What we’ve shipped
Every release, newest first. Want to shape what’s next? Sign in and share your ideas on the product roadmap.
Deeper AI-governance control coverage
- Improved The one-click starter control library now covers AI governance in depth: twelve new canonical controls - AI policy, AI roles and accountability, AI risk management, data governance for AI, responsible development, verification and validation, technical documentation, logging and records, transparency and disclosure, monitoring and incident reporting, responsible use, and AI supplier management - each pre-crosswalked to ISO 42001, the NIST AI RMF, and the EU AI Act. Every mapping points to a real, authored clause (checked by a test), and the open compliance-crosswalks dataset was regenerated to match.
Accountable sign-off on vendor assessments
- Improved Vendor-assessment decisions now scale with the vendor’s risk. Accepting or rejecting a critical- or high-tier vendor requires an accountable sign-off - an approver’s name and a written rationale - and accepting one requires a completed (submitted or scored) assessment first. Lower-tier vendors keep the quick one-click decision. The approver is recorded and shown on the decision, giving you the risk-based due-diligence trail auditors look for.
Build your continuity register from scenarios
- New Business continuity has a new "Build from common scenarios" button that populates your continuity register with the disruptions most organisations should plan for - office loss, a cloud/SaaS outage, ransomware, data loss, a key supplier failing, loss of a key person, and finance systems going down - each pre-filled with a suggested criticality, RTO/RPO, impact, dependencies, and recovery strategy to adapt. It skips anything already in your register, so it is safe to run more than once.
Records of Processing Activities (GDPR Article 30)
- New A new "Processing records (RoPA)" page maintains your GDPR Article 30 register - one record per activity where you process personal data, capturing its purpose, lawful basis, the data and people involved, recipients, retention, international transfers, and security measures. One click auto-populates it with the activities most companies run (HR, customers, billing, marketing, support, analytics) so you can adapt them instead of starting from a blank page.
Staff security rules digest
- New A new "Staff security rules" page gives you a plain-language, shareable digest of what everyone at the company needs to do - passwords and MFA, phishing, devices, handling data, working remotely, and reporting a problem. Use it in onboarding, pin it on your intranet, or print it as a one-pager; it backs up the security-awareness expectations behind ISO 27001 and SOC 2.
Risk scenario library
- New A new "Risk scenario library" saves you from starting your risk register on a blank page. It offers a curated set of common information-security risk scenarios for small and mid-sized teams - phishing, ransomware, lost devices, supplier breach, cloud misconfiguration, and more - each with a suggested inherent likelihood and impact and the ISO 27001 Annex A control areas that typically treat it. One click adds a scenario to your register, ready to refine and link to your controls.
DPIA threshold screener
- New A new "DPIA screener" tells you whether a processing activity needs a Data Protection Impact Assessment under the GDPR. Tick what applies and it decides live, based on the mandatory cases in Article 35(3) and the European Data Protection Board’s nine criteria (two or more generally require a DPIA). It’s a screening aid, not legal advice, and prompts you to record the decision either way.
Approved AI services register
- New A new "AI services register" keeps an inventory of the AI systems and tools your organization has vetted for use - the record ISO 42001 (AI management system) and the EU AI Act expect you to maintain. Log each service with its purpose, the data categories it processes, an EU AI Act risk tier (prohibited / high / limited / minimal), an owner, and an approval status (approved / under review / rejected / retired).
Risk ↔ SoA coverage checker
- New A new "Risk ↔ SoA coverage" page runs the cross-check an ISO 27001 auditor makes: it reconciles your Statement of Applicability against your risk register and flags the gaps - applicable Annex A controls that no risk traces to (Clause 6.1.3), and risks you've chosen to mitigate that have no implemented control behind them yet. It's fully deterministic (no AI) and updates live from your controls and risks.
AI opt-out enforced at the model layer
- Improved If a workspace switches AI off, that opt-out is now enforced at the single point where Keel talks to the AI model - not just in each feature. In practice AI already stopped for every feature when you turned it off; this makes the guarantee hold by construction, so no current or future feature can reach the model while your workspace is opted out. Keel processes no tenant content through AI when AI is off.
