Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Keeper Security Public Bounty Program
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Keeper Security Public Bounty Program? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 19 Sep 2026.

Keeper Security is transforming the way businesses and individuals protect their passwords and sensitive digital assets to significantly reduce cyber theft. Keeper is SOC 2 Certified, ISO 27001 Certified, FedRAMP Authorized and utilizes best-in-class encryption to safeguard its customers. Keeper Security is committed to the industry best practice of responsible disclosure of potential security issues. Guidelines: This Vulnerability Disclosure Policy sets out expectations when working with good-faith hackers, as well as what you can expect from us. If security testing and reporting are done within the guidelines of this policy, we: Consider it to be authorized in accordance with Computer Fraud and Abuse Act, Consider it exempt from DMCA, and will not bring a claim against you for bypassing any security or technology controls, Consider it legal, and will not pursue or support any legal action related to this program against you, Will work with you to understand and resolve the issue quickly, and Will recognize your contributions publicly if you are the first to report the issue and we make a code or configuration change based on the issue. If at any time you are concerned or uncertain about testing in a way that is consistent with the Guidelines and Scope of this policy, please contact us before proceeding. To encourage good-faith security testing and disclosure of discovered vulnerabilities, we ask that you: Avoid violating privacy, harming user experience, disrupting production or corporate systems, and/or destroying data, Perform research only within the scope set out below, and respect systems and activities which are out-of-scope, Contact us immediately if you encounter any user data during testing, Use the identified communication channels to report vulnerability information to us and, Keep information about any vulnerabilities you’ve discovered confidential until we’ve resolved them. Ratings/Rewards: For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. Please review the Quality Reporting section for additional guidelines as it pertains to Ratings/Rewards Note: To unwrap and display Vault <> Server communication on the Web Vault, open the developer tools and type: enableNetworkLog(true) This will allow you to see the request/response to the server in JSON On the Admin Console, the command to log additional request/response is: api.shouldLog=true If you need additional debug help, feel free to email us at security@keepersecurity.com. VRT Changes: Any submissions stemming from throttling or spam testing will be rated as a P4. Any domain/property of Keeper Security not listed in the targets section is out of scope. This includes any/all subdomains not listed above. This includes kepr.co and kepr.io.

Currency
USD
Submissions
Open
Scope entries
22 Bugcrowd’s count

Scope

22 assets
AssetTypeEligibilityMax severity
Keeper AD / LDAP Bridge api ✓ bounty not set
Keeper Admin Console (US, EU, AU, CA, JP, GovCloud) website ✓ bounty not set
Keeper Browser Extension (Chrome, Safari, Firefox, Edge) other ✓ bounty not set
Keeper Commander CLI/SDK api ✓ bounty not set
Keeper Connection Manager (KCM) other ✓ bounty not set
Show all 22 assets
AssetTypeEligibilityMax severity
Keeper Desktop App for Mac, PC, Linux other ✓ bounty not set
Keeper Endpoint Privilege Manager api ✓ bounty not set
Keeper Enterprise website ✓ bounty not set
Keeper for Android android ✓ bounty not set
Keeper for iOS ios ✓ bounty not set
Keeper Gateway api ✓ bounty not set
Keeper Secrets Manager SDK api ✓ bounty not set
Keeper Security Website website ✓ bounty not set
Keeper Web Vault (US, EU, AU, CA, JP, GovCloud) website ✓ bounty not set
KeeperChat for Android android ✓ bounty not set
KeeperChat for iOS ios ✓ bounty not set
KeeperChat for Mac other ✓ bounty not set
KeeperChat for Windows other ✓ bounty not set
KeeperDB other ✓ bounty not set
KeeperPAM Privileged Access Manager website ✓ bounty not set
SSO Connect Cloud and Automator Service api ✓ bounty not set
SSO Connect On-Prem api ✓ bounty not set