Product

One platform, every GRC job

Keel is built on a single control & evidence graph. Each module below is a view over the same data, so you collect evidence once and reuse it everywhere.

Prefer to click around yourself? Open the live, read-only demo — a fully-loaded workspace, no signup. Nothing can be edited, and a nightly job restores anything missing from the dataset.
Explore the live demo →
Product tour: your whole compliance program on one dashboard
app.keelgrc.com/risks
Keel risk register scoring risks by likelihood and impact, with inherent and residual scores, treatments, owners, and linked controls
app.keelgrc.com/vendors
Keel vendor risk view listing third parties by criticality with review cadences and an AI draft-from-website tool

Track every third party by criticality, with review cadences so nothing you depend on goes unreviewed.

AI, built into the work

The busywork, done for you

Keel’s AI isn’t a chatbot bolted on the side - it’s wired into the modules where the work actually happens. It writes the first draft so you approve instead of author, and every action is credit-metered and fully optional.

✦ New · AI Insights

One rundown of your whole program

Readiness gaps, missing or overlapping policies, vendors due for review, stale evidence and overdue access reviews, and framework crossover suggestions for your industry - each with a link to act. The core analysis runs with AI off and uses no credits; an optional deep pass adds a board-ready narrative and a prioritized plan.

app.keelgrc.com/insights
Overview
AI Insights
A total rundown of your workspace, each finding with a link to act. Runs on your live data and uses no AI credits.
7
Findings
1
Critical
3
High
2
Medium
1
Low
62% ISO 27001 78% SOC 2 91% AI Governance Essentials
Critical
1 security incident still open
Includes high severity. Unresolved: Phishing led to credential exposure.
Work incidents →
High
ISO 27001 is 62% ready with 14 requirements to close
48 of 62 applicable requirements covered (9 with no control mapped, 5 flagged as a gap).
Open ISO 27001 →
Medium
3 vendors due for review
1 is critical/high risk. Overdue or never reviewed: Acme Cloud, Northwind Mail +1 more.
Review vendors →
Low
Consider adding PCI DSS
Commonly pursued for your industry; 19 of your controls already overlap it.
Explore PCI DSS →
Deep analysis
A premium AI pass: board-ready narrative, duplicate detection, and a prioritized 30-day plan.
✦ Run deep analysis
✦ Insights

AI Insights: your whole program, analyzed

One rundown of your entire workspace - framework readiness gaps, missing or overlapping policies, vendors due for review, stale evidence and overdue access reviews, plus framework crossover suggestions for your industry. The core analysis runs on your live data with AI switched off and uses no credits; add an on-demand deep pass for a board-ready narrative and a prioritized plan.

✦ Policies

AI policy drafting from scratch

Name a policy - Access Control, Incident Response, Data Retention - and Keel writes a clean, framework-mapped first draft right in your editor, ready to tailor and export as a branded PDF.

✦ Risk register

AI risk drafting

Describe your business, or just your framework, and Keel drafts a set of concrete, scored risks to seed your register - each an editable starting point, never boilerplate.

✦ Policies

Policy & document import, cleaned up by AI

Drop in a messy Word doc or an old policy and Keel rewrites it into clean, framework-mapped Markdown you can approve and export as a branded PDF - no re-typing, no reformatting.

✦ Vendor risk

AI vendor profiles from a URL

Paste a vendor’s website and Keel drafts the risk profile for you - what they do, the data they touch, their certifications and sub-processors - so your inventory fills itself in.

✦ Vendor assessments

AI questionnaire builder

Describe the vendor and your concerns; Keel assembles a structured, auto-scored security questionnaire from a curated library of 100+ questions. Consistent, on-brand, and ready to send in one click.

✦ Controls

Control implementation guidance

For any control, Keel writes plain-English, step-by-step implementation guidance and the exact evidence to collect - so “where do I even start” becomes a checklist you can act on today.

✦ Questionnaire assist

Answer inbound questionnaires

When a prospect sends you a security questionnaire, Keel drafts the answers from your own controls and policies - honest, grounded, and ready to review - turning a day of copy-paste into minutes.