HTTPS-only hardening
- Improved Every Keel domain now sends its HSTS header with the "preload" directive, so browsers can enforce HTTPS-only from the very first visit once the domain is on the HSTS preload list. It is a small hardening step that removes the brief window on a first connection where a downgrade attack is theoretically possible.
- Improved Both the app and the marketing site now send an enforcing "upgrade-insecure-requests" policy, so any resource referenced over http is silently upgraded to https before it loads - no page content can be fetched over cleartext, even from a stray link.
Download your Statement of Applicability as Excel
- New The Statement of Applicability now has a "Download SoA (Excel)" button alongside the PDF. It exports the full Annex A grid auditors expect - one row per control with separate "Justification for inclusion" and "Reason for exclusion" columns, the implementation status, and the related controls - plus a header block with your organization, framework, ISMS scope, and approval details. Generated live from your controls, so it always matches what is in Keel.
Draft auditor answers from your own evidence
- New On any control, "✦ Draft auditor answers" now has AI write suggested answers to that control’s common auditor questions, grounded in the evidence you have actually linked to it. Each answer points to the specific evidence that supports it and flags the gaps where you still need to collect something, so you can walk into an audit prepared. Like Keel’s other AI tools it works from your evidence metadata (not the file contents), hedges accordingly, never invents evidence you do not have, and is a draft to review. Uses AI credits.
Know what an auditor will ask
- New Every control now shows a "What an auditor will ask" panel: the common questions an auditor tends to ask when testing that control, so you can rehearse and line up the right evidence before your audit. The questions are generic, practical prompts (for example, "Show me deprovisioning for a recent leaver, how quickly was access removed?"), curated across all of Keel’s canonical controls. AI-drafted answers grounded in your own evidence are coming next.
A guided path to ISO 27001 certification
- New A new "Get certified" page lays out the ISO/IEC 27001 journey as six milestones, define your ISMS scope, run your risk assessment, implement your controls, generate your Statement of Applicability, complete an internal audit, and hold a management review. Each milestone flips to done automatically based on what is actually in your workspace (real risks logged, a versioned SoA, a completed audit, a held review), not a checklist you tick yourself, so you always know the real next step toward your certification audit.
See what each control counts toward
- New Every control now shows an "Also counts toward" panel: the clauses that one control helps satisfy across the frameworks you have enabled, drawn from Keel’s crosswalk library. Map a control once and see, at a glance, that it counts toward (for example) ISO/IEC 27001, SOC 2, and NIST SP 800-53 at the same time, with a marker on the clauses you have already mapped to it. It is the "collect once, comply everywhere" idea made visible on every control.
Start with a 14-day free trial of Pro
- New Every new workspace now starts on a 14-day free trial of the Pro plan - no credit card required. You get the full Pro experience (more frameworks and seats, AI assist, integrations and API, and the full trust center) from day one. A banner keeps track of how many days are left, and you can upgrade any time to keep Pro. When a trial ends, the workspace simply moves to the Free plan and all of your data stays exactly where it is - nothing is deleted.
Controls now crosswalk to NIST SP 800-53
- Improved Keel’s canonical controls are now crosswalked to NIST SP 800-53 Rev. 5 (the FedRAMP / 800-53B Moderate baseline). Each security control maps to the specific 800-53 control identifiers it helps satisfy (for example multi-factor authentication to IA-2, encryption to SC-8 / SC-13 / SC-28, and incident response to IR-4 through IR-8), so the evidence you already collect counts toward an 800-53 program too. The open compliance-crosswalks dataset grows to 45 controls across 15 frameworks (300 mappings).
AI controls now crosswalk to four AI frameworks
- Improved The three AI-governance controls (AI system inventory, AI system impact assessment, and human oversight of AI) are now crosswalked to the EU AI Act and Keel’s AI Governance Essentials baseline, on top of their existing ISO/IEC 42001 and NIST AI RMF mappings. Each reference points to the specific article or clause the control helps satisfy, so one control counts toward all four at once. The open compliance-crosswalks dataset grows to 45 controls across 14 frameworks (248 mappings) as a result.
