Keeper Security Subprocessors List (September 2026): Changes and History

Keeper Security names 10 subprocessors on its published list. Read from the vendor's own page and re-checked daily.

Last checked September 28, 2026 Official source ↗

Keeper Security subprocessors (September 2026)

# Subprocessor Purpose Location
1 Amazon AWS Cloud Infrastructure (isolated to region elected by Customer during implementation) —
2 Braze Email address for marketing communications —
3 Hubspot Email address for marketing communications —
4 Aircall Telephonic Customer Support —
5 HelpScout Website chatbot —
6 Stripe Payment processor —
7 PayPal Payment processor —
8 Keeper Security, Inc. — —
9 Keeper Security EMEA Limited — —
10 Keeper Security APAC KK — —

Get an email when Keeper Security changes its subprocessors

ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.

Track Keeper Security free

Key DPA terms at Keeper Security

What Keeper Security's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?

Breach notification

Within 72 hours

“Keeper shall give prompt notice but no later than 72 hours to the Customer after confirming a breach has occurred”
DPA, www.keepersecurity.com ↗
Notice of a new subprocessor

10 days ahead

“Customer may, in good faith, reasonably object to Keeper's change of or use of a new Sub-Processor by providing written notice by e-mail at [email protected] within ten (10) business days of receiving notification from Keeper of a new Sub-Processor.”
DPA, www.keepersecurity.com ↗
Transfers outside the EU

Standard contractual clauses and the EU–US Data Privacy Framework

“the Parties agree to comply with the Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), which are incorporated herein by reference.”
“Keeper is an active participant in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework.”
DPA, www.keepersecurity.com ↗
Customer data after the contract ends

Deleted or returned when the contract ends

“Following expiration or termination of the Agreement, Keeper will delete or return to the Customer all Personal Data in its possession as provided in the Agreement”
DPA, www.keepersecurity.com ↗
Audit rights

Once a year

“Any audit or document inspection shall be carried out with reasonable prior written notice of no less than sixty (60) calendar days and shall not be conducted more than once a year.”
DPA, www.keepersecurity.com ↗

Certifications at Keeper Security

What Keeper Security's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?

SOC 2 Type II

Active

“Keeper has been certified as SOC 2 Type 2 compliant for over ten years in accordance with the AICPA Service Organization Control framework.”
Trust page, www.keepersecurity.com ↗
ISO 27001

Active

“Keeper is ISO 27001, 27017 and 27018 certified.”
Trust page, www.keepersecurity.com ↗
HIPAA

Active

“Keeper is GDPR compliant, CCPA compliant, HIPAA compliant, FedRAMP High and GovRAMP High Authorized, PCI DSS certified and certified by TrustArc for privacy.”
Trust page, www.keepersecurity.com ↗
PCI DSS

Active

“Keeper is GDPR compliant, CCPA compliant, HIPAA compliant, FedRAMP High and GovRAMP High Authorized, PCI DSS certified and certified by TrustArc for privacy.”
Trust page, www.keepersecurity.com ↗
EU–US Data Privacy Framework

Active

“We comply with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, the German Federal Data Protection Act (BDSG) and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") as set forth by the U.S. Department of Commerce.”
Trust page, www.keepersecurity.com ↗
FedRAMP

Active

“Keeper ICAM & Identity Security Platform for Government is a FedRAMP Certified provider at the High Impact Level, hosted in AWS GovCloud (US).”
Trust page, www.keepersecurity.com ↗

Documents we track for Keeper Security

DPA
checked September 28, 2026 www.keepersecurity.com ↗
Privacy policy
checked September 28, 2026 www.keepersecurity.com ↗
Subprocessor list
checked September 28, 2026 www.keepersecurity.com ↗
Terms of service
checked September 28, 2026 www.keepersecurity.com ↗
Trust page
checked September 28, 2026 www.keepersecurity.com ↗

Change history

Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.

Keeper Security subprocessors FAQ

How many subprocessors does Keeper Security use?
Keeper Security lists 10 subprocessors on its published list, including Amazon AWS, Braze, Hubspot, Aircall, and HelpScout and 5 more.
How quickly does Keeper Security report a personal data breach to customers?
According to its DPA, Keeper Security reports a personal data breach to customers within 72 hours: “Keeper shall give prompt notice but no later than 72 hours to the Customer after confirming a breach has occurred”
How much notice does Keeper Security give before adding a subprocessor?
Keeper Security's DPA gives 10 days' notice of a new subprocessor, the time customers have to object: “Customer may, in good faith, reasonably object to Keeper's change of or use of a new Sub-Processor by providing written notice by e-mail at [email protected] within ten (10) business days of receiving notification from Keeper of a new Sub-Processor.”
How does Keeper Security transfer personal data outside the EU?
Keeper Security's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “the Parties agree to comply with the Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), which are incorporated herein by reference.”
Does Keeper Security have a SOC 2 Type II report?
Yes. Keeper Security's trust page lists a SOC 2 Type II report: “Keeper has been certified as SOC 2 Type 2 compliant for over ten years in accordance with the AICPA Service Organization Control framework.”
Which security certifications does Keeper Security list?
Keeper Security's trust page lists SOC 2 Type II, ISO 27001, HIPAA, PCI DSS, EU–US Data Privacy Framework, and FedRAMP.
When was Keeper Security's subprocessor list last checked?
ClauseTrail last checked Keeper Security's subprocessor list on September 28, 2026. Lists are re-checked daily.
How do I find out when Keeper Security adds or removes a subprocessor?
ClauseTrail monitors Keeper Security's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.