✦ Policies & reports

Policy-gap & readiness analysis

Keel compares your policy set to a framework and flags what’s missing, and writes a board-ready audit-readiness summary over your live posture - the prep work, done for you.

✦ Across the app

Remediation, risks & summaries

Turn a failing control into a task list, draft vendor risks from a profile, summarize a control’s evidence and review whether it’s sufficient, flag odd access in a review, and generate trust-center copy - each an optional, credit-metered click.

Provenance

You can always tell what the AI wrote

An auditor’s first question about AI output is where it came from. Keel answers it on the record itself rather than in a policy document: every generated item is labelled, the label stays until a person acts, and Keel keeps generated drafts, computed findings and your actual evidence as three separate things.

“AI-drafted — review before use”

The default badge on anything an AI tool produced — policy drafts, control guidance, readiness and gap analyses, evidence and trust-center narratives, access-review notes, questionnaire answers, vendor risk drafts. It stays on the record until a person reviews it; nothing clears it on its own, and no plan turns it off.

“Human-reviewed”, with who and when

A member marks the content reviewed and the badge records their name and the date. Marking something reviewed never rewrites the text — it records the sign-off. Rolling out behind a feature flag, so it may not be switched on in your workspace yet; the AI-drafted label always is.

Computed, not generated

Readiness, control coverage, stale evidence and overdue reviews are derived from the data in your workspace, and they run with AI switched off. A number Keel calculated and a paragraph a model wrote are not shown as the same kind of thing.

A draft is not evidence

Evidence is the artifact itself — the export, the screenshot, the signed record. An AI draft never becomes evidence by sitting in the workspace, and a generated summary of a file is not a substitute for the file.

For questionnaire answers the badge sits next to an explainable confidence level and a confirm internally flag, raised when the answering engine could not fully ground an answer in your own controls and policies — so you know which answers to check first.

AI assists. You stay accountable. Every AI output in Keel is a starting point, not a verdict, and no model decides whether your organization is compliant — you review the work, and your auditor forms the opinion.

AI credits are included on every paid plan - 1,500/mo on Starter, 5,000 on Pro, 15,000 on Enterprise - with pay-as-you-go top-ups when you need more.

Frameworks

Crosswalked across every framework you need

Apply a framework and one-click a curated, pre-mapped control set. A single control satisfies clauses across all of them at once.

ISO/IEC 27001

The international standard for an Information Security Management System (ISMS), including the Annex A control set. Keel’s flagship framework.

CIS Critical Security Controls

A prioritized set of safeguards to mitigate the most common cyber attacks, mapped to Implementation Groups.

PCI DSS

Payment Card Industry Data Security Standard - requirements for organizations that store, process, or transmit cardholder data.

SOC 2

Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) for service organizations. The report buyers ask for most.

SOX (Sarbanes-Oxley) Section 404

Internal control over financial reporting for a US issuer, modelled against the five components and seventeen principles of the COSO Internal Control—Integrated Framework (2013) — the framework management evaluates ICFR against to make the assessment SOX Section 404(a) requires. SOX itself is a statute of eleven titles that publishes no control list: 15 U.S.C. 7262(a) requires an assessment of effectiveness, 17 CFR 240.13a-15(c) requires it to rest on “a suitable, recognized control framework”, and 17 CFR 229.308(a)(2) requires management’s report to name the framework it used. The seventeen principles are that framework and are the complete, declared scope here: the control environment (integrity, board oversight, structure and authority, competence, accountability), risk assessment (financial reporting objectives, risk analysis, fraud including management override, change), control activities (control design and precision, general controls over technology, deployment through policy and procedure), information and communication (information quality, internal and external communication), and monitoring (evaluation of the other four components — built into daily operations, run separately, or both — and deficiency evaluation and reporting). Deliberately outside that scope, each for a stated reason: the §302 and §906 officer certifications, the §404(b) auditor attestation, process-level controls over revenue, procure-to-pay, payroll, the financial close and management estimates, and COSO’s points of focus. ITGCs are not a separate authored layer — they are the subject of Principle 11, with the access, change-management and operations detail carried by the crosswalked starter controls.