Cookie consent and a fuller set of legal pages
- New Our marketing site now asks for your consent before loading any analytics or marketing cookies. Everything optional is off by default: you can accept all, reject all, or choose by category, and change your mind any time from the new "Cookie preferences" link in the footer. We also honor Global Privacy Control and Do Not Track browser signals. As a GRC company we hold ourselves to the same bar we help customers meet.
- New Published a fuller set of legal pages: a Terms of Service, a standalone Cookie Policy that lists every cookie and how long it lasts, a Data Processing Addendum (DPA) for customers who need one, and an Acceptable Use Policy, all linked from the site footer alongside our existing Privacy policy.
Canonical controls for AI governance
- New Added three canonical controls for AI governance: an AI system inventory, an AI system impact assessment, and human oversight of AI. Like every canonical control, each is pre-mapped to the framework clauses it helps satisfy (here ISO/IEC 42001 and the NIST AI Risk Management Framework), so applying one counts toward your AI-governance program automatically. The open compliance-crosswalks dataset grows to 45 controls across 12 frameworks (240 mappings) as a result.
A bigger open crosswalks dataset
- Improved Our free, openly licensed compliance-crosswalks dataset now carries 233 control-to-clause mappings across 10 frameworks, up from 216. Each mapping ties one of our canonical controls to a specific clause it helps satisfy, so you can see at a glance where a single control counts toward more than one framework. It stays free to use and cite under CC BY 4.0, published as JSON and CSV.
Verified access for shared incident pages
- Improved Shared incident status links now require email verification before anything is shown. When a recipient opens their link, Keel emails a 6-digit code to the exact address the link was issued to and asks them to enter it. A forwarded link can’t be used to view the page, because the code only ever goes to the original recipient. Codes are single-use and expire in 10 minutes, and once someone verifies, their browser is remembered for 7 days so they aren’t asked again during that window.
Share incident status with the clients affected
- New When a security incident affects a customer, you can now share a private, live status page for that one incident. Turn on sharing, write a plain-language impact statement, and add each contact to create their own link. They see only the updates you choose to publish, never your internal notes, on a page that carries your own logo and brand color from your Trust Center, with a live timeline, a phase stepper, the severity, when it was last updated, and an optional “next update expected by” time.
- New Recipients can acknowledge receipt, subscribe to be notified of new updates, reach the contact you set, and save a clean, branded PDF of the incident for their records. As the owner you can set a link expiry, resend a recipient their existing link, revoke any link instantly, and see a read-receipt roll-up of who has viewed and acknowledged. The page refreshes itself while an incident is live. There is no universal public status page, only these per-recipient links.
Migrate more of your program, in bigger moves
- Improved keel-migrate now brings your evidence documents across too, not just policies. The actual approved files are downloaded from your source platform’s official API, checksum-verified, and stored in your Keel evidence library on import. A few items a platform shares only as a link (for example Vanta’s approved-policy PDFs) still need a manual export.
- New A beta OneTrust source joins Vanta and Drata (it exports your users and risk register today). As always, the tool runs on your own machine against each platform’s official read-only API, and your credentials never leave your computer.
- Improved Very large exports are now split into several bundle files automatically, so a big evidence library exports and imports reliably within memory limits. Import each file in any order; the idempotent matching keeps everything de-duplicated.
Bring your policy documents with you
- Improved When you migrate into Keel, your policy documents now come with you, not just a link. keel-migrate downloads the actual approved files from your source platform and inlines them in the bundle, and Keel stores them in your evidence library on import, so the documents survive after you cancel the old tool. Files are checksum-verified and held to the same size and storage limits as any upload.
Migrate to Keel, plus richer vendor & people risk
- New Bring your data to Keel with keel-migrate, an open-source, read-only tool you run on your own machine to export your vendors, risks, people, and policies from Vanta or Drata into an open bundle, then import it into your workspace in a few clicks. Your source credentials never leave your computer, and re-imports are idempotent, so nothing is duplicated.
- Improved Vendor risk now separates inherent (pre-control) from residual (post-control) criticality, and can auto-lower the residual from a vendor’s access controls: MFA, SSO, and password-policy strength.
- New People can be tagged with groups, and both access reviews and training can be scoped to a group. Each person now has a readiness rollup that unifies training completion and policy acknowledgements into a single onboarding view.
