# Keel > Keel is a self-serve GRC (governance, risk, and compliance) and vendor-risk platform for growing businesses getting audit-ready for SOC 2, ISO 27001, HIPAA, PCI DSS, and more. One control and evidence graph is crosswalked across every framework, so you collect evidence once and comply everywhere. Keel also runs the product-quality side of ISO 9001 through its Keel Quality module, so a single graph can cover both your ISMS and your QMS. AI is woven through to draft policies, profile vendors, and build questionnaires. Keel is built for SMBs and MSPs pursuing their first or next audit. It bundles controls, evidence, policies, a risk register, vendor risk, access reviews, security-awareness training, an ISO 9001 quality module, and a public trust center. It is self-serve and priced for startups, with a genuine free tier (NIST CSF and AI Governance Essentials are free on every plan) and optional, credit-metered AI in every module. Keel is not affiliated with or endorsed by the bodies that publish the frameworks it references. ## Product - [Product overview](https://keelgrc.com/product/): Every GRC job on one control and evidence graph. - [Pricing](https://keelgrc.com/pricing/): Free, Starter, Pro, Enterprise, and MSP/Partner plans, plus a la carte add-ons. NIST CSF and AI Governance Essentials are free on every plan. - [Keel Quality (ISO 9001)](https://keelgrc.com/quality/): A $149/mo per workspace add-on, self-serve, that adds ISO 9001's product-quality modules on the same graph as your ISMS: nonconforming outputs (NCR), supplier quality and SCARs, complaints and feedback, change control, and a Quality dashboard over those four. Each workspace is its own subscription. Nonconformities and CAPA, the internal audit programme, objectives, competence, documented information and management review ship on every plan including Free; they need no add-on. - [For MSPs](https://keelgrc.com/msps/): Manage many client programs from one console with partner pricing. - [Industries](https://keelgrc.com/industries/): SaaS, fintech, healthcare, manufacturing, MSPs, and retail. - [Crosswalk explorer](https://keelgrc.com/crosswalk/): See exactly how many controls SOC 2, ISO 27001, PCI DSS, HIPAA, NIST CSF, and more share on one control library. - [Trust center](https://keelgrc.com/trust/): Keel's own security posture. ## Live frameworks Keel authors and scores content for these frameworks today: ISO/IEC 27001:2022, SOC 2, SOX (Sarbanes-Oxley) Section 404, PCI DSS 4.0.1, NIST Cybersecurity Framework 2.0, NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 2, HIPAA, GDPR, COPPA (16 CFR Part 312), Google Play Families, Amazon Appstore Child-Directed Apps, Apple App Store Kids Category, CIS Critical Security Controls v8.1, ISO 9001:2015, ESG Essentials, US Employment Law (federal baseline), and the AI governance shelf: AI Governance Essentials, ISO/IEC 42001, the NIST AI RMF, and the EU AI Act. NIST CSF and AI Governance Essentials are free on every plan. SOX here means Section 404 only, and specifically the five components and seventeen principles of the COSO Internal Control—Integrated Framework (2013) — the suitable, recognized framework management evaluates internal control over financial reporting against in order to make the assessment Section 404(a) requires, the Act itself being a statute of eleven titles that publishes no control list. Those seventeen principles are the complete declared scope: Keel does not model the whole Sarbanes-Oxley Act, the §302 and §906 officer certifications, the §404(b) auditor attestation, the process-level controls over revenue, procure-to-pay, payroll, the financial close and management estimates that a real 404 assessment scopes and tests, or COSO's points of focus. Scoring against it is an entity-level self-assessment, not a Section 404 conclusion, and Keel is not an auditor. NIST SP 800-171 covers all 110 security requirements across its 14 families, and is the requirement set a CMMC Level 2 assessment is conducted against; Keel is not an assessor and does not certify you. COPPA here means the FTC's Children's Online Privacy Protection Rule, 16 CFR Part 312 as amended in 2025; it binds operators of websites and online services directed to children under 13, and operators with actual knowledge they collect personal information from a child — it is not a general children's or teen privacy law, and it is not app-store policy. Google Play Families, Amazon Appstore Child-Directed Apps and the Apple App Store Kids Category are the store policies: they are contracts each store can change without notice rather than law (each is modelled as retrieved on 2026-08-13, and Google's replacement Families policy takes effect 2026-08-26), they are stricter than COPPA in places, satisfying COPPA does not satisfy any of them, and they conflict with one another most sharply on advertising — Google permits ads to children or unknown-age users only from a Families Self-Certified Ads SDK version, certified per version rather than per vendor, with no interest-based advertising or remarketing (in-house cross-promotion and direct-sold inventory aside); Amazon bars its own Amazon Advertising and Associates programmes from any child-directed area or known child outright, which parental consent does not lift; and Apple permits third-party advertising in the Kids Category only where it is contextual and the ad