFA 邻接能力和广泛安装认知 | 信任姿态仍受已披露的 2022 年事件和持续整改信息影响 |
| CyberArk | 邻近:身份安全 / PAM 套件 | 大型企业身份安全品牌 | 企业、云和安全买方 | 零常驻特权、每个身份控制、智能体身份和安全远程访问 | 相比纯员工保险库部署,平台更宽也可能更重 |
| Delinea | 邻近:PAM / 身份安全套件 | 成熟企业 PAM 平台,包含 Secret Server 和远程访问模块 | 企业和受监管买方 | 动态授权、AI 驱动审计、会话监控、密码轮换和远程特权访问 | 只需要员工保险库或轻量共享的买方,可能觉得范围过大 |
| BeyondTrust | 邻近:端点 / 特权管理 | 成熟端点和特权管理覆盖 | 企业安全和端点买方 | 端点覆盖和合规框架下的即时 / 恰量特权 | 相比直接保险库竞品,不那么聚焦消费者 / 员工密码 UX |
| HashiCorp Vault | 邻近:开发者机密平台 | 开发者和平台工程在机密引擎、动态凭据上的标准选择 | 平台工程、DevSecOps、多云团队 | 强 API/CLI、动态凭据和加密即服务路径 | 不是天然的员工密码共享产品 |
| 原生和捆绑替代品 | 替代 / 现状 | 以生态规模预装,或与现有云支出捆绑 | 消费者、轻管理团队、单云工程团队 | 无需新增软件采购、熟悉度高、平台集成紧密 | 对混合人类加机器身份控制,组织级治理较弱 |
表格覆盖买方解决同一凭据控制任务的主要方式:直接竞品、更广的 PAM 套件、开发者机密平台和捆绑替代品。
[CP001, CP002, CP003, CP005, CP007, CP009]用有证据支撑的序数评分,将主要竞争者放在治理 / 合规深度与身份控制范围广度两个维度上。
评分是基于已抓取官方页面的序数综合,不是经审计市场份额或基准指标。
[CP001, CP010, CP011, CP014, CP015, CP016]3.2 同行画像、能力取舍与定价姿态
在直接同行中,1Password 是已披露业务规模里最强的高端标杆:其企业页面称超过 200,000 家企业信任该平台,公司如今围绕密码、机密、设备、SSO 之外的应用、AI 发现和更宽的访问治理定位,而不只是保险库存储。Bitwarden 从相反方向进攻,凭借 80,000+ 家企业、开源透明度、云或自托管部署,以及量化的易部署和 ROI 主张。Dashlane 正把自己从密码管理器重塑为 Omnix 凭据安全平台,把安全保险库与凭据保护和风险检测模块配在一起。LastPass 仍是可识别的跨平台零知识品牌,并与 SSO、MFA 相邻;但其当前官网仍用相当篇幅解释 2022 年后整改和安全转型,显示信任拖累仍未完全消失。Keeper 自己的主张组合包括零知识架构、安全共享、SCIM / SSO、通行密钥、机密、KeeperPAM、MSP 支持、AI agent 机密访问和公共部门合规。相邻企业买家侧,CyberArk 和 Delinea 现在销售动态授权、AI 驱动审计、安全远程访问、机器身份和零常驻特权模型,能够吞并更简单的保险库点状方案。公开定价透明度参差不齐:多数已抓取页面展示按用户年度套餐或定制销售动作,但公开数字的可比性弱于品类买家预期,尤其当企业套装、ELA 和定制报价进入讨论后。[CP003, CP004, CP005, CP006, CP007, CP008]
| 购买标准 | Keeper | 1Password | Bitwarden | Dashlane | LastPass | CyberArk / Delinea | HashiCorp Vault | 原生内置 |
|---|---|---|---|---|---|---|---|---|
| 员工密码保险库 + 共享 | 高 | 高 | 高 | 高 | 高 | 中 | 低 | 中 |
| SCIM / SSO / 管理策略深度 | 高 | 高 | 高 | 高 | 中 | 高 | 低 | 低 |
| 通行密钥 / 无密码就绪度 | 高 | 中 | 高 | 中 | 中 | 低-中 | 低 | 高 |
| 机器机密 / DevOps 工作流 | 高 | 中 | 高 | 低 | 低 | 高 | 高 | 低 |
| 特权访问 / 会话控制 | 高 | 低-中 | 低 | 低 | 低 | 高 | 低 | 低 |
| 合规 / 公共部门姿态 | 高 | 中 | 中 | 中 | 中 | 高 | 中 | 低 |
| 部署控制 / 自托管或深度平台控制 | 中 | 中 | 高 | 低 | 低 | 高 | 高 | 低 |
评分是基于抓取到的官方页面做出的序位综合。「高」表示当前抓取表面明确前置该能力,并不代表供应商在所有场景都普遍最佳。
[CP012, CP013, CP014, CP015, CP016, CP017]| 供应商 | 价格 / 计费单位 / 合同模式 | 包含能力 | 折扣 / 未知项 | 含义 |
|---|---|---|---|---|
| Keeper | 按用户年度打包,高端模块走自定义报价路径 | 定价页面呈现商业、企业、家庭福利、机密、PAM 和 MSP 邻接能力 | 抓取文本无法干净还原精确标价;KeeperPAM 适用自定义报价 | 交叉销售广度有吸引力,但实际定价权不透明 |
| 1Password | 定价页面抓取成功,但提取文本中没有清楚暴露面向企业的公开数字价格 | 企业定位、强支持和更宽的访问平台范围 | 当前抓取提取中,企业价格不透明 | 传递高端定位信号,但也让直接标价对比更难 |
| Bitwarden | 年度订阅模式,包含 Teams 和 Enterprise 套餐 | 保险库、共享、企业支持、健康报告、可选机密扩展 | 当前提取的定价文本中没有精确数字 | 即便公开数字标价提取不完整,价值叙事仍然强 |
| Dashlane | 按用户 / 月计费、按年支付,另有自定义企业打包 | 密码管理、凭据保护、SSO/SCIM 和账号管理 | 公开定价页面更强调打包结构,而不是干净的数字对比 | 指向销售主导的企业路径,而不是纯自助对比 |
| LastPass | 付费套餐叠加在有限免费层之上 | 零知识保险库和更广的密码管理器功能 | 本次运行日期抓取企业定价页面返回 404 | 当前公开打包清晰度似乎弱于同行 |
| CyberArk / Delinea | 企业销售路径 | 更广的 PAM、动态授权、会话、机密和 AI 驱动审计 | 公开页面强调能力,而不是透明标价 | 这些供应商以更广套件竞争,不是低摩擦自助工具 |
| HashiCorp Vault | 产品主导文档,加企业部署路径 | 机密引擎、动态凭据、加密和 API/CLI 工作流 | 抓取到的文档表面未把公开定价放在核心位置 | 工程主导的机密买方可能先比较架构,再比较价格 |
| 原生 / 捆绑替代品 | 零新增成本或预先捆绑 | 现有生态中的密码 / 通行密钥存储或云机密 | 成本隐藏在平台或云关系中,而不是单独 SKU | 对低端和单云场景形成强替代压力 |
当前抓取页面没有暴露干净公开数字定价时,表格会明确保留未知项,而不是导入未说明的标价。
[CP015, CP017, CP019, CP022, CP023, CP029]直接密码同行和相邻套件在基础保险库能力上差距不大,真正差异在控制深度、机器身份和特权访问广度。
[CP012, CP013, CP014, CP015, CP016, CP017]3.3 切换成本、分发力量与护城河耐久性
Keeper 有真实但有条件的护城河。买家一旦配置文件夹、角色、SCIM 预配、SSO、会话控制和入职工作流,切换成本就有分量;但这些成本不是绝对的,因为竞争对手会主动宣传迁移、导入和快速上线。这让功能平价压力始终很高。分发力量越来越来自生态广度和买家信任,而不只是密码存储:1Password 伸向 SaaS 治理和 AI 发现,CyberArk 和 Delinea 伸向全身份特权控制,云原生机密存储则能靠已经在 AWS 或 Azure 内部“天然存在”取胜。已抓取页面中,Keeper 最强的护城河信号是偏合规姿态、公共部门就绪度、密码加机密加 PAM 的统一叙事,以及把运营简单性与安全一起销售的能力。最大替代风险是 Apple、Google 和平台厂商把基础保险库与通行密钥商品化,以及更宽身份安全玩家在高端推动套件竞争。因此,最重要的开放问题不是 Keeper 是否功能完整——大体上是完整的——而是它能否足够稳定、足够快地赢下中间那片重控制整合市场,以抵消下方的捆绑原生替代品和上方的更宽套件整合。缺少当前赢单 / 输单数据、实际定价和产品附加率之前,护城河耐久性应视为有前景,但尚未完全承销。[CP022, CP024, CP025, CP026, CP027, CP028]
| 护城河主张 | 威胁 | 严重性 | 缓释因素 / 当前信号 | 尽调问题 |
|---|---|---|---|---|
| 合规驱动的差异化 | 更广的平台型供应商复制了足够多的控制能力;面向商业买方时,只有公共部门和受监管账户仍能清晰区分 | 高 | Keeper 突出 FedRAMP/GovRAMP 和零知识架构 | 量化公共部门 ARR、续约率,以及相对 1Password 和 CyberArk 的赢单率 |
| 统一的人类 + 机器身份叙事 | AWS、Azure 和 HashiCorp 可吃掉机器密钥这一块,Apple/Google 则可吸收简单用户存储 | 高 | Keeper 定价和产品页显示,密钥管理、AI 智能体访问和 PAM 被放在同一平台 | 衡量密钥管理和 PAM 在新客户签约中的附加率 |
| 运营简洁性 | Bitwarden 和 Dashlane 都主打快速部署或管理员效率收益 | 中 | Keeper 企业页面称,可在数分钟内部署,并提供 24x7 支持 | 通过近期客户访谈验证实施时间和管理员投入 |
| 信任与安全架构 | LastPass 已证明,任何重大事件都可能迅速改写供应商选择 | 高 | Keeper 强调零知识、审计和合规姿态 | 索取事件历史、保险影响及大客户安全问卷 |
| 定价权 | 不透明的定制合同可能抹掉标价或打包优势 | 中 | Keeper 可把家庭计划、MSP、密钥管理和 PAM 打包,拉高价值 | 收集各细分市场的竞品报价和折扣区间,再判断定价耐久性 |
| 套件整合防线 | 1Password、CyberArk 和 Delinea 都把身份控制叙事从保险库扩到更广 | 高 | Keeper 已覆盖通行密钥、密钥管理和特权访问 | 评估买家是把 Keeper 视为真正的平台型候选,还是只视为保险库加附加模块 |
严重度衡量未来 12-36 个月可能出现的战略压力,而不是份额流失的确定性。
[CP008, CP010, CP011, CP016, CP017, CP024]概括 Keeper 相对直接和相邻竞品最重要的竞争耐久度指标。
[CP003, CP005, CP016, CP017, CP025, CP031]3.4 展示材料
04财务情况
4.1 收入模式、定价与变现架构
Keeper 的收入机制比经审计结果清晰得多。官方定价和产品页面显示,这是一门按席位订阅的业务,变现层次多于单一消费者应用。入口端,Keeper 向小团队销售 Business Starter;随后扩展到 Business 和 Enterprise 层级,提供更宽的管理、身份提供商集成、SCIM、RBAC 和开发者 API。公司还销售或打包更高价值的相邻模块:Secrets Manager 是商业计划的附加项,并包含在 KeeperPAM 中;KeeperPAM 本身采用定制报价;MSP 套餐暴露出面向渠道的收入面;每个企业用户免费获得 Keeper Family Plan,则是采用和留存增强器,即使它本身未必直接贡献增量 ARR。重要的财务解读是,Keeper 按账户层级、治理深度和相邻模块附加来变现访问控制,而不是按交易量或重服务实施来收费。这通常会改善收入质量,因为席位订阅、企业治理功能和模块扩张通常具备经常性和粘性。但公开的变现清晰度仍不等于公开的变现深度。这些页面说明了 Keeper 可以为什么收费;它们没有披露 ARR 有多少来自 SMB 密码管理、企业合同、公共部门、MSP、机密管理或 PAM,也没有披露折扣后的实际 ASP。因此,商业模式可以理解,但收入组合仍是私有信息。[CI001, CI002, CI003, CI004, CI005, CI006]
| 收入流 | 机制 | 单位 | 当前价值 / 状态 | 质量 | 尽调问题 |
|---|---|---|---|---|---|
| Business Starter 密码管理器 | 面向小团队的按席位经常性 SaaS | 按用户 / 月,按年计费 | 官方定位为 5–10 名用户 | 高 | 新客户数量中,有多少落在这里,而不是标准 Business 或 Enterprise? |
| Business 密码管理器 | 按席位经常性 SaaS | 按用户 / 月,按年计费 | 官方定位为全公司安全和管理层级 | 高 | 扣除席位折扣后的实际 ASP 是多少?这一层级贡献多少 ARR? |
| Enterprise 密码管理器 | 带更深治理的按席位经常性 SaaS | 按用户 / 月,按年计费,叠加谈判后的企业打包 | 官方营销重点包括 SCIM、SSO、RBAC 和 API | 高 | 企业合同贡献多少 ARR?这一队列的总留存率是多少? |
| Secrets Manager 附加项 | 商业计划的模块附加项;KeeperPAM 内含 | 按用户 / 年,或打包计费 | 官方称其是所有商业计划的附加项,并随 PAM 提供 | 高 | Secrets Manager 的附加率是多少,独立 ASP 是多少? |
| KeeperPAM | 销售驱动的经常性平台扩张 | 定制报价 | 官方仅通过销售团队销售,并按组织定价 | 中 | KeeperPAM 目前贡献多少 ARR 和毛利率? |
| MSP / 渠道打包 | 经合作伙伴转售或交付的经常性软件打包 | 客户或合作伙伴合同 | 定价页上有官方 MSP 入口 | 中 | 渠道来源 ARR 有多少?合作伙伴利润率结构如何? |
| 消费者 / 家庭相邻业务 | 每名企业用户附带免费家庭计划,加上面向消费者的保险库体验 | 家庭计划 / 消费者计划 | 更像采用和留存增强项,而非明确增量企业 ARR | 中 | 有多少员工用户因家庭计划权益而转化或留存? |
公开页面能看见收入来源,但看不见公开收入结构。这些页面揭示的是变现架构,而不是细分市场级 ARR 构成。
[CI001, CI002, CI003, CI004, CI005, CI006]| 价格 / 单位 / 合同 | 标价与实际价格 | 折扣 / 未知项 | 来源 | 影响 |
|---|---|---|---|---|
| Business Starter / Business / Enterprise 基于用户的年度打包 | 标价结构公开;抓取文本中未能稳定恢复具体数字 | 实际 ASP、折扣和最低席位数未披露 | Keeper 官方定价 | 确认按席位经常性变现,但不揭示收入密度 |
| KeeperPAM 定制定价 | 仅谈判定价 | 报价驱动结构遮住实际模块经济性 | Keeper 官方定价和 PAM FAQ | 高价值模块可能有更高 ASP,但公开透明度更弱 |
| Secrets Manager 作为商业计划附加项 | 结构部分公开 | 具体附加 ASP 和打包渗透率未披露 | Secrets Manager 官方页面 | 显示核心保险库之外仍有模块化 ARPU 扩张空间 |
| 每名企业用户附带免费家庭计划 | 不是直接的企业价格项 | 对留存、采用和支持成本的经济影响未知 | Keeper 官方定价和企业页面 | 可能提升采用,但会压低表观 ARPU |
| MSP 打包 | 由销售和合作伙伴主导的打包 | 经销商利润率和终端客户价格未披露 | Keeper 官方定价 | 渠道能放大分销,但会模糊实际经济性 |
| 企业捆绑、定制化定价和 ELA | 谈判形成的企业经济性 | 没有公开折扣区间或支持捆绑价格 | Keeper 官方企业和定价页面 | 仅靠标价页无法推断大客户单位经济性 |
官方公开定价提供结构,不足以分析实际收入。私营公司尽调必须从标价架构穿透到真实合同经济性。
[CI002, CI003, CI005, CI006, CI029, CI036]展示 Keeper 如何把账户采用转化为经常性收入,靠套餐升级和附加模块挂载拉动。
[CI001, CI002, CI003, CI004, CI025, CI036]2024–2026 年公开估计区间很宽,因为私营公司数据库和公司披露口径衡量的内容不同。
[CI007, CI008, CI012, CI013]4.2 GTM 动作、公开牵引力与单位经济代理指标
Keeper 2026 年 7 月披露显著改变了本报告的牵引力基线。公司现在称 ARR 为 US$225M,自 2021 年以来 ARR 增长超过 3x,保护超过 95,000 家组织,平均每月新增 850 家组织,并且 KeeperPAM 自 2025 年 2 月发布以来收入同比增长 10x。另一份与 SoftwareReviews 相关的 2026 年 PR 称,Keeper 2025 年全球收入增长率为 53.42%,是该稿引用的整体市场平均值的 3.45x。这些是公司来源数字,不应误认为经审计文件,但方向上重要,因为它们意味着 Keeper 已不再是小规模密码保险库厂商。GTM 动作看起来也不是纯企业销售驱动,而是混合型。商业和企业页面强调数分钟部署的入职、用户采用、24x7 支持和开箱即用的身份集成,说明小账户可能通过产品驱动或产品辅助进入。与此同时,KeeperPAM 的定制报价、偏合规的公共部门定位和更宽模块附加,又意味着较大企业和政府交易仍需要经典销售辅助动作。单位经济画像仍不完整。第三方数据库在员工数和估计收入上分歧很大,进一步说明私营公司数据源噪音很高。公开层面,最强的承销输入是公司最新 ARR / 增长主张和产品定价架构;最弱的恰恰是投资者最关心的指标:流失、净留存、CAC、回本周期、分段组合和实际扩张率。[CI007, CI008, CI009, CI010, CI011, CI012]
| 指标 | 数值 / 空值 | 置信度 | 为何重要 | 尽调问题 |
|---|---|---|---|---|
| ARR 里程碑 | US$225M ARR(公司声称,2026 年 7 月) | 中 | 为规模提供第一个较强公开锚点 | 索取按产品家族和细分市场拆分、经审计师审阅的 ARR 桥表 |
| 2021 年以来 ARR 增长 | 超过 3x | 中 | 支撑增长耐久性叙事 | 提供 2021 至 2026 年各年末 ARR,并拆分净新增和扩张 |
| 新客户速度 | 平均每月新增 850 家组织 | 中 | 反映漏斗强度和销售产能 | 展示按细分市场拆分的新增客户数、平均首年 ARR,以及向付费层级的转化 |
| KeeperPAM 增长 | 自 2025 年 2 月发布以来,收入同比增长 10x | 中 | 指向平台内高 ARPU 扩张路径 | 展示 KeeperPAM 的绝对 ARR、毛利率和附加率 |
| 2025 年全球收入增长代理指标 | 公司引用的 SoftwareReviews PR 显示,2025 年同比增长 53.42% | 中 | 支撑 2026 年 ARR 披露前的动能 | 提供这一数字背后的 GAAP/管理口径收入定义调节 |
| 毛利率 | null | 低 | 核心毛利质量仍未公开披露 | 提供整体 GAAP 毛利率,以及核心保险库、PAM、密钥管理分项毛利率 |
| CAC | null | 低 | 用来测试增长效率,并比较各细分市场的获客打法 | 提供混合和分细分市场 CAC,包括渠道来源交易 |
| CAC 回本周期 | null | 低 | 投资测算销售驱动的模块扩张时不可缺 | 按 SMB、企业、公共部门和合作伙伴渠道队列提供回本周期 |
| 净收入留存率(NRR) | null | 低 | 要给已安装账户内的席位扩张和模块附加估值,必须有该指标 | 提供按队列和产品家族拆分的 NRR 与总留存率 |
| 流失 | null | 低 | 低端密码品类可能掩盖付费耐久性弱的问题 | 提供按细分市场拆分的客户数流失和总金额流失 |
| 员工数 | 第三方估算相互冲突:Growjo 为 506 名员工,Tracxn 为 795 名 | 低 | 员工数冲突削弱外部成本和生产率建模 | 提供按职能和地区拆分的当前 FTE |
| 营运资金负担 | 可能较轻,但未披露 | 中 | 软件模式的营运资金强度应低于硬件或交易型业务 | 提供递延收入、账单节奏、DSO/DPO 和回款指标 |
空值才是真正的阻塞项。公开增长信号有用,但不能替代留存、毛利率或现金效率披露。
[CI007, CI008, CI010, CI011, CI012, CI013]公开证据支持增长和附加率代理指标,但核心 SaaS 效率指标仍未披露。
[CI007, CI008, CI009, CI010, CI028, CI040]4.3 成本结构、资本充足性与财务结论
关于 Keeper 成本结构,最稳妥的推断是它不是什么。它不是硬件、支付或库存业务。产品是云软件、客户端应用、身份集成、机密工作流和特权会话控制,因此主要成本项大概率是工程、云基础设施、安全运营、合规、客户成功和 GTM。公开身份软件可比公司有助于界定这种经济模型的形状,即使不能证明 Keeper 自己的利润率。Okta 2026 财年结果显示,GAAP 毛利率约 77%,销售和营销费用约占收入 35%,R&D 约占收入 22%,自由现金流率约 30%。这是观察规模化身份 SaaS 的有用标杆:高毛利、重但可控的销售投入,以及达到规模后强现金生成。Keeper 自己 2026 年 7 月 PR 称,公司同时具备盈利能力和无债务资本结构,这对资本充足性方向上有利。Insight 2020 年 US$60M 成长投资和 Summit Partners 2024 年少数股权投资也说明,Keeper 走到当前阶段并未明显依赖困境融资。但这些都不能替代当前现金、烧钱速度或现金跑道披露。因此,财务结论是:收入质量和可能的利润率形态偏有利;资本充足性方向谨慎正面;最关键的私营指标仍阻塞决策。简单说,Keeper 现在像一家成长快、订阅占比高、企业规模可信的身份平台,但公开记录仍太薄,无法有信心承销效率或下行保护。[CI016, CI020, CI021, CI022, CI026, CI028]
| 账上现金 | 月度烧钱 | 现金跑道(月) | 计划资金用途 | 下一轮触发因素 | 债务 / 项目融资义务 |
|---|---|---|---|---|---|
| 未公开披露 | 未公开披露 | 未公开披露 | 历史上:2020 年增长资本用于扩张;2024 年少数股权投资;2026 年强调 AI 原生身份、PAM 和平台扩张 | 未公开披露;公司强调的是公开上市选择权,而非紧急融资 | 2026 年 7 月 PR 称资本结构无债务;未发现公开项目融资义务 |
资本方向强于资本证明。公开来源显示近期没有明显困境,但当前现金、烧钱和跑道仍是私人信息。
[CI021, CI022, CI023, CI024, CI030]| 缺失的私营指标 | 影响 | 精确尽调路径 |
|---|---|---|
| 按产品和细分市场拆分 ARR | 没有该数据,就无法把 2026 年 ARR 里程碑的可持续性拆成核心保险库、PAM、密钥管理、MSP 和公共部门贡献 | 索取 2024-2026 年按细分市场、产品家族、地域和客户规模队列拆分的 ARR |
| GAAP 毛利率及托管 / 支持成本结构 | 无法直接判断软件毛利质量和可扩展性 | 索取整体及核心保险库、密钥管理、PAM 分项的经审计毛利率 |
| CAC、回本周期和渠道经济性 | 堵住对增长效率和合作伙伴杠杆的可信判断 | 按获客渠道和合同区间索取 CAC/回本周期,包括经销商经济性 |
| 按队列拆分 NRR、流失和扩张 | 交叉销售耐久性和下行风险无法判断 | 索取 SMB、企业、公共部门和 MSP 账户的留存队列 |
| 现金余额、烧钱和跑道 | 尽管方向正面,偿付能力和融资依赖仍未被证明 | 索取月度烧钱、非受限现金、债务额度和最低流动性目标 |
| 公共部门收入占比 | 合规驱动护城河的财务量化仍为空白 | 索取政府和受监管垂直领域的 ARR、预订量和留存 |
这些都是普通的私营公司披露项,但仍决定能否做投资级测算。
[CI015, CI021, CI024, CI028, CI030, CI040]Keeper 的资本强度看起来更像软件公司,但公开记录仍缺现金头寸和效率传导链。
[CI016, CI019, CI020, CI021, CI022, CI030]4.4 展示材料
05产品与技术
5.1 产品表面与操作者工作流
Keeper 的公开产品地图如今分为三层。基础层仍是员工和消费者保险库:安全密码、通行密钥、文件和机密数据存储,带策略控制、浏览器 / 移动覆盖和企业管理。第二层是机器与特权访问:KeeperPAM、Keeper Secrets Manager 和 Keeper Connection Manager 一起覆盖机密、凭据轮换、发现、基于浏览器的远程访问、隧道、会话录制和零信任访问工作流。第三层是受监管和专用包装:面向公共部门买家的 Government Cloud、用于受损凭据监测的 BreachWatch,以及快速增长的集成目录;该目录现在包括 AI agent 环境、CI/CD 工具、主要身份提供商和云服务。最重要的产品结论不是品类,而是架构:Keeper 试图让保险库成为人工和机器身份工作流的共享控制平面。这给公司提供了连贯的交叉销售叙事,因为通行密钥、机密、远程会话和策略执行都继承同一套管理员和加密姿态。这也意味着后续产品会以核心保险库的信任标准来评判,从而抬高运营、检测质量和发布纪律门槛。包装广度在这里很重要,因为 Keeper 现在能把同一套信任叙事卖进员工、开发者、特权管理员和公共部门场景。[CE001, CE002, CE003, CE004, CE005, CE006]
| 模块 | 主要用户 / 工作负载 | 交付模型 | 功能 | 当前尽调判断 |
|---|---|---|---|---|
| Business / Enterprise 保险库 | 员工用户和 IT 管理员 | SaaS 保险库,加浏览器、桌面和移动客户端 | 密码、通行密钥、文件、共享、管理员策略、SSO/SCIM/RBAC | 成熟核心平台,也是相邻模块的底座 |
| KeeperPAM | 安全、IT、DevOps 和基础设施团队 | 采用网关模式的云原生访问控制平面 | JIT 访问、会话代理、发现、轮换、会话监控和特权工作流 | 扩张引擎,也是产品范围跳出保险库最清晰的一步 |
| Keeper Connection Manager | 对主权敏感、自托管或气隙部署 | 基于 Docker 的自托管远程访问网关 | 基于浏览器的 RDP、SSH、VNC、K8s、数据库和内部 Web 访问,并支持录制 | 差异化部署选项,但运营更重 |
| Keeper Secrets Manager | DevOps、软件工程和机器身份工作流 | 带 SDK、CLI 和集成的全托管云服务 | 基础设施密钥、API 密钥、证书、服务账户轮换和 CI/CD 注入 | 与核心保险库相邻的强机器身份场景 |
| BreachWatch | 监控已泄露凭据的终端用户和管理员 | Keeper 客户端内的附加功能 | 对保险库记录进行本地扫描及暗网 / 泄露监控 | 成熟的辅助安全功能,不是独立平台 |
| Government Cloud (KSGC) | 联邦、州、地方和承包商工作负载 | 基于 AWS GovCloud 的受监管产品 | 密码、密钥、会话监控、安全远程访问和合规包装 | 围绕更广 Keeper 栈的重要受监管包装 |
| 通行密钥管理 | 消费者、员工用户和管理员 | 跨客户端的原生保险库能力 | 保存、同步、自动填充和共享通行密钥,并支持生物识别解锁 | 把保险库相关性延伸到无密码工作流 |
各行列出截至 2026-08-13 对产品尽调最关键的公开 Keeper 模块和打包层。
[CE001, CE002, CE003, CE004, CE005, CE006]| 用户细分 | 待完成任务 | Keeper 工作流 | 控制收益 | 限制 / 尽调问题 |
|---|---|---|---|---|
| 员工 | 存储凭据并安全登录 | 保险库 + 浏览器/移动端自动填充 + MFA/通行密钥 | 降低复用,并集中组织策略 | 需要按层级拆分的实际采用率和日活使用情况 |
| 基础设施管理员 | 访问敏感服务器和数据库,同时不共享凭据 | KeeperPAM 或 KCM 发起基于浏览器的会话、隧道或原生工具访问 | 支持 JIT、会话录制和无凭据访问 | 需要会话规模、延迟和正常运行时间指标 |
