Changelog
What we’ve shipped
Every release, newest first. Want to shape what’s next? Sign in and share your ideas on the product roadmap.
-
v1.76.0 — now
SOX Section 404 is live
- New SOX (Sarbanes-Oxley) Section 404 is now available and can be applied in one click. It went live on 2026-08-13, the date the catalog carries — ahead of the September date it had been scheduled for, because the content had been finished and crosswalked since the day it was authored and the later date was a go-to-market choice rather than a readiness one. Be precise about what it models, because the name invites a bigger reading than the framework supports: this is not the Sarbanes-Oxley Act. SOX is a statute of eleven titles that publishes no control list anywhere in it — 15 U.S.C. 7262(a) requires management to assess the effectiveness of internal control over financial reporting and names no framework, 17 CFR 240.13a-15(c) requires that assessment to rest on "a suitable, recognized control framework", and 17 CFR 229.308(a)(2) requires management’s report to name the framework it used. The framework registrants name is COSO’s Internal Control—Integrated Framework (2013), so that is what Keel models: 17 scored requirements, one per COSO principle, across the five components — control environment (5), risk assessment (4), control activities (3), information and communication (3), and monitoring activities (2). Those seventeen principles are the framework’s complete declared scope, it is declared complete against them in Keel’s completeness model, and a test fails the build if the count or the per-component distribution ever drifts.
- New What is deliberately outside that scope is stated in full on the framework’s catalog entry rather than summarised here, and it is worth reading before you apply it — the entry also carries a standing advisory that scoring 100% is an entity-level self-assessment against the COSO principle set, not a Section 404 conclusion that internal control over financial reporting is effective. If you are an SEC registrant, scope your assessment with your auditors.
- New Applying SOX seeds 30 starter controls drawn from the set Keel already ships, so the framework produces real work on day one rather than seventeen empty rows. Because they are the same controls, the access, change-management, operations, risk-assessment and monitoring evidence you already keep for ISO 27001, SOC 2, NIST 800-53 or PCI DSS counts toward SOX too. It is included on every paid plan within your framework allowance, or $49 a month applied à la carte.
-
v1.75.0
ESG Essentials doubles in size, checked against ISO 26000’s core subjects
- Improved ESG Essentials went from 24 requirements to 49 on 2026-08-13 — 12 environmental, 23 social, 14 governance. The new material fills the gaps a responsible-business baseline was missing rather than restating what was there: pollution prevention, climate risk and adaptation, land use and biodiversity, product life-cycle impact and an environmental obligations register; human rights due diligence, grievance and remedy for affected people, protection of vulnerable groups, worker classification, conditions of work, and freedom of association; fair marketing and substantiated claims, product safety, complaints and dispute resolution, accessible service, and sustainable-consumption information for customers; community engagement, local employment and skills, local procurement and community investment; and on the governance side stakeholder engagement, responsible political involvement, fair competition, respect for property and IP rights, and a scheduled programme review. Every existing requirement keeps its reference and its meaning — E.1–E.7, S.1–S.8 and G.1–G.9 are untouched, so nothing you have already answered or evidenced moved.
- Improved What the new content was checked against, and what that does not mean. The subjects were chosen by working through ISO 26000:2010’s seven core subjects of social responsibility — organisational governance, human rights, labour practices, the environment, fair operating practices, consumer issues, and community involvement and development — listing what ESG Essentials did not ask for, and then writing those expectations from scratch in Keel’s own words. **ISO 26000 is guidance, not a certifiable standard**: it contains no requirements, so nobody can be certified against it, and any offer to certify against it would be a misrepresentation — ISO says so itself in its free "Discovering ISO 26000" brochure. Keel therefore does not ship an ISO 26000 framework and does not score anyone against it. What Keel does ship is a map, in the content package: each ESG Essentials requirement is recorded against the ISO 26000 core subject it speaks to, together with the five ISO 26000 issues this baseline deliberately does not model and the reason for each. That map is data, so anything Keel says about the relationship is derived from it and a test fails the build if the two disagree.
- Improved Readiness percentages for workspaces using ESG Essentials will drop, and that is the number being honest rather than a regression. The denominator is the count of requirements in the framework, and it grew from 24 to 49; the work you have completed did not change. Starter controls have not been extended to the new requirements yet, so expect the new rows to start unmapped and be worked through directly.
-
v1.74.0
Apple App Store Kids Category is live
- New Apple App Store Kids Category is now available and can be applied in one click. It went live on 2026-08-13, the date the catalog carries — ahead of the September date it had been scheduled for, because the only thing holding it was a scope question, and that has now been settled. It comes to 20 scored requirements: Guideline 1.3 for the Kids Category itself — the App Store Connect age band, parental gates on links out and purchases and the adult-level task a gate has to be, no personally identifiable or device information sent to third parties even from adult-facing sections, human review of any advertising displayed, and third-party analytics and advertising excluded by default with narrow carve-outs — together with the age-restriction, tobacco-drugs-and-alcohol, metadata, sign-in, targeted-advertising, health-research and children’s-data guidelines whose duties are triggered by a child or a minor. Like Google Play Families and Amazon’s Child-Directed App policy, this is app-store programme terms rather than law: a contract you accept in order to distribute, which Apple rewrites without notice. It sits alongside COPPA rather than inside it, and satisfying COPPA does not satisfy Apple.
- New What makes this framework unusual is worth stating plainly, because it is the difference between a claim you can audit and one you have to trust. Apple publishes no delimited "children’s requirements" document the way Google and Amazon do — its children’s duties are scattered through the App Review Guidelines, which bind every developer in full. So Keel is complete against a PUBLISHED SCOPE RULE rather than against a document boundary. The rule: a guideline is in scope if its duty is triggered by a child, a minor, an underage user, or by the Kids Category; everything else is out, with one narrow stated exception for a provision that a child-triggered duty incorporates by reference and that would otherwise be unscoreable. And the rule is not just asserted — every one of the 115 excluded guidelines is enumerated by number in the framework source, alongside the 7 that are scored only in part with the unscored remainder of each named, and a register giving the reason each child-mentioning guideline that still fails the rule was left out anyway. 115 excluded plus 10 touched is 125: the whole document, accounted for. You can contest one line of that boundary rather than re-deriving it. This is the same posture as Keel’s HIPAA, which is complete against a declared subset of 45 CFR 164 — a line drawn silently could not support a completeness claim, and a line drawn, published and applied consistently can.
- New Two things to know before you opt in, because both surprise developers. Apple’s Kids Category obligations persist in subsequent updates even if you later deselect the category: once customers expect your app to follow those rules, deselecting does not release you. Joining is therefore close to one-way, and it belongs in a product decision rather than a metadata one. And "For Kids" and "For Children" are reserved terms in App Store metadata — they may only be used by an app actually in the Kids Category, so they are not available as a positioning phrase for an app that merely happens to suit children.
