Craig Lurey CTO Co-founder Keeper Security

Keeper Security Adds Automated Secrets Sync Across AWS, Azure And Google Cloud

Surprisingly Useful AI Article Enhancements

Keeper Security has released a new capability within its KeeperPAM platform that automatically distributes rotated credentials and secrets to cloud environments, targeting what the company describes as “credential drift” across multi-cloud deployments.

Universal Secrets Sync pushes updated secrets to AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager the moment they are rotated within KeeperPAM. The aim is to eliminate the manual steps and custom scripts that organisations typically rely on to keep credentials in sync between their privileged access management platform and production environments.

The Problem Of Credential Drift

When credentials stored in a PAM platform fall out of sync with what is actually running in production, the consequences can range from access failures and delayed incident response to what Keeper describes as “shadow secrets” – credentials carrying active privileges that no security team can see, govern or revoke.

The gap is not simply about exposure. Stale or orphaned credentials sitting in downstream cloud environments represent a governance blind spot, particularly for organisations operating across multiple cloud providers.

Research cited by Keeper found that 86 per cent of IT and security leaders agree their organisation would benefit from a PAM solution. Yet even among organisations that already have PAM in place, 46 per cent still struggle to manage privileged access consistently across cloud and hybrid environments.

Universal Secrets Sync is designed to close that gap by making credential distribution automatic rather than manual.

How The Sync Works

Universal Secrets Sync monitors one or more Keeper Secrets Manager shared folders and automatically distributes their contents to configured cloud targets. When a secret rotates in KeeperPAM, every connected cloud environment receives the updated credential without manual exports, custom integration scripts or reconfiguration.

Craig Lurey, CTO and Co-Founder of Keeper Security (pictured), described credential drift as an underappreciated risk in enterprise security.

“Organizations unknowingly leave stale credentials active in downstream cloud environments when distribution is manual,” Lurey explained. “Universal Secrets Sync makes distribution automatic and auditable. Every secret rotation updates to all connected targets simultaneously, with Dry Run mode giving teams full visibility into what will change before anything is written.”

Built-In Safeguards And Configuration Options

The system includes a Dry Run mode that lets security teams preview exactly what will change before any secret is distributed to a cloud target. Keeper says this makes the tool compatible with change control requirements and environments that need oversight before credentials are pushed.

Multi-folder sync allows secrets from multiple Keeper shared folders to be synchronised in a single configuration. Administrators can also specify a dedicated IAM role, managed identity or service account with least-privilege access for the Keeper Gateway to assume during sync operations.

Error recovery is built in, with missing secrets and permission errors surfaced automatically to reduce the risk of sync failures going undetected.

Two Retrieval Paths For Different Workloads

The feature is designed to support two access patterns depending on the workload.

Cloud-native applications that require high throughput and low latency can continue reading directly from AWS Secrets Manager, Azure Key Vault or Google Cloud Secret Manager using native SDKs and IAM controls. Keeper says this path suits services performing hundreds of thousands or millions of retrievals per day.

For CI/CD pipelines, scripts, internal tools and services running outside the cloud, developers can retrieve secrets directly from Keeper Secrets Manager via the KSM SDK or CLI, with zero-knowledge protection maintained end-to-end.

The result, according to Keeper, is a single source of truth with two complementary retrieval methods – native cloud access where throughput matters and direct KSM access where zero-knowledge control is the priority.

Availability

Universal Secrets Sync is available now as part of KeeperPAM and is included in existing KeeperPAM licences. Existing customers can contact their Keeper customer success manager to enable the feature. New customers can request a demo at keepersecurity.com.

Last Updated on June 15, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.