Skip to content

KeeperPAM

KeeperPAM is a cloud-native privileged access management (PAM) platform for IT and security teams, developed by Keeper Security, that rotates passwords, opens RDP, SSH and database sessions without exposing credentials and records every access for audit. It runs with one lightweight Keeper Gateway per network, with no agent on the servers, and is licensed per privileged user on an annual subscription, as a full license or as a Keeper Enterprise add-on.

Fabricantes: Keeper Security
Category: Multimídia
Learn more about KeeperPAM

Request a Quote

What is KeeperPAM?

KeeperPAM is a cloud-native privileged access management (PAM) platform for IT, security and DevOps teams, developed by Keeper Security, that controls, records and audits access by people, machines and AI agents to servers, databases, web applications and workloads. It brings enterprise password management, secrets management, connection management, endpoint privilege management, zero-trust network access and remote browser isolation together in a single product, all operated the same Keeper zero-knowledge vault.

KeeperPAM's architecture relies on a single local component: the Keeper Gateway, a lightweight service installed on Docker, Linux or Windows in each managed network. The gateway opens outbound connections only, so it needs no inbound firewall rules and no direct line of sight between the user and the server. KeeperPAM replaces the combination of VPN, jump server and administrator password spreadsheet, and solves the problem of static privileged credentials that are shared and used without any record.

Key features of KeeperPAM

KeeperPAM covers the full privileged access lifecycle, discovery to audit:

  • Password rotation: automatically changes Active Directory, OpenLDAP, Windows, Linux, AWS and Azure credentials and updates Windows services and scheduled tasks that use the account.
  • Privileged sessions: opens RDP, SSH, VNC, Telnet and Kubernetes connections with one click the vault, with no agent on the server and no password exposed to the user.
  • KeeperDB: provides access to MySQL, PostgreSQL, SQL Server and Oracle directly the vault, with no password stored on the client.
  • TCP tunnels: create an encrypted connection between the vault and the target to use native tools such as database clients and admin consoles.
  • Remote Browser Isolation: opens internal web applications in an isolated Chromium browser, with recording and file transfer.
  • Session recording with KeeperAI: records graphical and text sessions, generates an AI summary and automatically terminates sessions classified as high risk.
  • Discovery: scans local networks by CIDR range and AWS, Azure and Google Cloud environments to find machines, databases, directories and privileged accounts.

Benefits of KeeperPAM

KeeperPAM eliminates standing privileged passwords because automated rotation changes the credential after use or on a defined schedule, and the user reaches the server through the vault session without ever seeing the password.

Deployment is faster because access requires no agent on each server and no inbound ports: a single Keeper Gateway per network is enough, communicating with the Keeper cloud through outbound connections.

Audits are complete because every RDP, SSH or database session is recorded and can be replayed, and events flow to SIEMs such as Splunk, Sumo Logic, Datadog, Elastic, IBM and LogRhythm.

Vendor and AI agent access stays under control because ephemeral accounts with just-in-time elevation grant privilege for a limited time, and secrets management with MCP support delivers credentials to AI agents without writing them into code.

Who KeeperPAM is for

KeeperPAM serves CISOs, infrastructure managers, system administrators and DevOps teams responsible for administrator accounts, service accounts and third-party access. Typical scenarios: a company that must prove to auditors who accessed each server and when; an infrastructure team that wants to give a vendor access to SQL Server without handing over the password or opening a VPN; and a hybrid operation with on-premises Active Directory, AWS and Azure that needs to rotate service account passwords without stopping applications.

What sets KeeperPAM apart

KeeperPAM is PAM and password manager in the same vault: the license includes SCIM, AD/LDAP and SAML 2.0 SSO provisioning, RBAC, BreachWatch, advanced reporting, Compliance Reports and more than 100 integrations. The license also includes the self-hosted Keeper Connection Manager, built by the creators of Apache Guacamole, for isolated networks with no internet access. The entire platform inherits Keeper's certifications — SOC 2 Type 2, SOC 3, ISO 27001, 27017 and 27018, FIPS 140-3 — and there is an AWS GovCloud version with FedRAMP High authorization. According to Keeper, the company was included in the 2025 Gartner Magic Quadrant for Privileged Access Management.

System requirements

KeeperPAM is SaaS and only requires the Keeper Gateway in each managed environment. Keeper recommends running the gateway on Docker on a Linux or Windows host with an x86-64 CPU; native installation is also available on Enterprise Linux 8 and 9 and on Windows. Remote Browser Isolation sessions require significantly more hardware resources than standard connections. Users access the platform through the web vault, the desktop app for Windows, macOS and Linux, or Keeper Commander on the command line.

KeeperPAM editions and licenses

KeeperPAM can be purchased in two ways: as a full KeeperPAM license, which already includes Keeper Enterprise features, or as a Privileged Access Manager add-on on top of an existing Keeper Business or Enterprise license, applied only to users who need PAM features. Customers with the legacy Keeper Secrets Manager or Keeper Connection Manager add-ons can move to the Privileged Access Manager add-on, which includes both. Endpoint privilege management, delivered by Keeper Endpoint Privilege Manager, is sized by the number of endpoints.

How much does KeeperPAM cost?

KeeperPAM is licensed per privileged user, on an annual subscription: only people who use PAM features such as rotation, sessions, tunnels and recording are counted. There is no single list price because the investment depends on sizing: number of privileged users, purchase as a full license or as an add-on to Keeper Business or Enterprise, volume of non-human identities and workloads, number of endpoints in Keeper Endpoint Privilege Manager and whether it is a new purchase, a renewal or an expansion.

The counting rule follows Keeper's official example: a company with 100 Enterprise users where only 10 administer infrastructure buys 100 Enterprise licenses and 10 Privileged Access Manager add-ons. Beyond users, the license includes 24 active non-human identities per year (service accounts and agents transacting through the Keeper Gateway) and 5,000 workloads on endpoints governed by Endpoint Privilege Manager. Above that, volume moves into tiers: Tier 1 (25 to 99 NHIs), Tier 2 (100 to 249), Tier 3 (250 to 749) and Enterprise (750 or more).

To buy KeeperPAM in Brazil, OSB Software scopes this with you, sends the commercial proposal, issues the invoice and delivers the licenses — request a quote to get the exact figure for your scenario.

Frequently asked questions

Does KeeperPAM require an agent on the servers? No. KeeperPAM connections are agentless: one Keeper Gateway per managed network is enough, opening outbound connections only and projecting the session to the user's vault.

Does KeeperPAM work on an isolated network with no internet? Yes, with the self-hosted Keeper Connection Manager included in the KeeperPAM license, which runs on Docker inside the network and works in air-gapped environments.

Which databases can KeeperPAM access? MySQL, PostgreSQL, SQL Server and Oracle, through interactive sessions in the vault and through KeeperDB, plus Azure SQL for credential rotation.

I already use Keeper Enterprise. Do I need to change licenses? No. Just add the Privileged Access Manager add-on for the users who will administer infrastructure; everyone else stays on the Enterprise license.

Why buy KeeperPAM OSB Software?

OSB Software is an official Keeper Security partner in Brazil and supplies 100% genuine KeeperPAM licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.

When you buy KeeperPAM OSB Software, you get:

  • Consultative, specialist support — specialists who size your per-privileged-user licensing to your actual operation, avoiding over- or under-buying.
  • Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
  • Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
  • Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
  • Proven track record — thousands of customers served across Brazil.

If you are looking for where to buy KeeperPAM in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.

We help you choose

Not sure which software
you need?

Tell us about your need and our team helps you choose the ideal solution — from over 10,000 options in our catalog.