KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

For it teams

Shared admin access, without shared passwords everywhere

Network gear, cloud consoles, service accounts and SSH keys: keep them in collections your team can use, with a log of who opened what.

Get a quote

Prices and options by email

Start business trial

How to get started today

The problem with passwords here

IT teams hold the most powerful credentials in the organization, and often share them in the least safe ways.

Secrets in too many places

Admin passwords in a spreadsheet, SSH keys on laptops, API tokens in chat history.

Hard to tell who knows what

When someone leaves, nobody is sure which shared passwords they could see.

Second factors that block the team

A shared admin account with two-step login tied to one person's phone.

How KeyCare Pass helps

Collections

One collection per system

Group credentials by system or environment and give each person or group exactly the access they need, up to managing the collection.

  • Store SSH keys: generate Ed25519 or RSA keys or import yours
  • Keep API tokens and recovery codes in secure notes
  • Attach config files and certificates, encrypted

Shared two-step login

Authenticator codes the whole team can use

Put a shared account's authenticator key in its login, in a collection, and everyone with access gets the current code without passing a phone around.

Accountability

Every view and change, logged

The event log records who viewed a password, edited an item or changed a collection, with the IP address. Read it in the Admin Console or pull it with the public API.

Recommended setup

Enterprise, with these policies on

Turn the policies on before you invite anyone, then deploy the extension to managed browsers.

Compare plans

  • Require two-step login and set master password requirements
  • Single organization, then account recovery administration
  • Collections per system, groups per team
  • Install the extension with the ExtensionInstallForcelist policy
  • Consider self-hosting for networks that must stay closed

Frequently asked questions

Can KeyCare Pass rotate passwords on servers for us?

No. KeyCare Pass stores and shares credentials; it does not log in to your systems to change them. GovPAM's Gov PAM platform does privileged access management of that kind.

Can we use KeyCare Pass from the command line?

A command-line client is not available to download yet. Today, use the web vault or the browser extension.

Can the server run in an isolated network?

A self-hosted KeyCare Pass server does not need to contact GovPAM. Managed computers can get the extension through a browser policy, from the Chrome Web Store or, where the store is blocked, from a signed package. For IT administrators.

Get your team's admin credentials under control

Tell us about your organization, or start setting up today.

Get a quote

Prices and options by email

Start business trial

How to get started today