| DevOps / 平台工程师 | 把密钥注入自动化和应用 | KSM CLI / SDK / CI/CD 集成将密钥拉入流水线 | 移除硬编码密钥,并集中审计轨迹 | 需要按环境拆分的附加率和轮换覆盖 |
| 政府运营方 | 满足零信任和联邦合规控制 | KSGC 运行在 AWS GovCloud,带 PIV/CAC、SIEM 和受监管打包 | 提升主权和合规适配度 | 需要当前 ATO 包深度和部署参考 |
| 安全团队 | 发现弱凭据或已泄露凭据 | BreachWatch 本地扫描,并对泄露密码发出告警 | 无需把明文密码移到 Keeper 服务器,也能增加监控 | 需要实测修复率和告警有效性 |
| 使用 AI 工具的开发者 | 让智能体安全访问凭据,而不是把密钥粘贴进聊天 | Keeper Agent Kit 及其集成把密钥工作流接入 Claude Code、Copilot、Codex 和 MCP 场景 | 用 RBAC 和审计日志把 Keeper 延伸到智能体工作流 | 需要生产采用和护栏性能数据 |
本表覆盖官方页面和文档可见的主要人类、机器和受监管工作流。
[CE002, CE003, CE004, CE006, CE008, CE020]特权工作流的核心,是从 Keeper 密码库按策略受控访问目标系统,而不把长期凭证暴露给最终用户。
[CE020, CE021, CE023, CE033]5.2 架构、加密、部署与信任控制
作为一家私营软件公司,Keeper 的技术核心披露异常明确。安全架构页面描述了客户端记录和文件夹密钥、主密码流程中一百万次迭代的 PBKDF2、用于 SSO 和无密码流程的基于 ECC 的设备批准、存储数据的 AES-256 GCM、传输中的 TLS 1.3 加载荷封装,以及 2026 年 Q1 在传输密钥外增加一层抗量子封装。同一来源、用户指南和企业指南都强化了中心主张:加密和解密都在已批准设备本地完成,因此 Keeper 员工无法解密客户数据。部署上,KeeperPAM 使用云访问控制平面和轻量级出站网关模式;Keeper Connection Manager 则服务那些需要完全自托管、内网或隔离网络中基于浏览器网关的客户。这种灵活性有战略价值:它拓宽了 Keeper 在商业云、混合环境和受监管政府环境中的适配面。但它也带来更多需要保护的运行模式。自托管 KCM 会把 Docker、SSL、数据库和补丁管理义务交给客户;云托管流程仍依赖设备信任、浏览器扩展行为和身份提供商完整性。架构看起来强且有差异化;攻击面也比简单保险库产品更宽。[CE009, CE010, CE011, CE012, CE013, CE014]
| 层级 | 组件 / 设计 | 证据 | 优势 | 风险 / 未知项 |
|---|---|---|---|---|
| 客户端加密 | 记录密钥、文件夹密钥、用户数据密钥、本地缓存密钥、设备本地加解密 | 安全架构页面 | 最小权限和爆炸半径收缩逻辑清晰 | 需要独立架构评审和密钥处理审计 |
| 认证和设备批准 | 主密码流程使用 PBKDF2;SSO/无密码使用 ECC-256 设备密钥和 DEDK | 安全架构页面 | 登录模式划分清楚,设备信任模型明确 | 终端或扩展沦陷仍是关键风险 |
| 托管访问平面 | 云原生 KeeperPAM,加出站网关模型,无需入站开放 | KeeperPAM 页面和文档 | 比依赖堡垒机的传统方案更容易部署 | 缺少公开可靠性和规模数据 |
| 自托管访问网关 | KCM Docker 部署,包含 Guacamole、NGINX、Tomcat 和支持的数据库 | KCM 概览和安全文档 | 适合隔离网络和内网控制需求 | 客户要承担更多补丁、SSL 和数据库安全态势责任 |
| 机器机密层 | KSM SDK、CLI、REST 和 CI/CD 集成 | 机密管理页面和开发者文档 | 为机器身份提供广泛自动化接口 | 需要按客户分层披露模块挂载和轮换深度数据 |
| 信任和恢复层 | 记录版本、备份、恢复短语、管理员策略控制 | 安全页面和指南 | 纸面上的数据韧性很强 | 恢复操作和支持介入的还原未公开量化 |
| 政府市场封装 | AWS GovCloud 部署,配合受监管身份和合规主张 | 政府页面及 AWS GovCloud 背景 | 扩展到高管控公共部门工作负载 | 具体授权包和工作负载案例深度未公开 |
公开资料细到可以梳理 Keeper 的主要运行层,但还不够支撑实证测试。
[CE009, CE010, CE011, CE012, CE013, CE014]| 控制领域 | 当前公开证据 | 置信度 | 重要性 | 缺口 |
|---|---|---|---|---|
| 零知识设计 | 设备本地加解密,并声称员工无法解密访问 | 高 | 相比更简单的云凭据库,这是核心差异点 | 需要 NDA 下的最新第三方验证 |
| 加密控制 | AES-256、ECC、PBKDF2 1,000,000 次迭代、TLS 1.3、载荷包装,以及 QRC 推出声明 | 中 | 建立具体技术信任模型 | 需要模块边界映射和实现评审 |
| 合规认证 | SOC 2 Type 2、ISO 27001/27017/27018、FedRAMP High 口径、GovRAMP High 口径 | 中 | 支撑企业和政府采购 | 需要认证报告和范围边界 |
| FIPS 证据 | 安全页面引用 FIPS 140-3 证书 | 中 | 联邦和受监管买家很看重 | 需要产品到模块映射和当前证书适用性 |
| 安全测试和披露 | 季度渗透测试、Bugcrowd 管理的 VDP、历史安全公告 | 高 | 显示漏洞管理流程在持续运转 | 需要最近测试摘要和修复 SLA |
| 日志和可审计性 | PAM 流程中的会话录制、SIEM 集成和管理员事件报告 | 高 | 对特权访问治理至关重要 | 需要保留默认值、存储成本和调查工作流细节 |
信任态势是 Keeper 较强的公开产品资产之一,但部分主张仍靠公司自述材料支撑,而不是可独立查验的报告。
[CE009, CE013, CE016, CE017, CE018, CE019]Keeper 的公开架构如今把零知识密码库、特权访问控制平面、机密管理工具和可选自托管网关模式,叠在共享管理与合规控制之上。
[CE001, CE002, CE004, CE009, CE015, CE021]Keeper 的灵活性来自云原生控制、自托管组件和端点信任锚的组合。这种组合扩大适配面,也拉宽运营依赖。
[CE015, CE027, CE028, CE033, CE034, CE035]5.3 工程信号、发布速度与技术风险结论
公开工程信号扎实,虽然并非完全开放。Keeper 文档门户显示,2026 年中后台 API、网页保险库、移动客户端、浏览器扩展、Commander、SDK、网关组件、管理控制台和数据库管理模块都有频繁更新。GitHub 组织暴露出有意义但选择性的开发者表面:Commander、Secrets Manager、PowerCommander、一个 GitHub Action 和一个 Terraform provider 都指向真实的可编程性和生态触达,但不意味着完整平台开放。这是一家商业安全厂商的健康模式:公开代码和 SDK 证据足以验证自动化深度,但不足以假设产品处处透明。主要技术风险信号也公开可见。Keeper Connection Manager 有可见的历史公告列表,OpenCVE 仍索引影响 KeeperChat、KeeperFill 等相邻产品的客户端边缘问题。这不会否定平台成熟度;它只说明 Keeper 是一家真实的安全软件公司,资产面很宽,因此自然背负漏洞管理负担。发布流在商业上也重要:用户客户端、网关和开发者工具频繁更新,说明 Keeper 在为平台维护投入资金,而不是简单收割旧保险库资产。产品技术结论偏有利。Keeper 在技术上看起来已经超出“密码管理器”标签,具备可信的机密和特权访问基础设施;但在承销最新 AI 和政府控制表面之前,尽调仍应要求实时可靠性数据、独立当前测试结果,以及按模块拆分的使用采用情况。[CE024, CE025, CE026, CE029, CE030, CE031]
| 产品面 | 公开信号 | 2026 年成熟度判断 | 重要性 | 缺失证据 |
|---|---|---|---|---|
| Web Vault / 桌面端 / 浏览器 / 移动端 | 2026 年客户端各界面频繁发布 | 成熟 | 核心 UX 与密码 / passkey 覆盖面仍在积极维护 | 需要崩溃、留存和升级摩擦指标 |
| Keeper Gateway / KCM / KeeperDB | 2026 年夏季网关和数据库相关组件多次发布 | 成熟至扩张 | 显示公司在特权工作流上继续投入运营能力 | 需要部署数量和事故率 |
| Commander / SDKs / CLI | 发布说明,以及公开 GitHub 仓库和文档 | 成熟 | 可编程性和管理员自动化信号强 | 需要企业分层使用情况和支持负担 |
| Secrets Manager 生态 | SDK 文档、集成目录、GitHub 仓库,以及 Terraform / Actions 引用 | 成熟至扩张 | 重要的机器身份切入口 | 需要付费采用、轮换覆盖率和 NHI 增长 |
| AI / 智能体集成 | 集成页面现已列出 Claude Code、Codex、Cursor、Copilot 和 MCP 工作流 | 早期扩张 | 把 Keeper 延伸到新的开发者工作流预算 | 需要生产案例、滥用控制和检测有效性 |
| Government Cloud 套件 | 营销和合规叙事很强 | 扩张 | 可能是高价值受监管客群 | 需要在用客户案例和授权包细节 |
发布活动和公开仓库显示工程推进仍在继续,但采用率和可靠性仍未公开。
[CE024, CE025, CE026, CE032, CE037]从公开资料看,Keeper 在密码库、会话访问和自动化上最成熟;AI 智能体和部分监管使用工作流仍是较新的扩张方向。
[CE024, CE025, CE032, CE037]5.4 展示材料
06客户情况
6.1 客户分段、规模与具名客户覆盖
Keeper 可见的客户地图至少横跨七个有意义的分段。一端是使用跨设备保险库、安全共享和 BreachWatch 的消费者个人与家庭;应用商店评分、家庭计划包装和反复出现的“数百万人”表述支撑了庞大的长尾用户基础。中间是 SMB 和中端市场企业客户,它们使用带 SSO、SCIM、报告和安全共享的核心企业密码平台。高端则是关注特权访问、机密、会话监控和审计控制的企业和高度受监管买家。公共部门、高等教育和非营利用户显然是真实子分段,而不是营销抽象:New Mexico Taxation and Revenue Department、Illinois College、Oregon State University 和 Alzheimer’s Association 都出现在 Keeper 案例库中,Government Cloud 信息也强化了专门的公共部门定位。MSP / 渠道需求也可见于 Lucidica 和 KeeperMSP 材料,其中买家是服务提供商,下游用户同时包括 MSP 员工和托管客户。最后,一个技术操作者分段如今叠在基础保险库业务之上:Asite、Williams 和 Nokia 这些案例突出的是需要特权会话、机密、凭据代理或远程访问基础设施的买家,而不只是员工密码存储。重要结论是,Keeper 并不依赖单一客户故事。它的参考集合横跨商业、教育、金融、公共部门、电信、法律和托管服务,说明用途广泛,且没有明显单一垂直极端集中。[CU001, CU002, CU003, CU004, CU005, CU006]
| 细分客群 | 买家 / 用户 / 付款方 | 用例 | 公开规模信号 | 战略价值 | 缺口 |
|---|---|---|---|---|---|
| 个人消费者 | 个人 = 买家 / 用户 / 付款方 | 密码、passkey、私人保险库、安全文件、暗网监测 | 数百万人;229K iOS 评分;111K Android 评分 | 品牌、漏斗,以及指引产品方向的广泛数据集 | 付费转化和流失未公开 |
| 家庭 / 住户 | 家庭组织者 = 付款方;家庭成员 = 用户 | 家庭共享凭据和紧急访问 | 公开打包,并与企业-家庭权益挂钩 | 留存增强器和消费者扩张路径 | 家庭挂载和续约率未公开 |
| SMB / 中端市场企业 | IT / 管理员 = 买家;员工 = 用户;公司 = 付款方 | 共享保险库、管理员控制、SSO、合规和报告 | 95,000+ 组织中的重要子集 | 核心落地路径和席位扩张引擎 | 客群结构和实际 ASP 未公开 |
| 企业 / 受监管商业 | 安全 / IT / 合规 = 买家;员工 = 用户 | SSO/SCIM、审计、机密、特权访问、策略执行 | 公司引用多家 Fortune 500 企业 | 高端合同和模块挂载机会 | 头部账户集中度和留存未公开 |
| 公共部门 / 教育 / 非营利 | 机构 / CIO / IT 领导 = 买家;员工和学生 = 用户 | Government Cloud、凭据管理、远程访问、合规 | New Mexico 税务部门、Illinois College、Oregon State、Alzheimer’s Association | 强信任 / 合规切入口 | 公共部门当前签约 ARR 未公开 |
| MSP / 渠道 | MSP 管理层 = 买家 / 付款方;MSP 员工 + 被管理客户 = 用户 | 多租户密码治理和客户凭据共享 | Lucidica 和 KeeperMSP 案例 | 可在客户组合下游放大席位数 | 渠道收入占比和合作伙伴集中度未公开 |
| 特权访问 / 开发者 / 运维买家 | 安全 / 平台 / 基础设施团队 = 买家;管理员和开发者 = 用户 | PAM、机密、隧道、安全远程访问、会话录制 | Williams、Asite、Nokia 和 New Mexico KCM 用例 | 超出核心保险库的更高价值扩张 | 挂载率和续约深度未公开 |
客户分层来自 Keeper 2025-2026 年的产品、评论和案例研究页面。
[CU001, CU002, CU003, CU006, CU007, CU009]| 客户 | 客群 | 部署 / 用例 | 生产环境还是试点 | 结果 / 证据点 | 限制 |
|---|---|---|---|---|---|
| Atlassian Williams F1 Team | 企业 / 技术运营 | KeeperPAM 用于全球员工和赛事运营的特权访问 | 生产环境 | 员工分布在 20+ 个国家;前安全负责人给出安全性 + 易用性引述 | 未披露合同金额或席位数 |
| Asite | 全球 SaaS / 企业 | 密码、机密和 PAM 统一 | 生产环境 | 500+ 名员工、9 个数据中心,替换昂贵 / 复杂的传统工具 | 案例研究由公司撰写 |
| Lucidica | MSP / 渠道 | KeeperMSP 加 BreachWatch,覆盖员工和托管客户用户 | 生产环境 | 支撑数十个组织和数百名托管用户;同步和共享问题不再出现 | 未披露下游客户收入 |
| Illinois College | 高等教育 | 带 SSO、预配和 MFA 的企业密码管理器 | 生产环境 | 帮助台工单显著下降,学生采用率上升 | 未披露续约或活跃用户比例 |
| Peak Trust | 金融服务 / 信托公司 | 共享文件夹、合规报告和董事会层面使用 | 生产环境 | 支持 FFIEC 报告,扩展到姊妹公司和董事会用户 | 案例可追溯到 2022 年 |
| Oregon State University | 高等教育 | 整合 IT 团队使用共享密码保险库 | 生产环境 | 4,500+ 名员工;安全记分卡改善,非技术员工采用率高 | 当前 2026 年使用情况未公开 |
| NokiaEDU | 电信 / 培训 | KCM 用于远程培训实验室 | 生产环境 | 每月数千名学生;无客户端远程访问和地理冗余带来收益 | KCM 案例较早,产品谱系已有演进 |
| New Mexico Taxation and Revenue Department 税务与收入部 | 州政府 | KCM 用于大规模安全远程桌面 | 生产环境 | 不到一周为 700+ 名员工开通安全浏览器访问 | 案例源于疫情时期的远程办公需求 |
| Alzheimer’s Association 协会 | 非营利 / 医疗相关 | 凭证管理现代化 | 生产环境 | 具名非营利客户证明拓宽了垂直行业覆盖 | 可提取的成效细节弱于较新的案例 |
| 英国全球技术服务商 | 大型企业 | 在 11,000+ 名员工中统一密码管理 | 生产环境 | 实施顺畅、用户采用率高,合规可见性更强 | 客户名称未披露,参考质量下降 |
具名客户证明比多数私营网络安全供应商更宽,覆盖传统密码库以及较新的 PAM / KCM 使用场景。
[CU007, CU014, CU015, CU016, CU017, CU018]Keeper 的主路径,是从不安全或碎片化的凭证习惯,转向集中采用密码库,再扩展到 SSO、机密管理、PAM、家庭用户外溢或公共部门部署等更高控制功能。
[CU001, CU011, CU012, CU028, CU031, CU038]具名客户证明在客群多样性和生产环境证据上很强,但新鲜度和财务深度因案例而差异明显。
[CU014, CU015, CU016, CU017, CU018, CU019]6.2 采用轨迹、部署模式与满意度代理指标
公开采用证据不完美,但方向上强。Keeper 2026 年 7 月 PR 称公司保护超过 95,000 家组织,每月大约新增 850 家组织;2025 年 12 月 G2 博客引用 1,172 条总评价、满足需求满意度 94%、推荐率 92%。后来一篇与 G2 相关的公司博客称超过 100,000 家组织选择 Keeper,应把它理解为更新的发布时点,而不是与 95,000+ 数字的清晰矛盾。外部评论平台大体呼应这个正面图景。GetApp 显示 507 条已验证评价和 82% 正面留存情绪;G2 评论摘录强调快速上线、SSO / SCIM 自动化、跨设备同步和管理员易用性;TrustRadius、SourceForge 风格列表浮现高总体评分,并反复称赞安全共享、可审计性和易用性。具名案例也显示真实部署深度,而不是浅层标识借用。New Mexico 在不到一周内让 700+ 名员工转向安全远程桌面。Nokia 每月为数千名学生使用 KCM。Illinois College 报告帮助台工单显著下降,学生采用持续增长。Asite 在 500+ 员工的全球 SaaS 团队和九个数据中心位置中,将密码、机密和 PAM 标准化。这些都是有明确结果的生产部署,不是抽象背书。限制也可见。这些来源都没有披露日活用户、每账户席位渗透、全客户群部署成功率或按队列续约曲线。因此,采用强度清楚,但精度不足。[CU003, CU005, CU006, CU011, CU012, CU013]
| 指标 | 数值 | 日期 | 来源 | 置信度 | 含义 | 缺失分母 |
|---|---|---|---|---|---|---|
| 受保护组织数 | 95,000+ | Jul 2026 | ARR 新闻稿 | 中 | 存量客户基础强 | 每个组织的活跃席位数 |
| 后续公开页面披露的组织数 | 100,000+ 个组织选择 Keeper | Dec 2025 博客快照 | G2 Winter 2026 博客 | 中 | 暗示规模至少在五位数高位且仍在上升 | 精确计数方法和更新滞后 |
| 每月新增组织 | 平均每月 850 | Jul 2026 | ARR 新闻稿 | 中 | 显示新客户动能延续 | 转化为实质性 ARR 和留存的情况 |
| G2 评论数 | 共 1,172 条评论 | Dec 2025 | Keeper G2 博客 | 中 | 密码产品有大量社会证明 | 客群和地域偏差 |
| iOS 评分基数 | 229K 评分,4.9/5 | Aug 2026 商店快照 | Apple App Store | 中 | 消费者 / 移动端参与度代理指标强 | 付费与免费用户、企业用户重叠度 |
| Android 评分基数 | 111K 评分,4.7/5 | Aug 2026 商店快照 | Google Play | 中 | Android 覆盖面大,消费者持续使用 | 付费与免费用户、企业用户重叠度 |
| GetApp 认证评论 | 507 | Jul 2026 | GetApp | 中 | 广泛 SMB / 中端市场评论证据 | 评论自选择偏差 |
| Nokia 培训吞吐量 | 每月数千名学生 | 2022 案例研究 | Nokia KCM 案例 | 中 | 证实远程访问部署可规模化重复使用 | 当前 2026 年量级未公开 |
| New Mexico 部署 | 不到一周部署 700+ 个远程桌面 | 2020 案例;2022 PDF 中仍被引用 | New Mexico 案例 | 中 | 显示公共部门可快速部署 | 长期席位留存未公开 |
| Illinois College 覆盖 | 300 名员工,学生采用率增长 | 2026 案例研究 | Illinois College 案例 | 中 | 校园范围落地并扩张的证据 | 活跃学生采用比例 |
| Asite 员工覆盖 | 覆盖 9 个数据中心地点的 500+ 名员工 | 2026 案例研究 | Asite 案例 | 中 | 证实适配全球中端市场 / 企业客户 | 已部署席位深度和使用中的模块 |
公开采用证据最强的是总客户数、评论量和部分部署故事;席位深度和留存仍未公开。
[CU003, CU005, CU006, CU012, CU013, CU016]| 指标 | 数值 / 空值 | 分群 | 置信度 | 尽调要求 |
|---|---|---|---|---|
| G2 推荐率 | 92% | 密码管理器用户 | 中 | 按 SMB 与企业客户拆分,并披露 2026 年样本量趋势 |
| G2 需求满足度 | 94% | 密码管理器用户 | 中 | 提供按队列划分的管理员与终端用户满意度,以及 2025 年以来的净变化 |
| SoftwareReviews 推荐意愿 | 93% | KeeperPAM 用户 | 中 | 提供原始受访者数量和企业规模构成 |
| SoftwareReviews 价格价值比公平度 | 87% | KeeperPAM 用户 | 中 | 按分群展示赢单 / 输单和续约价格敏感度 |
| GetApp 正向留存情绪 | 82% | 混合客户群 | 中 | 将情绪与实际客户数留存和收入留存对齐 |
| 净留存率(NRR) | 未披露 | 所有商业分群 | 低 | 提供按 SMB、企业、公共部门和 MSP 拆分的 NRR |
| 总留存率(GRR) | 未披露 | 所有商业分群 | 低 | 提供按产品线和队列拆分的 GRR |
| 客户数流失 | 未披露 | 所有分群 | 低 | 提供年度客户数流失和主要驱动因素 |
| 合同期限 / 续约组合 | 未完全披露 | 商业和企业客户 | 低 | 按分群提供月付、年付和多年期组合 |
| 活跃席位使用率 | 未披露 | 商业和企业客户 | 低 | 按客户规模提供已部署席位、MAU/DAU 和管理员参与度 |
| 消费者重复使用 | 从大型应用商店评分基数推断 | 消费者 | 低 | 提供月活消费者密码库和付费转化 |
满意度公开;留存经济性不公开。
[CU022, CU023, CU024, CU026, CU027, CU031]示意漏斗展示 Keeper 如何从认知推进到密码库上线,再进入更高价值的模块采用。绝对转化率未公开;下列数值只是分析师用于示意的方向性占位。
[CU011, CU012, CU028, CU038]6.3 留存、扩张、集中度与客户结论
Keeper 的客户质量看起来有前景,但公开记录仍未达到投资级留存证明。扩张向量很容易看见:商业和企业账户内的按席位增长、企业到家庭的外溢、Secrets Manager 和 KeeperPAM 附加、通过 Government Cloud 向公共部门增购,以及通过服务提供商客户实现 MSP 式下游席位倍增。评论来源和案例研究也暗示,易实施性在商业上重要,因为低摩擦上线会同时提高采用和续约概率。与此同时,公开负面信号真实存在,不应忽视。G2、GetApp 和 Slashdot 风格评论反复提到价格高或混乱、涨价、附加项疲劳、自动填充不一致、报告缺口,以及一些管理控制台或独立应用限制。这些投诉还没严重到暗示信任危机,但确实指出了流失或采购摩擦会积累的实践区域,尤其是在较小或成本敏感账户中。集中度风险在公开层面仍基本不可知。参考集合跨垂直和地域多元,反对任何单一行业的极端依赖,但前 10 大客户收入、最大客户席位数和按模块拆分的续约表现都是私有信息。新鲜度也不均衡:部分 KCM 参考可追溯到 2022 年,而许多密码管理器和 KeeperPAM 参考来自 2025-2026 年。因此,整体客户结论是有利但不完整:Keeper 似乎拥有多元化装机基础、真实生产参考和良好客户情绪,但决定耐久性的关键指标——NRR、GRR、流失、续约定价行为和集中度——在公开证据中仍未验证。[CU025, CU026, CU027, CU028, CU029, CU030]
| 扩张驱动因素 | 集中度 / 摩擦风险 | 影响 | 尽调路径 |
|---|---|---|---|
| 商业和企业客户内部的按席位扩张 | 席位渗透率和席位收缩率未公开 | 核心 ARR 增长驱动因素可能重要,但尚未验证 | 要求按初始交易规模和年度扩张提供席位队列 |
| PAM 与 Secrets Manager 附加销售 | 模块附加率未公开 | 高价值交叉销售可能显著抬高 ARPU | 要求按分群提供附加率、产品线 ARR 和续约率 |
| 商业向家庭套餐溢出 | 真实转化或留存提升未知 | 可能提高采用率,并降低员工抵触 | 要求提供家庭套餐用户的使用、转化和留存差异 |
| 公共部门和教育增长 | 采购周期和合同集中度未公开 | 可能提高增长韧性,但拉长销售周期 | 要求提供受监管买方的赢单率、周期长度和 ARR 占比 |
| MSP / 渠道扩张 | 下游客户集中度和伙伴依赖未公开 | 能高效放大分销,但伙伴流失可能反噬 | 要求提供头部伙伴收入占比和下游席位分布 |
| 定价和附加项摩擦 | 评论中反复抱怨价格调整、附加项和报告额外收费 | 可能拖慢扩张,或让续约更复杂 | 要求按分群提供续约提价、折扣历史和流失原因 |
| 垂直行业集中度 | 公开客户证明很多元,但头部客户收入未知 | 多元化看起来有利,但无法用财务数据证明 | 要求提供前 10 大客户收入集中度和合同条款 |
可见客户叙事支持扩张潜力,但公开的集中度证据偏定性,不是财务数据。
[CU025, CU028, CU029, CU030, CU032, CU036]Keeper 各细分客群 24 个月留存队列估计。Keeper 不披露实际 NRR/GRR 或队列曲线;这些数值是基于部署黏性、评测情绪和细分客群行为的方向性估计。
[CU026, CU027, CU035, CU036]6.4 展示材料
07风险
7.1 监管、法律与信任风险
最核心的法律和监管风险,是偏合规 GTM 下的信任失效。Keeper 面向 FedRAMP High、GovRAMP High、FIPS、SOC 2、ISO 和 NIST 对齐的采购场景销售,并明确把自己定位为特权身份、机密和 AI agent 的控制平面。这会放大任何认证失效、披露错误或安全事件的后果。公司公开材料正确地把许多控制项描述为差异化优势,但同一定位也意味着它们可能成为下行放大器。远程访问组件的漏洞、设备批准失败,或有争议的数据处理问题,都可能迅速转化为采购摩擦、续约延迟或法律审查,因为买家购买的不是低风险消费者工具,而是信任和合规系统。公开证据已经显示 Keeper 并非无风险。Connection Manager 公告页面列出历史 CVE,包括一个高严重级别 SAML 验证问题;OpenCVE 还追踪其他 Keeper 相关客户端或相邻产品问题。这些都不能证明当前平台薄弱,但确实证明大攻击面的正常现实。缓释因素也很实质:零知识设计、季度测试、Bugcrowd 披露、区域隔离和明确的加密控制。法律 / 监管结论不是 Keeper 异常脆弱,而是公司选择了受监管、重控制客户分段;在那里,任何信任失误都会付出不成比例的代价。[CR001, CR002, CR003, CR004, CR005, CR006]
| 规则 / 案件 / 义务 | 管辖区 | 状态 | 可能性 | 严重性 | 缓释措施 | 剩余敞口 | 尽调路径 |
|---|---|---|---|---|---|---|---|