- New Applying the framework seeds the children’s-app starter controls Keel already ships — the app-store audience declaration and metadata, child-appropriate experience and parental gates, children’s advertising and monetisation, third-party SDK and API governance, and neutral age screening — so the audience determination, SDK inventory and ad-review records you keep for COPPA, Google Play Families or Amazon count toward Apple as well. Two things Keel deliberately does not claim: this is NOT a model of the App Review Guidelines as a whole and it does not predict App Review outcomes — all 125 numbered guidelines still bind your app, and scoring 100% here means you have addressed the child-triggered ones, not that you will pass review. Apple publishes no version number, no ratification date and no change log for either source page, so the framework carries the date Keel retrieved them, 2026-08-13, in place of a version, and a monthly drift monitor now watches both pages so a rewrite is noticed rather than discovered.
-
v1.73.0
App-store children’s policies: Google Play Families and the Amazon Appstore are live
- New Google Play Families and Amazon Appstore Child-Directed Apps — the Amazon Appstore’s Child-Directed App (COPPA) Policy — are now available and can be applied in one click. Both went live on 2026-08-13, the date the catalog carries. Be clear what they are: app-store policies, not law. They are contracts you accept in order to distribute, the stores rewrite them without notice, and they are stricter than COPPA in places. So they sit alongside COPPA rather than inside it, deliberately — a developer shipping only to Google Play should not be scored against Amazon’s rules, and although Keel crosswalks both to COPPA, satisfying COPPA does not satisfy either store. Google Play Families comes to 36 scored requirements — the Play Console target-audience and data-safety declarations; the Families Policy Requirements on child-appropriate content, disclosing what is collected from children including through SDKs, the persistent identifiers a child-only app may not transmit (AAID, SIM serial, Build serial, BSSID, MAC, SSID, IMEI, IMSI), the AD_ID permission on API 33 and above, precise location, Companion Device Manager for Bluetooth, SDK approval for child-directed services, augmented-reality safety warnings, and online-safety reminders and adult controls on social features; and the Families Ads and Monetization rules on certified ad SDKs, interest-based advertising and remarketing, age-appropriate creative, ad walls, five-second closeability, launch interstitials, multiple placements and virtual currency. Amazon Appstore Child-Directed Apps comes to 8: the child-directed determination, age-appropriate content, COPPA compliance, the advertising bars and the SDK rules. Both are declared complete in Keel’s completeness model against the published policy, and a test fails the build if either count drifts.
- New One scope fact catches people out, so Keel states it rather than burying it: Amazon defines a child as under 13 — or under 16 in the European Union, Australia and Japan — which is wider than COPPA, so a programme scoped to COPPA alone is under-scoped for that store in three markets. Amazon also treats a multi-audience app as child-directed unless the developer confirms children are not using it, so the determination is something you have to make and record, not something you fall outside of by default.
- New The single most useful thing to know before you build: there is no one ad configuration that ships on all three children’s app stores. Amazon prohibits serving ads through any Amazon Advertising or Amazon Associates programme to anyone you know is a child or in any child-directed part of your app, and parental consent does not lift that — an app directed only at children cannot use those programmes at all, which inverts the usual privacy logic where consent unlocks the activity. Google permits ads to children or to users of unknown age only from a Families Self-Certified Ads SDK — a version on Google’s published list, since certification is per version, not per vendor — with no interest-based advertising and no remarketing. Apple’s Kids Category permits third-party advertising only as contextual advertising, and only from a provider whose Kids Category practices are publicly documented and include human review of ad creatives (Keel authors Apple’s rules but has not shipped them — see below). Those are three different rules, not three wordings of one, and they conflict: an SDK that satisfies Google’s certification does not make your ads contextual-only for Apple, and neither store’s permission touches Amazon’s flat bar on its own programmes. Monetisation has to be planned per store.
- New These are contracts, not standards: no store publishes a version number, a ratification date or a change log, and all of them rewrite without notice. So each framework carries the date Keel retrieved the source — 2026-08-13 — in place of a version, and both the framework and the catalog entry name the exact source URL. Where a store numbers nothing, Keel uses its own visibly-Keel reference scheme (families/ads/certified-sdk-only, child-directed/sdk/child-suitable) rather than inventing clause numbers that would look like citations the store publishes. One live consequence to know about: Google has a replacement Families policy taking effect on 2026-08-26 that expands the restriction on anonymous chat apps targeting children. Keel models the policy in force today, not the preview, and both the framework and the completeness record say so.
- New Applying either framework seeds a starter control set built for children’s apps: app-store audience declarations and metadata, child-appropriate experience and parental gates, children’s advertising and monetisation controls, third-party SDK and API governance, neutral age screening for mixed audiences, and online-safety controls for social features — alongside the COPPA controls Keel already shipped for the audience determination, privacy notices, verifiable parental consent, parent review and deletion, and minimised collection. Those controls crosswalk across all of them, so one audience determination, one SDK inventory and one age screen count toward every children’s framework you run, plus the ISO 27001, SOC 2, GDPR and other work already in place.
- Improved Apple’s Kids Category rules were authored but held back when this release shipped, and that was on purpose. Google and Amazon each publish a single, delimited children’s policy that can be enumerated end to end; Apple does not — its children’s duties are spread across 125 numbered App Review Guidelines that all bind the same developer, and Guideline 1.3 points at a separate parental-gate page. Any boundary between "Apple’s kids rules" and the rest of that document is Keel’s, not Apple’s, and Keel will not declare itself complete against a line it drew silently. That scope question has since been settled the only way it honestly can be: the rule is stated — a guideline is in scope if its duty is triggered by a child, a minor, an underage user, or by the Kids Category — the parental-gate page has been retrieved and modelled, and every excluded guideline is enumerated by number in the framework file, so the line is published rather than merely drawn. That is the same shape as Keel’s HIPAA, which is complete against a declared subset of 45 CFR 164. This paragraph originally ended by saying the framework would stay unavailable until a scheduled September launch date. That is no longer true and is corrected here rather than left standing: Apple went live on 2026-08-13, the same day, and is announced in 1.74.0 above.
-
v1.72.0
COPPA is live
- New COPPA — the FTC’s Children’s Online Privacy Protection Rule, 16 CFR Part 312, as amended in 2025 — is now available and can be applied in one click. It went live on 2026-08-13, the date the catalog carries. The Rule binds operators of websites and online services directed to children under 13, and any operator with actual knowledge that it collects personal information from a child; it is not a general children’s or teen privacy law, and Keel does not present it as one. Keel models it at the Rule’s own paragraph level rather than one item per section, because §312.8(a)’s reasonable procedures and §312.8(b)(3)’s safeguards sized to the volume and sensitivity of the data at risk are separate duties with separate evidence. That comes to 32 scored requirements: the prohibition on unlawful collection, notice to parents and on the service, verifiable parental consent and the narrow exceptions to it, the parent’s right to review and delete, the ban on conditioning a child’s participation on excess collection, the written children’s information security programme, and the retention-and-deletion duty. The framework is declared complete in Keel’s completeness model against the eCFR text of Part 312, and a test fails the build if the authored count ever drifts from the 32 the Rule’s scored provisions come to.