- New The public API gained people and policies endpoints, so you can sync your directory and policies into Keel programmatically via the REST API and webhooks.
Keel Quality: change control (Clause 6.3 / 8.5.6)
- New A new Change control module brings ISO 9001 Clause 6.3 (planning of changes) and 8.5.6 (control of changes) into Keel Quality. Raise a change request for a process, product, document, supplier, or system, and work it through a controlled lifecycle: requested → assessing → approved / rejected → implementing → verified → closed, with an impact assessment, a risk level, an approver, and post-change verification.
- New Changes awaiting approval and high-risk changes surface on the Quality dashboard, so nothing significant changes without review.
Keel Quality: customer complaints & feedback (Clause 9.1.2)
- New A new Complaints & feedback module captures customer complaints however they arrive (email, phone, portal, in person, social, or survey), the ISO 9001 Clause 9.1.2 (customer satisfaction) and 10.2 (nonconformity) requirement. Track each through open → investigating → resolved → closed with a severity, the customer, and the resolution.
- New When a complaint reveals a systemic problem, raise a CAPA from it in one click: the nonconformity is created and linked back, so a customer complaint flows straight into root-cause analysis. Open and high-severity complaints roll up onto the Quality dashboard.
Keel Quality: supplier quality & SCARs (Clause 8.4)
- New A new Supplier quality module brings ISO 9001 Clause 8.4 (control of externally provided processes, products, and services) into Keel Quality. Keep an approved-supplier list with each supplier’s category, qualification status (pending / approved / conditional / disqualified), and a 0–100 quality score, and set a re-evaluation date that Keel flags when it comes due.
- New Raise Supplier Corrective Action Requests (SCARs) against a supplier and drive each to closure through open → containment → corrective action → verify → closed, the supplier-facing sibling of your internal CAPA loop. Open SCARs surface on the supplier list and the Quality dashboard.
Quality dashboard
- New Keel Quality now has a home: a single Quality dashboard that pulls your whole quality-management system onto one surface: nonconforming outputs, nonconformities & CAPA, the audit programme, objectives, competence, and document control, each with its live counts and a link straight to the module.
- New A “Needs attention” roll-up at the top surfaces exactly what’s overdue or at risk right now: NCRs awaiting disposition, CAPA verifications due, audits overdue, objectives at risk, competence gaps, and documents past review, so a quality manager sees the day’s priorities the moment they land.
Document awareness & acknowledgment (Clause 7.3)
- New Controlled documents can now require the right people to read and acknowledge them, the ISO 27001 Clause 7.3 awareness expectation. Add required readers to any document in the Documented information register and track who has acknowledged the current version and who’s still pending.
- New When you publish a new version of a document, every reader’s acknowledgment resets to pending automatically, so people must confirm they’ve read the revision. No more wondering whether the team saw the update. Publishing a version also stamps the document as published in one step.
Audit programme & calendar (Clause 9.2.2)
- New A new Audit programme plans your internal audits across a period, the ISO 27001 / 9001 Clause 9.2.2 requirement. Create a programme (period + objectives), then schedule audits by process/area with an assigned auditor and a planned date. An upcoming-and-overdue calendar view shows what’s due next across every programme, with overdue and due-soon flags.
- New Set a cadence on any scheduled audit (e.g. every 12 months) and Keel rolls the next occurrence forward automatically when you launch it, so your annual plan maintains itself instead of being re-typed each year. Launch a scheduled audit in one click and it becomes a full internal audit, pre-filled and linked back to the schedule.
Deeper CAPA: action types, 8D, and effectiveness scheduling
- New Corrective actions now carry a type: correction (immediate containment), corrective (removes the root cause), or preventive (stops it happening elsewhere), so a nonconformity’s response reads the way ISO 9001 / 27001 Clause 10 expects, not as one undifferentiated to-do list.
- New Schedule the effectiveness check: set a date to re-verify that a fix actually held, and Keel flags it on the nonconformity and on the register when it comes due, so “we’ll check later” doesn’t quietly slip.
- New Optional 8D report: for significant or recurring problems, turn on the structured Eight Disciplines (D1–D8) template (team, problem, interim containment, root cause, permanent corrective actions, implementation, prevention, and closure) right on the nonconformity.