provider publicly documents Kids Category practices that include human review of ad creatives. Other standards in the catalog — including ISO/IEC 27701, HITRUST CSF, ISO/IEC 27002, NIS2, DORA and CCPA/CPRA — are listed as coming soon and are not yet authored or scored. - [All frameworks](https://keelgrc.com/frameworks/) - [SOC 2](https://keelgrc.com/frameworks/soc-2/) - [ISO 27001](https://keelgrc.com/frameworks/iso-27001/) - [SOX (Sarbanes-Oxley) Section 404](https://keelgrc.com/frameworks/sox/): Scoped to the COSO 2013 components and principles that Section 404(a) assessments are made against. - [HIPAA](https://keelgrc.com/frameworks/hipaa/) - [PCI DSS](https://keelgrc.com/frameworks/pci-dss/) - [NIST CSF](https://keelgrc.com/frameworks/nist-csf/) - [ISO 9001](https://keelgrc.com/frameworks/iso-9001/) ## AI governance - [AI governance overview](https://keelgrc.com/ai-governance/): Govern your AI across ISO/IEC 42001, the NIST AI RMF, and the EU AI Act, starting from the free AI Governance Essentials. - [ISO 42001](https://keelgrc.com/frameworks/iso-42001/) - [NIST AI RMF](https://keelgrc.com/frameworks/nist-ai-rmf/) - [EU AI Act](https://keelgrc.com/frameworks/eu-ai-act/) ## Free tools - [SOC 2 Evidence Kit](https://keelgrc.com/toolkits/soc-2-evidence-kit/): Every Trust Services Criterion mapped to the concrete evidence to collect. - [SOC 2 cost calculator](https://keelgrc.com/tools/soc-2-cost-calculator/): Estimate first-year SOC 2 cost by scope, auditor, and readiness approach. - [Compliance readiness self-assessment](https://keelgrc.com/tools/compliance-readiness-assessment/): A short quiz that scores your readiness and recommends the frameworks that fit. ## Solutions by industry Guides to the frameworks that matter for each industry, with the work reused across them. - [SOC 2 for SaaS](https://keelgrc.com/solutions/soc-2-for-saas/) - [ISO 27001 for SaaS](https://keelgrc.com/solutions/iso-27001-for-saas/) - [SOC 2 for fintech](https://keelgrc.com/solutions/soc-2-for-fintech/) - [PCI DSS for fintech](https://keelgrc.com/solutions/pci-dss-for-fintech/) - [HIPAA for healthcare and healthtech](https://keelgrc.com/solutions/hipaa-for-healthcare/) - [ISO 9001 for manufacturers](https://keelgrc.com/solutions/iso-9001-for-manufacturing/) - [All industry guides](https://keelgrc.com/solutions/) ## Compare Honest comparisons for teams evaluating GRC platforms. Trademarks belong to their owners; Keel is not affiliated with them. - [Keel vs Vanta](https://keelgrc.com/compare/keel-vs-vanta/) - [Keel vs Drata](https://keelgrc.com/compare/keel-vs-drata/) - [Keel vs Secureframe](https://keelgrc.com/compare/keel-vs-secureframe/) - [Keel vs Sprinto](https://keelgrc.com/compare/keel-vs-sprinto/) ## Research Original, reproducible analysis computed from Keel's own open crosswalk data. - [Research hub](https://keelgrc.com/research/): Original data and cited analysis on GRC for SMBs. - [How much do compliance frameworks overlap?](https://keelgrc.com/research/compliance-framework-overlap/): SOC 2 and ISO 27001 share almost every control; measured against Keel's open control library. - [AI governance is new work, but you only do it once](https://keelgrc.com/research/ai-governance-framework-overlap/): How much ISO 42001, the NIST AI RMF, and the EU AI Act overlap with each other and with security frameworks. - [What SOC 2 really costs an SMB](https://keelgrc.com/research/soc-2-true-cost-for-smbs/): A synthesis of public data on SOC 2 cost and timeline, every figure cited. ## Answers and knowledge base - [Answers](https://keelgrc.com/answers/): Direct answers to common SOC 2, ISO 27001, HIPAA, AI-governance, and GRC-buying questions. - [Knowledge base](https://keelgrc.com/knowledge-base/): Plain-language explainers of GRC concepts and terms. ## Developers and open data - [Open source](https://keelgrc.com/open-source/): keel-migrate (data portability), the keelgrc-mcp server, and the open compliance-crosswalks dataset (CC BY 4.0). - [Documentation](https://docs.keelgrc.com/): Product docs, the REST API reference, and the MCP server guide. - [Migrate to Keel](https://keelgrc.com/migrate/): Move your program from Vanta, Drata, or OneTrust with the open-source keel-migrate tool. - [Product deep-dives](https://keelgrc.com/software/): Landing pages for each software category Keel covers. - [Templates and downloads](https://keelgrc.com/templates/): Free policy templates and starter kits. ## Learn - [Blog and guides](https://keelgrc.com/blog/): No-jargon guides to SOC 2 and ISO 27001 for first-time compliance owners. - [SOC 2 guide for startups](https://keelgrc.com/blog/soc-2-guide-for-startups/) - [ISO 27001 vs SOC 2](https://keelgrc.com/blog/iso-27001-vs-soc-2/) - [SOC 2 audit cost](https://keelgrc.com/blog/soc-2-audit-cost/) - [How to choose a SOC 2 auditor](https://keelgrc.com/blog/how-to-choose-a-soc-2-auditor/) - [FAQ](https://keelgrc.com/faq/): Straight answers about what Keel does and does not do. ## Company - [About](https://keelgrc.com/about/): Why Keel exists. - [Changelog](https://keelgrc.com/changelog/): What is new in the product. - [Contact and support](https://keelgrc.com/contact/): Reach the team. ## Legal - [Privacy policy](https://keelgrc.com/legal/privacy/) - [Legal and trademarks](https://keelgrc.com/legal/trademarks/): Framework names are referenced factually; Keel is not affiliated with or endorsed by their owners.