- New Only obligations binding an operator are scored — the same line Keel draws for GDPR. Scope and definitions, enforcement, the safe harbor programme requirements, and the Commission’s voluntary approval processes are cited for reference but are not part of your readiness score: you cannot implement the Commission’s duties or a safe harbor programme’s, and loading them into the denominator would deflate every score for no compliance benefit. This is not a claim that they do not apply — an operator is subject to the whole Part. Every excluded provision is listed by number in the framework’s source, so the scope is auditable rather than a matter of taste.
- New Applying COPPA seeds a starter control set built for the Rule: a programme-level assessment of whether the service is directed to children, the direct and online notices, verifiable parental consent, handling of the consent exceptions, parent review, refusal and deletion requests, and minimised collection in children’s activities — alongside the security programme controls the Rule leans on, covering access control and MFA, encryption, logging and monitoring, vulnerability management, vendor management, data classification, retention and disposal, incident response, risk assessment and internal audit. Those controls are crosswalked to the frameworks you may already run, so evidence collected for ISO 27001, SOC 2, NIST 800-53, PCI DSS, HIPAA or GDPR counts toward COPPA too.
-
v1.71.0
NIST SP 800-171 is live
- New NIST SP 800-171 Rev. 2 is now available and can be applied in one click. All 110 security requirements, across all 14 families — Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. Not a selection of the important ones: the framework is declared `complete` in Keel’s completeness model, and a test fails the build if the authored count ever drifts from the 110 the published standard defines.
- New 800-171 is the requirement set a CMMC Level 2 assessment is conducted against, which is why it decides whether many suppliers can bid on defense work at all. Keel is not an assessor and does not certify you — a C3PAO does that. What Keel gives you is every requirement they will assess, in front of you, with your evidence already mapped to it.
- Improved Because 800-171 runs on the same crosswalked control library as everything else, work already done for ISO 27001, SOC 2, NIST 800-53 or CIS Controls counts toward it immediately rather than being re-collected under a new label. A workspace that has been running another framework does not start 800-171 at zero.
- Improved Launched 2026-08-11, ahead of the 2026-09-07 date the catalog previously advertised. The content was finished; the date was not waiting on it.
-
v1.70.0
GDPR is live
- New GDPR (Regulation (EU) 2016/679) is now available and can be applied in one click. Keel models every provision of the Regulation that binds a controller or processor, at the Regulation’s own numbered-paragraph level rather than one item per Article — because Article 30(1), the controller’s register, and Article 30(2), the processor’s register, are different documents with different owners and different evidence. That comes to 110 scored requirements: Chapters II to V (principles and lawful basis, data-subject rights, controller and processor obligations, and transfers to third countries) plus Article 89(1) on research and archiving safeguards.
- New What Keel does not score, it says so rather than quietly counting it. Provisions addressed to Member States, the Commission, supervisory authorities and the European Data Protection Board, and Chapter VIII’s remedies, liability and penalties, are cited for reference but are not part of your readiness score — you cannot implement a supervisory authority’s duties, and loading them into the denominator would deflate every score for no compliance benefit. This is not a claim that they do not apply: a controller is bound by the whole Regulation. Every excluded provision is listed by number in the framework’s source, so the scope is auditable rather than a matter of taste.
- New Applying GDPR seeds a starter control set covering individual privacy rights, data classification, retention and disposal, vendor and processor management, encryption, access control and MFA, logging and monitoring, incident response, business continuity, and security awareness. Those controls are crosswalked to the frameworks you may already run, so evidence collected for ISO 27001, SOC 2, NIST 800-53, PCI DSS or HIPAA counts toward GDPR too. The Processing records (RoPA) and DPIA screener pages Keel already shipped now sit alongside the framework that requires them.
-
v1.69.0
Automated checks now file evidence
- New A passing automated check now files real evidence against the control it backs. Keel already ran credential-free TLS, security-header, SPF and DMARC checks every six hours; until now those results lived only in the check history. Each check keeps one evidence record, refreshed in place on every sweep, so the evidence list stays readable rather than filling up with a row per run. Nothing is backfilled: evidence appears on the next sweep, or straight away if you use “Run all checks now”.
- New Evidence from a check is withdrawn when the check stops passing — on a failure, on an error that stopped it running, and when you pause it. A check that cannot run is not proof of anything, and a paused check is no longer being re-proven, so leaving the record in place would show you evidence that is no longer true. Withdrawal happens at the run that observes it, except for pausing, which takes effect immediately. When a check stops passing, Keel emails the control’s accountable party once — not on every subsequent failing sweep — falling back to the workspace’s owners and admins when no accountable party has been assigned in RACI.
- Improved Because these records are re-proven every six hours rather than ageing, they carry no expiry date and the freshness meter does not nag about them. They do count toward a control’s evidence readiness, so that figure now moves on its own as checks pass and fail. Evidence is only ever filed against a control the check’s control key actually matches; a key matching nothing files nothing, and the checks page says so rather than implying coverage you do not have. If the control is later deleted or the key is changed to one that matches nothing, the evidence is withdrawn rather than left behind unlinked.
-
v1.68.0
US employment law, state by state
- New US employment law now works end to end. Record the states you employ people in and Keel shows the federal baseline plus that state’s deltas, grouped by topic, each requirement labelled with whether it comes from federal law or a named state and citing the statute it paraphrases. Overlays cover all 50 states and DC. With no states selected you see the federal baseline alone: Keel does not guess a footprint, because the wrong state means the wrong obligations. Find it under Frameworks, or at /frameworks/employment.
- New The employment framework now ships a full control set. Applying it creates canonical controls for worker classification, statutory leave, benefit plan administration, anti-discrimination and accommodation, workplace notices, protected activity, and workforce-reduction notice, each with evidence guidance and auditor questions. Crosswalks to the other frameworks are deliberately conservative: we map only where the same control genuinely satisfies both.
- Fixed US employment law was missing from the in-app framework catalog and the pricing page because both grouped frameworks by a hand-maintained category list that had never been updated for it. That list is now derived from a single source, so a category cannot exist without a place to render.
-
v1.67.0
Explore Keel live, no signup
- New There’s now a public, read-only demo of Keel you can click through without signing up. It’s a fully-loaded sample workspace — a program overview with readiness scoring, the control register with its framework crosswalk, the risk register, the third-party vendor register, and the policy library — so you can see how the pieces fit together before creating an account. The demo is genuinely live (real pages, real data), not a set of mock-ups, and a nightly job restores anything missing from the dataset. It’s surfaced from the homepage, the product page, and the docs, and links straight to app.keelgrc.com/demo.
-
v1.66.0
Vendor & posture health scoring
- New Vendors now carry a credential-free health score you can recompute on demand. Keel reads public signals — the domain’s DNS email authentication (SPF and DMARC) and a keyword match against the CISA Known-Exploited-Vulnerabilities catalog — and combines them into a 0–100 score and a Strong/Fair/Weak band, with a plain-language rationale for every point. It uses no questionnaire, no credentials, and no AI credits, and it’s deliberately conservative: a signal it can’t observe scores as “unknown” and earns no credit rather than being assumed to pass. Point the same checks at your own claimed domain to see your self-posture — the SPF/DMARC and KEV picture a prospect or auditor could observe about you. It’s a best-effort external signal, not a penetration test: the KEV match is keyword-based and DKIM, TLS, and a scheduled refresh are not yet included.