NIST Cybersecurity Framework

Outcome-based framework organized by the Govern, Identify, Protect, Detect, Respond, and Recover functions.

NIST SP 800-53

Security and privacy controls for information systems and organizations, scoped to the 800-53B Moderate baseline.

NIST SP 800-171

Protecting Controlled Unclassified Information (CUI) in nonfederal systems (CMMC-aligned).

HIPAA

US regulation for protected health information, modeled to 45 CFR Part 164 leaf level: the Security Rule’s administrative, physical and technical safeguards with every required and addressable implementation specification, the Breach Notification Rule, and the Privacy Rule’s individual rights and administrative duties (§164.520-§164.530). The Privacy Rule’s permitted-use and disclosure provisions (§164.502-§164.514) are legal permissions rather than implementable controls, so they are deliberately not scored.

GDPR

EU General Data Protection Regulation - every obligation the Regulation places on a controller or processor, modelled at its own numbered-paragraph level: principles and lawful basis, data-subject rights, accountability, processor contracting, records, security, breach handling, DPIAs, the DPO and international transfers. Provisions addressed to Member States, the Commission, supervisory authorities and the Board, and the remedies and penalties of Chapter VIII, are cited but not scored.

COPPA

The FTC’s Children’s Online Privacy Protection Rule (16 CFR Part 312), as amended in 2025, modelled to the Rule’s own paragraph level: notice to parents and on the service, verifiable parental consent with its recognised methods and its exceptions, the parent’s right to review and delete, the ban on conditioning a child’s participation on excess collection, the written children’s information security programme, and the retention-and-deletion duty. It binds operators of websites and online services directed to children under 13, and any operator with actual knowledge it collects personal information from a child. Scope (§312.1), definitions (§312.2), enforcement (§312.9), safe harbor programmes (§312.11), the Commission’s voluntary approval processes (§312.12) and severability (§312.13) are cited but not scored: they impose no implementable operator duty, or they bind the Commission or a safe harbor programme rather than an operator.

Google Play Families

Google Play’s Families Policies, modelled requirement by requirement: the Play Console target-audience and data-safety declarations; the Families Policy Requirements covering child-appropriate content, disclosure of what is collected from children, the persistent identifiers a child-only app may not transmit (AAID, SIM serial, Build serial, BSSID, MAC, SSID, IMEI, IMSI) and the wider mixed-audience rule that also covers users of unknown age, the AD_ID permission on API 33 and above, precise location, Companion Device Manager for Bluetooth, SDK approval for child-directed services, augmented-reality safety warnings, online-safety reminders and adult controls on social features, and compliance with COPPA and the GDPR; and the Families Ads and Monetization requirements - ads to children or unknown-age users only from Families Self-Certified Ads SDK versions, no interest-based advertising or remarketing, age-appropriate creative, and the ad format rules on ad walls, five-second closeability, launch interstitials, multiple placements and virtual currency. Google publishes no version number or clause numbering, so this carries the date Keel retrieved the policy and uses Keel’s own reference scheme. A replacement Families policy takes effect on 2026-08-26; Keel models the policy in force as at retrieval and does not author the preview. Requirements Google places on ads SDK vendors and mediation platforms bind those parties rather than the developer, and are cited but not scored.

Amazon Appstore Child-Directed Apps

The Amazon Appstore’s Child-Directed App (COPPA) Policy, modelled requirement by requirement: the child-directed determination and the factors behind it, age-appropriate content, compliance with COPPA and other applicable children’s privacy law, the bar on serving ads through any Amazon Advertising or Amazon Associates programme to a known child or in a child-directed area of the app - which parental consent does not lift - the complete bar on those programmes in an app directed only at children, and the rules on which SDKs may collect personal information from children. Note the scope: Amazon treats a multi-audience app as child-directed unless the developer confirms children are not using it, and defines children as under 13, or under 16 in the European Union, Australia and Japan - a wider band than COPPA’s. Amazon publishes no version number or clause numbering, so this carries the date Keel retrieved the policy alongside Amazon’s own last-updated date of 2020-06-01, and uses Keel’s own reference scheme. Amazon’s separate Advertising ID, User Data Privacy and Appstore Advertising policies are different documents and are not modelled here.

