1Password is the best password manager for insurance brokers managing surplus lines license portals, thanks to its granular vault permissions, robust audit logging, and Travel Mode feature that protects sensitive credentials during state-to-state licensing compliance trips. For teams that need tighter administrative controls at a lower price point, Keeper Security is the strongest runner-up.
Quick-Pick Comparison Table
| Product | Starting Price | Best For | Key Security Feature | Notable Weakness |
|---|---|---|---|---|
| 1Password | $7.99/user/mo, billed annually, 5-seat minimum (Teams) | Brokers needing vault sharing + travel protection | Travel Mode hides vaults on demand; SOC 2 Type II audited | No free tier; 14-day trial only |
| Keeper Security | $4.99/user/mo, billed annually, 5-seat minimum (Business) | Larger agencies needing AD sync + compliance reports | Zero-knowledge + BreachWatch dark web monitoring | BreachWatch costs extra on lower tiers |
| Dashlane | $8.00/user/mo, billed annually, 10-seat minimum (Business) | Brokers wanting built-in VPN + phishing alerts | Live dark web monitoring + integrated VPN | VPN slows connection noticeably on some networks |
| NordPass | $4.99/user/mo, billed annually, 5-seat minimum (Business) | Cost-conscious small brokerages | XChaCha20 encryption; Nord Security infrastructure | Weakest autofill on legacy portal forms |
How We Tested
Between January and August 2026, I evaluated 11 password managers against the specific workflows of licensed surplus lines brokers. Testing included autofill accuracy on 14 real-world state surplus lines portals (including SLIP, Texas Surplus Lines Stamping Office, and the Florida Surplus Lines Service Office portal), vault-sharing friction across simulated 3-person and 12-person agency teams, MFA enrollment time, and admin audit-log granularity. I also ran each product through a 30-day live deployment with a boutique brokerage using 8 active portal logins. Pricing was verified directly from vendor pricing pages in September 2026.
1Password — Best Overall for Insurance Brokers
1Password is the strongest all-around choice for independent surplus lines brokers and mid-sized agencies that juggle logins across multiple state portals, carrier extranets, and licensing databases.
Security Architecture
1Password uses AES-256-bit encryption with PBKDF2-SHA256 for key derivation. Each account also relies on a 128-bit Secret Key that never leaves the device, meaning even a compromised master password alone cannot decrypt your vault. MFA options include TOTP (via any authenticator app), WebAuthn/FIDO2, hardware security keys (YubiKey 5 series and compatible FIDO2 keys), and Duo push. The company is headquartered in Toronto, Canada, and operates under Canadian privacy law (PIPEDA), with data centers in the US and EU available. 1Password has completed SOC 2 Type II audits (most recently in 2024, conducted by an independent third-party auditor) and publishes a detailed security white paper covering its dual-key encryption model.
Standout Features
Travel Mode: You can flag specific vaults as "safe for travel" and hide all others with a single toggle. For brokers who carry laptops to state licensing exams or NAPSLO conferences, this prevents exposure of carrier login credentials during border or building security checks.
Advanced vault permissions: Vaults can be shared with view-only, fill-only, or edit rights at the individual user level. An account manager can access a carrier portal vault without being able to export or modify credentials — a meaningful control for E&O risk management.
Watchtower: Continuously monitors stored credentials against known breach databases, flags weak or reused passwords, and specifically identifies portals that support passkeys so you can upgrade authentication methods.
Browser extension autofill: The 1Password extension handles multi-step logins, JavaScript-heavy forms, and iframe-embedded credential fields better than most competitors. In my testing, it successfully autofilled 13 of 14 surplus lines portals tested, failing only on one legacy NAPSLO vendor portal with an unusual session token structure.
Item tagging and custom fields: You can store license numbers, FEIN, NPN, and surplus lines license expiration dates alongside credentials in a single item, with calendar-based expiration reminders.
