Keeper Security launches Universal Secrets Sync for multi-cloud credential management
Keeper Security has released Universal Secrets Sync in KeeperPAM to automatically push rotated secrets to AWS, Azure and Google Cloud as soon as they change. The feature is designed to reduce credential drift, improve visibility and cut manual work for teams managing secrets across cloud and hybrid environments.
Why it matters: - Secrets drift can leave active credentials out of sync across production systems, creating access failures, slower incident response and hidden privileges that teams cannot easily govern or revoke. - Keeper Security is positioning Universal Secrets Sync as a way to keep one source of truth across multi-cloud environments while reducing manual distribution work. - The feature also targets change-control and oversight needs with preview and recovery tools built into the sync process.
What happened: - Keeper Security announced the availability of Keeper Universal Secrets Sync on June 4 as part of KeeperPAM. - The capability automatically distributes credentials and secrets to external secrets managers and cloud platforms the moment they rotate. - The feature supports AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager. - Existing KeeperPAM customers can enable the feature through their Keeper customer success manager. - New customers can request a demo at KeeperSecurity.com.
The details: - Universal Secrets Sync monitors one or more Keeper Secrets Manager shared folders and pushes their contents to configured cloud targets. - A secret rotation in KeeperPAM triggers an automatic update across connected cloud environments. - The workflow requires no manual exports, no custom integration scripts and no reconfiguration after rotation. - Automatic sync sends any change in a linked shared folder to all connected cloud targets in the background through the Gateway. - Dry Run mode previews exactly what will change before anything is distributed. - Multi-folder sync allows secrets from multiple Keeper shared folders to be synchronized in one configuration. - Sync Identity lets administrators assign a dedicated IAM role, managed identity or service account with least-privilege access for sync operations. - Error recovery surfaces missing secrets and permission errors automatically. - Keeper says the feature is included in existing KeeperPAM licenses.
Between the lines: - Keeper is trying to bridge two common operating models: cloud-native apps that need direct access from AWS, Azure or Google SDKs, and off-cloud tools that need direct access through Keeper Secrets Manager. - The company is betting that “drift” is now a central enterprise risk, not just an inconvenience, especially in hybrid environments. - CTO and co-founder Craig Lurey said manual distribution leaves stale credentials active downstream and that Universal Secrets Sync is designed to make distribution automatic and auditable. - Global research cited by Keeper found 86% of IT and security leaders say their organisation would benefit from a PAM solution, while 46% still struggle to manage privileged access consistently across cloud and hybrid environments.
What's next: - Keeper says cloud-native applications can continue reading directly from native cloud secret stores using SDKs and IAM controls. - CI/CD pipelines, scripts, internal tools and services running outside the cloud can retrieve secrets from Keeper Secrets Manager using the KSM SDK or CLI. - Keeper is urging existing customers to contact their customer success manager to turn on the feature. - The company is marketing the release as part of a broader cloud-native access and visibility strategy inside KeeperPAM.
The bottom line: - Universal Secrets Sync is meant to keep rotated secrets aligned across cloud platforms automatically, cutting down the risk and friction of credential drift.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The Consumer News Network
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.