← All guides
Running a Security Tune-Up
This is the paid visit: you sit down with the customer, log into their accounts with them, and leave every one of them in better shape than you found it. Here's the script.
Before you start
Say this to a customer"Today I'm going to go through your important accounts with you. For each one, I'll help you set a strong new password that Keeper will remember for you, turn on two-factor authentication where it's offered, and clean up anything — like an old device or an unused login — that shouldn't still have access. You'll be signed in the whole time; I'm just guiding you through the buttons."
The checklist, per account
- Open the account, sign in as normal. Let Keeper offer to save it if it's not already saved.
- Look at what's already there. Old passkeys? Old sessions? An authenticator the customer doesn't recognize? Note it — you'll clean it up at the end.
- Change the password. Use Keeper's generator (16+ characters). Confirm Keeper updated the saved record, not just the website.
- Turn on two-factor authentication if the site offers it and it isn't already on. Store the secret as a Two-Factor Code field, and save the recovery codes to the notes.
- Offer a passkey if the site supports one. It's the best long-term outcome — frame it as "even less to remember."
- Remove anything stale you noted in step 2 — old devices, unrecognized passkeys, unused sessions.
- Sign out and back in together so the customer sees Keeper fill everything — password, 2FA code, or passkey — with no typing.
Practice it here first
Every step above has a matching mission in the Training Track. Ask your trainer for a practice account on the "Customer needs a security tune-up" scenario — it starts with a weak password, no 2FA, and one stale passkey already planted, so you can run the entire script start to finish before doing it with a real customer.
Common questions customers ask
- "Why can't I just remember my passwords?" "You could, but that means either reusing them (one breach exposes everything) or picking something guessable. Keeper remembers a different long random one for every site, and only you can unlock the vault."
- "Is my information safe with Keeper?" "Keeper never sees your unencrypted data — everything is encrypted on your own device before it's stored. Not even Keeper's engineers can read it."
- "What if I lose my phone?" "That's exactly what recovery codes and account recovery are for — we'll make sure those are set up today too."