-
v1.65.0
A free, no-signup tools hub
- Improved The free tools hub at /tools is now a proper $0, no-signup entry point: a clear "no credit card, no email wall" promise up top, per-tool time-to-value, and one-click access to the SOC 2 cost calculator, the compliance readiness self-assessment, the framework crosswalk explorer, and the SOC 2 evidence kit. It is promoted from the homepage and footer so a first-time visitor can get a real answer in minutes, then start a genuinely free program (NIST CSF and AI Governance Essentials are free on every plan).
-
v1.64.0
Know what your AI drafted vs what a human approved
- New Every piece of AI-generated content in Keel now carries a clear provenance label so you - and your auditors - know exactly what to trust. AI-drafted control guidance, policy-gap and readiness analyses, evidence and trust-centre narratives, access-review notes, questionnaire answers, vendor risk drafts, and AI Insights all show an "AI-drafted — review before use" badge, alongside the grounded answering engine's existing confidence and "confirm internally" signals. Content is never shown as human-reviewed unless a person actually approved it. The sign-off step itself - marking content reviewed so the badge flips to "Human-reviewed" with who approved it and when - is built and rolling out behind a flag; until it is switched on for your workspace, AI output always displays as AI-drafted.
-
v1.63.0
Evidence-readiness meter
- New A new evidence-readiness meter shows how audit-ready your evidence actually is, as "N of M expected evidence artifacts present". The expected count is drawn from Keel’s own "evidence to collect" guidance for the controls in your program — the concrete artifacts an auditor expects — so it’s never an invented number. The present count is the evidence you’ve linked, counted per control and capped at what that control expects, so the meter can never over-state your coverage. It appears on the dashboard for the framework you’re viewing (following the framework switcher) and across your whole program in questionnaire assist. It’s derived entirely from evidence you already have — nothing new to fill in, and it uses no AI credits.
-
v1.62.0
Deeper AI-governance control coverage
- Improved The one-click starter control library now covers AI governance in depth: twelve new canonical controls - AI policy, AI roles and accountability, AI risk management, data governance for AI, responsible development, verification and validation, technical documentation, logging and records, transparency and disclosure, monitoring and incident reporting, responsible use, and AI supplier management - each pre-crosswalked to ISO 42001, the NIST AI RMF, and the EU AI Act. Every mapping points to a real, authored clause (checked by a test), and the open compliance-crosswalks dataset was regenerated to match.
-
v1.61.0
Accountable sign-off on vendor assessments
- Improved Vendor-assessment decisions now scale with the vendor’s risk. Accepting or rejecting a critical- or high-tier vendor requires an accountable sign-off - an approver’s name and a written rationale - and accepting one requires a completed (submitted or scored) assessment first. Lower-tier vendors keep the quick one-click decision. The approver is recorded and shown on the decision, giving you the risk-based due-diligence trail auditors look for.
-
v1.60.0
Build your continuity register from scenarios
- New Business continuity has a new "Build from common scenarios" button that populates your continuity register with the disruptions most organisations should plan for - office loss, a cloud/SaaS outage, ransomware, data loss, a key supplier failing, loss of a key person, and finance systems going down - each pre-filled with a suggested criticality, RTO/RPO, impact, dependencies, and recovery strategy to adapt. It skips anything already in your register, so it is safe to run more than once.
-
v1.59.0
Records of Processing Activities (GDPR Article 30)
- New A new "Processing records (RoPA)" page maintains your GDPR Article 30 register - one record per activity where you process personal data, capturing its purpose, lawful basis, the data and people involved, recipients, retention, international transfers, and security measures. One click auto-populates it with the activities most companies run (HR, customers, billing, marketing, support, analytics) so you can adapt them instead of starting from a blank page.
-
v1.58.0
Staff security rules digest
- New A new "Staff security rules" page gives you a plain-language, shareable digest of what everyone at the company needs to do - passwords and MFA, phishing, devices, handling data, working remotely, and reporting a problem. Use it in onboarding, pin it on your intranet, or print it as a one-pager; it backs up the security-awareness expectations behind ISO 27001 and SOC 2.
-
v1.57.0
Risk scenario library
- New A new "Risk scenario library" saves you from starting your risk register on a blank page. It offers a curated set of common information-security risk scenarios for small and mid-sized teams - phishing, ransomware, lost devices, supplier breach, cloud misconfiguration, and more - each with a suggested inherent likelihood and impact and the ISO 27001 Annex A control areas that typically treat it. One click adds a scenario to your register, ready to refine and link to your controls.
-
v1.56.0
DPIA threshold screener
- New A new "DPIA screener" tells you whether a processing activity needs a Data Protection Impact Assessment under the GDPR. Tick what applies and it decides live, based on the mandatory cases in Article 35(3) and the European Data Protection Board’s nine criteria (two or more generally require a DPIA). It’s a screening aid, not legal advice, and prompts you to record the decision either way.
-
v1.55.0
Approved AI services register
- New A new "AI services register" keeps an inventory of the AI systems and tools your organization has vetted for use - the record ISO 42001 (AI management system) and the EU AI Act expect you to maintain. Log each service with its purpose, the data categories it processes, an EU AI Act risk tier (prohibited / high / limited / minimal), an owner, and an approval status (approved / under review / rejected / retired).
-
v1.54.0
Risk ↔ SoA coverage checker
- New A new "Risk ↔ SoA coverage" page runs the cross-check an ISO 27001 auditor makes: it reconciles your Statement of Applicability against your risk register and flags the gaps - applicable Annex A controls that no risk traces to (Clause 6.1.3), and risks you've chosen to mitigate that have no implemented control behind them yet. It's fully deterministic (no AI) and updates live from your controls and risks.
-
v1.53.0
AI opt-out enforced at the model layer
- Improved If a workspace switches AI off, that opt-out is now enforced at the single point where Keel talks to the AI model - not just in each feature. In practice AI already stopped for every feature when you turned it off; this makes the guarantee hold by construction, so no current or future feature can reach the model while your workspace is opted out. Keel processes no tenant content through AI when AI is off.
-
v1.52.0
HTTPS-only hardening
- Improved Every Keel domain now sends its HSTS header with the "preload" directive, so browsers can enforce HTTPS-only from the very first visit once the domain is on the HSTS preload list. It is a small hardening step that removes the brief window on a first connection where a downgrade attack is theoretically possible.
- Improved Both the app and the marketing site now send an enforcing "upgrade-insecure-requests" policy, so any resource referenced over http is silently upgraded to https before it loads - no page content can be fetched over cleartext, even from a stray link.