| FedRAMP / GovRAMP / FIPS / 受监管控制声明 | 美国联邦和 SLED | 正在发挥作用的战略差异点 | 中 | 高 | 专门的合规姿态、Government Cloud 产品包、已发布的控制声明 | 任何认证失效或范围错配都可能削弱公共部门管线 | 要求提供当前授权包、范围文件和续期日程 |
| 漏洞披露和事件响应 | 全球 | 持续运营要求 | 高 | 高 | Bugcrowd 计划、季度测试、安全公告页面、已发布的安全模型 | 一起严重信任事件会很快冲击采购、续约和估值 | 要求提供最新事件指标、响应 SLA 和渗透测试摘要 |
| 隐私 / 身份 / 审计义务 | 美国、欧盟和全球企业买方 | 持续 | 中 | 高 | 零知识设计和审计控制降低明文暴露 | 控制边界表述不准或客户误用仍可能触发审查 | 要求提供 DPA 模板、默认留存设置和隐私事件历史 |
| 出口 / 公共部门处理义务 | 美国和全球 | 持续 | 低-中 | 中 | 安全文档中已发布合规姿态和出口参考 | 敏感工作负载一旦发生泄露或控制错误,后果会更严重 | 审查出口分类和敏感工作负载治理流程 |
各行按剩余严重性排序,而不是按当前是否存在执法行动排序。
[CR001, CR002, CR003, CR004, CR005, CR006]7.2 运营、依赖与人员风险
运营上,Keeper 已经超出经典密码管理器较简单的失效模式。平台现在横跨云托管保险库、出站网关模式、自托管 Connection Manager、机密工具、特权会话、AI 监控和公共部门变体。这种广度有战略意义,但也扩大了执行暴露。最可见的依赖风险在 AWS 和 GovCloud 基础设施、企业 IdP、浏览器、移动操作系统、应用商店,以及 KCM 底层继承的 Apache Guacamole 技术栈。自托管客户场景下,Keeper 还会从它并不完全控制的环境中继承微妙品牌风险:如果客户错误配置 SSL、数据库补丁滞后,或在 KCM 中处理升级不当,运营事故仍可能在情绪上归因于 Keeper。评论来源还添加了另一个运营信号:客户反复称赞易部署,但也提到定价复杂、报告缺口、自动填充不一致,以及一些管理控制台摩擦。这些不是生死问题,却正是在新增客户速度保持高位时会随规模复合的烦恼。人员维度同样重要。创始人连续性是优势,但也意味着关键人物依赖在公司外部叙事和产品方向中仍有分量。快速平台扩张需要安全工程、支持、合规、公共部门运营和产品管理上的深厚梯队;公开来源没有证明这些梯队薄弱,但也没有证明继任深度或组织冗余。主要运营判断因此是典型扩张风险:Keeper 的产品广度同时变成战略资产和协调负担。[CR014, CR015, CR016, CR017, CR018, CR019]
| 失效模式 | 可能性 | 严重性 | 缓释成熟度 | 剩余敞口 | 未解决缺口 |
|---|---|---|---|---|---|
| 密码库、机密或特权会话信任出现重大安全事件 | 中 | 非常高 | 高 | 信任冲击蔓延至整个平台 | 需要当前独立测试证据和事件历史 |
| KCM / 自托管配置错误或部署未打补丁 | 中 | 高 | 中 | 客户自管环境仍可能伤害 Keeper 声誉 | 需要安装基数构成、升级遵循度和支持负担数据 |
| 客户端 / 扩展 / 设备审批边界漏洞 | 中 | 高 | 中 | 零知识不能消除端点或扩展风险 | 需要端点事件模式和补丁延迟数据 |
| AI 监控误报 / 漏报 | 中 | 中-高 | 低-中 | 可能削弱客户对新增高级功能的信任 | 需要基准准确率和生产采用数据 |
| 平台扩张导致发布速度回落或质量滑坡 | 中 | 中-高 | 中 | 许多产品现在跨多个界面快速发布 | 需要缺陷漏出率和回滚指标 |
| 当前增长速度下的支持 / 入门压力 | 中 | 中 | 中 | 每月新增 850 家组织可能压迫客户成功、支持和培训 | 需要支持配比、实施时间和积压数据 |
剩余评级为方向性判断,综合公开证据,而非已披露事件频率。
[CR009, CR010, CR011, CR014, CR015, CR020]| 依赖 | 对手方 | 角色 | 集中度 | 失效场景 | 严重性 | 缓释措施 | 剩余敞口 |
|---|---|---|---|---|---|---|---|
| 云托管和主权区域 | AWS / AWS GovCloud | 核心托管底座和受监管部署环境 | 高 | 宕机、区域问题或商业条款变化影响可用性或公共部门定位 | 高 | 多区域架构和 GovCloud 专长 | 可用性与采购上的实质依赖仍然存在 |
| 企业认证层 | 客户 IdP / SSO / SCIM 生态 | 访问和预配依赖 | 高 | SAML/OIDC 问题、SCIM 偏移或 IdP 宕机阻断访问或预配 | 高 | 设备审批、管理员控制和集成广度 | 上游身份依赖在结构上仍然重要 |
| 浏览器 / OS / 应用商店分发 | Apple、Google、浏览器厂商 | 客户端交付、自动填充、passkeys 和移动触达 | 高 | 平台政策或 API 变化削弱 UX,拖累消费者 / 商业采用 | 中-高 | 跨平台支持和多客户端 | 原生替代品和政策变化仍是长期威胁 |
| 开源远程访问底座 | Apache Guacamole | 底层 KCM 会话栈 | 中 | 上游漏洞或集成问题带来紧急补丁负担 | 中-高 | Keeper 对上游问题的维护和监控 | 开源依赖仍带来补丁紧迫性 |
| 评论 / 分析师 / 声誉生态 | G2、GetApp、SoftwareReviews 和口碑 | 发现渠道和社会证明 | 中 | 情绪恶化会拖慢新客户获取 | 中 | 当前客户证明和评论量强 | 安全品类里的声誉仍有路径依赖 |
集中度反映功能关键性,而不是已披露支出占比或合同排他性。
[CR016, CR017, CR018, CR019, CR022, CR023]| 角色 / 职能 | 依赖或缺口 | 可能性 | 严重性 | 缓释措施 | 尽调路径 |
|---|---|---|---|---|---|
| 创始人领导力 | CEO/CTO 延续性是战略优势,也是关键人风险 | 中 | 高 | 可见的高管梯队和投资方支持的董事会 | 要求提供继任规划,以及下放后的产品 / GTM 负责人归属 |
| 合规和公共部门运营 | 受监管业务面扩大,需要更深的专业流程能力 | 中 | 高 | Government Cloud、FedRAMP/GovRAMP 姿态和审计工具 | 要求提供组织架构图和认证人员覆盖 |
| 安全工程和事件响应 | 产品快速扩张提高协同和响应要求 | 中 | 高 | 季度测试、披露计划和高频发布 | 要求提供人员配比、值班模型和修复 SLA |
| 支持 / 客户成功 / 培训 | 新客户获取速度高,可能压垮实施资源 | 中 | 中 | 评论目前称赞支持和入门 | 要求提供 CSM 覆盖、支持队列数据和入门周期 |
| 跨产品产品管理 | Vault + PAM + KSM + AI + 政府场景提高优先级排序复杂度 | 中 | 中-高 | 统一控制平面叙事有助于产品连贯性 | 要求提供路线图治理和发布质量指标 |
公开资料显示创始人突出、平台覆盖面宽,但没有披露内部组织架构图或继任覆盖。
[CR020, CR024, CR025, CR030, CR031]关键依赖横跨云基础设施、上游身份系统、客户端平台和开源 KCM 技术栈。
[CR016, CR017, CR018, CR019, CR023]7.3 财务 / 模型风险、缓释因素与投资逻辑破坏点
最大模型风险,是增长叙事和可承销持久性之间的落差。相比一年前,Keeper 现在讲得出一个强得多的公开规模故事:保护超过 95,000 家组织、每月新增 850 家组织、满意度指标扎实,并给出年经常性收入(ARR)迈向 US$1B 的路径。但投资人仍然看不到决定增长韧性的指标:净留存率(NRR)、总留存率(GRR)、客户账户流失、席位深度、头部客户集中度、公共部门 ARR 占比、获客成本(CAC)回本周期,以及公司自称盈利之外的当前现金生成能力。缺失这些数据很关键,因为几个已识别风险会直接传导到估值。原生平台管理器的竞争压力会压缩低端定价。BeyondTrust 和 AWS Secrets Manager 等高端竞品可能侵蚀附加销售率,或拿下控制要求更高的工作负载。安全事件或认证问题会拖慢公共部门增长,并伤害销售效率。支持压力或定价反弹可能拉低转化或续约质量。好消息是,Keeper 也有看得见的缓释因素:差异化的零知识信任模型、广泛客户证明、与受监管市场的适配、评论背书的易用性,以及超越单纯密码库的模块宽度。核心投资逻辑失效触发点因此可监控:若新客户增长明显放缓,若 PAM / 机密凭证附加销售停滞,若公开评论情绪恶化,若发生重大安全事件,或若管理层在尽调中无法证明留存持久、收入多元,乐观情景会迅速削弱。这里的风险并不抽象,而是一组能识别的传导路径,会打到客户增长、利润质量和退出倍数支撑。[CR026, CR027, CR028, CR029, CR030, CR031]
| 风险 | 可监控触发项 | 阈值 / 事件 | 行动含义 |
|---|---|---|---|
| 安全事件 / 信任失效 | 公开披露、重大 CVE 或认证事件 | 一起影响核心密码库 / PAM 信任的重大安全事件 | 重算悲观情景;客户和估值风险升为首要变量 |
| 增长可持续性 | 新客户获取速度和模块附加 | 明显低于每月 850 家组织,且 PAM/Secrets 附加疲弱 | 重新评估高增长估值倍数和 IPO 时间假设 |
| 留存 / 定价质量 | 续约摩擦和评论情绪 | 关于涨价、附加项或价值错配的投诉扩大 | 压力测试总留存和 ASP 假设 |
| 受监管市场执行 | FedRAMP/GovRAMP 范围或续期滑坡 | 公共部门授权状态延误或受损 | 下调对高价值政府扩张的信心 |
| 运营扩张 | 支持积压、实施时间、缺陷漏出率 | 高频发布下仍持续恶化 | 上调执行折价和利润率风险假设 |
| 依赖冲击 | AWS / IdP / 浏览器政策变化或宕机事件 | 关键触点反复出现可用性或兼容性问题 | 上调平台依赖折价,并加大业务连续性审查 |
触发阈值是基于公开信号得出的尽调启发式,而非公司给出的 KPI 护栏。
[CR033, CR034, CR035, CR036, CR037, CR038]最高残余风险集中在安全事件、合规姿态和执行质量会同时传导到客户信任和估值的环节。
[CR001, CR009, CR014, CR026, CR028, CR033]Keeper 的主要风险先传导到信任,再压到转化、留存、利润率质量和估值。
[CR004, CR015, CR026, CR033, CR035, CR038]7.4 附录
08估值
8.1 建议仍应保持观察,因为平台证明强于价格证明
Keeper 的产品和客户证明已经足够强,不能再把它描述成小规模或困境资产。公司公开披露,2026 年 7 月年经常性收入(ARR)为 $225 million,保护超过 95,000 家组织,每月新增 850 家组织,2021 年以来增长超过三倍,同时盈利且资产负债表无债。前文的客户和市场证据也显示,Keeper 已经有实质性的企业、公共部门和 PAM 采用,而不是一个纯消费者密码管理器故事。这些事实支撑估值。问题不在公司质量,而在承销深度。公开来源仍未披露净收入留存、总留存、毛利率、自由现金流、头部客户集中度、公共部门 ARR 占比,也未披露决定名义企业价值对新资金是否有吸引力的股权结构表和优先权条款。开源融资数据库同样令人失望:只显示有限融资历史,却没有干净的当前投后估值标记。因此,正确建议是观察 / 继续研究,而不是买入:Keeper 看起来是一个强劲的私有网络安全资产,但公开证据尚不足以支撑不计价格的信心;如果卖方预期显著高于当前披露 ARR 和上市可比公司隐含的低 $3B 区间,这一点尤其成立。[CV001, CV002, CV003, CV004, CV005, CV006]
| 维度 | 评估 | 原因 | 决策含义 |
|---|---|---|---|
| 建议 | 观察 / 继续研究 | 公司质量证据强,但价格支撑不完整 | 继续尽调;不要只凭公开证据承销 |
| 信心 | 中 | 规模和可比公司证据尚可,但经济性披露不完整 | 用区间和尽调关口,不追求单点精度 |
| 风险评级 | 中 | 品类高度依赖信任,同时竞争和披露风险真实存在 | 仓位保守,并把后续工作绑定到可监控触发项 |
| 估值立场 | 合理至偏高 | 独角兽估值有支撑,但公开数据目前难以撑起 $4B 中段要价 | 升级前要求价格纪律或更充分披露 |
| 决策阈值 | 对证据敏感 | 判断主要应随留存、利润率和股权结构披露而调整 | 只有耐久性和股权经济性被证明后才升级 |
| 可能退出视角 | IPO 或战略退出可选性 | 规模、盈利能力和品类关联度可见,时点不可见 | 建模多条退出路径,不要只押一个具体日期的结果 |
这是价格敏感型建议,不是笼统判断 Keeper 是一家高质量公司。
[CV001, CV002, CV004, CV007, CV025, CV029]| 论点 | 当前证据 | 改变观点的条件 |
|---|---|---|
| 投资逻辑:Keeper 已经是有真实规模的身份安全平台 | 披露 $225M ARR、95k+ 组织、每月新增 850 家组织、已盈利且产品面广 | 若证据显示 ARR 质量或模块挂载明显弱于收入增速暗示的水平 |
| 投资逻辑:监管市场与 PAM 敞口,能支撑相较普通密码工具的溢价 | FedRAMP 认证政府合规姿态、GovRAMP High、KeeperPAM 增长和企业客户验证 | 信任受损、公共部门牵引变弱,或企业模块挂载经济性偏弱 |
| 反向逻辑:公开估值支撑不完整 | 未公开 NRR、GRR、毛利率、集中度、现金流或优先股堆叠披露 | 管理层披露能证明 ARR 质量耐久、股权经济性干净 |
| 反向逻辑:信任和定价问题会迅速压缩倍数 | 安全事件、状态 / 正常运行时间复杂度、评论网站上的定价摩擦,在这个品类都很关键 | 长期干净运营记录,加上更强的留存和定价质量数据 |
将公司质量论点与价格支撑论点拆开,建议才能保持纪律。
[CV001, CV003, CV004, CV005, CV006, CV007]最终判断取决于:已披露规模能否抵消持续性和股权经济性上仍然很大的透明度缺口。
[CV001, CV004, CV007, CV012, CV019, CV045]Keeper 在市场、产品和客户验证上得分高,但估值支撑和披露质量只属中等。
[CV001, CV004, CV005, CV006, CV007, CV029]8.2 可比公司测算支持独角兽结果,但不能自动支撑中段 $4B 估值
对 Keeper 最干净的公开框架,是锚定已披露规模,再用上市身份 / 安全软件倍数做压力测试。本次最有决策价值的参照组是 Okta、SailPoint 和 CyberArk。按 2026 年 8 月市值和最新披露的过去十二个月收入,StockAnalysis 与 CompaniesMarketCap 隐含 Okta 销售额倍数约 8.5x,SailPoint 约 9.5x,CyberArk 约 15x。这些可比公司并不完美:Okta 是更宽的身份平台,SailPoint 是身份治理专家且有完整上市公司披露,CyberArk 则是溢价 PAM 可比公司,企业控制深度更强。但这个参照组仍有用,因为三家公司都处在对信任敏感的身份 / 安全品类,披露也远多于 Keeper。把这一区间低端套到 Keeper 披露的 $225M ARR 上,企业价值约为 $1.9B 至 $2.1B;12x 倍数约为 $2.7B;CyberArk 式 15x 溢价约为 $3.4B;即便 20x 也只有约 $4.5B。这并不意味着 Keeper 在 $3B 以上任何价格都高估,因为 ARR 不等同于收入,私有资产稀缺性也可能有价值。但它意味着,任何达到或超过中段 $4B 的估值,都需要管理层证明 ARR、留存、利润质量或战略稀缺性显著强于当前公开记录。[CV009, CV010, CV011, CV012, CV013, CV014]
| 情景 | 假设 | 示意估值逻辑(USD M) | 概率信号 | 支撑条件 |
|---|---|---|---|---|
| 乐观 | ARR 升至约 275-325,盈利能力守住,PAM / Secrets 模块挂载增强,且没有信任冲击 | 13x-15x => 约 3,575-4,875 | 可能成立,但尚未证明 | 证明 NRR 耐久、高挂载经济性和干净治理 / 股权结构条款 |
| 基准 | ARR 维持在约 225-260,增速放缓但仍健康,利润率扎实,风险姿态保持稳定 | 9x-12x => 约 2,025-3,120 | 证据支撑最强的区间 | 在尽调中验证留存、集中度和利润率质量 |
| 悲观 | ARR 下滑至 180-220 附近,定价压力上升,或信任 / 合规问题拖慢增长 | 5x-8x => 约 900-1,760 | 若披露或风险姿态不及预期,下行空间真实存在 | 变现质量较弱或信任再度受损的证据 |
区间是基于已披露 ARR 搭出的情景启发式;Keeper 未披露收入、留存或利润率细节,模型无法更紧。
[CV013, CV014, CV015, CV016, CV017, CV018]| 可比对象 | 当前指标集 | 估值 / 倍数 / 状态 | 参考意义 | 限制 |
|---|---|---|---|---|
| Okta | TTM 收入约 $3.00B;公开证券文件体系和市场数据支撑当前披露深度 | 市值约 $25.82B;销售额约 8.5x | 大型上市身份平台提供成熟品类的倍数底部 | 产品范围更宽,利润率不同,披露远比 Keeper 充分 |
| SailPoint | TTM 收入约 $1.12B;公开 10-K 和市场数据体现完整披露纪律 | 市值约 $10.62B;销售额约 9.5x | 有现行公开文件支撑,是有用的身份安全可比对象 | 产品重心不同,披露强于 Keeper |
| CyberArk | 2025 收入约 $1.36B;具战略稀缺性的高端 PAM 龙头 | 市值约 $20.63B;销售额约 15x | KeeperPAM 和受监管工作负载最好的高端控制型可比对象 | 企业控制深度更大,战略定位更高端 |
| Keeper 公开语境 | 披露 ARR $225M、已盈利、无债务状态和强客户增长叙事,但没有公开 NRR / GRR / 利润率细节 | 能支撑独角兽可能性,但对 $4B 中段价格的直接支撑不完整 | 目标资产本身,业务模型最贴近 | 私营公司不透明,精确选择倍数很脆弱 |
本轮使用决策最有用的公开身份 / 安全参考,而不是假装存在完美的 Keeper 上市可比对象。
[CV003, CV009, CV010, CV011, CV012, CV013]在已披露的 $225M ARR 基础上,估值倍数选择是公开市场估值支撑的最大变量。
[CV013, CV014, CV015, CV016, CV017, CV018]公开证据支撑的区间很宽,基准情景中枢明显低于 $4B 中段估值。
[CV026, CV027, CV028, CV041]8.3 升级路径很简单:证明 ARR 质量持久,股权经济干净
Keeper 下一步尽调问题并不复杂,因为主要障碍不是品类不清,而是私有公司不透明。公开证据现在已经支撑真实的退出可选性:Keeper 看起来规模足够大、盈利能力足够强、战略相关性也足够高,可以进入 IPO 准备,或吸引身份、PAM 或更广义安全在位者的可信战略兴趣。但任何严肃投委会都不应在看到决定持久性和普通股结果的数字之前,就把这一观察转成买入结论。管理层需要提供当前按产品和分部拆分的 ARR 桥、NRR、GRR、客户账户流失、毛利率、营业利润率、现金生成、头部客户集中度、公共部门占比、PAM 与机密凭证模块附加销售,以及与过往轮次绑定的实际优先股堆叠或老股交易标记。风险章节也必须继续直接连到估值。另一次重大信任事件、新客户新增明显放缓,或定价摩擦增长快于产品扩张的证据,都会迅速把公司重估到可比区间低端。在这些问题回答之前,纪律性立场应是估值合理至偏满、置信度中等、保持观察而非买入。换句话说,尽调瓶颈可以解决,但今天仍足够真实,足以主导价格纪律。[CV026, CV027, CV028, CV029, CV030, CV032]
| 触发项 | 阈值 / 事件 | 对投资逻辑的传导 | 行动含义 |
|---|---|---|---|
| 安全或信任冲击 | 一起影响核心保险库、PAM 或受监管控制可信度的重大事件 | 高端信任叙事走弱,倍数迅速压缩 | 转入下行情景并重新定价 |
| 增长耐久性不达标 | 新客户增速和模块挂载较当前轨迹明显恶化 | 高增长叙事走弱,可比对象集合下移 | 重估情景区间,降低可接受入场价格 |
| 定价 / 留存恶化 | 投诉扩大,续约偏弱或扩张缩小 | 溢价定价权看起来不那么耐久 | 推进前要求提供队列指标 |
| 披露不及预期 | 管理层无法证明健康的 NRR、GRR、利润率或干净股权结构 | 公开估值不透明仍未解决 | 维持观察 / 不买立场 |
| 公共部门或合规滑坡 | FedRAMP / GovRAMP 范围或续期姿态走弱 | 政府业务溢价和控制叙事可信度恶化 | 下调倍数假设和延展价值 |
阈值是扎根公开证据的尽调启发式,不是公司给出的 KPI 护栏。
[CV006, CV007, CV024, CV029, CV030, CV037]| 主题 | 缺失证据 | 重要性 | 负责人或尽调路径 |
|---|---|---|---|
| ARR 质量 | 按产品、地区和客户分群拆分的当前 ARR 桥 | 判断已披露规模是否集中、耐久,并支撑组合迁移 | 索取 CFO 材料包和董事会级 KPI 演示材料 |
| 留存 | 按企业 / SMB / 公共部门拆分的 NRR、GRR、logo 流失和队列扩张 | 支撑溢价倍数最重要的输入 | 索取月经常性收入队列分析 |
| 利润率和现金 | 毛利率、贡献利润率、运营费用结构、自由现金流和现金余额 | 判断盈利能力说法是结构性强,还是定义很轻 | 索取经审计或董事会审阅的财务报表 |
| 集中度 | 前 10 大客户、公共部门占比和渠道集中度 | 限定续约延迟或客户流失带来的下行 | 索取 ARR 集中度和续约日历 |
| 模块经济性 | KeeperPAM 与 Secrets 挂载、赢率和实施负担 | 判断平台扩张相对纯密码同行是否配得上溢价 | 索取按分群拆分的产品挂载和赢 / 输数据 |
| 股权结构和优先权 | 清算优先权、保护性条款、老股交易和任何 2023 年后的估值标记 | 仅企业价值无法决定普通股吸引力 | 索取法律版股权结构材料包和交易历史 |
每个尽调请求都因会实质改变建议、倍数或下行校准而入选。
[CV004, CV026, CV030, CV031, CV032, CV033]免责声明
本报告基于截至 2026-08-13 的公开信息。Keeper Security 是未上市公司,估值判断依赖已披露 ARR、情景分析和上市可比公司,而非经审计的内部财务报表。
证据索引
| 编号 | 陈述 | 可信度 | 来源 |
|---|---|---|---|
| CO001 | Keeper’s homepage positions the company as a unified control plane for privileged access, secrets, remote connections, endpoints and databases. | 中 | SO001 |
| CO002 | Keeper publicly markets a zero-trust and zero-knowledge architecture with end-to-end encryption in which only the customer can decrypt stored data. | 高 | SO001, SO006 |
| CO003 | Keeper’s homepage claims the company serves more than 150 countries, more than 93,000 business customers and 4 million people. | 中 | SO001 |
| CO004 | Darren Guccione is publicly listed as CEO & Co-Founder and Craig Lurey is publicly listed as CTO & Co-Founder as of the run date. | 高 | SO002, SO017 |
| CO005 | Keeper’s current public executive bench includes Amy Lindenmeyer as CFO, Tim Strickland as CRO, Tracy Dale-Baker as CHRO and Shane Barney as CISO. | 高 | SO002, SO015 |
| CO006 | Keeper’s current board list includes Darren Guccione, Thomas Krane of Insight Partners and Len Ferrington of Summit Partners. | 高 | SO002, SO013 |
| CO007 | Keeper publicly lists Chicago, El Dorado Hills, Cork and Tokyo as its office locations for global headquarters, product development, EMEA sales and APAC sales respectively. | 高 | SO002, SO018 |
| CO008 | Keeper’s public terms page identifies the company as Keeper Security, Inc. and lists 311 W. Monroe Street, Suite 406, Chicago, Illinois as an address. | 高 | SO003, SO002 |
| CO009 | Keeper’s terms state that the governing law and venue for the applicable U.S. Keeper entity are Delaware, United States. | 中 | SO003 |
| CO010 | Reviewed public materials support treating Keeper as a private growth-equity-backed company rather than a public issuer. | 高 | SO002, SO013, SO014 |
| CO011 | Historical public sources trace the original Keeper product back to 2009. | 中 | SO017, SO018 |
| CO012 | Multiple accessible public sources describe Keeper Security, Inc. as being co-founded in 2011 by Darren Guccione and Craig Lurey. | 中 | SO011, SO013, SO018 |
| CO013 | Keeper disclosed a US$60 million minority investment from Insight Partners in August 2020, and Crunchbase News described it as the company’s first equity raise. | 中 | SO011, SO012 |
| CO014 | Insight Partners principal Thomas Krane joined Keeper’s board as part of the 2020 investment. | 高 | SO011, SO002 |
| CO015 | Insight Partners said Keeper’s B2B business was growing at triple-digit rates in 2020 and posted its best month in company history in July 2020. | 中 | SO012 |