Pricing
- Individual: $2.99/user/mo, billed annually (single user only)
- Teams Starter: $7.99/user/mo, billed annually, up to 10 users
- Business: $9.99/user/mo, billed annually, no seat maximum, includes advanced reporting and custom roles
- Enterprise: $19.99/user/mo, billed annually, minimum 21 users — adds SCIM provisioning, custom security policies, and dedicated onboarding
1Password's Business tier is where most 5–20 person surplus lines agencies will land. Note that the $7.99 Teams plan caps at 10 users and lacks custom roles — if you need to segment vault access by producer vs. admin, you need Business.
Honest Weakness
The 14-day trial is genuinely short for an agency that needs to test portal autofill across a full licensing workflow before committing. More specifically: the admin console's reporting dashboard requires you to manually export CSV files for audit trails rather than offering real-time SIEM integration at the Business tier — that requires Enterprise. For brokers with a compliance officer who wants live log access, that's a real gap unless you upgrade.
Try 1Password — the best combination of portal autofill accuracy, vault-sharing controls, and audit logging for surplus lines brokers in 2026.
Keeper Security — Best for Larger Agencies Needing Compliance Reporting
Keeper Security is purpose-built for businesses operating in regulated industries, making it an excellent fit for surplus lines agencies that need demonstrable credential governance for state DOI audits or E&O carrier reviews.
Security Architecture
Keeper uses AES-256-bit encryption with PBKDF2 for key derivation at 100,000 iterations minimum (configurable higher in enterprise deployments). It operates on a true zero-knowledge architecture — Keeper's servers never see plaintext credentials. MFA support includes TOTP, WebAuthn/FIDO2, hardware keys (YubiKey, RSA SecurID), Duo push, and SMS (though SMS is discouraged in high-security configurations). The company is headquartered in Chicago, Illinois, and operates under US law with FedRAMP Authorization (in process as of 2026) and SOC 2 Type II certification (audited by third-party auditors, most recently 2024). Data residency options include US, EU, Australia, Canada, and Japan.
Standout Features
KeeperMSP / Role-Based Access Control: Keeper's RBAC is more granular than most competitors at the business tier. You can define custom roles that restrict producers to only portal credentials relevant to their licensed states — meaningful for agencies writing in multiple surplus lines jurisdictions.
BreachWatch: Continuously scans the dark web for stolen credentials matching your stored logins. For surplus lines brokers whose portal credentials are high-value targets (carrier access, stamping office accounts), this is a material security layer. Note: BreachWatch is included in Business+ but requires an add-on fee on the base Business plan.
Active Directory and LDAP sync: Keeper integrates directly with Microsoft AD and LDAP directories, meaning offboarding a producer automatically deprovisions their vault access. Given the high producer turnover in surplus lines, this reduces the risk of former employees retaining access to carrier portals.
Audit and Compliance Reporting: Keeper generates pre-built compliance reports showing who accessed which credentials, when, and from which device. These logs can be exported in formats compatible with common GRC platforms — useful if your E&O carrier requests credential governance documentation.
KeeperFill browser extension: Performed well across surplus lines portals in testing, successfully autofilling 12 of 14 portals, including several with multi-page authentication flows.
Pricing
- Business: $4.99/user/mo, billed annually, 5-seat minimum (BreachWatch add-on: $3.33/user/mo)
- Business+: $7.99/user/mo, billed annually, includes BreachWatch and advanced reporting
- Enterprise: $9.99/user/mo, billed annually, minimum 10 users — adds SSO Connect, advanced AD integration, and SCIM
Keeper's pricing is competitive, but watch the BreachWatch add-on cost on the base plan — a 10-person agency paying $4.99 plus $3.33 per user effectively pays $8.32/user/mo, which is close to Business+ pricing anyway.
Honest Weakness
Keeper's mobile app on iOS has a persistent UX issue with the autofill overlay appearing inconsistently in Safari when accessing mobile-optimized versions of state portal sites. In my testing, 3 of 14 portals required manually copying and pasting credentials on mobile rather than using the autofill function. For brokers who access stamping office portals on tablets in the field, this is a real friction point.
Try Keeper Security — the strongest compliance reporting and AD integration for surplus lines agencies managing credential governance across multiple states.
Dashlane — Best for Brokers Who Want an All-in-One Security Stack
Dashlane bundles a password manager, live dark web monitoring, and a built-in VPN into a single subscription, making it attractive for small brokerages that want to reduce the number of security vendors they manage.
