Keeper Security Subprocessors List (September 2026): Changes and History
Keeper Security names 10 subprocessors on its published list. Read from the vendor's own page and re-checked daily.
Keeper Security subprocessors (September 2026)
| # | Subprocessor | Purpose | Location |
|---|---|---|---|
| 1 | Amazon AWS | Cloud Infrastructure (isolated to region elected by Customer during implementation) | — |
| 2 | Braze | Email address for marketing communications | — |
| 3 | Hubspot | Email address for marketing communications | — |
| 4 | Aircall | Telephonic Customer Support | — |
| 5 | HelpScout | Website chatbot | — |
| 6 | Stripe | Payment processor | — |
| 7 | PayPal | Payment processor | — |
| 8 | Keeper Security, Inc. | — | — |
| 9 | Keeper Security EMEA Limited | — | — |
| 10 | Keeper Security APAC KK | — | — |
Get an email when Keeper Security changes its subprocessors
ClauseTrail re-checks this list every day and tells you exactly who was added or removed — including when a vendor starts sending data to an AI provider. The first vendors are free.
Key DPA terms at Keeper Security
What Keeper Security's data processing agreement commits to, with the sentence each answer comes from. SCCs or the Data Privacy Framework: what's the difference?
- Breach notification
-
Within 72 hours
“Keeper shall give prompt notice but no later than 72 hours to the Customer after confirming a breach has occurred”
DPA, www.keepersecurity.com ↗ - Notice of a new subprocessor
-
10 days ahead
“Customer may, in good faith, reasonably object to Keeper's change of or use of a new Sub-Processor by providing written notice by e-mail at [email protected] within ten (10) business days of receiving notification from Keeper of a new Sub-Processor.”
DPA, www.keepersecurity.com ↗ - Transfers outside the EU
-
Standard contractual clauses and the EU–US Data Privacy Framework
“the Parties agree to comply with the Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), which are incorporated herein by reference.”
“Keeper is an active participant in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework.”
DPA, www.keepersecurity.com ↗ - Customer data after the contract ends
-
Deleted or returned when the contract ends
“Following expiration or termination of the Agreement, Keeper will delete or return to the Customer all Personal Data in its possession as provided in the Agreement”
DPA, www.keepersecurity.com ↗ - Audit rights
-
Once a year
“Any audit or document inspection shall be carried out with reasonable prior written notice of no less than sixty (60) calendar days and shall not be conducted more than once a year.”
DPA, www.keepersecurity.com ↗
Certifications at Keeper Security
What Keeper Security's trust page lists, with the text each one comes from. SOC 2 Type I or Type II: what's the difference?
- SOC 2 Type II
-
Active
“Keeper has been certified as SOC 2 Type 2 compliant for over ten years in accordance with the AICPA Service Organization Control framework.”
Trust page, www.keepersecurity.com ↗ - ISO 27001
-
Active
“Keeper is ISO 27001, 27017 and 27018 certified.”
Trust page, www.keepersecurity.com ↗ - HIPAA
-
Active
“Keeper is GDPR compliant, CCPA compliant, HIPAA compliant, FedRAMP High and GovRAMP High Authorized, PCI DSS certified and certified by TrustArc for privacy.”
Trust page, www.keepersecurity.com ↗ - PCI DSS
-
Active
“Keeper is GDPR compliant, CCPA compliant, HIPAA compliant, FedRAMP High and GovRAMP High Authorized, PCI DSS certified and certified by TrustArc for privacy.”
Trust page, www.keepersecurity.com ↗ - EU–US Data Privacy Framework
-
Active
“We comply with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, the German Federal Data Protection Act (BDSG) and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") as set forth by the U.S. Department of Commerce.”
Trust page, www.keepersecurity.com ↗ - FedRAMP
-
Active
“Keeper ICAM & Identity Security Platform for Government is a FedRAMP Certified provider at the High Impact Level, hosted in AWS GovCloud (US).”
Trust page, www.keepersecurity.com ↗
Documents we track for Keeper Security
- DPA
- checked September 28, 2026 www.keepersecurity.com ↗
- Privacy policy
- checked September 28, 2026 www.keepersecurity.com ↗
- Subprocessor list
- checked September 28, 2026 www.keepersecurity.com ↗
- Terms of service
- checked September 28, 2026 www.keepersecurity.com ↗
- Trust page
- checked September 28, 2026 www.keepersecurity.com ↗
Change history
Tracking since September 28, 2026. No change has been published since; additions, removals and document changes will appear here as they're published.
Keeper Security subprocessors FAQ
- How many subprocessors does Keeper Security use?
- Keeper Security lists 10 subprocessors on its published list, including Amazon AWS, Braze, Hubspot, Aircall, and HelpScout and 5 more.
- How quickly does Keeper Security report a personal data breach to customers?
- According to its DPA, Keeper Security reports a personal data breach to customers within 72 hours: “Keeper shall give prompt notice but no later than 72 hours to the Customer after confirming a breach has occurred”
- How much notice does Keeper Security give before adding a subprocessor?
- Keeper Security's DPA gives 10 days' notice of a new subprocessor, the time customers have to object: “Customer may, in good faith, reasonably object to Keeper's change of or use of a new Sub-Processor by providing written notice by e-mail at [email protected] within ten (10) business days of receiving notification from Keeper of a new Sub-Processor.”
- How does Keeper Security transfer personal data outside the EU?
- Keeper Security's DPA relies on standard contractual clauses and the EU–US Data Privacy Framework: “the Parties agree to comply with the Standard Contractual Clauses approved under Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"), which are incorporated herein by reference.”
- Does Keeper Security have a SOC 2 Type II report?
- Yes. Keeper Security's trust page lists a SOC 2 Type II report: “Keeper has been certified as SOC 2 Type 2 compliant for over ten years in accordance with the AICPA Service Organization Control framework.”
- Which security certifications does Keeper Security list?
- Keeper Security's trust page lists SOC 2 Type II, ISO 27001, HIPAA, PCI DSS, EU–US Data Privacy Framework, and FedRAMP.
- When was Keeper Security's subprocessor list last checked?
- ClauseTrail last checked Keeper Security's subprocessor list on September 28, 2026. Lists are re-checked daily.
- How do I find out when Keeper Security adds or removes a subprocessor?
- ClauseTrail monitors Keeper Security's subprocessor list, DPA, privacy policy and terms and emails you the exact change — who was added or removed and what the page said before and after. The first vendors are free.