| CO016 | Summit Partners announced that it completed a significant minority investment in Keeper, but did not disclose the size or valuation of the transaction. | 中 | SO013, SO014 |
| CO017 | Len Ferrington of Summit Partners joined Keeper’s board in connection with Summit’s investment. | 高 | SO013, SO002 |
| CO018 | Summit said Keeper had added several hundred employees, doubled revenue while maintaining strong gross margins and recorded its strongest quarter on record in Q1 2023. | 中 | SO013 |
| CO019 | Summit attributed Keeper’s post-2020 progress to the Glyptodon acquisition, FedRAMP and StateRAMP authorizations, new data centers in Australia, Canada and Japan, and broader partner expansion across NorAm, EMEA and APAC. | 中 | SO013 |
| CO020 | KeeperPAM combines enterprise password management, secrets management, connection management, zero-trust network access and remote browser isolation in a single cloud-native platform. | 高 | SO006, SO029 |
| CO021 | Keeper Secrets Manager is marketed as a cloud-based system for API keys, certificates, service credentials, CI/CD pipelines, containers, automation scripts and other non-human identities. | 中 | SO007 |
| CO022 | Keeper Security Government Cloud is publicly described as a FedRAMP High and GovRAMP High authorized zero-trust PAM solution hosted in AWS GovCloud. | 高 | SO008, SO009, SO010 |
| CO023 | Keeper’s December 2025 FedRAMP High announcement says FedRAMP Moderate authorization had been achieved in August 2022. | 中 | SO009 |
| CO024 | Keeper’s February 2026 GovRAMP High announcement says Keeper Security Government Cloud has maintained GovRAMP authorization since 2022. | 中 | SO010 |
| CO025 | Keeper’s current public materials advertise FedRAMP High, GovRAMP High, FIPS 140-3, ISO 27001/27017/27018, PCI DSS and TrustArc-related privacy certifications. | 高 | SO001, SO008, SO010 |
| CO026 | Keeper began integrating Glyptodon after acquiring it in December 2021 and announced Keeper Connection Manager on 2022-05-04 as the reworked zero-trust remote-access layer. | 中 | SO026 |
| CO027 | Keeper’s 2023 retrospective says the company opened its Asia-Pacific headquarters in Tokyo in May 2023. | 中 | SO027 |
| CO028 | Keeper’s 2023 retrospective characterizes Summit’s investment and the KeeperPAM platform launch as defining milestones of 2023. | 中 | SO027 |
| CO029 | Keeper’s retrospective says the company introduced passkey support in its browser extension during 2023. | 中 | SO027, SO018 |
| CO030 | Keeper extended passkey management and autofill to iOS and Android on 2024-03-25. | 高 | SO028, SO030 |
| CO031 | Keeper’s April 2025 product update reiterates that KeeperPAM is the unifying control plane for password management, secrets management, connection management, zero-trust network access and remote browser isolation. | 高 | SO029, SO006 |
| CO032 | Keeper’s Connection Manager advisories page documents multiple disclosed vulnerabilities from 2020-2021, including CVE-2021-43999 rated High 8.7, and points researchers to a Bugcrowd-managed disclosure program. | 中 | SO020 |
| CO033 | OpenCVE currently lists Keeper-related vulnerabilities including a disputed 2023 plaintext-memory exposure and a 2025 KeeperChat biometric-authentication issue. | 中 | SO019 |
| CO034 | Built In’s AI-generated employer profile describes Keeper as founder-led and execution-first, but warns of top-down pressure, shifting priorities, transparency concerns and burnout risk. | 低 | SO021 |
| CO035 | The reviewed source set did not surface a public report of a catastrophic Keeper vault breach; the accessible adverse record is centered on disclosed vulnerabilities and culture critique instead. | 低 | SO019, SO020, SO021, SO025 |
| CO036 | Keeper’s about page names cryptographer Adam Everspaugh and former CISA CIO David Epperson among its public advisors. | 中 | SO002 |
| CO037 | Keeper’s FedRAMP High announcement names the Departments of Justice, Energy, Transportation and the Interior, FEMA and NASA as major federal agencies using Keeper. | 中 | SO009 |
| CO038 | Keeper’s accessible official pages are not perfectly synchronized on scale, with the homepage claiming 93,000+ business customers while the December 2025 FedRAMP post claims 85,000+ organizations. | 高 | SO001, SO009 |
| CO039 | Craft describes Keeper as an AI-enabled cybersecurity platform serving enterprise, medical and military sectors. | 中 | SO016 |
| CO040 | The accessible public record does not disclose Summit’s exact check size, Keeper’s latest valuation, or a detailed current cap table. | 中 | SO013, SO014 |
| CO041 | Accessible public sources do not pin a precise current headcount; they only show that Keeper added 120 employees around 2020 and several hundred employees after the 2020 funding round. | 中 | SO011, SO013 |
| CO042 | Keeper’s government-cloud materials say the platform supports CAC and PIV smart-card authentication and aligns with FIPS 201 and NIST SP 800-63 identity requirements. | 中 | SO009 |
| CO043 | Keeper’s partner page describes the Keeper Partner Network as a global community of expert partners. | 中 | SO023 |
| CO044 | Keeper’s integrations directory shows direct integrations with Okta, Entra ID, Google Workspace, AWS, Azure, Splunk, Chronicle and major cloud secret stores. | 中 | SO031 |
| CO045 | Keeper’s terms include a 99.9% monthly uptime-availability commitment for the Keeper Services API, excluding emergency maintenance and force-majeure events. | 中 | SO003 |
| CM001 | Keeper’s current product surface spans workforce password management, privileged access management, secrets management, remote connections, passkeys and government identity security rather than a single-purpose consumer vault. | 高 | SM001, SM002, SM003, SM004 |
| CM002 | Google Password Manager and Apple’s Passwords app provide built-in password and passkey management, creating a zero-price substitute for consumers and lightly managed users. | 高 | SM015, SM016 |
| CM003 | AWS Secrets Manager and Azure Key Vault already cover centralized machine-secret storage and rotation inside their own cloud ecosystems. | 高 | SM021, SM022 |
| CM004 | BeyondTrust’s endpoint privilege offering shows that least-privilege elevation and just-in-time access are contested by established adjacent incumbents, not only by password-vault vendors. | 中 | SM020 |
| CM005 | Keeper’s practical category is narrower than full IAM and broader than a personal password vault: it is the governed credential-control layer linking passwords, passkeys, secrets and privileged access. | 高 | SM001, SM002, SM004 |
| CM006 | Mordor Intelligence and Research and Markets both estimate the password-management market at US$2.94B in 2026 and US$8.07B by 2031, implying a 22.39% CAGR from 2026 to 2031. | 中 | SM006, SM008 |
| CM007 | Fortune Business Insights estimates the password-management market at US$3.79B in 2026 and US$10.63B by 2034, implying a 13.77% CAGR from 2026 to 2034. | 中 | SM007 |
| CM008 | Published password-management TAM estimates disagree enough that Keeper’s market should be treated as a bounded range rather than a single point estimate. | 中 | SM006, SM007, SM008 |
| CM009 | Cloud deployment dominates current category spend, with publishers citing either 64.4% share in 2025 or 79.1% share in 2026 depending definition and sample. | 中 | SM006, SM007 |
| CM010 | Hybrid deployment is a major growth area, with Mordor / Research and Markets projecting a 23.9% CAGR as data-residency and regulated-workload needs persist. | 中 | SM006, SM008 |
| CM011 | Large organizations represented 63.4% of 2025 password-management spending in Mordor / Research and Markets, while SMEs are projected to grow fastest at 24.3% CAGR through 2031. | 中 | SM006, SM008 |
| CM012 | BFSI accounted for 29.1% of 2025 revenue in Mordor-style market work, while healthcare and life sciences were projected to grow fastest at 25.9% CAGR. | 中 | SM006 |
| CM013 | North America remains the largest regional pool for password-management spend, with published 2025 share estimates ranging from 33.17% to 38.93%, while Asia Pacific is the fastest-growing region. | 中 | SM006, SM007, SM008 |
| CM014 | Keeper’s most defensible practical SAM is the paid, multi-user slice where buyers need policy control, least privilege, secrets, passkeys and regulated deployment support. | 高 | SM001, SM002, SM004, SM006 |
| CM015 | Keeper’s buyer map spans consumers, SMB IT generalists, enterprise CISOs or IAM leads, platform-engineering teams and public-sector security buyers. | 高 | SM001, SM002, SM004, SM005 |
| CM016 | The paying budget for Keeper shifts by segment from personal discretionary spend to enterprise security, IT, engineering and public-sector compliance budgets. | 高 | SM001, SM002, SM004 |
| CM017 | A plausible Keeper enterprise adoption path runs from admin evaluation into IdP/MFA integration, credential migration, least-privilege policy rollout, monitoring and expansion into broader PAM or secrets use cases. | 高 | SM001, SM005, SM023, SM024 |
| CM018 | An EMA survey summarized by Keeper and DRJ found that 69% of organizations adopt PAM primarily to prevent credential theft and mitigate cyber threats. | 中 | SM023, SM025 |
| CM019 | Verizon’s 2026 DBIR says the most frequent breach causes continue to heavily involve the human element, phishing and stolen credentials. | 中 | SM009 |
| CM020 | IBM’s 2026 report says the global average cost of a data breach reached US$4.99M, a 12% year-over-year increase and a record high. | 中 | SM010 |
| CM021 | NIST SP 800-207 and CISA’s Zero Trust Maturity Model both define zero trust around least-privilege, granular access decisions rather than network location-based trust. | 高 | SM011, SM012 |
| CM022 | NIST SP 800-63B requires a phishing-resistant option at AAL2 and requires federal staff, contractors and partners to use phishing-resistant authentication for federal information systems. | 中 | SM013 |
| CM023 | Microsoft will start making passkeys the default authentication experience in Entra ID on 2026-09-01 and will retire Microsoft-provided native SMS and voice delivery on 2027-02-01. | 中 | SM014 |
| CM024 | FIDO describes passkeys as phishing-resistant cryptographic credentials that reduce phishing, credential stuffing and authentication-service costs. | 高 | SM018, SM019 |
| CM025 | Built-in consumer stacks from Apple and Google intensify substitute pressure on independent password vendors at the low end of the market. | 高 | SM015, SM016, SM019 |
| CM026 | Keeper argues that its passkey value comes from cross-platform sync, centralized vault control and secure sharing rather than device-bound storage alone. | 高 | SM003, SM019 |
| CM027 | Keeper’s government-cloud materials align the company with public-sector and regulated buyers by emphasizing least privilege, auditability and FedRAMP/GovRAMP authorization. | 中 | SM004 |
| CM028 | Keeper’s integrations directory shows material connectors to IdPs, SIEMs, CI/CD workflows and cloud providers, supporting cross-functional buyer involvement in deals. | 中 | SM005 |
| CM029 | Keeper’s EMA summary says 60% of KeeperPAM users described deployment as very easy versus 22% of users of competing PAM tools, and only 15% required dedicated staff versus nearly 40% for others. | 中 | SM023, SM025 |
| CM030 | Keeper’s SoftwareReviews release says the platform led implementation-related metrics with 85% ease of implementation and 85% ease of IT administration. | 中 | SM024 |
| CM031 | Legacy PAM complexity and staffing burden remain a real market constraint, which is why cloud-native ease-of-deployment is a material wedge in current PAM evaluations. | 高 | SM020, SM023, SM025 |
| CM032 | Passkeys are simultaneously a tailwind and a threat for Keeper: they validate the move toward phishing-resistant authentication while making native platform managers more capable. | 高 | SM014, SM015, SM016, SM019 |
| CM033 | IBM’s 2026 breach report argues that organizations need stronger identity access and control to secure AI agents and machine identities as AI threats grow. | 中 | SM010 |
| CM034 | Market-growth drivers for Keeper cluster around zero trust, public-sector mandates, phishing-resistant authentication, cyber-insurance pressure and the need to reduce credential sprawl across humans and machines. | 高 | SM006, SM011, SM012, SM013, SM018 |
| CM035 | Keeper competes across multiple overlapping budgets because cloud secret stores, built-in password managers and privilege vendors each solve part of the same job. | 高 | SM003, SM020, SM021, SM022 |
