Keeper Security

Keeper Security achieves SOC 3 compliance

Posted by
Share

Singapore: Cybersecurity provider Keeper Security has achieved SOC 3 compliance, which shows that the organisation is adhering to security, availability, processing integrity, confidentiality, and privacy controls, as verified by a third-party auditor.

Keeper Security achieves SOC 3 compliance

Keeper Security, which provides zero-trust and zero-knowledge Privileged Access Management (PAM) software for security said that it has achieved System and Organisation Controls (SOC) 3 compliance, demonstrating the company’s commitment to the highest standards of security for all users.

The SOC 3 report, governed by the American Institute of Certified Public Accountants (AICPA), is a public-facing certification that validates the security, availability and confidentiality of Keeper’s systems.

As part of an annual Type II audit process, an independent third-party auditor conducted rigorous testing and evaluation of Keeper’s internal controls to ensure they meet the highest industry standards. SOC 3 report is for broad public distribution, offering a high-level summary of Keeper’s compliance posture and risk management practices.

“SOC 3 is more than a certification – it’s a public demonstration of the trust we’ve earned through rigorous security and compliance practices,” said Zoya Schaller, Director of Cybersecurity Compliance – Keeper Security.

“Transparency is non-negotiable in today’s cybersecurity landscape. This achievement reinforces our ongoing commitment to protecting sensitive data and holding ourselves to the highest standards,” added Schaller.

Keeper has earned a reputation for relentless security and compliance leadership. It is among the most audited and certified cybersecurity platforms in the industry, with the SOC 3 report building on Keeper’s long-standing SOC 2 and ISO 27001, 27017 and 27018 certifications. Its solutions are also FIPS 140-3 certified, PCI DSS compliant, GDPR and CCPA compliant and TrustArc certified for privacy.

Additionally, Keeper is FedRAMP Authorised at the Moderate Impact Level, as well as GovRAMP Authorised, with continued adherence to the National Institute of Standards and Technology Special Publication 800-53 Rev. 5 security control framework.

The company is now pursuing FedRAMP High, the programme’s most rigorous security baseline, which includes more than 400 controls designed to protect sensitive government data and support critical operations. In parallel, Keeper is working toward DoD IL5 certification, which enables cloud service providers to store and process controlled unclassified information and certain National Security Systems data – meeting strict DoD cybersecurity standards.