-
v1.51.0
Download your Statement of Applicability as Excel
- New The Statement of Applicability now has a "Download SoA (Excel)" button alongside the PDF. It exports the full Annex A grid auditors expect - one row per control with separate "Justification for inclusion" and "Reason for exclusion" columns, the implementation status, and the related controls - plus a header block with your organization, framework, ISMS scope, and approval details. Generated live from your controls, so it always matches what is in Keel.
-
v1.50.0
Draft auditor answers from your own evidence
- New On any control, "✦ Draft auditor answers" now has AI write suggested answers to that control’s common auditor questions, grounded in the evidence you have actually linked to it. Each answer points to the specific evidence that supports it and flags the gaps where you still need to collect something, so you can walk into an audit prepared. Like Keel’s other AI tools it works from your evidence metadata (not the file contents), hedges accordingly, never invents evidence you do not have, and is a draft to review. Uses AI credits.
-
v1.49.0
Know what an auditor will ask
- New Every control now shows a "What an auditor will ask" panel: the common questions an auditor tends to ask when testing that control, so you can rehearse and line up the right evidence before your audit. The questions are generic, practical prompts (for example, "Show me deprovisioning for a recent leaver, how quickly was access removed?"), curated across all of Keel’s canonical controls. AI-drafted answers grounded in your own evidence are coming next.
-
v1.48.0
A guided path to ISO 27001 certification
- New A new "Get certified" page lays out the ISO/IEC 27001 journey as six milestones, define your ISMS scope, run your risk assessment, implement your controls, generate your Statement of Applicability, complete an internal audit, and hold a management review. Each milestone flips to done automatically based on what is actually in your workspace (real risks logged, a versioned SoA, a completed audit, a held review), not a checklist you tick yourself, so you always know the real next step toward your certification audit.
-
v1.47.0
See what each control counts toward
- New Every control now shows an "Also counts toward" panel: the clauses that one control helps satisfy across the frameworks you have enabled, drawn from Keel’s crosswalk library. Map a control once and see, at a glance, that it counts toward (for example) ISO/IEC 27001, SOC 2, and NIST SP 800-53 at the same time, with a marker on the clauses you have already mapped to it. It is the "collect once, comply everywhere" idea made visible on every control.
-
v1.46.0
Start with a 14-day free trial of Pro
- New Every new workspace now starts on a 14-day free trial of the Pro plan - no credit card required. You get the full Pro experience (more frameworks and seats, AI assist, integrations and API, and the full trust center) from day one. A banner keeps track of how many days are left, and you can upgrade any time to keep Pro. When a trial ends, the workspace simply moves to the Free plan and all of your data stays exactly where it is - nothing is deleted.
-
v1.45.0
Controls now crosswalk to NIST SP 800-53
- Improved Keel’s canonical controls are now crosswalked to NIST SP 800-53 Rev. 5 (the FedRAMP / 800-53B Moderate baseline). Each security control maps to the specific 800-53 control identifiers it helps satisfy (for example multi-factor authentication to IA-2, encryption to SC-8 / SC-13 / SC-28, and incident response to IR-4 through IR-8), so the evidence you already collect counts toward an 800-53 program too. The open compliance-crosswalks dataset grows to 45 controls across 15 frameworks (300 mappings).
-
v1.44.0
AI controls now crosswalk to four AI frameworks
- Improved The three AI-governance controls (AI system inventory, AI system impact assessment, and human oversight of AI) are now crosswalked to the EU AI Act and Keel’s AI Governance Essentials baseline, on top of their existing ISO/IEC 42001 and NIST AI RMF mappings. Each reference points to the specific article or clause the control helps satisfy, so one control counts toward all four at once. The open compliance-crosswalks dataset grows to 45 controls across 14 frameworks (248 mappings) as a result.
-
v1.43.0
Cookie consent and a fuller set of legal pages
- New Our marketing site now asks for your consent before loading any analytics or marketing cookies. Everything optional is off by default: you can accept all, reject all, or choose by category, and change your mind any time from the new "Cookie preferences" link in the footer. We also honor Global Privacy Control and Do Not Track browser signals. As a GRC company we hold ourselves to the same bar we help customers meet.
- New Published a fuller set of legal pages: a Terms of Service, a standalone Cookie Policy that lists every cookie and how long it lasts, a Data Processing Addendum (DPA) for customers who need one, and an Acceptable Use Policy, all linked from the site footer alongside our existing Privacy policy.
-
v1.42.0
Canonical controls for AI governance
- New Added three canonical controls for AI governance: an AI system inventory, an AI system impact assessment, and human oversight of AI. Like every canonical control, each is pre-mapped to the framework clauses it helps satisfy (here ISO/IEC 42001 and the NIST AI Risk Management Framework), so applying one counts toward your AI-governance program automatically. The open compliance-crosswalks dataset grows to 45 controls across 12 frameworks (240 mappings) as a result.
-
v1.41.0
A bigger open crosswalks dataset
- Improved Our free, openly licensed compliance-crosswalks dataset now carries 233 control-to-clause mappings across 10 frameworks, up from 216. Each mapping ties one of our canonical controls to a specific clause it helps satisfy, so you can see at a glance where a single control counts toward more than one framework. It stays free to use and cite under CC BY 4.0, published as JSON and CSV.
-
v1.40.0
Verified access for shared incident pages
- Improved Shared incident status links now require email verification before anything is shown. When a recipient opens their link, Keel emails a 6-digit code to the exact address the link was issued to and asks them to enter it. A forwarded link can’t be used to view the page, because the code only ever goes to the original recipient. Codes are single-use and expire in 10 minutes, and once someone verifies, their browser is remembered for 7 days so they aren’t asked again during that window.
-
v1.39.0
Share incident status with the clients affected
- New When a security incident affects a customer, you can now share a private, live status page for that one incident. Turn on sharing, write a plain-language impact statement, and add each contact to create their own link. They see only the updates you choose to publish, never your internal notes, on a page that carries your own logo and brand color from your Trust Center, with a live timeline, a phase stepper, the severity, when it was last updated, and an optional “next update expected by” time.
- New Recipients can acknowledge receipt, subscribe to be notified of new updates, reach the contact you set, and save a clean, branded PDF of the incident for their records. As the owner you can set a link expiry, resend a recipient their existing link, revoke any link instantly, and see a read-receipt roll-up of who has viewed and acknowledged. The page refreshes itself while an incident is live. There is no universal public status page, only these per-recipient links.
-
v1.38.0
Migrate more of your program, in bigger moves
- Improved keel-migrate now brings your evidence documents across too, not just policies. The actual approved files are downloaded from your source platform’s official API, checksum-verified, and stored in your Keel evidence library on import. A few items a platform shares only as a link (for example Vanta’s approved-policy PDFs) still need a manual export.
- New A beta OneTrust source joins Vanta and Drata (it exports your users and risk register today). As always, the tool runs on your own machine against each platform’s official read-only API, and your credentials never leave your computer.
- Improved Very large exports are now split into several bundle files automatically, so a big evidence library exports and imports reliably within memory limits. Import each file in any order; the idempotent matching keeps everything de-duplicated.