| CM036 | Public-sector buyer journeys are more procurement- and compliance-heavy than commercial buyers, which makes FedRAMP/GovRAMP readiness part of the adoption path rather than just a product feature. | 高 | SM004, SM012, SM013 |
| CM037 | Category-wide market reports disagree enough on absolute size and scope that Keeper-specific SAM and share must be evidence-constrained rather than extrapolated from one headline TAM number. | 中 | SM006, SM007, SM008 |
| CM038 | Mobile and cross-device usability are important demand drivers because market reports and platform documentation both emphasize smartphones, browser sync and device-spanning credential access. | 高 | SM006, SM015, SM016 |
| CM039 | Self-service and low-friction password-management functions are a large current revenue pool, but that portion of the market is more vulnerable to commoditization than privileged and regulated workflows. | 中 | SM006, SM007 |
| CP001 | Keeper’s competitor set spans direct password peers, adjacent PAM/identity suites, developer-secret tools, native built-ins and cloud-native substitutes rather than one simple list of vault apps. | 高 | SP001, SP014, SP019, SP021, SP023 |
| CP002 | Keeper’s clearest direct paid peers in workforce credential management are 1Password, Bitwarden, Dashlane and LastPass, each of which markets business password management and administrative control. | 高 | SP004, SP006, SP009, SP011 |
| CP003 | 1Password says more than 200,000 businesses trust the platform. | 中 | SP004 |
| CP004 | 1Password positions itself beyond basic vaulting by emphasizing passwords, secrets, apps, devices, apps outside SSO and AI/SaaS discovery on its business surface. | 中 | SP004 |
| CP005 | Bitwarden says it is trusted by 80,000+ businesses worldwide. | 中 | SP006 |
| CP006 | Bitwarden markets open-source transparency, optional self-hosting, rapid deployment and 24x7 business support as core competitive advantages. | 中 | SP006 |
| CP007 | LastPass still markets a cross-platform zero-knowledge vault with SSO and MFA adjacency and a paid-versus-free tier distinction. | 中 | SP009 |
| CP008 | LastPass’s current official surface still devotes significant space to post-2022 remediation and security transformation, indicating that trust recovery remains part of its competitive posture. | 高 | SP009, SP010 |
| CP009 | Dashlane is explicitly repositioning from password manager toward Omnix credential security and Credential Protection, pairing vaulting with risk detection and domain protection. | 高 | SP011, SP012, SP013 |
| CP010 | CyberArk’s current pages market a broader identity-security platform centered on privileged access, zero-standing privileges, machine identities and agentic AI security. | 高 | SP014, SP015 |
| CP011 | Delinea’s current pages position the company around dynamic authorization, remote privileged access, session monitoring, password rotation and Secret Server vaulting rather than simple workforce password sharing. | 高 | SP016, SP017 |
| CP012 | BeyondTrust, CyberArk and Delinea show that Keeper competes in enterprise deals against broader privilege-control suites, not just other password managers. | 高 | SP014, SP016, SP018 |
| CP013 | HashiCorp Vault competes most directly on machine secrets, dynamic credentials and API/CLI-led workflows rather than on workforce vault UX. | 高 | SP019, SP020 |
| CP014 | Google Password Manager and Apple Passwords provide built-in password and passkey storage, making low-end credential management available at zero incremental software price. | 高 | SP021, SP022 |
| CP015 | AWS Secrets Manager and Azure Key Vault are credible substitutes for Keeper’s machine-secret wedge in single-cloud environments. | 高 | SP023, SP024 |
| CP016 | Keeper differentiates itself by combining zero-knowledge vaulting with passkeys, secrets, PAM and a public-sector compliance posture across its business, enterprise and pricing pages. | 高 | SP001, SP002, SP003 |
| CP017 | Keeper’s pricing and product surfaces show cross-sell breadth into family plans, MSP, secrets, AI-agent access and KeeperPAM rather than a single-SKU vault offer. | 高 | SP002, SP003 |
| CP018 | 1Password’s competitive direction is broader access governance, not only password storage, because it foregrounds apps outside SSO, trusted devices and AI/SaaS discovery. | 中 | SP004 |
| CP019 | Bitwarden’s direct competitive wedge is operational simplicity plus control: go-live-in-days claims, self-host flexibility, admin oversight and priority support. | 高 | SP006, SP007 |
| CP020 | Dashlane markets role-based access, encrypted audit logs, SAML login, automated provisioning and admin vault policies for enterprise teams. | 高 | SP011, SP012 |
| CP021 | LastPass still competes on cross-platform coverage, zero-knowledge vaulting and SSO/MFA breadth, but its current free tier is constrained relative to paid usage. | 中 | SP009 |
| CP022 | Public pricing transparency is uneven across the field: several vendors show annual per-user or custom-sales motions, but fetched public pages often do not expose clean business list prices in comparable form. | 高 | SP003, SP005, SP007, SP012 |
| CP023 | Keeper’s current fetched pricing text makes higher-end modules like KeeperPAM appear quote-led rather than transparently self-serve. | 中 | SP003 |
| CP024 | Operational simplicity is a key competitive battleground because Keeper, Bitwarden and Delinea each highlight fast deployment or reduced implementation burden. | 高 | SP001, SP006, SP017 |
| CP025 | CyberArk and Delinea compete for high-value enterprise deals by extending privilege control across human, machine and remote-access workflows that go well beyond shared passwords. | 高 | SP014, SP015, SP016, SP017 |
| CP026 | HashiCorp Vault, AWS Secrets Manager and Azure Key Vault can each absorb part of the machine-secret budget that Keeper would otherwise target. | 高 | SP019, SP020, SP023, SP024 |
| CP027 | Native passkey momentum from Google, Apple and Microsoft increases substitute pressure on simple vault use cases even as it validates passwordless demand. | 高 | SP021, SP022, SP027 |
| CP028 | The LastPass incident shows that trust shocks can re-rank category winners even when core password-manager functionality remains comparable. | 高 | SP009, SP010 |
| CP029 | Switching costs are meaningful but not absolute because major vendors market migration, import or fast onboarding rather than proprietary lock-in alone. | 高 | SP001, SP006, SP011 |
| CP030 | Base feature parity among direct peers is high on password vaulting, secure sharing, admin control and provisioning, so differentiation increasingly comes from trust, compliance, scope and ease-of-use. | 高 | SP001, SP004, SP006, SP011 |
| CP031 | Keeper’s sharpest wedge appears in compliance-heavy, control-heavy and public-sector-friendly deployments rather than in generic consumer or lightly managed team use cases. | 高 | SP001, SP002, SP003, SP014, SP021 |
| CP032 | 1Password and CyberArk both extend the category toward AI and every-identity security narratives, increasing platform-consolidation pressure around Keeper. | 高 | SP004, SP015 |
| CP033 | Bitwarden and Dashlane both market quantified or explicit productivity gains from simpler deployment or reduced admin effort, raising the proof burden for Keeper’s similar simplicity claims. | 高 | SP006, SP011 |
| CP034 | The competitive field is structurally split among direct password peers, broader PAM suites, developer-secret platforms and bundled substitutes. | 高 | SP004, SP014, SP019, SP021, SP023 |
| CP035 | Status-quo and internal-build alternatives include native browser or device storage, hard-coded secrets and ad hoc sharing, not just named software vendors. | 高 | SP008, SP021, SP022 |
| CP036 | Multi-homing is likely in enterprise environments because workforce vaulting, privileged access and machine-secret lifecycle needs are increasingly served by overlapping but non-identical tool categories. | 高 | SP003, SP014, SP019, SP023 |
| CP037 | Opaque discounting and custom contract structure remain a real diligence blocker because public pages do not provide a clean apples-to-apples business price comparison across the field. | 高 | SP003, SP005, SP012 |
| CP038 | The low end of the market is structurally difficult to monetize because password and passkey storage are increasingly bundled into dominant operating systems, browsers and cloud ecosystems. | 高 | SP021, SP022, SP023, SP024, SP027 |
| CP039 | Keeper faces visible scale and platform-breadth pressure from 1Password’s 200,000+ business claim, Bitwarden’s 80,000+ business claim and CyberArk’s broader identity-security narrative. | 高 | SP004, SP006, SP015 |
| CP040 | Without current win/loss data, realized pricing, attach rates for KeeperPAM or secrets, and segment-level renewal evidence, Keeper’s moat durability cannot be fully underwritten from public materials alone. | 高 | SP003, SP025 |
| CI001 | Keeper’s visible revenue streams are primarily recurring software subscriptions rather than transactions, hardware or labor-heavy services. | 高 | SI002, SI003, SI004 |
| CI002 | Keeper publicly markets a tiered seat-based ladder from Business Starter to Business to Enterprise, with deeper governance and integration features appearing in higher tiers. | 高 | SI003, SI004 |
| CI003 | Keeper Secrets Manager is positioned as an add-on to business password-manager plans and is included with KeeperPAM. | 高 | SI004, SI006 |
| CI004 | KeeperPAM is sold through custom pricing tailored to organization size, infrastructure and privileged-access needs rather than a simple public self-serve SKU. | 高 | SI004, SI005 |
| CI005 | Keeper’s pricing surfaces reveal the monetization architecture but not realized ASP, discounting or seat-minimum economics. | 高 | SI003, SI004 |
| CI006 | The free Family Plan for business users functions more like an adoption and retention enhancer than a clearly visible direct ARR stream. | 高 | SI002, SI003, SI004 |
| CI007 | Keeper announced in July 2026 that it had reached US$225M in ARR. | 中 | SI001 |
| CI008 | Keeper says its ARR has grown more than 3x since 2021. | 中 | SI001 |
| CI009 | Keeper says it protects over 95,000 organizations worldwide. | 中 | SI001 |
| CI010 | Keeper says KeeperPAM revenue has grown 10x year-over-year since its February 2025 launch and that the company adds an average of 850 new organizations per month. | 中 | SI001 |
| CI011 | Keeper’s SoftwareReviews 2026 PR says the company achieved 53.42% year-over-year global revenue growth in 2025, or 3.45x the overall market average cited in that release. | 中 | SI009 |
| CI012 | Third-party private-company databases put Keeper’s 2024 revenue around US$90.6M to US$97.8M, showing how noisy outside estimates remain for a private company. | 中 | SI013, SI014 |
| CI013 | Third-party headcount estimates for Keeper conflict materially, with Growjo showing 506 employees and Tracxn showing 795 employees. | 中 | SI012, SI013 |
| CI014 | Because third-party revenue and headcount estimates conflict so sharply, public database profiles are better used as rough ranges than as underwritten financial facts. | 中 | SI012, SI013, SI014 |
| CI015 | Public sources do not disclose Keeper’s revenue mix across SMB, enterprise, public sector, MSP, secrets and PAM. | 高 | SI001, SI004 |
| CI016 | Keeper’s likely primary cost buckets are engineering, cloud infrastructure, security operations, compliance, support and go-to-market rather than inventory or manufacturing. | 高 | SI002, SI003, SI005 |
| CI017 | Okta’s fiscal 2026 results imply roughly 77% GAAP gross margin on US$2.919B of revenue, providing a reasonable benchmark for scaled identity SaaS margin shape. | 高 | SI016, SI017 |
| CI018 | Okta’s fiscal 2026 results imply sales and marketing expense equal to roughly 35% of revenue and R&D expense equal to roughly 22% of revenue, illustrating that identity SaaS remains sales- and product-investment heavy even at scale. | 高 | SI016, SI017 |
| CI019 | Okta’s fiscal 2026 free cash flow of US$863M on US$2.919B of revenue implies about a 30% free-cash-flow margin, showing that identity software can become strongly cash generative at scale. | 高 | SI016, SI017 |
| CI020 | Keeper appears capital-light relative to hardware or payments businesses because its monetization is software-based and there is no visible inventory, manufacturing or project-finance burden in public materials. | 高 | SI002, SI003, SI004 |
| CI021 | Keeper’s July 2026 ARR release says the company has a debt-free capital structure. | 中 | SI001 |
