Keeper: Cloud-Native PAM for DACH Companies

Keeper addresses one of the most persistent targets for attackers: privileged accounts. A single set of access rights can be enough to control systems, data and identities. Yet many organisations still rely on permanent administrator privileges, shared credentials and incomplete logging. Consequently, this is more than a technical weakness. It also makes robust evidence harder to provide to auditors, particularly under NIS-2, DORA and the revised Swiss Data Protection Act. This article assesses Keeper as a cloud-native Privileged Access Management platform. It explains Zero-Knowledge and Just-in-Time Access, and identifies the trade-offs that every evaluation should consider.

Why privileged access is the crown-jewels problem of IT security

Anyone who controls administrative access to domain controllers, cloud consoles, databases or remote-maintenance portals may also control critical business processes. In practice, however, legacy structures often obstruct effective oversight. These include permanent administrator accounts, shared passwords, overlooked service accounts and remote access without consistently enforced multi-factor authentication. This combination allows attackers to turn one compromised credential into extensive access at speed.

The 2026 Data Breach Investigations Report by Verizon illustrates the continuing importance of credentials to attackers. As an initial access vector, vulnerability exploitation overtook credential misuse for the first time, at 31 versus 13 percent. Across the attack chain, however, credential misuse remained the most prevalent technique, appearing in about 39 percent of the breaches examined. The conclusion is uncomfortable but clear. Even when attackers enter through an unpatched vulnerability, they often use accounts and credentials, preferably privileged ones, to escalate access and move laterally.

Recent incidents show how quickly a situation can escalate when safeguards for privileged or potentially privileged access are absent. According to public reports, the 2024 attack on Change Healthcare began through a remote-access portal without MFA. Lateral movement and Ransomware deployment followed. During the wave of Snowflake-related incidents in 2024, the decisive weakness was not the platform itself. Instead, attackers used compromised customer credentials, including in environments where MFA was not enforced. The underlying pattern was similar in both cases: one access path became a lever for reach, speed and impact.

The lesson therefore concerns governance more than features. Privileged access remains a structural risk without clear responsibilities, mandatory MFA, traceable approvals, session control and reliable rotation of Secrets. Privileged Access Management addresses precisely this problem.

What Keeper is and how the platform works

Keeper is the Privileged Access Management platform from Keeper Security. It combines core components such as Vault, Secrets Management, Connection Management, Session Recording and Zero Trust remote access in a cloud-native operating model. This approach can be particularly relevant for companies without a dedicated PAM team. It enables them to establish initial controls and audit evidence with manageable operational effort, provided they define governance and responsibilities beforehand.

TECHWAY - Keeper

Keeper combines Vault, session control and Just-in-Time Access in a unified platform

Keeper architecture: Vault, Gateway and Zero-Knowledge

A central principle is the encrypted Vault. Keeper encrypts sensitive content, such as passwords and keys, on the client side so that the provider cannot view the plaintext. Security professionals commonly describe this design as a Zero-Knowledge architecture. In other words, the platform operator need not be treated as an additional insider with access to Secrets.

The Keeper Gateway runs within the customer’s network and provides the technical bridge to target systems. It typically handles discovery and rotation, as well as session brokering and logging. The model is generally agentless for target systems. Moreover, the encrypted connection to the cloud backend is outbound, which can simplify network configuration compared with traditional jump-host architectures.

Just-in-Time Access instead of Standing Privileges

For many organisations, the central design decision is the shift from Standing Privileges to Just-in-Time Access. The aim is to grant privileged rights for limited periods and in a traceable manner, rather than retaining them permanently. In practice, organisations enable role elevation or accounts for a defined task and withdraw them afterwards. Alternatively, they rotate the underlying credentials. Approval workflows, Session Recording for common protocols and controlled browser sessions complement these controls. Together, they provide audit evidence and help organisations detect misuse earlier.

Certifications and audit evidence

For compliance leaders, the decisive issue is not the feature list but the evidence available during an audit. In its public communications, Keeper Security refers to FIPS 140-3 validation and SOC 3 compliance. The publicly available SOC 3 report can serve as a signal of transparency in procurement processes. In addition, Keeper’s technical documentation cites a SOC 2 Type II attestation and ISO 27001 certification. However, certifications cannot replace an organisation’s own assessment. Instead, they provide a starting point for reviewing scope, applicability and practical auditability.