-
v1.37.0
Bring your policy documents with you
- Improved When you migrate into Keel, your policy documents now come with you, not just a link. keel-migrate downloads the actual approved files from your source platform and inlines them in the bundle, and Keel stores them in your evidence library on import, so the documents survive after you cancel the old tool. Files are checksum-verified and held to the same size and storage limits as any upload.
-
v1.36.0
Migrate to Keel, plus richer vendor & people risk
- New Bring your data to Keel with keel-migrate, an open-source, read-only tool you run on your own machine to export your vendors, risks, people, and policies from Vanta or Drata into an open bundle, then import it into your workspace in a few clicks. Your source credentials never leave your computer, and re-imports are idempotent, so nothing is duplicated.
- Improved Vendor risk now separates inherent (pre-control) from residual (post-control) criticality, and can auto-lower the residual from a vendor’s access controls: MFA, SSO, and password-policy strength.
- New People can be tagged with groups, and both access reviews and training can be scoped to a group. Each person now has a readiness rollup that unifies training completion and policy acknowledgements into a single onboarding view.
- New The public API gained people and policies endpoints, so you can sync your directory and policies into Keel programmatically via the REST API and webhooks.
-
v1.35.0
Keel Quality: change control (Clause 6.3 / 8.5.6)
- New A new Change control module brings ISO 9001 Clause 6.3 (planning of changes) and 8.5.6 (control of changes) into Keel Quality. Raise a change request for a process, product, document, supplier, or system, and work it through a controlled lifecycle: requested → assessing → approved / rejected → implementing → verified → closed, with an impact assessment, a risk level, an approver, and post-change verification.
- New Changes awaiting approval and high-risk changes surface on the Quality dashboard, so nothing significant changes without review.
-
v1.34.0
Keel Quality: customer complaints & feedback (Clause 9.1.2)
- New A new Complaints & feedback module captures customer complaints however they arrive (email, phone, portal, in person, social, or survey), the ISO 9001 Clause 9.1.2 (customer satisfaction) and 10.2 (nonconformity) requirement. Track each through open → investigating → resolved → closed with a severity, the customer, and the resolution.
- New When a complaint reveals a systemic problem, raise a CAPA from it in one click: the nonconformity is created and linked back, so a customer complaint flows straight into root-cause analysis. Open and high-severity complaints roll up onto the Quality dashboard.
-
v1.33.0
Keel Quality: supplier quality & SCARs (Clause 8.4)
- New A new Supplier quality module brings ISO 9001 Clause 8.4 (control of externally provided processes, products, and services) into Keel Quality. Keep an approved-supplier list with each supplier’s category, qualification status (pending / approved / conditional / disqualified), and a 0–100 quality score, and set a re-evaluation date that Keel flags when it comes due.
- New Raise Supplier Corrective Action Requests (SCARs) against a supplier and drive each to closure through open → containment → corrective action → verify → closed, the supplier-facing sibling of your internal CAPA loop. Open SCARs surface on the supplier list and the Quality dashboard.
-
v1.32.0
Quality dashboard
- New Keel Quality now has a home: a single Quality dashboard that pulls your whole quality-management system onto one surface: nonconforming outputs, nonconformities & CAPA, the audit programme, objectives, competence, and document control, each with its live counts and a link straight to the module.
- New A “Needs attention” roll-up at the top surfaces exactly what’s overdue or at risk right now: NCRs awaiting disposition, CAPA verifications due, audits overdue, objectives at risk, competence gaps, and documents past review, so a quality manager sees the day’s priorities the moment they land.
-
v1.31.0
Document awareness & acknowledgment (Clause 7.3)
- New Controlled documents can now require the right people to read and acknowledge them, the ISO 27001 Clause 7.3 awareness expectation. Add required readers to any document in the Documented information register and track who has acknowledged the current version and who’s still pending.
- New When you publish a new version of a document, every reader’s acknowledgment resets to pending automatically, so people must confirm they’ve read the revision. No more wondering whether the team saw the update. Publishing a version also stamps the document as published in one step.
-
v1.30.0
Audit programme & calendar (Clause 9.2.2)
- New A new Audit programme plans your internal audits across a period, the ISO 27001 / 9001 Clause 9.2.2 requirement. Create a programme (period + objectives), then schedule audits by process/area with an assigned auditor and a planned date. An upcoming-and-overdue calendar view shows what’s due next across every programme, with overdue and due-soon flags.
- New Set a cadence on any scheduled audit (e.g. every 12 months) and Keel rolls the next occurrence forward automatically when you launch it, so your annual plan maintains itself instead of being re-typed each year. Launch a scheduled audit in one click and it becomes a full internal audit, pre-filled and linked back to the schedule.
-
v1.29.0
Deeper CAPA: action types, 8D, and effectiveness scheduling
- New Corrective actions now carry a type: correction (immediate containment), corrective (removes the root cause), or preventive (stops it happening elsewhere), so a nonconformity’s response reads the way ISO 9001 / 27001 Clause 10 expects, not as one undifferentiated to-do list.
- New Schedule the effectiveness check: set a date to re-verify that a fix actually held, and Keel flags it on the nonconformity and on the register when it comes due, so “we’ll check later” doesn’t quietly slip.
- New Optional 8D report: for significant or recurring problems, turn on the structured Eight Disciplines (D1–D8) template (team, problem, interim containment, root cause, permanent corrective actions, implementation, prevention, and closure) right on the nonconformity.
-
v1.28.0
Keel Quality: nonconforming outputs (NCR, Clause 8.7)
- New Introducing Keel Quality, a new add-on that brings the product-quality half of ISO 9001 onto the same control-and-evidence graph as your ISMS. The first module is a nonconforming-outputs (NCR) register for ISO 9001 Clause 8.7: log a nonconforming product or output, record where it was found and how much is affected, contain it in quarantine, and capture the disposition decision: use-as-is (concession), rework, repair, scrap, return to supplier, regrade, or segregate, with the authority who approved it and re-verification of conformity after rework.
- New When an NCR needs root-cause, raise a CAPA from it in one click: the nonconformity is created and linked back, so Clause 8.7 (nonconforming outputs) and Clause 10.2 (corrective action) stay connected. Filter the register by status or disposition, and read your posture from summary tiles: awaiting disposition, critical open, units affected, and closed.
- Improved Keel Quality is a paid add-on layered on any plan. It’s managed from Billing; pricing is being finalized.
-
v1.27.0
Documented information register (Clause 7.5)
- New A new Documented information register gives you the controlled master list of every document your ISMS depends on, the ISO 27001 Clause 7.5 requirement. Register policies, procedures, work instructions, forms, records, plans, and manuals, each with a document code, owner, approver, security classification, version, lifecycle status, and where the controlled copy lives. It sits alongside the Policies module, which holds your authored policy bodies.
- New Every document gets a review cadence and a next-review date, and Keel flags anything overdue or due within 30 days, right on the register and on each document, so controlled information never quietly goes stale. Mark a document reviewed and the next-review date rolls forward automatically. Add a retention rule and a distribution note to close out the Clause 7.5 control.
