Vendor-independent cloud backup for Microsoft 365, Salesforce and other SaaS platforms
Review by EuropeanStack EditorialUpdated Verified
Return to that phishing scenario. If the bank's backup had lived inside the same Microsoft tenant the attacker compromised, the outcome could have been catastrophic rather than merely disruptive. Keepit's core architectural choice — its own cloud, physically and organisationally separate from the SaaS platforms it protects — is a genuine, defensible answer to that risk, not just a marketing angle.
Keepit is a Copenhagen-based SaaS data protection company that backs up Microsoft 365, Microsoft Entra ID, Salesforce, Google Workspace, Zendesk, and a growing list of cloud applications on its own dedicated cloud infrastructure rather than on top of AWS or Azure. Founded in 2007 by Frederik Schouboe and Morten Felsvang, Keepit describes itself as the only vendor-neutral, cloud-native backup provider in its category, and it sells exclusively through a partner network of resellers, MSPs, and distributors rather than direct self-service signup. In July 2026 it upsized its credit facilities with EIFO and HSBC Innovation Banking to $90M, alongside roughly $90M in equity raised to date, while remaining independently owned.
Headquarters
Copenhagen, Denmark
Founded
2007
Pricing
EU Data Hosting
Yes
Employees
501-1000
Contact Sales
Contact Sales
Contact Sales
Billing: annual, usage-based
Imagine an IT administrator at a mid-sized European bank discovering that a phishing attack compromised an admin account inside Microsoft 365. The attacker deleted mailboxes, wiped SharePoint sites, and — because the organisation's backup tool ran inside the same Microsoft tenant it was protecting — came uncomfortably close to reaching the backup data too. That scenario is precisely the failure mode Keepit was built to prevent.
Frederik Schouboe and Morten Felsvang founded Keepit in Copenhagen in 2007, after years running their own hosting company and watching the shift to SaaS coming early. They built Keepit on its own dedicated cloud rather than on top of AWS or Azure. Every other major SaaS backup vendor sits somewhere inside a hyperscaler's infrastructure, often the very hyperscaler whose applications they are backing up. Keepit's pitch is that this proximity is a risk, not a convenience, and that genuine vendor independence means owning the stack end to end.
That independence recently faced an odd test. In September 2025, Keepit announced it had upsized and refinanced its credit facilities to $60M with Denmark's EIFO and HSBC Innovation Banking — routine, healthy corporate finance news. Somewhere in the data-tracking ecosystem, that announcement got mislabelled on at least one third-party database as an acquisition by Sentia. It was not. That release and a further $90M upsizing in July 2026 both describe debt financing raised by Keepit on its own account, with no change of ownership. No acquisition of Keepit has been announced by the company or by any named acquirer.
Keepit operates seven data-centre regions — Copenhagen, Frankfurt, London, and Zurich in EMEA; Washington DC and Toronto in the Americas; Sydney in APAC — built specifically for SaaS backup rather than general-purpose cloud hosting. The company states this design means no third-party sub-processors touch customer backup data, since Keepit itself operates the infrastructure rather than reselling capacity from AWS or Azure. For a European bank or insurer that must document every sub-processor in its data-processing agreements, that is one fewer entity to disclose.
Once data lands in Keepit, the company says its architecture exposes no API or overwrite path that could alter stored backups. That design is meant to survive exactly the ransomware scenario described above, where an attacker with admin credentials tries to reach the backup alongside the live environment. Combined with the physically separate cloud infrastructure, this gives customers a genuine air gap between production data and backup data, not just a logically separate folder inside the same tenant.
Keepit protects Microsoft 365, Microsoft Entra ID, Google Workspace, Salesforce, Dynamics 365, Power Platform, Azure DevOps, Zendesk, Jira, Confluence, Okta, Docusign, BambooHR, Miro, GitHub, monday.com, and Autodesk Forma. That list keeps growing, but it stops firmly at SaaS applications. Unlike Veeam, Keepit does not back up on-premises servers, virtual machines, physical endpoints, or NAS storage. An IT team protecting both a VMware cluster and a Microsoft 365 tenant will need Keepit for one half of that job and a separate tool for the other.
Keepit sells exclusively through a network of resellers, managed service providers, and distributors — a "partner-only" model the company formalised with its Keepit Partner Network launch in 2024. That structure means our IT administrator from the opening scenario would never buy Keepit directly from a website checkout. They would go through an MSP, who handles onboarding, billing, and first-line support, with Keepit providing the underlying platform, a Partner Management Console, and API access for automation and SIEM integration.
ISO/IEC 27001:2013 certification, an annual ISAE 3402 Type II audit performed by Deloitte, and TISAX certification for automotive-sector customers all sit behind Keepit's platform. The company positions its architecture as directly supporting GDPR, NIS2, and DORA compliance obligations, which matters increasingly for EU financial institutions and critical-infrastructure operators now facing NIS2 enforcement.
Keepit formalised its reseller-only approach with the Keepit Partner Network in January 2024, sorting partners into registered, select, and elite tiers based on revenue and training commitments. Canalys recognised the programme as a "scaler" in its 2023 Managed Backup and Disaster Recovery Matrix. For an MSP already reselling Microsoft 365 licensing, adding Keepit backup through the same partner relationship is a smaller sale than pitching a wholly new vendor directly to the end customer.
