Crosswalk-native GRC

Crosswalk-native GRC: author a control once, comply everywhere

In most GRC tools every framework is a separate checklist, so you re-do the same work for every audit. Keel inverts that. A control is the unit of work and each framework is a view over your controls, so a single control satisfies clauses across all the frameworks you have applied at once. Author your evidence once and it counts everywhere, on an open API you can automate and with data you can take with you.

Start free See the product

One control, many frameworks · REST API, webhooks & MCP · keel-migrate (MIT) · public pricing.

What sets Keel apart

Built around one idea: reuse the control, not the busywork

Crosswalk-native is the foundation, and three principles build on it. Each one is something Keel does today, not a promise.

Crosswalk-native

One control, many frameworks

Controls are the atom, frameworks are views over them. Author a control once and it satisfies clauses across every framework you have applied at the same time. Collect the evidence once, comply everywhere.

Connected

Fits the stack you already run

A REST API, outbound webhooks (REST Hooks), a Model Context Protocol (MCP) server for AI agents, a Zapier app (private beta), and directory sync. Your program is data you can read, push, and automate.

Portable

Your data leaves as easily as it arrives

keel-migrate is an open-source (MIT), read-only tool that exports your registers, policies, and evidence to a neutral, documented bundle, into Keel or anywhere. Portability is a principle, not a favor.

Transparent

Self-serve, public pricing, start free

No mandatory sales call to see a price or start a program. Public pricing, a real free tier, and a product you can stand up yourself in an afternoon. What you see is what you pay.

Crosswalk-native

The crosswalk is the architecture, not a report

In checklist-based GRC, each framework is a separate list and you re-do the same work for every audit. Keel makes the control the unit of work, and every framework a view over your controls. Author a control once and it satisfies mapped clauses across all the frameworks you have applied at the same time. Apply your second framework and a large share of it is already covered by the controls you built for the first.

One control library

Apply a framework and one-click a curated, pre-mapped starter control set instead of starting from a blank page.

Collect evidence once

Attach evidence to a control once and it counts everywhere that control is mapped, no duplicated evidence per framework.

See the overlap

The crosswalk explorer shows how clauses in one framework line up with another, so you can see reuse before you commit.

Live frameworks in the crosswalk

ISO/IEC 27001

The international standard for an Information Security Management System (ISMS), including the Annex A control set. Keel’s flagship framework.

CIS Critical Security Controls

A prioritized set of safeguards to mitigate the most common cyber attacks, mapped to Implementation Groups.

PCI DSS

Payment Card Industry Data Security Standard - requirements for organizations that store, process, or transmit cardholder data.

SOC 2

Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) for service organizations. The report buyers ask for most.

NIST Cybersecurity Framework

Outcome-based framework organized by the Govern, Identify, Protect, Detect, Respond, and Recover functions.

NIST SP 800-53

Security and privacy controls for information systems and organizations, scoped to the 800-53B Moderate baseline.

HIPAA

US regulation for protected health information: Security Rule safeguards (administrative, physical, technical), Breach Notification, and core Privacy Rule standards.

ISO 9001

Quality Management System (QMS) requirements - consistent quality and continual improvement.

AI Governance Essentials

A Keel-authored baseline for responsible-AI governance - plain-language expectations across governance, risk, data, transparency, human oversight, security, lifecycle, and third parties, ready to evidence today and later map to a formal AI standard.

ISO/IEC 42001

AI Management System (AIMS) - governance for responsible development and use of AI. Management clauses 4-10 plus the Annex A reference controls (nine objective groups).

NIST AI Risk Management Framework

Voluntary framework for managing AI risks, organized around the Govern, Map, Measure, and Manage functions (the nineteen categories across the four functions).

EU AI Act

EU regulation on artificial intelligence (Regulation (EU) 2024/1689), setting obligations by risk tier: prohibited practices, high-risk requirements and obligations, transparency, and general-purpose AI models.

ESG Essentials

A Keel-authored baseline ESG program (Environmental, Social, Governance) for SMBs - plain-language expectations you can evidence today and later map to a formal standard.