Keeper and cloud-native PAM versus traditional PAM architectures

Traditional PAM architectures developed around data-centre models, with dedicated infrastructure, jump hosts, complex segmentation and substantial operational effort. Cloud-native PAM platforms such as Keeper move parts of this model into a SaaS environment. Meanwhile, a gateway component runs on site for each network segment. This approach typically reduces the customer’s infrastructure burden and can shorten implementation times. The benefit is particularly relevant when organisations begin with their most critical accounts and systems.

Trade-offs that belong in every evaluation

A cloud-native operating model lowers barriers to entry, but it also raises new questions. First: data residency. According to publicly available vendor information, EU regions in Frankfurt and Ireland are available. However, the cited information does not document dedicated data hosting in Switzerland. Customers with strict requirements should therefore consult their data-protection and legal advisers. This is especially important when particularly sensitive personal data or specific contractual clauses are involved. A Zero-Knowledge architecture can reduce technical risk, but it does not replace a legal assessment. Keeper also states that it participates in the Swiss-U.S. Data Privacy Framework, which can support the legal assessment of transfers to the United States.

Second: vendor dependency and jurisdiction. When working with a US provider, companies must consider possible disclosure requests in their risk analysis, including those under the US CLOUD Act. At its core, Zero-Knowledge means that the provider cannot supply plaintext without the customer’s keys. Nevertheless, organisations should document how they assess this protection in their specific legal and technical context.

Third: exit strategy. Before implementation, organisations should clarify export options and data portability for Vault contents, session recordings and audit logs. This is not merely best practice. In regulated environments, it is also part of sound third-party risk management.

A vendor-neutral comparison of PAM approaches, including alternatives with a stronger on-premises focus, forms part of our advisory work. Our article on the least-privilege principle examines why organisations should minimise privileged rights and grant them only for limited periods. This is not merely a vendor position, as official standards demonstrate. The BSI defines Least Privilege and restrictive permission allocation as baseline requirements in its IT-Grundschutz module ORP.4 Identity and Access Management.

Regulatory context: NIS-2, DORA, revised Swiss Data Protection Act and FINMA

None of the relevant regulations mandates a particular PAM product category. In practice, however, their requirements for access control, logging and demonstrable oversight are difficult to meet without structured processes and appropriate technical controls for privileged access.

NIS-2: The directive requires affected organisations to implement risk-based cybersecurity measures, including policies on access control and, where appropriate, multi-factor authentication. It also imposes incident-reporting obligations. Consequently, management bodies face greater pressure to document decisions and controls, since governance and evidence can themselves become subjects of scrutiny.

DORA: In the financial sector, DORA places greater emphasis on ICT risk management, logging and oversight of ICT third-party providers. For privileged activities, the ability to trace actions comprehensively and reconstruct them when necessary is therefore a natural control objective.

Revised Swiss Data Protection Act: The revised Swiss Data Protection Act requires appropriate technical and organisational measures. In practice, these include access restrictions, minimisation of privileged rights and logging that supports a traceable investigation after an incident.

FINMA: Supervised institutions must address segregation of duties, access control and the monitoring of critical systems within their operational-risk frameworks. Privileged access warrants particular protection because it concentrates risks to integrity, availability and confidentiality.

From a compliance perspective, the core question is not whether a PAM solution offers particular functions on paper. Rather, it is whether its operational logs, session recordings and reports are consistent enough to serve as evidence for internal and external auditors. Auditability is therefore not a secondary concern. It is a central selection criterion.

TECHWAY’s position on Keeper and PAM governance

As a vendor-neutral cybersecurity adviser, we regard Privileged Access Management first as a governance discipline and only then as a question of tools. Organisations that introduce a PAM tool without defining responsibilities, account classifications, access reviews, break-glass procedures and approvals usually improve the interface, not their control.

In our view, two arguments justify placing PAM higher on the priority list. First, NIS-2 and DORA increase the corporate responsibility of management bodies. In practice, this responsibility requires documented decisions, controls and evidence of effectiveness. Second, auditability matters. Comprehensive session recordings and regular access reports provide important evidence during ISO 27001 audits, internal audits and regulatory inspections.

