Free · no signup

Seven questions to ask before you renew

A compliance platform is easiest to evaluate in the month before the invoice, and hardest to evaluate once you have been inside it for two years and stopped noticing what it does not do. These are the seven questions that separate a program you can defend from a dashboard that looks reassuring.

They are questions, not accusations. We have not run every platform on the market and are not going to pretend otherwise — so each one is phrased to be put to your vendor, and each is followed by Keel’s own answer, because a checklist published by an interested party should say so.

1

Does your framework coverage equal the standard’s own requirement count?

A platform can “support” a standard by authoring the requirements someone had time to write. Ask for two numbers: how many requirements they have authored, and how many the published standard contains. If those differ, your 100% is a percentage of a subset somebody else chose, and you will find out which parts were missing when an assessor asks.

Keel’s answer: Both numbers are on every framework’s page on this site: what Keel has authored, the leaf count in the scope Keel declares for that standard, and the document that scope was checked against — plus what is missing where Keel models only part of a standard. A test fails the build if the two counts drift apart. NIST SP 800-171 is all 110 requirements across 14 families; ISO 27001 is 116. Where a standard also binds a regulator rather than the organisation it regulates, the page names what is scored and what is only cited: GDPR’s 110 are the duties the Regulation places on a controller or processor, and every exclusion is published Article by Article.

2

Can your readiness score go down on its own?

Ask what happens when an automated check that was passing starts failing. If the answer is that a task appears somewhere but the score holds, the number is measuring how long you have had the account rather than whether you are compliant today.

Keel’s answer: Checks re-run on a schedule and file dated evidence when they pass. On a failure, an error, or a pause, that evidence is withdrawn and the score falls.

3

How old is the oldest piece of evidence still counting toward your score?

Ask to sort the evidence library by date. A screenshot proves one moment, and it keeps counting for as long as it sits there. The oldest artifact still being counted is the true age of your compliance posture.

Keel’s answer: Evidence carries the date the check produced it, and the readiness meter caps each control at the number of artifacts it actually expects, so attaching nine where three are wanted does not inflate anything.

4

What is excluded from the score, and can you see the list?

Every framework contains provisions a company cannot itself implement — obligations addressed to regulators, for instance. Excluding them is usually correct. Not being able to see which ones were excluded is not. Ask for the list by clause number.

Keel’s answer: Exclusions are listed by number in the framework’s source, so the denominator can be audited rather than taken on trust.

5

What does your AI do when your evidence cannot answer the question?

Ask it something your program genuinely does not cover, and watch. A confident, plausible answer on a security questionnaire does not cost you an awkward correction — it costs you the deal, and possibly a contract you already signed.

Keel’s answer: Keel’s answering engine abstains in four places: nothing relevant retrieved (no model call at all), a citation that was not retrieved, a draft claiming more than its source supports, and a near-match from your answer bank that is not the same question. Enforced by tests that fail the build.

6

What does it cost to give your auditor access?

Ask whether an auditor seat consumes a licensed seat. If it does, you are being charged for the act of being audited, which is the reason you bought the platform.

Keel’s answer: The auditor seat is free on every plan, including the free one, and does not count against the seat limit. It is read-only, enforced in the application.

7

Can you export everything today, without asking anyone?

Not “is there an export” — actually run it, before you renew rather than after you decide to leave. Ask specifically for registers, policy bodies, evidence files and their control mappings. A platform that holds your mappings hostage has made the renewal decision for you.

Keel’s answer: keel-migrate is open source, MIT, read-only and runs on your own machine against official APIs. It moves data out of Vanta, Drata and OneTrust (beta) into Keel — and the same openness applies leaving Keel.

Check ours the same way

Most of the answers above you can check without talking to anyone. The demo workspace is public and needs no account, the crosswalk data the product runs on is published under CC-BY-4.0, keel-migrate is public and MIT, and each framework page states how much of its standard Keel actually models — including EU AI Act and PCI DSS, which model only part of theirs.

What you cannot inspect yourself: Keel’s application source is not public, so the build-time tests behind those declarations are something you have our word on. Ask us for anything here you would rather see than be told.

Open the live demo See framework completeness See the open data