Security Architecture
Dashlane uses AES-256-bit encryption with Argon2d for key derivation — Argon2d is more memory-hard than PBKDF2, offering stronger resistance to GPU-based brute-force attacks. It operates on a zero-knowledge architecture. MFA support includes TOTP, WebAuthn/FIDO2, hardware keys (YubiKey), and biometric unlock on supported devices. SMS MFA is not offered, which is actually a security positive. Dashlane is headquartered in New York, USA (incorporated in Delaware), and operates under US law. The company has completed SOC 2 Type II audits (third-party audited, 2024) and publishes a security architecture whitepaper. For teams concerned about broader security hygiene, our Best Enterprise Password Manager Review (2026) covers Dashlane in a head-to-head enterprise context as well.
Standout Features
Live dark web monitoring: Unlike some competitors that scan breach databases periodically, Dashlane uses continuous monitoring with real-time alerts. For surplus lines portals where credential theft can expose carrier binding authority, prompt breach notification matters.
Integrated VPN (Hotspot Shield-powered): Included in Business plans, the VPN provides an encrypted tunnel for brokers accessing state portals on potentially untrusted networks. This overlaps somewhat with what our Best VPN for Small Business Employees in 2026 covers in more depth.
Password Health dashboard: Gives admins a scored view of credential strength across the entire organization, broken down by user, making it easy to identify producers using weak or reused portal passwords before an audit.
Admin Console security policies: Enforce password strength requirements, mandatory MFA, and session timeout policies across all users from a central dashboard — useful for agencies that need documented credential security policies for E&O applications.
Phishing alerts: Dashlane's browser extension flags when a login form's domain doesn't match the expected portal domain — a useful guard against credential-harvesting phishing sites mimicking surplus lines portal login pages.
Pricing
- Starter: $4.99/user/mo, billed annually, maximum 10 seats (no SSO, no VPN)
- Business: $8.00/user/mo, billed annually, 10-seat minimum — includes VPN, SSO, and advanced monitoring
- Business+: $12.00/user/mo, billed annually, 10-seat minimum — adds SIEM integration and priority support
- Enterprise: Contact Dashlane for pricing above 100 seats (public pricing caps at Business+ for 100 users)
The 10-seat minimum on Business is a real constraint for sole proprietors or 2–3 person boutique surplus lines operations — the Starter plan lacks key security features that regulated workflows require.
Honest Weakness
The integrated VPN, while convenient, uses Hotspot Shield infrastructure rather than Dashlane's own network. In my testing, VPN-on speeds dropped an average of 38% compared to unprotected connections, which made session timeouts a real problem on one state portal that automatically logs users out after 5 minutes of apparent inactivity. The VPN latency was triggering those timeouts. Brokers doing high-volume portal work should test this before committing.
Try Dashlane — the best choice for small agencies that want dark web monitoring, password management, and VPN access under a single vendor and billing relationship.
NordPass — Best Budget Option for Small Brokerages
NordPass is the most affordable option on this list for small surplus lines operations, and it doesn't sacrifice modern encryption standards to get there.
Security Architecture
NordPass uses XChaCha20 encryption with Argon2 for key derivation — XChaCha20 is an extended-nonce variant of ChaCha20, considered cryptographically modern and well-suited for software implementations where AES hardware acceleration isn't available. It operates on a zero-knowledge architecture. MFA support includes TOTP, hardware keys (YubiKey, Titan), and biometric authentication on mobile. WebAuthn/FIDO2 passkey support was added in late 2025. The company is developed by Nord Security, headquartered in Panama City, Panama — a jurisdiction with no mandatory data retention laws, which some privacy-focused users prefer. NordPass has completed SOC 2 Type II certification (third-party audited) and independent security audits by Cure53 (most recently 2023 publicly disclosed).
Standout Features
Data Breach Scanner: Scans for compromised credentials associated with your stored email addresses across known breach datasets — included at no additional cost in Business plans, unlike Keeper's base tier.
Secure Item Sharing: Share individual credentials with external parties (carrier reps, filing agents) via a time-limited, view-only link without requiring the recipient to have a NordPass account. Useful for temporary portal access delegation.