Apple App Store Kids Category

The App Store rules whose duties are triggered by a child, a minor, an underage user, or by the Kids Category - the stated scope rule this framework is complete against, with every excluded guideline enumerated by number in the framework file. Guideline 1.3 (the Kids Category: the App Store Connect age band, parental gates on links out and purchases and the adult-level task a gate must be, requirements that persist after the category is deselected, no personally identifiable or device information sent to third parties even from adult-facing sections, human review of any advertising displayed, and third-party analytics and advertising excluded by default with narrow carve-outs), plus Guidelines 1.2.1(a) and 4.7.5 (age restriction for creator content and for mini apps, games, chatbots and emulators), 1.4.3 (encouraging minors to consume tobacco, drugs or alcohol), 2.3.8’s reservation of “For Kids” and “For Children” metadata, 2.5.13 (an alternative to facial-recognition sign-in for under-13s), 2.5.18 (no targeted or behavioural advertising on data from kids), 5.1.3(iii) (parent or guardian consent for a minor in health research), 5.1.4 (kids’ personal data, reaching apps intended primarily for kids and apps merely capable of sharing a minor’s information), and 5.1.1(i) for the contents of the privacy policy 5.1.4(b) requires. This is NOT a model of the App Store Review Guidelines as a whole and does not predict App Review outcomes: all 125 numbered guidelines still bind the app. Apple publishes no delimited Kids requirements document and no version number, so this carries the date Keel retrieved the two source pages.

ISO 9001

Quality Management System (QMS) requirements - consistent quality and continual improvement.

AI Governance Essentials

A Keel-authored baseline for responsible-AI governance - plain-language expectations across governance, risk, data, transparency, human oversight, security, lifecycle, and third parties, ready to evidence today and later map to a formal AI standard.

ISO/IEC 42001

AI Management System (AIMS) - governance for responsible development and use of AI. Management clauses 4-10 plus the Annex A reference controls (nine objective groups).

NIST AI Risk Management Framework

Voluntary framework for managing AI risks, organized around the Govern, Map, Measure, and Manage functions, modeled to the seventy-two subcategories of the Core.

EU AI Act

EU regulation on artificial intelligence (Regulation (EU) 2024/1689), setting obligations by risk tier: prohibited practices, high-risk requirements and obligations, transparency, and general-purpose AI models.

ESG Essentials

A Keel-authored baseline ESG program (Environmental, Social, Governance) for SMBs - plain-language expectations you can evidence today and later map to a formal standard. Its social-responsibility coverage was checked against the seven core subjects of ISO 26000:2010, which is guidance and cannot be certified against.

US Employment Law - Federal Baseline

The federal floor for US employment compliance - wage and hour, leave, anti-discrimination, safety, benefits, classification, labor relations, and required notices - that applies nationwide, with state-delta overlays for all 50 states and DC applied to the states you employ in.

All 21 frameworks above are live today, and more are added as data, not code. Framework names are referenced factually; Keel is not affiliated with their owners.

Also included

Prove it, not just claim it

Framework crosswalk

Map a control to many frameworks at once, the “collect once, comply everywhere” engine.

One-click starter controls

Apply a curated, pre-mapped control set for your framework in a single click.

Guided onboarding

A step-by-step setup hub takes you from zero to a working program in an afternoon.

Readiness reports

Branded, auditor-ready reports and a posture digest you can email yourself in a click.

Statement of Applicability

Generate the mandatory ISO 27001 SoA from your program (all 93 Annex A controls with applicability, justification, and status) as a branded PDF.

