Keeper Security launches Universal Secrets Sync to stop credential drift

By Staff Writer on Aug 3, 2026 1:53PM
Keeper Security launches Universal Secrets Sync to stop credential drift
Craig Lurey, Keeper Security.
Supplied

Keeper Security has launched Universal Secrets Sync, a KeeperPAM capability that automatically distributes rotated credentials to AWS, Azure and Google Cloud the moment they change, aimed at eliminating the “secrets drift” that leaves stale credentials active in production environments.

The company framed the feature around a risk it says is under-appreciated: when credentials stored in a privileged access management (PAM) platform fall out of sync with what is running in production pipelines, organisations face access failures, delayed incident response and “shadow secrets” - credentials that still carry active privileges but that no security team can see, govern or revoke.

Universal Secrets Sync monitors one or more Keeper Secrets Manager shared folders and pushes their contents to configured cloud targets, including AWS Secrets Manager, Azure Key Vault and Google Cloud Secret Manager.

When a secret rotates in KeeperPAM, every connected environment receives the update automatically, with no manual exports, custom integration scripts or reconfiguration.

A Dry Run mode lets teams preview exactly what will change before anything is written, which Keeper positioned as important for change-control processes, and a Sync Identity feature lets administrators assign a dedicated least-privilege role for the Keeper Gateway to use during sync, alongside multi-folder sync and automatic error recovery.

For retrieval, the company said cloud-native applications that need high throughput keep reading directly from the native cloud secrets managers, while CI/CD pipelines, scripts and services running outside the cloud pull secrets from Keeper Secrets Manager via its SDK or command-line tool with zero-knowledge protection - a single source of truth with two access patterns.

“Secrets drift is one of the most under-appreciated risks in enterprise security programs,” said Craig Lurey, chief technology officer and co-founder of Keeper Security.

"Organisations unknowingly leave stale credentials active in downstream cloud environments when distribution is manual. Universal Secrets Sync makes distribution automatic and auditable. Every secret rotation updates to all connected targets simultaneously, with Dry Run mode giving teams full visibility into what will change before anything is written."

Universal Secrets Sync is available now as part of KeeperPAM and is included in existing KeeperPAM licences.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?