Why Keel exists
Keel exists to help growing organizations build trust through governance that is practical, transparent, and verifiable.
Good governance should not require unnecessary bureaucracy or specialized expertise at every turn. Organizations should be able to understand their obligations, manage risk responsibly, and produce credible evidence of the work they have done.
We built Keel to make that possible. It connects the work across governance, risk, compliance, and assurance so teams can see where they stand, focus on what matters, and prove their progress.
Our approach
Do the work once. Everything in Keel is a projection of one unified control & evidence graph: collect evidence once, satisfy many frameworks, and show your work in a trust center. New frameworks are data, not code, so breadth never means bloat.
What we value
- Tell the truth plainly: No exaggerated capability, no implied guarantee about an audit outcome, and no pretending software alone makes an organization compliant. A limitation stated clearly is the copy doing its job.
- Simplify without cutting corners: We remove the work that carries no assurance value - duplicate evidence, re-keyed mappings, ceremony for its own sake. We never remove the work the standard actually requires, and we do not pretend compliance is easy.
- Show the work: You should be able to see why a conclusion exists: the evidence behind it, the mapping that produced it, the audit trail under it, and whether a model or a person wrote it.
- Build for the people doing the work: Founders, operators, IT and security leaders, MSPs, consultants and small teams - the person who will personally do the task, not a procurement committee.
- Keep people in control: AI assists. People remain accountable. Automation removes labour, never the human who is answerable for the result.
- Respect ownership: Open formats, exports and documented mappings, and no artificial lock-in. Your program is yours, and leaving Keel should never mean losing the work.
We run on Keel
We build Keel on the same control & evidence graph our customers use, and we hold ourselves to the security practices and frameworks we help you adopt. If it isn’t good enough for us, it isn’t good enough for you.
Who builds it
Chris Brock
Founder, Keel · LinkedIn
I did not set out to build a compliance product. I am a CIO, and I came to compliance the way most people do: a client contract required it. Once security questionnaires and audit clauses started deciding which work we won, it became my problem.
So I built the program. ISO 27001, SOC 2 Type 2 and HIPAA, from essentially nothing to audit-ready in under a year, without hiring a compliance team, and through the annual audits every year since. What made that possible was refusing to run three separate projects: one set of controls, evidence collected once, mapped to whichever clause needed it. The tools I could buy did not think that way, and the ones that came close assumed a budget and a dedicated GRC hire I did not have.
Keel is that approach, built properly. One crosswalked control and evidence graph, priced so a small team can start without a sales call. It is the tool I wanted when I was the person about to be handed a first audit.