| CI022 | Keeper’s July 2026 ARR release says the company combines best-in-class growth with profitability, but does not quantify margin or earnings. | 中 | SI001 |
| CI023 | Keeper’s funding chronology—Insight’s 2020 US$60M growth round followed by Summit’s 2024 minority growth-equity investment—suggests the company has had access to expansion capital before the 2026 ARR milestone. | 高 | SI010, SI011 |
| CI024 | Management now frames future financing in terms of optionality for a public offering rather than immediate capital need, but current cash and runway remain undisclosed. | 高 | SI001, SI011 |
| CI025 | If KeeperPAM and Secrets Manager continue to attach within the installed base, Keeper’s revenue quality should improve through higher ARPU and deeper workflow lock-in. | 高 | SI001, SI005, SI006 |
| CI026 | Bundled substitutes from Google, Apple, AWS and Azure create real pricing pressure on the low end of password and secrets management. | 高 | SI019, SI020, SI021, SI022 |
| CI027 | Keeper’s GTM motion is likely blended: lighter-touch deployment for Business tiers and more sales-assisted motion for Enterprise, PAM and government-led opportunities. | 高 | SI002, SI003, SI004, SI007 |
| CI028 | The most important public financial blockers are undisclosed gross margin, CAC, payback, NRR, churn, current cash and burn. | 高 | SI001, SI004 |
| CI029 | Custom pricing for KeeperPAM and opaque enterprise discounts make realized ASP materially harder to underwrite than the pricing architecture alone would suggest. | 高 | SI004, SI005 |
| CI030 | Public evidence is directionally positive on capital adequacy but insufficient to prove solvency because the company does not disclose current cash, runway or debt covenants. | 高 | SI001, SI010, SI011 |
| CI031 | Business and enterprise pages emphasize deploy-in-minutes onboarding, identity integrations, training and 24x7 support, suggesting implementation is not unusually services-heavy for the category. | 高 | SI002, SI003 |
| CI032 | Keeper’s public-sector and compliance positioning likely supports larger contract values or stickier retention, but public evidence does not reveal the actual revenue contribution. | 高 | SI003, SI007 |
| CI033 | Average additions of 850 organizations per month signal strong top-of-funnel momentum, but do not by themselves reveal average contract value or customer quality. | 中 | SI001 |
| CI034 | The gap between third-party 2024 revenue estimates and Keeper’s 2026 ARR claim could reflect both rapid enterprise growth and the difference between revenue and ARR definitions. | 中 | SI001, SI013, SI014 |
| CI035 | Keeper’s claim of having added over 400 features and products to KeeperPAM in the prior fifteen months implies continued product reinvestment, which likely weighs on opex even if it strengthens enterprise expansion. | 中 | SI001 |
| CI036 | Keeper’s pricing surface is modular, with add-on upsell paths for secrets, PAM and advanced enterprise governance rather than one flat password-manager SKU. | 高 | SI003, SI004, SI006 |
| CI037 | The free Family Plan and personal/business vault separation indicate Keeper deliberately blends workforce adoption with user-convenience features that may support retention but dilute clean ARPU analysis. | 高 | SI002, SI003, SI004 |
| CI038 | For a business of Keeper’s type, working-capital and capex burdens are likely lower than the go-to-market and product-investment burdens. | 高 | SI002, SI017 |
| CI039 | Even scaled identity vendors rely heavily on non-GAAP framing and careful metric normalization, so Keeper’s unquantified profitability claim should be interpreted cautiously until audited detail is available. | 高 | SI001, SI017 |
| CI040 | The overall financial verdict is that Keeper now shows credible recurring-revenue scale and positive capital-direction signals, but still lacks enough public efficiency and solvency detail for full investor-grade underwriting. | 高 | SI001, SI004, SI017 |
| CE001 | Keeper now markets a unified identity-security platform spanning password management, privileged sessions, endpoint privilege, secrets, database access, zero-trust access, remote browser isolation, and a shared admin control plane. | 中 | SE002, SE010, SE019 |
| CE002 | KeeperPAM is presented as a cloud-based privileged access platform that unifies password management, secrets management, connection management, database management, endpoint privilege management, zero-trust network access, and remote browser isolation in one product. | 中 | SE002, SE010 |
| CE003 | Keeper Connection Manager is a self-hosted, agentless remote desktop gateway included with KeeperPAM and positioned for buyers that need a fully hosted, in-network or air-gapped deployment they manage themselves. | 中 | SE002, SE011 |
| CE004 | Keeper Secrets Manager is positioned as a fully managed, cloud-based, zero-knowledge service for infrastructure secrets, API keys, certificates, service accounts and other machine-identity credentials. | 中 | SE003, SE015, SE017 |
| CE005 | The Business, Enterprise and Enterprise Guide surfaces show that secure workforce vaulting, policy enforcement, SSO/SCIM and admin controls remain the base layer underneath Keeper’s newer adjacent products. | 中 | SE007, SE008, SE019 |
| CE006 | BreachWatch continuously monitors for compromised credentials tied to records in the vault and performs a local scan of stored passwords on the user’s device after activation. | 中 | SE013 |
| CE007 | Keeper’s passkey feature stores passkeys in the vault, syncs them across devices, supports autofill and biometric unlock, and allows vault-to-vault passkey sharing between Keeper users. | 中 | SE005 |
| CE008 | Keeper’s integrations catalog now spans AI coding agents, identity providers, browser extensions, cloud services, CI/CD platforms and SaaS rotation plugins, indicating a broad ecosystem strategy rather than a closed vault experience. | 中 | SE006, SE014, SE015 |
| CE009 | Keeper’s central technical claim is a zero-knowledge design in which encryption and decryption occur locally on approved devices and company personnel cannot decrypt customer vault data. | 中 | SE001, SE020 |
| CE010 | Keeper publicly describes a layered client-side key model using record keys, folder keys, a user data key and a local cache key to reduce the blast radius of any single shared object. | 中 | SE001 |
| CE011 | For master-password logins, Keeper says the key that unwraps the data key is derived locally from the user’s master password using PBKDF2 with 1,000,000 iterations. | 中 | SE001 |
| CE012 | For SSO and passwordless logins, Keeper says it uses ECC-256 device keys and a device-encrypted data key that is delivered through local device approval workflows rather than a decryptable server-side secret. | 中 | SE001 |
| CE013 | Keeper’s current security page says vault data is encrypted locally with AES-256 GCM, data in transit uses TLS 1.3 plus payload wrapping, and Q1 2026 introduced rollout of an additional quantum-resistant wrapper on the transmission key. | 中 | SE001 |
| CE014 | Keeper says it super-encrypts device-generated ciphertext with multi-region HSMs and keeps encrypted backups replicated across multiple geographies for disaster recovery. | 中 | SE001 |
| CE015 | Keeper’s public hosting model relies on AWS regional infrastructure, preferred-region isolation and multiple high-availability data centers, while Government Cloud adds an AWS GovCloud deployment path for U.S. regulated workloads. | 高 | SE001, SE004, SE027 |
| CE016 | The Government Cloud product page claims FedRAMP High, GovRAMP High, FIPS 140-3, SIEM support, smart-card authentication and support for NIST-aligned government workflows. | 中 | SE004, SE029, SE031 |
| CE017 | Keeper’s official trust posture includes SOC 2 Type 2, ISO 27001/27017/27018, quarterly third-party penetration testing, and a Bugcrowd-managed vulnerability disclosure and bug bounty program. | 高 | SE001, SE012, SE026 |
| CE018 | Keeper’s current security page cites FIPS 140-3 certificate | 中 | SE001, SE030 |
| CE019 | Keeper Connection Manager security documentation separately references FIPS 140-2 certificate | 中 | SE012 |
| CE020 | Keeper Connection Manager supports browser-based access to RDP, SSH, VNC, Kubernetes, databases and internal web applications, plus session recording, RBI, MFA, PIV/CAC and IdP integrations. | 中 | SE011 |
| CE021 | KeeperPAM publicly claims just-in-time access, ephemeral account provisioning, dynamic role or group elevation, discovery, credential rotation, encrypted tunnels and a gateway pattern that requires only outbound connectivity to Keeper Cloud. | 高 | SE002, SE010 |
| CE022 | Keeper’s developer documentation and product pages show SDK and CI/CD coverage across GitHub Actions, Jenkins, Terraform, Kubernetes, Docker and multiple programming languages. | 高 | SE003, SE014, SE015, SE017 |
| CE023 | Keeper Commander exposes CLI, SDK and REST service mode interfaces for vault access, admin functions, device approvals, PAM automation, session launch and password rotation. | 中 | SE016, SE017, SE022 |
| CE024 | Keeper’s release notes show high-frequency summer-2026 shipping across backend API, web vault, desktop, browser extension, mobile, admin console, Keeper Gateway, Commander, SDKs and KeeperDB. | 中 | SE018 |
| CE025 | The KeeperPAM, BreachWatch, developer-tools, Commander and user-guide pages all show recent update timestamps in 2026, supporting a read of active documentation and product maintenance. | 中 | SE010, SE013, SE014, SE016, SE018 |
| CE026 | Keeper’s public GitHub signal is meaningful but selective: the organization page highlights Commander, Secrets Manager, PowerCommander, a GitHub Action and a Terraform provider rather than the full commercial platform. | 中 | SE021, SE022, SE023 |
| CE027 | Keeper Connection Manager’s security architecture explicitly depends on Apache Guacamole, NGINX, Tomcat and a supported database, which increases operator control but also expands the set of customer-managed components. | 高 | SE012, SE028 |
| CE028 | The self-hosted and air-gapped positioning of Keeper Connection Manager is a differentiator for sovereignty-sensitive buyers, but it shifts patching, SSL configuration and database posture onto the customer operations team. | 中 | SE011, SE012 |
| CE029 | Keeper’s Connection Manager advisories page records historical vulnerabilities including CVE-2021-43999, a high-severity improper validation of SAML responses issue. | 中 | SE024 |
| CE030 | OpenCVE still indexes client-edge issues tied to Keeper surfaces, including a 2025 KeeperChat iOS biometric-escalation issue and a disputed KeeperFill/Desktop memory-disclosure issue. | 中 | SE025 |
| CE031 | Public product materials do not disclose measured service SLA, historical uptime, latency performance, AI-monitoring false-positive rates or session-detection efficacy metrics. | 高 | SE002, SE010, SE018 |
| CE032 | Product maturity appears highest in core vaulting, session access, admin policy and secrets workflows, while AI session monitoring and some government-specific packaging look newer and less publicly proven. | 高 | SE006, SE010, SE018 |
| CE033 | Keeper’s strongest architectural differentiator is deployment flexibility: a cloud-native control plane and outbound gateway model for standard deployments plus optional self-hosted KCM for in-network control. | 高 | SE002, SE010, SE011 |
| CE034 | Zero-knowledge design reduces provider-side plaintext exposure, but client devices, browser extensions and device-approval workflows remain critical trust anchors and therefore meaningful residual risk points. | 高 | SE001, SE020, SE025 |
| CE035 | Keeper’s Guacamole lineage gives it an open-source browser-based remote-session foundation with documented APIs and a large external user base, which helps explain the depth of its web-session tooling. | 高 | SE011, SE028 |
| CE036 | Public product pages tie passkeys, secrets and privileged access back into the same Keeper vault and admin-control posture instead of presenting them as isolated point tools. | 高 | SE002, SE003, SE005, SE019 |
| CE037 | Keeper’s integrations catalog and developer docs show the company is expanding from workforce password management toward machine and AI-agent identity workflows. | 高 | SE006, SE014, SE015, SE018 |
| CE038 | As of August 2026, Keeper looks like a broad and technically credible identity-security platform with real engineering motion, but the newest surfaces still require private reliability, adoption and independent security-test evidence before they can be underwritten with the same confidence as the core vault. | 高 | SE002, SE018, SE021, SE024 |