Frameworks are added as data, not code. NIST SP 800-171 and GDPR are on a scheduled rolling launch. See the full, current list on the frameworks page, or open the crosswalk explorer. Framework names are referenced factually; Keel is not affiliated with their owners.

Connected

Built to connect, and to hand to your AI agents

A control program is more useful when your other systems can reach it. Keel exposes your compliance data through standard, documented interfaces, so you can automate the busywork and let the tools (and AI agents) you already run do the reading and the writing.

REST API

Read and write your controls, evidence, risks, and more programmatically. Your program is queryable, not trapped behind a UI.

Outbound webhooks (REST Hooks)

Subscribe your systems to events in Keel and get pushed the moment something changes, so your stack reacts in real time.

MCP server

A Model Context Protocol server lets the AI agents you already use read from and act in Keel through a standard interface.

Zapier app (private beta)

No-code automation across 6,000+ apps: trigger tasks, log evidence, open risks, and alert your team. In private beta today.

Directory sync

Sync staff from Microsoft Entra or Google Workspace (or CSV) so access reviews and people data stay current automatically.

keel-migrate (open source)

An MIT-licensed CLI that exports your data from other platforms using their official APIs, read-only, running on your own machine.

See integrations, API & webhooks Explore Zapier
Portable, no lock-in

Your data leaves as easily as it arrives

Lock-in is the quiet cost of closed GRC: the harder it is to leave, the less a vendor has to earn your renewal. Keel rejects that. Your registers, policies, and evidence are yours, and keel-migrate is a real open-source (MIT), read-only tool that runs on your own machine and exports them to a neutral, documented bundle, to bring into Keel, or to take anywhere. We built it on official, supported APIs precisely because your right to your own data should not depend on anyone's permission.

Open source, auditable

The exporter is public under the MIT license. Read exactly what it does before you run it, no black box, no account required.

A neutral bundle format

It writes documented bundle files in a neutral format. Import them into Keel, or just keep them. Your data is not tied to any one destination.

How migration works
Transparent

Self-serve, public pricing, start free

There is no mandatory sales call to see a price or to start a program. Keel has public pricing and a genuine free tier, so you can stand up a real program yourself, apply a framework, and watch how much of the next one your controls already cover.

Start free See pricing
FAQ

Common questions about crosswalk-native GRC

What does "crosswalk-native" mean?

It means the crosswalk is the architecture, not a report bolted on afterward. In Keel a control is the unit of work and each framework is a view over your controls, so a single control satisfies mapped clauses across many frameworks at once. Apply a second framework and much of it is already covered by controls you authored for the first.

How is Keel different from other GRC tools?

Four things: it is crosswalk-native (one control covers many frameworks), it connects to your stack through a REST API, webhooks, and an MCP server, your data is portable with the open-source keel-migrate exporter, and it is self-serve with public pricing. In short, less duplicated work and no lock-in.

Which frameworks can Keel crosswalk today?

Live frameworks are ISO/IEC 27001, CIS Critical Security Controls, PCI DSS, SOC 2, NIST Cybersecurity Framework, NIST SP 800-53, HIPAA, ISO 9001, AI Governance Essentials, ISO/IEC 42001, NIST AI Risk Management Framework, EU AI Act and ESG Essentials, with NIST SP 800-171 and GDPR on a scheduled rolling launch. Frameworks are added as data, so the catalog on the frameworks page is always the current, accurate list.

How does Keel avoid vendor lock-in?

Data portability is a first-class principle. keel-migrate is an open-source (MIT) tool that exports your registers, policies, and evidence to a neutral, documented bundle you can keep or import anywhere. Combined with the REST API and webhooks, your compliance program is never trapped in one vendor.

Do I have to talk to sales to start?

No. Keel is self-serve with public pricing and a free tier. You can start a real program yourself, apply a framework, and see how much of the next one your controls already cover, no demo gate required.

Framework names are referenced factually; Keel is not affiliated with, endorsed by, or sponsored by their owners. Third-party product and standard names are trademarks of their respective owners. See our legal and trademarks page.

Run every framework off one control library

Author once, comply everywhere, and take your data with you. Start free, apply a framework, and see the reuse for yourself.

Start free See the product