- Improved Filter the register by document type or status, and read your posture at a glance from summary tiles: published, in progress, review overdue, due soon, and retired.
-
v1.26.0
Automatic vendor risk scoring
- New When you review a submitted vendor assessment, Keel now computes a weighted risk score (0–100) and a suggested tier (low, medium, high, or critical) straight from the answers. Each scored question is weighted by how material it is, risky or missing answers count against the vendor, and any response you flag as a finding is folded in too. The breakdown is shown, so the number is transparent, not a black box.
- Improved Apply the suggested score in one click and Keel sets the vendor’s risk tier for you. No more picking it by hand. You stay in control: it’s a suggestion you apply, and you can still accept or reject the assessment separately.
-
v1.25.0
Competence & training-gap matrix (Clause 7.2)
- New A competence matrix, the ISO 27001 Clause 7.2 requirement to show the people doing security work are competent for it. For each person and role, record the competences they need, how each is established (education, training, experience, or certification), a status (met, in progress, or gap), and the evidence, with an expiry on time-bound certifications.
- New See at a glance how many competences are met, how many are gaps, and which certifications expire within 60 days, the training-gap view that pairs with the Training module and closes the loop on Clause 7.2.
-
v1.24.0
Business continuity & BIA register (Annex A 5.29 & 5.30)
- New A business impact analysis and continuity register, the ISO 27001 Annex A 5.29 (information security during disruption) and 5.30 (ICT readiness for business continuity) requirement. For each critical process or service, capture its criticality, recovery objectives (RTO and RPO), the impact of disruption, its dependencies, and a recovery strategy, then record each continuity test so ICT readiness is evidenced, not assumed.
- New See at a glance how many processes are high or critical, how many have had their continuity tested, and which are still untested or missing an owner, the readiness view an auditor expects for 5.29 and 5.30.
-
v1.23.0
Security objectives & KPIs (Clause 6.2)
- New Set measurable information security objectives and track them to target, the ISO 27001 Clause 6.2 requirement. Each objective carries a metric, a baseline, a target, and a current value, an owner, a target date, and a status (not started, on track, at risk, achieved, or missed), so your program has goals to steer by, monitored over time, not just controls to maintain.
- New See at a glance how many objectives are achieved, on track, or at risk, and which still need an owner, the measurable, monitored objectives an ISO 27001 auditor expects under Clause 6.2.
-
v1.22.0
Legal & regulatory requirements register (Annex A 5.31)
- New A register for the legal, statutory, regulatory, and contractual requirements that apply to you, the ISO 27001 Annex A 5.31 obligation. Record each requirement with its type, jurisdiction, and citation, assign an accountable owner, and track a compliance status (met, partially met, not met, or not yet assessed) with a note on how you meet it.
- New See at a glance how many obligations are met, how many have gaps, and which are still unassessed or missing an owner, so nothing an auditor asks about is a surprise.
-
v1.21.0
Information asset register (Annex A 5.9 & 5.12)
- New An information asset register, the ISO 27001 Annex A 5.9 (inventory of information and other associated assets) and 5.12 (classification of information) requirement. Inventory each asset with a type, an accountable owner, and a classification (public, internal, confidential, restricted), then rate it for confidentiality, integrity, and availability. It’s the foundation the rest of your ISMS builds on: every risk, control, and Statement of Applicability decision traces back to the assets you’re protecting.
- New See at a glance how many assets are confidential or restricted, how many carry a high CIA rating, and which are still missing an owner, so gaps in your inventory are obvious before an auditor finds them.
-
v1.20.0
Management reviews (Clause 9.3)
- New A management review module, the ISO 27001 / 9001 Clause 9.3 requirement. Keel pre-fills the agenda with the inputs the standard asks for, pulled live from your program: internal audit results, open nonconformities, security incidents, and per-framework readiness. Record attendees, minutes, and decisions, and track the action items that come out of the review to done.
- New Export branded, auditor-ready management-review minutes (PDF), with the agenda inputs, minutes, decisions, and actions, the record a certification auditor expects for Clause 9.3. This completes the run-and-prove-your-ISMS set: SoA, internal audit, nonconformities & CAPA, incidents, and management review.
-
v1.19.0
Security incident register (Annex A 5.24–5.28)
- New A security incident register: the ISO 27001 Annex A 5.24–5.28 workflow, and the record SOC 2 auditors expect. Report an incident with a severity, then work it through its lifecycle: investigate, contain, find the root cause, and capture lessons learned, with an at-a-glance view of what’s open and how many high-severity incidents are still live.
- New Incidents feed corrective action: raise a nonconformity (CAPA) from any incident in one click, pre-filled from the incident and linked back, so the follow-up is tracked to closure with an effectiveness check.
-
v1.18.0
Internal audits (Clause 9.2)
- New An internal audit module, the ISO 27001 / 9001 Clause 9.2 requirement. Plan an audit against any framework you’ve enabled, and Keel generates a clause-by-clause checklist straight from that framework’s requirements. Work through it recording a result for each clause (conforming, nonconformity, observation, or opportunity for improvement) with notes.
- New Findings flow into corrective action: promote any nonconformity finding into the CAPA register in one click, pre-filled and linked back to the audit. Export a branded, auditor-ready internal audit report (PDF) with the scope, conclusion, and every finding.
-
v1.17.0
Nonconformities & corrective action (CAPA)
- New A nonconformity & corrective-action (CAPA) register, the ISO 27001 / 9001 Clause 10 loop. Log a nonconformity (from an audit, an incident, a risk, or a control gap), work a guided root-cause analysis (5 Whys or Fishbone), assign corrective actions with owners and due dates, and track each one to done.
- New A real closure gate: a nonconformity can only be closed once you’ve recorded and confirmed that the corrective action was effective, the effectiveness-verification step auditors look for, enforced by the workflow, not left to a checkbox in a spreadsheet.
-
v1.16.0
Statement of Applicability: your ISO 27001 SoA, generated
- New A Statement of Applicability (SoA) generator, the mandatory ISO 27001 deliverable (Clause 6.1.3). Keel builds it from your program: every one of the 93 Annex A:2022 controls, whether it applies, a justification for inclusion or exclusion, and its live implementation status pulled from the controls you’ve already mapped. Export a branded, auditor-ready SoA PDF in a click.
- New Applicability stays in sync with your scope: excluding an Annex A control on the SoA (or on the Scope page) updates both, and your readiness score, from one place. Add document-control details (version, ISMS scope statement, approver and date) that print on the SoA header.
-
v1.15.0
CIS Critical Security Controls v8.1 is live
- New CIS Critical Security Controls v8.1 is now available: all 18 Controls and 153 Safeguards, organized by Implementation Group (IG1–IG3). Apply it in one click and Keel seeds the recommended controls, crosswalked so evidence you collect for SOC 2, ISO 27001, NIST, PCI, or HIPAA counts toward CIS too.
- New A CIS-scoped “evidence to collect” guide: for each control CIS expects, see the concrete artifacts that satisfy it and which ones you still need. The reference doubles as a per-framework gap checklist.