There is no public price list. Because Keepit sells only through partners, pricing depends on seat count, which SaaS platforms need coverage, retention length, and whichever margin structure the specific MSP or reseller applies on top. Independent industry estimates have suggested entry pricing in the region of a few dollars per seat per month. Nothing Keepit itself publishes confirms a number, so treat any such figure as a rough industry estimate rather than an official rate.
For our hypothetical bank IT administrator, this means the actual quote depends heavily on which partner they work with, not just which Keepit tier they select. That is a real friction point compared to Acronis, which at least publishes named product tiers (Standard, Advanced, Cloud) even though its own per-workload pricing also requires a quote.
Keepit is a Danish company (Keepit A/S) operating fully within EU jurisdiction and GDPR. Its seven-region data-centre footprint includes Copenhagen and Frankfurt, giving European customers a genuine EU-hosted option rather than a "processed in the EU, stored elsewhere" workaround. The ISO 27001 certification and Deloitte-audited ISAE 3402 Type II report give compliance teams independently verified evidence rather than self-attestation alone.
NIS2, the expanded EU cybersecurity directive now pulling more mid-sized organisations into scope, is where Keepit's pitch centres on immutability, air-gapped storage, and the absence of third-party sub-processors handling backup data. DORA, which applies specifically to financial-sector ICT resilience, draws on that same architecture to support the operational-resilience testing that regulated banks and insurers must now demonstrate to supervisors.
IT and security teams at regulated European organisations — banks, insurers, public bodies — often need to document exactly where SaaS backup data lives and who can access it. Keepit's own-cloud, no-sub-processor model answers those procurement questions more directly than hyperscaler-hosted competitors can.
Organisations already committed to buying through an MSP or reseller relationship, rather than direct self-service, fit Keepit's partner-only distribution model naturally. Teams that specifically need Microsoft 365, Entra ID, or Salesforce backup, without also needing server or VM backup in the same tool, get a focused product. That is a real advantage over a general-purpose backup suite that treats SaaS as an afterthought.
Organisations needing a single vendor for both infrastructure and SaaS backup should look elsewhere, since Keepit deliberately does not cover servers, VMs, or endpoints the way Veeam or Acronis do. Companies wanting transparent, published per-seat pricing before engaging sales will also find Keepit's quote-only, partner-mediated model slower than a self-service signup.
Buyers who prefer purchasing software directly from the vendor, without a reseller relationship in the middle, should factor in Keepit's partner-only model before shortlisting it. That structure is a deliberate choice by Keepit, not a temporary go-to-market gap, so it is unlikely to change for anyone hoping to wait it out.
Return to that phishing scenario. If the bank's backup had lived inside the same Microsoft tenant the attacker compromised, the outcome could have been catastrophic rather than merely disruptive. Keepit's core architectural choice — its own cloud, physically and organisationally separate from the SaaS platforms it protects — is a genuine, defensible answer to that risk, not just a marketing angle.
What that story leaves out is scope and access. Keepit only protects SaaS applications, sells only through partners, and publishes no pricing anywhere. Those are real limitations for a team hoping for a single backup vendor and a straightforward online quote. For organisations that specifically need vendor-independent, immutable SaaS backup and are comfortable buying through a partner, Keepit's differentiation is substantive rather than cosmetic.
No. Keepit is scoped entirely to SaaS applications — Microsoft 365, Entra ID, Salesforce, Google Workspace, and similar cloud platforms. It does not protect on-premises servers, VMware or Hyper-V virtual machines, physical endpoints, or NAS storage, all of which Veeam covers. Organisations with mixed infrastructure typically run Keepit alongside a separate infrastructure backup tool.
No. This appears to be a data-tracking error on some third-party company databases. The event on that date was Keepit's own announcement that it had upsized and refinanced its credit facilities to $60M with EIFO and HSBC Innovation Banking — debt financing, not a change of ownership. Keepit continued to raise debt on its own account, upsizing that facility to $90M in July 2026. No acquisition has been announced by the company or by any named acquirer.
Keepit runs its own dedicated cloud infrastructure across seven data-centre regions: Copenhagen, Frankfurt, London and Zurich in EMEA, Washington DC and Toronto in the Americas, and Sydney in APAC. European customers can choose EU-based storage in Copenhagen or Frankfurt.
Not typically. Keepit operates a partner-only sales model, selling through a network of resellers, managed service providers, and distributors rather than offering direct self-service signup or a published price list.
Yes. Keepit is a Danish company subject to GDPR, holds ISO/IEC 27001:2013 certification, and undergoes an annual ISAE 3402 Type II audit by Deloitte. Its immutable, EU-hosted backup architecture also supports customers' NIS2 and DORA compliance obligations.
Award-winning cybersecurity solutions for consumers and enterprises
Alternative to Norton, Mcafee, Crowdstrike
Client-side encryption for your cloud storage files
Alternative to Dropbox, Google Drive
Search, observability, and security platform built on Elasticsearch and the ELK Stack