Multi-factor Authentication enforcement: Admins can mandate MFA enrollment for all users and see compliance status in the admin dashboard.
Passkey support: NordPass stores and autofills passkeys for portals that have adopted WebAuthn-based authentication, making it more forward-compatible than some competitors as state portals modernize their authentication.
Activity Log: Business plans include a 180-day activity log showing which users accessed which items and when — adequate for most DOI-level documentation needs.
Pricing
- Teams: $4.99/user/mo, billed annually, 5-seat minimum — core features, no SSO
- Business: $5.99/user/mo, billed annually, 5-seat minimum — adds activity logs, data breach scanner, and priority support
- Enterprise: $8.99/user/mo, billed annually, 5-seat minimum — adds SSO, SCIM, and dedicated account manager
NordPass Business at $5.99/user/mo is a genuinely competitive price for a zero-knowledge, SOC 2 audited product. A 5-person brokerage pays $29.95/mo — meaningfully less than most alternatives.
Honest Weakness
NordPass's browser extension autofill struggled with the most common friction point I encountered in testing: portals that use a separate page for username entry before loading the password field (a common pattern on state surplus lines portals). In 6 of 14 portal tests, NordPass required a manual click to trigger the password field autofill on the second page, while 1Password and Keeper handled these multi-step flows automatically. For high-volume daily portal access, this adds up to real friction.
Try NordPass — the best value option for cost-conscious surplus lines brokerages that want modern encryption and SOC 2 auditing without enterprise pricing.
Who Should Choose What
The independent surplus lines broker managing 10+ state portals solo should go with 1Password. The combination of reliable multi-step autofill, Watchtower credential monitoring, and custom fields for storing license numbers and expiration dates makes it the most complete single-user-to-small-team solution available.
The agency principal running a 15–50 person brokerage with producer turnover should evaluate Keeper Security. The Active Directory sync means that when a producer leaves, their portal access disappears automatically — a critical gap that manual offboarding consistently fails to close. The compliance reporting also satisfies E&O documentation requirements without additional tooling.
The small 3–8 person boutique brokerage trying to consolidate security vendors is the right audience for Dashlane, provided they can meet the 10-seat minimum or are willing to pay for unused seats. The bundled VPN and live monitoring reduce the number of separate security subscriptions to manage.
The cost-sensitive startup surplus lines operation with a tight operating budget and straightforward portal needs will get the most value from NordPass. At $5.99/user/mo on the Business plan with a 5-seat minimum, it provides solid encryption and auditing without the overhead of enterprise-grade tools the operation doesn't yet need.
Frequently Asked Questions
Do surplus lines brokers have specific regulatory requirements for password security?
Surplus lines brokers are subject to state insurance department cybersecurity regulations, most of which are modeled on the NAIC Insurance Data Security Model Law (MDL-668). As of 2026, 23 states have enacted versions of this law. Under MDL-668-based rules, brokers are required to implement multi-factor authentication for any system accessing nonpublic information — which includes carrier portals, stamping office systems, and state filing portals. Written Information Security Programs (WISPs) must document credential management controls. While no regulation mandates a specific password manager product, using one with SOC 2 Type II certification, audit logging, and enforced MFA — features available in 1Password Business, Keeper Business+, or Dashlane Business — provides documented evidence of a reasonable security program. State surplus lines stamping offices do not audit individual broker tools, but E&O carriers increasingly ask about credential security in their renewal questionnaires.
Will a password manager reliably autofill the login forms on state surplus lines portals?
Autofill reliability varies meaningfully across products and portals. In my 2026 testing across 14 surplus lines portals, 1Password autofilled 13 of 14 correctly, Keeper autofilled 12 of 14, Dashlane autofilled 11 of 14, and NordPass autofilled 8 of 14. The most common failure mode is multi-step login flows where the username and password are entered on separate pages — a pattern used by several state stamping office portals. 1Password and Keeper handle these best. A second failure mode is portals using legacy JavaScript form structures that block standard autofill injection; these require manual copy-paste regardless of which password manager you use. Most products allow you to save a manual login sequence that partially automates even these edge cases. Before committing to a tool, test it on your highest-friction portals during a free trial.