-
v1.14.0
A policy template library, continuous checks & bulletproof backups
- New A library of 50+ framework-mapped policy templates (ISO 27001, SOC 2, GDPR, CIS Controls, ISO 9001 and more). Search, filter by framework, and create an editable draft with your company details pre-filled, then version, approve, and export a branded PDF.
- Improved The Policies page is now a full register: search and status filters, per-policy owner and review-due dates, one-click bulk status and archive, and a coverage checklist that shows which recommended policies you still need. Create any gap straight from a template.
- New Reset any policy back to its template at any time. Your document-control fields are kept and the previous version is saved to the revision history first.
- New Continuous automated checks: credential-free monitors verify real-world controls over HTTPS and DNS (TLS/HTTPS, security headers, SPF, DMARC) on a schedule and record each pass/fail in the check’s dated run history.
- New Connect your own AI agents and tools to Keel through a Model Context Protocol (MCP) server over the Keel API: list controls, check readiness, and manage tasks and webhooks programmatically.
- Improved Reliability, hardened: nightly off-provider encrypted database backups with automated monthly restore drills, a deep health endpoint for external uptime monitoring, and a documented disaster-recovery / business-continuity runbook.
-
v1.13.0
A People page, smarter evidence & finer AI controls
- New Dedicated People page: manage your whole employee directory in one place: search, add, edit, and offboard, with each person’s training status at a glance. It feeds access reviews and training.
- New Questionnaire assist now takes a file: upload a Word, Excel, or CSV security questionnaire and Keel detects the questions and drafts answers grounded in your own controls and policies.
- Improved The Evidence page’s “evidence to collect” guide is now scoped to your enabled frameworks and marks, per control, whether you’ve already linked evidence, a running per-framework gap checklist.
- New Turn all AI off for a workspace with a single switch in Settings → AI credits; every AI button then disables until you switch it back on. AI credit activity also shows which user ran each action.
- Improved Training catalog filters (by topic and framework) and illustrated courses.
- Improved Program polish: a ⌘K command palette, teaching empty states, controls grouped by domain, evidence freshness tracking, and readiness-over-time trend charts on Reports.
-
v1.12.0
New frameworks on the way
- New Three more frameworks are landing on a rolling schedule - CIS Controls v8.1, GDPR, and NIST 800-171 (CMMC-aligned). See their launch dates in the Frameworks catalog.
- Improved The Frameworks catalog now shows a launch month for scheduled frameworks instead of a bare "Coming soon".
-
v1.11.0
Ten new AI tools & a dedicated MSP plan
- New Control implementation guidance: for any control, get plain-English steps and the exact evidence to collect.
- New One-click remediation tasks from a not-yet-met control, and AI-drafted risks straight from a vendor profile.
- New Questionnaire assist: draft answers to inbound security questionnaires from your own controls and policies.
- New Policy-gap analysis, audit-readiness executive summaries, evidence summaries, plain-language rewrites, trust-center narratives, and access-review anomaly notes - each an optional, credit-metered click.
- New MSP / Partner is now a dedicated plan with the multi-client console, white-label, and per-client partner pricing - separate from Enterprise. On scope, which this originally left open: white-label is entitled per workspace and resolves against the workspace being viewed, so it does not travel to the clients you provision. A client workspace created from the console starts on Free, and white-labels its own trust center once that workspace is itself on a partner or Enterprise plan, or carries the Trust Center Pro add-on.
-
v1.10.0
Welcome AI credits & promo codes
- New New workspaces start with a one-time welcome bonus of AI credits to try every AI feature - the unused remainder expires after a short window.
- New Redeem promo codes for bonus AI credits from Settings → AI credits.
-
v1.9.0
AI drafting for risks & policies
- New Draft risk-register entries with AI - tailored to your framework and company profile, scored, and ready to edit.
- New Draft a full policy from scratch with AI: name a topic and get a clean, framework-mapped first version in your editor.
-
v1.8.0
MSP client provisioning & guided-setup checklist
- New Create a new, isolated client workspace right from the MSP multi-client console (Enterprise) - you become its owner and can run guided setup for them immediately.
- Improved The dashboard getting-started checklist is now progress-driven and dismissible, linking straight to each remaining setup step.
- Fixed Support and Help links now resolve reliably to the in-app Help page and contact.
-
v1.7.0
Weekly digest
- New Opt-in weekly readiness digest email: readiness, gaps to close, open risks and tasks, vendors due for review, and outstanding training - summarized every week. Turn it on in Settings.
- Improved The on-demand "email me a digest" summary is now far more comprehensive.
-
v1.6.0
Training, governance & vulnerability monitoring
- New Security-awareness training: assign framework-mapped courses to your team, track completion, and auto-collect certificates as evidence.
- New RACI matrix across controls, policies, and risks - assign Responsible / Accountable / Consulted / Informed, with a printable export.
- New Executive board pack: a one-click management-review (ISO 27001 Clause 9.3) / steering-committee deck.
- New CISA Known Exploited Vulnerabilities (KEV) catalog with search and ransomware filtering, refreshed from CISA’s feed.
- New Risk heat map - a 5×5 likelihood × impact view of your register.
- Improved Vendor questionnaire portal: the vendor contact can invite colleagues to help answer, and any of them can submit.
- New Opt-in domain-based workspace join, so teammates on your company domain land in the same workspace.
-
v1.5.0
Vendor assessments & questionnaire builder
- New Send security questionnaires to vendors via a secure, no-login portal - with a library of 100+ curated questions.
- New AI questionnaire builder assembles a scored, structured questionnaire from your concerns in seconds.
- New Vendors can upload evidence files (SOC 2 reports, certs) directly in the portal.
- New Admin-managed global questionnaire catalog available in every workspace.
- Improved Automatic vendor risk scoring on submission, with reviewer flagging and findings.
-
v1.4.0
AI, embedded
- New AI policy & document import - drop in a Word doc and get a clean, framework-mapped policy.
- New AI vendor profiles: paste a website and Keel drafts the vendor’s risk profile.
- New Metered AI credits included on every paid plan, with pay-as-you-go top-ups.
- Improved Monthly AI credit allotment is now granted automatically.
-
v1.3.0
Risk register & reporting
- New First-class risk register with inherent/residual scoring, treatments, owners, and control links.
- New Branded, print-ready compliance readiness report.
- New Readiness digest you can email yourself.
-
v1.2.0
Team, trust center & integrations
- New Shared team workspaces with invites and owner/member roles.
- New Public, branded trust center to share your posture with prospects.
- New Directory sync (Microsoft Entra / Google) and periodic access reviews.
- New REST API and outbound webhooks (REST Hooks).
-
v1.1.0
Frameworks & evidence
- New One control library crosswalked across SOC 2, ISO 27001, PCI DSS, HIPAA, ISO 9001, NIST CSF, and ESG.
- New One-click starter control sets per framework.
- New Evidence library with control linkage and branded policy PDF export.
-
v1.0.0
Keel launch
- New Self-serve GRC: stand up a real compliance program in an afternoon - controls, evidence, policies, and readiness, no sales call.