| CU001 | Keeper’s visible customer base spans consumers, families, SMBs, enterprise, public sector, education/nonprofit, MSP/channel and privileged-access-heavy technical buyers. | 中 | SU004, SU024, SU025, SU026 |
| CU002 | Buyer, user and payer differ materially by segment, with consumer users buying directly, IT/security teams buying for workforce users, and MSPs buying for both their staff and managed clients. | 中 | SU009, SU024, SU025 |
| CU003 | Keeper said in July 2026 that it protects over 95,000 organizations. | 中 | SU001 |
| CU004 | The same July 2026 PR says Keeper’s customer base includes many Fortune 500 enterprises and public-sector agencies. | 中 | SU001 |
| CU005 | Keeper’s current public organization-count messaging varies across fresh company surfaces from 95,000+ organizations to over 100,000 organizations, implying large scale but also publication-timing drift. | 中 | SU001, SU006 |
| CU006 | Consumer adoption appears meaningfully large because Keeper still describes millions of users globally and the mobile apps show 229K iOS ratings and 111K Android ratings as of August 2026. | 中 | SU001, SU021, SU022 |
| CU007 | Named customer proof spans motorsport, global SaaS, MSP services, higher education, finance/trust, telecom training, nonprofit and state government. | 中 | SU004, SU007, SU008, SU009, SU011, SU012, SU014, SU015, SU016 |
| CU008 | The named reference set is geographically broad enough to show UK, US and globally distributed deployments rather than a single-country customer profile. | 中 | SU005, SU007, SU008, SU009, SU014 |
| CU009 | The MSP/channel motion is real and not hypothetical, with Lucidica using KeeperMSP for its own staff and downstream managed client users. | 中 | SU009 |
| CU010 | Public-sector, education and nonprofit demand are substantive visible segments, supported by Government Cloud positioning plus named deployments at New Mexico, Illinois College, Oregon State and Alzheimer’s Association. | 中 | SU011, SU013, SU015, SU016, SU026 |
| CU011 | A recurring pre-Keeper customer pain point is fragmented password handling through spreadsheets, browser tools, text files, printed notes or legacy password managers. | 中 | SU005, SU009, SU011, SU012, SU013 |
| CU012 | Ease of deployment and operational simplicity appear repeatedly in both case studies and reviews as reasons Keeper wins adoption. | 中 | SU002, SU007, SU008, SU011, SU017 |
| CU013 | Keeper says it is adding an average of 850 new organizations every month. | 中 | SU001 |
| CU014 | Keeper has unusually rich named customer proof for a private cybersecurity vendor, with at least ten identifiable reference deployments available publicly. | 中 | SU004, SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015, SU016 |
| CU015 | Atlassian Williams F1 Team uses KeeperPAM to secure privileged access across a globally distributed workforce operating in more than 20 countries each season. | 中 | SU007 |
| CU016 | Asite’s case study shows KeeperPAM in a 500+ employee global SaaS environment with nine data-center locations, replacing separate legacy PAM and secrets tools. | 中 | SU008 |
| CU017 | Lucidica’s case study shows KeeperMSP serving both its internal team and hundreds of managed client users across dozens of customer organizations. | 中 | SU009 |
| CU018 | Illinois College reports growing student adoption and a significant decrease in IT help-desk tickets after deploying Keeper across campus workflows. | 中 | SU011 |
| CU019 | Peak Trust uses Keeper for employees, shared teams, external specialists and regulatory reporting, and later migrated a sister company and outside directors from Dashlane to Keeper. | 中 | SU012 |
| CU020 | NokiaEDU uses Keeper Connection Manager to support remote training for thousands of students each month. | 中 | SU014 |
| CU021 | The New Mexico Taxation and Revenue Department case shows 700+ employees enabled for secure remote desktop access in less than a week. | 中 | SU015 |
| CU022 | Keeper’s December 2025 G2 blog cites 1,172 total reviews, a 4.6/5 rating, 94% satisfaction for meeting requirements and a 92% recommendation rate. | 中 | SU006 |
| CU023 | Keeper’s SoftwareReviews 2026 PR cites 93% likelihood to recommend, 87% fair cost-to-value, 85% ease of implementation and 81% usability for KeeperPAM. | 中 | SU002 |
| CU024 | GetApp shows 507 verified user reviews, 82% positive retention sentiment and password management as the dominant use case for Keeper reviewers. | 中 | SU020 |
| CU025 | Public adverse feedback clusters around pricing, price changes, add-on costs, autofill inconsistency, reporting gaps and occasional app or plugin friction. | 中 | SU017, SU020, SU023 |
| CU026 | Keeper does not publicly disclose NRR, GRR, logo churn, deployed-seat utilization or active-vault cohort curves by segment. | 高 | SU001, SU024, SU025 |
| CU027 | The best public retention proxies are review sentiment, recurring usage evidence in named deployments and the operational stickiness implied by SSO, shared-folder, reporting and privileged-access workflows, not actual cohort data. | 高 | SU006, SU020, SU011, SU013 |
| CU028 | Keeper’s main customer expansion levers appear to be seat growth, family-plan spillover, Secrets Manager and KeeperPAM attach, public-sector packaging and MSP downstream client expansion. | 高 | SU001, SU009, SU024, SU025, SU026 |
| CU029 | Public customer concentration appears diversified by vertical and use case, but top-customer revenue concentration cannot be tested because those figures are private. | 中 | SU004, SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015, SU016 |
| CU030 | Customer-proof freshness is mixed: many password-manager and KeeperPAM stories are 2025-2026, while several KCM references still date to 2022-era deployment narratives. | 中 | SU005, SU007, SU008, SU011, SU014, SU015 |
| CU031 | Review signals consistently praise secure sharing, cross-device sync, SSO/Entra integration, admin usability and customer support as major reasons to adopt or retain Keeper. | 中 | SU017, SU018, SU019, SU020 |
| CU032 | Negative review signals also point to potential procurement and renewal friction around extras-based pricing, reporting limitations, standalone-app performance and autofill behavior. | 中 | SU017, SU020, SU023 |
| CU033 | Keeper’s named public references overwhelmingly describe production use rather than pilot evaluation, because they discuss rollout, active usage, support experience, user adoption or operational outcomes. | 中 | SU007, SU008, SU009, SU011, SU012, SU013, SU014, SU015 |
| CU034 | The free family-plan benefit included with business licenses can plausibly accelerate workforce adoption by giving employees a personal-use incentive alongside work deployment. | 高 | SU005, SU024 |
| CU035 | Customer satisfaction appears materially positive, but review platforms are self-selected and therefore should be treated as sentiment proxies rather than direct retention evidence. | 高 | SU017, SU020, SU021, SU022 |
| CU036 | The overall customer verdict is favorable on breadth, reference quality and user sentiment, but still blocked on concentration, renewal economics, module-specific retention and active-seat depth. | 高 | SU001, SU006, SU017, SU020 |
| CU037 | Government Cloud positioning plus public-sector case studies suggest Keeper is winning not only generic enterprise accounts but also higher-control government and education environments. | 高 | SU015, SU026, SU011, SU013 |
| CU038 | Reviews, case studies and named references likely feed Keeper’s top-of-funnel because satisfied customers create the proof surfaces that future buyers use during discovery. | 高 | SU003, SU004, SU006, SU017 |
| CR001 | Keeper’s downside is unusually trust-sensitive because the company sells identity, secrets, privileged access and government controls rather than a low-stakes utility product. | 高 | SR004, SR005, SR006, SR021 |
| CR002 | FedRAMP, GovRAMP, FIPS and NIST-aligned positioning increase the severity of any control failure because they are central to Keeper’s regulated-market pitch. | 高 | SR005, SR015, SR021, SR022, SR026 |
| CR003 | There is no first-order public evidence of current enforcement or active litigation dominating the risk case today. | 高 | SR001, SR004, SR005 |
| CR004 | Keeper Connection Manager’s advisories page shows the remote-access surface has had historical vulnerabilities, including a high-severity SAML response validation issue. | 中 | SR010 |
| CR005 | OpenCVE tracks additional Keeper-related client or adjacent-product issues, showing that residual edge-surface vulnerability risk remains even without evidence of a platform-wide catastrophe. | 中 | SR013 |
| CR006 | Keeper’s zero-knowledge design meaningfully reduces provider-side plaintext exposure, but it does not eliminate endpoint, browser-extension or device-approval risk. | 高 | SR004, SR009, SR013 |
| CR007 | The company’s trust posture is supported by concrete mitigations including published cryptographic detail, quarterly testing, Bugcrowd disclosure and region-isolated hosting. | 高 | SR004, SR009, SR020 |
| CR008 | Because Keeper positions itself as a unified control plane for privileged access and AI agents, a security incident would likely transmit quickly into procurement friction, customer trust and valuation. | 高 | SR006, SR014, SR024 |
| CR009 | Self-hosted KCM deployments create operational risk because customers must manage Docker, SSL, database posture and upgrades in environments Keeper does not fully control. | 高 | SR009, SR025 |
| CR010 | The public materials and release cadence indicate Keeper is now operating a wider and more complex product estate than a classic password manager. | 高 | SR006, SR007, SR011, SR012 |
| CR011 | Review sources repeatedly surface pricing complexity, add-on fatigue, reporting gaps and autofill inconsistency as practical risks to customer satisfaction. | 中 | SR017, SR018, SR019 |
| CR012 | Review complaints appear operationally irritating rather than existential, but they are precisely the kind of friction that can accumulate in renewal or procurement cycles. | 中 | SR016, SR017, SR018 |
| CR013 | IBM and Verizon both underscore that stolen credentials and identity failures remain economically severe, which increases the downside cost of any Keeper trust event. | 高 | SR023, SR024 |
| CR014 | Keeper’s risk is broader than a simple vault product because it now spans PAM, secrets, remote access, AI monitoring and government-control surfaces. | 高 | SR005, SR006, SR007, SR012 |
| CR015 | Rapid shipping across many surfaces raises the chance of quality regressions, support strain or coordination failures even when release velocity is a strength. | 中 | SR011, SR016 |
| CR016 | Keeper has material platform dependence on AWS and AWS GovCloud for core hosting and regulated deployment. | 高 | SR004, SR005, SR020 |
| CR017 | Enterprise IdPs and provisioning systems are structurally important dependencies because Keeper’s business value often relies on SSO, SCIM and device-approval workflows. | 高 | SR003, SR006, SR021 |
| CR018 | Browsers, mobile operating systems and app stores remain meaningful external dependencies because they affect autofill, passkeys, distribution and consumer/business usability. | 高 | SR007, SR017, SR027 |
| CR019 | KCM’s Guacamole lineage creates upstream open-source dependency risk even if it also provides technical depth and commercial differentiation. | 高 | SR009, SR025 |
| CR020 | Founder continuity under Darren Guccione and Craig Lurey is a strategic strength but also a real key-person and succession risk. | 高 | SR001, SR014 |
| CR021 | Growing 850 organizations per month can pressure implementation, support and customer-success systems if staffing and process depth lag demand. | 中 | SR014, SR016 |
| CR022 | Native platform defaults and bundled cloud services, including passkeys and AWS Secrets Manager, increase commoditization risk at the low end and can displace point needs. | 高 | SR027, SR028 |
| CR023 | Dependency risk is not purely technical because review platforms and customer-sentiment surfaces function as discovery infrastructure in security software buying. | 中 | SR008, SR017, SR018 |
| CR024 | Keeper’s public mitigations look more mature than aspirational because they combine detailed architecture pages, active advisories, frequent releases and strong review-backed implementation scores. | 中 | SR009, SR010, SR011, SR016 |