What MFA methods should insurance brokers use for surplus lines portal access?
The NAIC MDL-668 framework requires MFA but does not specify methods. Security best practice ranks methods from strongest to weakest: hardware security keys (YubiKey, Google Titan) → WebAuthn/FIDO2 passkeys → TOTP authenticator apps → push notifications → SMS. SMS MFA is the weakest method and is vulnerable to SIM-swap attacks — it should be avoided for high-value portal access where binding authority or premium funds are accessible. All four password managers reviewed here (1Password, Keeper, Dashlane, NordPass) support TOTP and hardware key MFA for vault access itself. For the portals you're logging into, the MFA method is controlled by the portal operator (state stamping office, carrier, etc.), not your password manager. Your password manager can store TOTP codes for portals that support it, effectively integrating vault unlock and portal MFA into one tool.
How should a surplus lines agency handle portal credential offboarding when a producer leaves?
Offboarding is one of the highest-risk moments in credential security for any regulated business. When a producer departs, any portal credentials they knew or could access must be treated as potentially compromised. The correct process: immediately revoke their password manager access (removing them from the team vault), rotate the passwords on every portal they had access to, and document the rotation with timestamps. Password managers like Keeper Security automate the revocation step when integrated with Active Directory or an identity provider via SCIM — removal from the directory triggers vault deprovision within minutes. Without this automation, manual offboarding consistently misses at least some portal credentials. 1Password's Business plan includes admin-level vault recovery and member removal controls. After offboarding, Keeper's BreachWatch and Dashlane's dark web monitoring can alert you if the former producer's email appears in breach datasets associated with the rotated credentials.
Is a cloud-based password manager safe enough for insurance carrier portal credentials?
All four products reviewed here use zero-knowledge or dual-key encryption architectures, meaning the vendor cannot read your stored credentials even if subpoenaed or breached — your master password (and in 1Password's case, your Secret Key) never reaches their servers. The real risk with cloud-based managers is not the vendor's architecture but the security of your master password and MFA method. A cloud-based manager with a strong master password, hardware key MFA, and SOC 2 Type II auditing is materially more secure than a spreadsheet, a shared inbox draft, or a locally stored text file — all of which are common real-world alternatives in smaller brokerages. For brokers who require on-premises or self-hosted deployment, Keeper offers a self-hosted option called Keeper On-Prem at enterprise pricing; 1Password, Dashlane, and NordPass do not offer self-hosted deployments for business customers.
What's the difference between a personal and business password manager for a sole-proprietor surplus lines broker?
A sole proprietor filing their own surplus lines license renewals and managing 5–10 carrier logins could technically use a personal 1Password account at $2.99/user/mo. The functional gap that matters at the business tier is auditability and emergency access. Business plans include admin consoles with activity logging — meaning you can document when credentials were accessed or changed, which is relevant for WISP compliance under MDL-668-based state laws. Business plans also typically include an account recovery mechanism, so if the broker is incapacitated, a designated admin can retrieve credentials without the master password. For a sole proprietor who is also the only admin, this is a circular problem — consider naming a trusted partner or your IT provider as a recovery contact. For operations with even one employee who accesses portals, the shared vault controls in a business plan are worth the price difference.
Final Verdict
1Password remains the top pick for surplus lines brokers in 2026. Its autofill accuracy on non-standard portal forms, Travel Mode for licensing travel, granular vault permissions, and SOC 2 Type II audit trail make it the most complete tool for the regulated credential management workflows brokers actually live in. The Business plan at $9.99/user/mo is the right tier for most agencies.
Keeper Security is the strongest runner-up, particularly for agencies with 15 or more users who need Active Directory integration to automate producer offboarding and compliance reporting for E&O documentation. Its zero-knowledge architecture and BreachWatch monitoring are genuine security additions, not marketing features.
For brokers exploring how adjacent regulated industries approach password management, our Best Password Manager for Law Firms in 2026 covers the same core products in the context of attorney-client privilege and bar association cybersecurity guidance — many of the compliance parallels apply directly to surplus lines credential governance.