KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

Compliance

KeyCare Pass and SOC 2

If your company is preparing for a SOC 2 examination, KeyCare Pass can support controls in the logical access and monitoring parts of the Trust Services Criteria.

Get a quote

Prices and options by email

Start business trial

How to get started today

Please read this first

KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.

What SOC 2 asks for

SOC 2 reports, issued by an independent auditor under the AICPA's attestation standards, evaluate a service organization's controls against the Trust Services Criteria for security, availability, processing integrity, confidentiality and privacy.

The report is about your organization's system and controls. KeyCare Pass does not have a SOC 2 report of its own.

Where KeyCare Pass fits

Common Criteria where a password manager can be part of your controls.

What is asked forHow KeyCare Pass can helpPlans
CC6.1 Logical access securityVault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS. Two-step login is available on every account.All plans; required by policy on Enterprise
CC6.2 Registering and removing usersInvite and confirm members, revoke access to suspend them, and remove them when they leave.Teams, Enterprise
CC6.3 Role-based access and least privilegeCollection permissions from view-only to manage, groups and custom roles.Custom roles on Enterprise
CC7.2 Monitoring for anomaliesEvent logs with IP addresses, sign-in activity and alerts about sign-ins from new addresses.Teams, Enterprise

What stays with you

A password manager is one control among many. These remain your organization's work:

  • Defining your controls and gathering evidence for the auditor
  • Vendor management, including GovPAM as a vendor
  • Access reviews on a schedule your auditor accepts
  • Retaining logs for as long as your controls require

Frequently asked questions

Can you give us your SOC 2 report?

KeyCare Pass does not have a SOC 2 report. We can describe its design, hosting and data handling for your vendor review.

Will event logs satisfy our auditor?

They are useful evidence of access and changes. Whether they are sufficient depends on your controls and your auditor.

Need details for your auditor?

Ask us about KeyCare Pass's design, hosting and data handling.