| CR025 | The company’s unified-platform narrative is strategically attractive, but it also increases prioritization and organizational-complexity risk across product, engineering and compliance functions. | 中 | SR006, SR012 |
| CR026 | The biggest financial-model risk is that public growth evidence improved sharply in 2026 while public durability data did not. | 中 | SR014, SR016 |
| CR027 | Strong current satisfaction metrics are a mitigating factor because they suggest customer experience is not presently in obvious distress. | 中 | SR008, SR016 |
| CR028 | Competitive pressure can compress low-end pricing while also forcing Keeper to prove attach-rate value for PAM, secrets and government-control modules. | 高 | SR017, SR022, SR028 |
| CR029 | Public-sector sales cycles and authorization maintenance likely improve contract quality but can also lengthen revenue timing and create renewal or scope risk. | 高 | SR005, SR015, SR022 |
| CR030 | Public sources do not prove weak bench depth below the founders, which leaves real but unquantified succession and organizational-redundancy risk. | 中 | SR001 |
| CR031 | High review praise for support and usability is encouraging, but it can become a margin or reputation risk if the company cannot maintain service quality during fast growth. | 中 | SR008, SR016, SR017 |
| CR032 | Keeper has visible mitigating strengths in customer proof, review-backed ease of implementation, regulated-market fit and technical differentiation. | 高 | SR005, SR008, SR016 |
| CR033 | A material security incident is the clearest thesis-break trigger because it would hit trust, customer conversion, renewals and valuation simultaneously. | 高 | SR004, SR010, SR024 |
| CR034 | A pronounced slowdown in new-logo growth or module attach would challenge the premium-growth and IPO-optional narrative management is now presenting. | 中 | SR014 |
| CR035 | Broadening complaints about price increases, add-ons or value mismatch would be an important leading indicator of retention and sales-efficiency pressure. | 中 | SR017, SR018 |
| CR036 | Monthly or quarterly monitorable indicators should include new-logo adds, support backlog, implementation time, module attach, review-sentiment drift, release-quality metrics and certification status. | 中 | SR011, SR014, SR016 |
| CR037 | The absence of public NRR, GRR, churn, top-customer concentration, CAC payback and detailed cash data is itself a material risk because it prevents clean downside calibration. | 中 | SR014, SR017, SR018 |
| CR038 | Keeper’s overall risk profile is manageable but meaningfully residual, because several monitorable but non-trivial threats can flow from technical or commercial friction into growth quality and valuation. | 中 | SR014, SR017, SR024 |
| CR039 | The FedRAMP Marketplace lists Keeper ICAM & Identity Security Platform for Government as FedRAMP Certified, Class D (High), with six authorizations and a certified-since date of 2025-12-18, which reduces doubt about authorization existence but raises the importance of continuous compliance maintenance. | 高 | SR005, SR033 |
| CR040 | Keeper’s public terms and privacy materials explicitly disclaim continuous website availability, incorporate privacy and DPA governance, and place lawful use, export compliance and some security/backup responsibilities on customers or administrators. | 高 | SR029, SR030 |
| CR041 | Keeper’s public status surface spans multiple geographic data centers plus client apps, on-prem connectors and SCIM/API services, which demonstrates resilience intent but also shows a broad operational surface where localized outages can still affect customer experience. | 高 | SR031, SR032 |
| CR042 | Independent review coverage still describes Keeper as highly secure but relatively expensive and without a free option, reinforcing that pricing pressure is visible beyond user-review marketplaces. | 中 | SR034, SR035 |
| CV001 | Keeper’s July 2026 disclosure of $225M ARR, 95,000+ organizations protected and 850 new organizations added per month proves the company has real operating scale, not just category buzz. | 中 | SV001 |
| CV002 | Management’s claim that Keeper is profitable and debt-free is valuation-supportive because it reduces immediate financing overhang and downside refinancing pressure. | 中 | SV001 |
| CV003 | Open-source financing data remains opaque: public databases show limited funding history, but not a clean current post-money valuation that investors can underwrite against. | 中 | SV002 |
| CV004 | Because public sources still do not disclose NRR, GRR, gross margin, free cash flow, concentration or preference terms, the recommendation must remain price-sensitive and evidence-sensitive. | 中 | SV001, SV002 |
| CV005 | Keeper’s product breadth, public-sector posture and user-satisfaction signals support the view that this is a strong private cybersecurity asset rather than a narrow consumer vault business. | 中 | SV005, SV006, SV023 |
| CV006 | A material trust incident would likely compress Keeper’s valuation quickly because identity and privileged-access vendors sell assurance first and features second. | 高 | SV021, SV027, SV028 |
| CV007 | Public evidence supports unicorn plausibility, but public evidence alone does not support a price-insensitive buy call. | 中 | SV001, SV002, SV013, SV018 |
| CV008 | Independent review surfaces praising security while flagging pricing or value friction mean premium pricing power still needs diligence rather than assumption. | 中 | SV007, SV008, SV009, SV029 |
| CV009 | Okta’s August 2026 market cap of about $25.82B against roughly $3.00B of trailing revenue implies a public multiple of about 8.5x sales. | 中 | SV013, SV014 |
| CV010 | SailPoint’s August 2026 market cap of about $10.62B against roughly $1.12B of trailing revenue implies a public multiple of about 9.5x sales. | 中 | SV018, SV019 |
| CV011 | CyberArk’s August 2026 market cap of about $20.63B against 2025 revenue of about $1.36B implies a multiple a little above 15x sales. | 中 | SV015, SV016 |
| CV012 | The most decision-useful public-comp band for Keeper from this run is therefore roughly 8.5x to 15x. | 中 | SV013, SV014, SV015, SV016, SV018, SV019 |
| CV013 | Applying an 8.5x multiple to Keeper’s disclosed $225M ARR yields about $1.9B of enterprise value support. | 中 | SV001, SV013, SV014 |
| CV014 | Applying about 9.5x to Keeper’s disclosed $225M ARR yields about $2.1B of enterprise value support. | 中 | SV001, SV018, SV019 |
| CV015 | Applying a 12x multiple to Keeper’s disclosed $225M ARR yields about $2.7B of enterprise value support. | 中 | SV001, SV013, SV018 |
| CV016 | Applying a 15x multiple to Keeper’s disclosed $225M ARR yields about $3.4B of enterprise value support. | 中 | SV001, SV015, SV016 |
| CV017 | An 18x multiple on Keeper’s disclosed ARR yields about $4.05B, while 20x yields about $4.5B. | 中 | SV001, SV013, SV015 |
| CV018 | A rumored or discussed mid-$4B outcome therefore requires either a very premium multiple on current disclosed ARR or materially higher ARR than Keeper has publicly disclosed. | 中 | SV001, SV013, SV015, SV018 |
| CV019 | Because Keeper disclosed ARR rather than GAAP revenue, direct comparison against public sales multiples is more generous than conservative. | 中 | SV001, SV013, SV018 |
| CV020 | CyberArk’s premium positioning shows what public markets may pay for control-heavy identity assets, but that premium normally comes with richer disclosure and deeper enterprise control depth. | 中 | SV015, SV016, SV021 |
| CV021 | SailPoint’s public 10-K availability underscores the disclosure gap between Keeper and a public identity comp even before any opinion about relative quality. | 高 | SV017, SV018, SV019 |
| CV022 | Okta’s live SEC-filings infrastructure similarly highlights that public comps provide filing-grade transparency that Keeper does not. | 高 | SV013, SV030 |
| CV023 | The current cloud/software market is open enough to support healthy multiples, but the BVP cloud index context does not suggest investors should pay any price for growth alone. | 中 | SV020, SV013, SV018 |
| CV024 | Keeper’s FedRAMP Certified and GovRAMP High public-sector posture can justify some premium relative to consumer-only vault vendors because it widens procurement scope and switching relevance. | 高 | SV004, SV005, SV023 |
| CV025 | Keeper’s public status surface, security posture and legal materials reduce the likelihood of a distress narrative, but they do not close the valuation-opacity gap. | 中 | SV010, SV022, SV025, SV026 |
| CV026 | A reasonable bull case requires ARR moving into roughly the $275M-$325M range, continued profitability, healthy attach for PAM and secrets and no trust shock. | 中 | SV001, SV006, SV023 |
| CV027 | A reasonable base case keeps Keeper around roughly $225M-$260M ARR with 9x-12x support, implying about $2.0B-$3.1B of value. | 中 | SV001, SV013, SV018 |
| CV028 | A reasonable bear case assumes ARR drifting toward about $180M-$220M with weaker growth or trust damage and 5x-8x support, implying about $0.9B-$1.8B of value. | 中 | SV001, SV021, SV027 |
| CV029 | Exit readiness is helped by Keeper’s disclosed scale, profitability, debt-free status and enterprise/public-sector relevance. | 中 | SV001, SV004, SV005 |
| CV030 | Exit readiness is still constrained by missing public data on retention, concentration, margins, cash generation and equity terms. | 中 | SV001, SV002, SV017, SV030 |
| CV031 | Keeper’s 95,000+ organizations and current new-logo pace imply sufficient breadth to support multibillion-dollar outcomes if retention and margins are healthy. | 中 | SV001, SV024 |
| CV032 | Profitability and debt-free status are important mitigants because they reduce the need for value-destructive emergency fundraising. | 中 | SV001, SV002 |
| CV033 | The public-comp set is imperfect because Okta is broader identity, SailPoint is identity governance and CyberArk is a premium PAM leader. | 中 | SV013, SV015, SV017, SV018 |
| CV034 | The same public-comp set remains decision-useful because all three sell trust-sensitive identity or control software into enterprise buyers and public markets. | 中 | SV013, SV015, SV017, SV018 |
| CV035 | Keeper’s open-source funding history and absent public post-money terms prevent clean calculation of common-equity attractiveness even if enterprise value looks plausible. | 中 | SV002 |
| CV036 | Point-in-time public comp multiples can move quickly with market sentiment, so scenario ranges are safer than a single exact fair value. | 中 | SV014, SV016, SV019, SV020 |
| CV037 | Platform-native passkeys and bundled cloud secrets tools cap low-end multiple expansion because they pressure simpler password-only or secrets-only use cases. | 中 | SV011, SV012 |
| CV038 | Strong review-backed usability and satisfaction help offset some commoditization risk and support ongoing relevance. | 中 | SV006, SV007, SV009, SV024 |
| CV039 | Review-site pricing complaints argue against blindly assuming that strong product proof translates into durable premium pricing power. | 中 | SV007, SV008, SV009 |
| CV040 | If a seller’s expectation is closer to the low-$2B to low-$3B range and diligence verifies retention, margins and clean equity terms, Keeper could screen fair; if the ask is materially above $4B, public evidence looks full. | 中 | SV001, SV013, SV015, SV018 |
| CV041 | The final recommendation should be track / research-more rather than buy because company quality currently exceeds price proof. | 中 | SV001, SV002, SV013, SV018, SV021 |
| CV042 | Overall confidence should remain medium because disclosed ARR materially improved the evidence base, but the company is still far less transparent than public comps on durability and equity economics. | 中 | SV001, SV017, SV030 |
| CV043 | Keeper’s July 2026 disclosure materially improved public valuation evidence relative to earlier periods by revealing ARR, profitability and new-logo velocity in one place. | 中 | SV001 |
| CV044 | Even after that improvement, Keeper still discloses less than public comps do on revenue composition, retention and standardized filing detail. | 高 | SV001, SV017, SV030 |
| CV045 | The evidence-supported valuation stance today is fair-to-full rather than cheap. | 中 | SV001, SV013, SV015, SV018, SV021 |
| CV046 | A stronger buy case would require diligence proof of ARR materially above $300M or unusually strong retention, margin and cap-table quality that public evidence does not yet show. | 中 | SV001, SV002, SV013, SV015 |