Keeper Security has launched KeeperAI, a new agentic AI feature within its KeeperPAM platform that brings automated, real-time monitoring and response to privileged accounts. The system continuously analyzes active sessions, classifies anomalies by risk level, and can terminate high-risk activity in seconds, well before an incident escalates.Jeremy London, Director of Engineering, AI and Threat Analytics at Keeper Security told MSSP Alert, “KeeperAI represents a fundamental shift from legacy PAM solutions that rely on manual log reviews and static, rule-based alerts. Traditional PAM vendors have layered limited AI features onto existing tools, often creating noise without actionable context. KeeperAI, by contrast, is an AI-native solution purpose-built for privileged session analysis,” said
“KeeperAI is designed to support MSSPs by extending real-time detection and automated response into each client environment while preserving strict tenant isolation. Each gateway is owned and configured by the customer, ensuring data sovereignty while allowing providers to deliver advanced monitoring and threat response as part of their managed services,” London explained.
100% Automated Analysis Across Privileged Sessions
KeeperAI continuously analyzes session activity, from metadata and keystrokes to command execution. Detected anomalies are classified into risk levels ranging from low to critical. Based on policies set by administrators, the system can automatically terminate risky sessions, send alerts, or continue monitoring while flagging activity for review.London explained how this raises the bar compared to existing tools. He explained, "With KeeperAI, threats are detected and categorized in under 10 seconds, with automated termination of high-risk sessions - eliminating the hours or days of lag common with log aggregation or post-event analysis. It enables organizations to achieve 100% automated analysis across privileged sessions, compared to less than 5% with manual review.”Core Features at a Glance
KeeperAI delivers automated session analysis to detect anomalies across privileged activity, with threat classification that assigns severity levels ranging from low to critical. Administrators can configure responses - whether to terminate a session, send an alert, or simply continue monitoring - based on policy. The platform also makes sessions fully searchable, allowing security teams to track specific commands or behaviors across histories. And with support for both cloud and on-premises inference, including integration with AWS Bedrock, Anthropic, Google Gemini, and OpenAI, KeeperAI fits into a wide range of deployment models without locking customers into a single provider.Accuracy and false positives are major concerns for enterprises deploying AI in security. London addressed this directly.He explains, “KeeperAI was designed to give security teams accuracy and control, not more noise. The system provides contextual, command-by-command analysis and categorizes activity by risk level, which dramatically reduces false positives. Teams can start in a ‘Monitor’ mode to build confidence before enabling automated termination for high-risk sessions. That combination of context, customization and gradual rollout prevents alert fatigue while ensuring legitimate work isn’t disrupted.”Built with Sovereignty in Mind
KeeperAI is built to fit within different operational environments. It supports SSH sessions with plans to extend to RDP, VNC, RBI, and databases. Incident data and risk assessments flow into the Keeper Vault UI, giving teams one place to investigate, document, and maintain compliance. Integration with SIEM and SOC tools is enabled through Keeper’s Advanced Reporting and Alerts Module.The deployment model is also built with sovereignty in mind. "KeeperAI is built on our zero-knowledge foundation, which means all analysis happens within the customer’s own environment - Keeper never has access to their data. Session files are encrypted with the customer’s private key, and communication flows directly to the LLM provider of their choice. Whether in the cloud or fully air-gapped on-premises, customers retain full ownership of their infrastructure, keys and data,” London said.Balancing Automation with Data Control
This design helps highly regulated industries adopt AI-driven defense without introducing third-party risk. By supporting both cloud and on-premises inference, KeeperAI provides flexibility without forcing vendor lock-in. That balance of automation and control ensures scalability without compromising governance.For managed security service providers (MSSPs), the platform also extends into multi-client operations.“KeeperAI is designed to support MSSPs by extending real-time detection and automated response into each client environment while preserving strict tenant isolation. Each gateway is owned and configured by the customer, ensuring data sovereignty while allowing providers to deliver advanced monitoring and threat response as part of their managed services,” London explained.