Four evaluation criteria for tool selection:

1) Data sovereignty and operating model: Where may Vault data, metadata and session recordings reside? Which region is acceptable under contractual and regulatory requirements? Is a SaaS model viable, or does the requirements profile demand full on-premises data retention? Keeper can provide a pragmatic entry point for companies without a dedicated PAM team, provided EU hosting and the associated trade-offs are acceptable. Where sovereignty requirements are stricter, organisations should assess alternative approaches without prejudging the outcome.

2) Auditability: Which reports, session recordings and recertification workflows are available without additional development? Furthermore, how effectively can the resulting signals be integrated into existing SIEM, GRC and ticketing processes?

3) Implementation focus: How quickly can the most critical privileged accounts and access paths be brought under control, including mandatory MFA, approvals and logging? Cloud-native models can reduce the infrastructure burden. However, the governance work remains unchanged.

4) Exit capability: Can Vault contents, Secrets, session recordings and audit logs be exported in standardised formats, with sufficient metadata for future traceability? This question belongs in every evaluation, regardless of the provider.

Conclusion: where Keeper fits

Keeper is a credible option for companies in the DACH region that want to establish Privileged Access Management without operating extensive on-premises PAM infrastructure. Its Zero-Knowledge architecture, Just-in-Time Access and emphasis on auditability address key control objectives associated with NIS-2, DORA, the revised Swiss Data Protection Act and FINMA expectations. At the same time, organisations must assess and document data residency, jurisdictional exposure and exit arrangements transparently.

The tool should follow the requirements, not the other way round. Organisations that treat PAM as a governance discipline and apply clear evaluation criteria can reduce the risks associated with privileged access. Moreover, they create evidence that increasingly matters to executive management and the board of directors.

No-obligation PAM evaluation consultation

Are you evaluating a PAM solution, or would you like to assess your existing access management against NIS-2, DORA and revised Swiss Data Protection Act requirements? As a vendor-neutral advisory partner, we support you with requirements analysis, evaluation criteria and tool selection. Keeper is one of several options that we assess comparatively.

🎯 Key takeaways for decision-makers

Summary for the board of directors, executive management and CISO:

✓ PAM is governance first: Responsibilities, account classification, mandatory MFA and access reviews form the foundation. Tool selection follows.

✓ Responsibility requires evidence: NIS-2 and DORA raise expectations for documented controls and traceable decisions by management bodies.

✓ Keeper as a possible entry point: Keeper offers a cloud-native model with Zero-Knowledge, Just-in-Time Access and certification evidence. It can suit organisations without a dedicated PAM team, provided the operating model meets their requirements.

✓ State the trade-offs clearly: Data residency, jurisdiction and exit capability belong in every evaluation.

✓ Treat auditability as a selection criterion: Session recordings and access reports provide essential evidence for auditors.

Frequently asked questions about Keeper

What is Keeper?

Keeper is the cloud-native Privileged Access Management platform from Keeper Security. It combines an encrypted Vault, Secrets Management, Connection Management, Session Recording, Zero Trust remote access and Just-in-Time Access in a unified solution. Keeper operates as SaaS, while the Keeper Gateway is installed in the customer network. Target systems generally do not require agents.

What does Zero-Knowledge architecture mean in a PAM solution?

Zero-Knowledge means that sensitive data is encrypted on the client side before it leaves the endpoint. The provider cannot access plaintext passwords or Secrets. This reduces the risk that companies must treat the platform operator as an additional insider with access to credentials.

Which regulatory requirements does Privileged Access Management address?

PAM supports control objectives associated with NIS-2, including access control, MFA and evidence; DORA, including ICT risk management, logging and third-party risk; the revised Swiss Data Protection Act, including appropriate technical and organisational measures; and FINMA expectations concerning segregation of duties and monitoring of critical systems. None of these frameworks prescribes PAM as a product category. However, meeting their evidentiary requirements is difficult in practice without structured management of privileged access.

How quickly can Keeper be implemented?

As a cloud-native SaaS model, Keeper can accelerate implementation compared with traditional PAM platforms because customers operate less infrastructure. In many projects, organisations can bring their most critical privileged accounts under controlled management within a few weeks. Governance preparation remains essential, particularly the definition of responsibilities, account classifications, approvals and review processes.

Coro Cybersecurity Platform: Replace Six Tools with One Solution
Data Security Posture Management: SME Implementation
TECHWAY - Keeper

Send us a message!

Fill out this field
Fill out this field
Please enter a valid email address.
Fill out this field

By: