Surprisingly Useful AI Article Enhancements
Keeper Security has published a case study detailing how DrillDocs, a technology startup building computer vision software for the offshore oil and gas industry, deployed the KeeperPAM platform to secure privileged access across a globally distributed workforce that includes third-party engineering partners working from personal devices.
The case study outlines how DrillDocs moved from informal access management processes to a structured identity security model as the company expanded internationally and brought on external partners to provide around-the-clock production support.
From Machine Access To Human Sessions
DrillDocs had already established secure machine-to-machine access using Keeper Secrets Manager as part of its DevOps workflows. During automated deployments, credentials were programmatically retrieved and injected directly into memory, meaning they were never stored in plaintext on production systems.
That approach addressed automated access, but the company’s security requirements changed as it scaled. The introduction of an external engineering services firm providing 24/7 production support created a new set of challenges around interactive privileged sessions.
The workforce now included a mix of internal engineers and third-party partners, many of whom were operating from personal devices under a bring-your-own-device model. Managing access provisioning and revocation across that distributed environment, while maintaining visibility into privileged activity, required a different approach.
Francois Ruel, Co-Founder and Chief Science Officer of DrillDocs, described the concern that prompted the shift.
“We were getting worried about how to best manage security when work is done from personal machines,” Ruel explained. “We trust our partners, but we needed to switch to a trust-but-verify culture.”
What KeeperPAM Provides
KeeperPAM is a cloud-native privileged access management platform that combines password management, secrets management, privileged session management and endpoint privilege management within a zero-trust, zero-knowledge architecture. The platform has been recognised in the Gartner Magic Quadrant for Privileged Access Management.
In practical terms, engineers and external partners connect to production systems through secure, browser-based sessions. No VPN is required and no credentials are exposed to the end user. Access is scoped by role, every session is recorded and auditable, and provisioning or revocation of access can be carried out in seconds.
For DrillDocs, the platform replaced what had been informal access processes with controls that matched the scale and risk profile of the company’s offshore operations.
Rapid Deployment
One of the details highlighted in the case study is the speed of deployment. DrillDocs completed its initial setup in a single onboarding session, moving from trial to active use within hours rather than weeks.
“The day we decided to start our trial, we were able to get everything set up in a two-hour session,” Ruel noted. “From there, we started using Keeper right away.”
That timeline is notable given the complexity of the access environment involved. DrillDocs needed to structure access across internal teams and external engineering partners, establish session recording and audit capabilities and build the compliance foundation required to support SOC 2 certification.
A Broader Industry Problem
Darren Guccione, CEO and Co-Founder of Keeper Security, positioned DrillDocs’ experience as representative of a wider challenge facing organisations that extend privileged access beyond their own employees.
“The security problem DrillDocs solved is not unique to offshore drilling,” Guccione remarked. “Any organisation extending privileged access to external partners, multi-cloud environments or a distributed workforce faces the same exposure.”
Related: Best Business Laptops for work & school
Related: Best Gaming Laptops
Related: Best Portable Laptop
“Implicit trust is not a security model. KeeperPAM enforces verified, session-level access control from day one across all human and non-human identities – and in the case of DrillDocs was implemented at scale.”
The scenario Guccione describes is common across industries where operational technology environments are supported by a mix of internal staff and contracted specialists. In sectors such as energy, mining and utilities, field operations often depend on third-party engineers who require access to production systems but sit outside the organisation’s direct IT control.
The BYOD Dimension
The DrillDocs case also touches on a specific challenge within that broader problem: managing privileged access when the endpoint is not a corporate-managed device.
In many enterprise environments, security controls assume the organisation owns and manages the device being used to access sensitive systems. BYOD arrangements complicate that assumption, as the organisation has limited visibility into the security posture of personal laptops and workstations.
KeeperPAM addresses this by shifting the security boundary away from the endpoint. Because sessions are browser-based and credentials are never exposed to the local device, the platform reduces the risk associated with unmanaged hardware. The access controls and audit trail remain consistent regardless of whether the user is working from a corporate laptop or a personal machine.
Compliance And Audit Readiness
The case study also covers how DrillDocs used the platform to build the audit foundation needed to support SOC 2 compliance. SOC 2 is a widely used framework for evaluating how technology companies manage customer data, with requirements around security, availability, processing integrity, confidentiality and privacy.
For a startup operating in the energy sector and handling data from offshore drilling operations, the ability to demonstrate structured access controls, session recording and role-based provisioning represents a practical step toward meeting those compliance requirements.
The full case study, including details on how DrillDocs structured access across internal and external teams, is available through Keeper Security.
Last Updated on June 4, 2026 by Nick Ross



