Every school has passwords living in a spreadsheet, on a card inside a drawer, or in one person’s head. Keeper gives them somewhere to live that survives a leaver, an audit, and a bad Tuesday.
Ceidwad supplies it, helps you work out who actually needs what, and sets it up so the answer to the question above stops being “I’m not sure”.

Also supplied by Ceidwad
Four people can open it, and none of them changed the password when the fifth one left. Nobody is quite sure who the fifth one was.
Shared once, for reports, in a week when somebody was off. It is still shared, and the audit trail says one name for three people.
It had to live somewhere everyone could find it, and a laminated card by the printer was the only place that worked.
Set up when the cameras went in, by a company that may not still hold the contract. It has never been used by anybody at the school.
None of this is negligence. It is what happens when a school runs more systems than it has people to run them, and has never been given an agreed place to put a password.
Product names are Keeper’s own. A school buys some of these and not others; most start with the vault and add privileged access when they are ready.
The account that can change everything is the one nobody should hold permanently. KeeperPAM hands it over for the job in front of somebody, records what happened, and takes it back afterwards — which is the difference between an audit trail and a shrug.
The DfE’s digital and technology standards expect a school to control privileged accounts and to know who holds access to what. Ceidwad Atlas asks you that question as part of the cyber security standard, and a great many schools cannot answer it without a conversation in the office first.
Keeper is one way to answer that question, not the way — and buying it does not move your Atlas score. Ceidwad sells assurance and supplies controls, which is a conflict of interest, and we publish that rather than leave you to notice it. Our findings stay vendor-neutral: an assessment will never mark a school down for choosing something else, or up for choosing this.
Ceidwad Atlas does not integrate with Keeper, read your vault, or know what is in it. Two products, two companies, bought and run separately.
A vault does not make a school compliant with anything. What it gives you is a defensible answer to a question you will be asked, and a record behind it.
Keeper holds and shares credentials properly. Multi-factor authentication is still the control that stops a stolen one being used.
Keeper publishes a zero-knowledge architecture — their claim that they cannot read what you store — and states certification against FedRAMP High, ISO 27001, 27017 and 27018, SOC 2, FIPS 140-3 and PCI DSS Level 1.
Those are Keeper’s published claims about Keeper, quoted so you can check them at source. Ceidwad has not audited any of them, and shows no certification marks — ours or theirs.