Information asset register

Inventory your information and associated assets with an owner and a classification (the ISO 27001 Annex A 5.9 and 5.12 register), each rated for confidentiality, integrity, and availability.

Nonconformities & CAPA

Run the ISO 27001 / 9001 Clause 10 loop: log a nonconformity, guided 5 Whys / Fishbone root cause, corrective actions, and an effectiveness check before it can close.

Internal audits

Plan a Clause 9.2 internal audit, work a checklist auto-generated from the framework’s clauses, record findings, raise nonconformities, and export a branded audit report.

Audit programme & calendar

Plan and maintain the internal-audit programme (the ISO 27001 / 9001 Clause 9.2.2 requirement), scheduling audits by area on a cadence, with an upcoming-and-overdue calendar and one-click launch into a full audit.

Security incident register

Report, triage, contain, and learn from incidents (the ISO 27001 Annex A 5.24–5.28 workflow), and raise corrective actions, with the record SOC 2 expects.

Business continuity & BIA

A business impact analysis and continuity register (the ISO 27001 Annex A 5.29 and 5.30 requirement), with RTO, RPO, recovery strategy, and continuity-test tracking per critical process.

Management reviews

Run the Clause 9.3 review with the agenda pre-filled from your program (audit results, nonconformities, incidents, readiness), plus minutes, decisions, and a branded PDF.

Legal & regulatory register

Track the legal, statutory, regulatory, and contractual obligations that apply to you (the ISO 27001 Annex A 5.31 register), each with an owner and a compliance status.

Security objectives & KPIs

Set measurable information security objectives (the ISO 27001 Clause 6.2 requirement), with a metric, baseline, target, owner, and a live on-track / at-risk / achieved status.

Competence & training-gap matrix

Evidence that the people doing security work are competent (the ISO 27001 Clause 7.2 requirement), with per-person competences, basis, status, and certification expiry.

Documented information register

The controlled master list of every document the ISMS depends on (the ISO 27001 Clause 7.5 requirement), each with an owner, approver, classification, version, review cadence, and retention rule.

Nonconforming outputs (NCR)

Control nonconforming product and outputs (the ISO 9001 Clause 8.7 requirement), with quarantine, the full disposition set, re-verification after rework, and a one-click bridge to CAPA. Part of the Keel Quality add-on.

Quality dashboard

The whole quality-management system on one surface (nonconforming outputs, CAPA, the audit programme, objectives, competence, and document control), with a live “needs attention” roll-up. The home of the Keel Quality add-on.

Supplier quality & SCARs

Control externally provided products and services (the ISO 9001 Clause 8.4 requirement), with an approved-supplier list, qualification status, quality scores, and Supplier Corrective Action Requests (SCARs). Part of the Keel Quality add-on.

Complaints & feedback

Capture, investigate, and resolve customer complaints across any channel (the ISO 9001 Clause 9.1.2 / 10.2 requirement), and escalate systemic ones to a linked CAPA. Part of the Keel Quality add-on.

Change control

Plan and control changes to processes, products, documents, and systems (the ISO 9001 Clause 6.3 / 8.5.6 requirement), through impact assessment, approval, implementation, and verification. Part of the Keel Quality add-on.

Directory sync & access reviews

Automated staff sync plus periodic access certification, a real SOC 2 / ISO control.

Security-awareness training

A built-in library of framework-mapped courses: assign to your whole team or specific people, let staff self-enroll, and collect certificates and a per-person history as evidence.

Continuous checks

Credential-free monitors verify TLS, security headers, SPF, and DMARC on a schedule. A pass files dated evidence against the linked control; a failure withdraws it, so coverage never overstates.

Trust center

A customizable public page, logo, cover, checklist, documents, that helps close deals.

API, webhooks & MCP

A REST API, webhooks, and a Model Context Protocol server connect Keel to the tools (and AI agents) you already use.

AI built in

Draft policies, profile vendors, and assemble questionnaires in seconds - AI woven through every module, with credits included on every paid plan.

Start free See pricing