Keel Quality: nonconforming outputs (NCR, Clause 8.7)
- New Introducing Keel Quality, a new add-on that brings the product-quality half of ISO 9001 onto the same control-and-evidence graph as your ISMS. The first module is a nonconforming-outputs (NCR) register for ISO 9001 Clause 8.7: log a nonconforming product or output, record where it was found and how much is affected, contain it in quarantine, and capture the disposition decision: use-as-is (concession), rework, repair, scrap, return to supplier, regrade, or segregate, with the authority who approved it and re-verification of conformity after rework.
- New When an NCR needs root-cause, raise a CAPA from it in one click: the nonconformity is created and linked back, so Clause 8.7 (nonconforming outputs) and Clause 10.2 (corrective action) stay connected. Filter the register by status or disposition, and read your posture from summary tiles: awaiting disposition, critical open, units affected, and closed.
- Improved Keel Quality is a paid add-on layered on any plan. It’s managed from Billing; pricing is being finalized.
Documented information register (Clause 7.5)
- New A new Documented information register gives you the controlled master list of every document your ISMS depends on, the ISO 27001 Clause 7.5 requirement. Register policies, procedures, work instructions, forms, records, plans, and manuals, each with a document code, owner, approver, security classification, version, lifecycle status, and where the controlled copy lives. It sits alongside the Policies module, which holds your authored policy bodies.
- New Every document gets a review cadence and a next-review date, and Keel flags anything overdue or due within 30 days, right on the register and on each document, so controlled information never quietly goes stale. Mark a document reviewed and the next-review date rolls forward automatically. Add a retention rule and a distribution note to close out the Clause 7.5 control.
- Improved Filter the register by document type or status, and read your posture at a glance from summary tiles: published, in progress, review overdue, due soon, and retired.
Automatic vendor risk scoring
- New When you review a submitted vendor assessment, Keel now computes a weighted risk score (0–100) and a suggested tier (low, medium, high, or critical) straight from the answers. Each scored question is weighted by how material it is, risky or missing answers count against the vendor, and any response you flag as a finding is folded in too. The breakdown is shown, so the number is transparent, not a black box.
- Improved Apply the suggested score in one click and Keel sets the vendor’s risk tier for you. No more picking it by hand. You stay in control: it’s a suggestion you apply, and you can still accept or reject the assessment separately.
Competence & training-gap matrix (Clause 7.2)
- New A competence matrix, the ISO 27001 Clause 7.2 requirement to show the people doing security work are competent for it. For each person and role, record the competences they need, how each is established (education, training, experience, or certification), a status (met, in progress, or gap), and the evidence, with an expiry on time-bound certifications.
- New See at a glance how many competences are met, how many are gaps, and which certifications expire within 60 days, the training-gap view that pairs with the Training module and closes the loop on Clause 7.2.
Business continuity & BIA register (Annex A 5.29 & 5.30)
- New A business impact analysis and continuity register, the ISO 27001 Annex A 5.29 (information security during disruption) and 5.30 (ICT readiness for business continuity) requirement. For each critical process or service, capture its criticality, recovery objectives (RTO and RPO), the impact of disruption, its dependencies, and a recovery strategy, then record each continuity test so ICT readiness is evidenced, not assumed.
- New See at a glance how many processes are high or critical, how many have had their continuity tested, and which are still untested or missing an owner, the readiness view an auditor expects for 5.29 and 5.30.
Security objectives & KPIs (Clause 6.2)
- New Set measurable information security objectives and track them to target, the ISO 27001 Clause 6.2 requirement. Each objective carries a metric, a baseline, a target, and a current value, an owner, a target date, and a status (not started, on track, at risk, achieved, or missed), so your program has goals to steer by, monitored over time, not just controls to maintain.
- New See at a glance how many objectives are achieved, on track, or at risk, and which still need an owner, the measurable, monitored objectives an ISO 27001 auditor expects under Clause 6.2.
Legal & regulatory requirements register (Annex A 5.31)
- New A register for the legal, statutory, regulatory, and contractual requirements that apply to you, the ISO 27001 Annex A 5.31 obligation. Record each requirement with its type, jurisdiction, and citation, assign an accountable owner, and track a compliance status (met, partially met, not met, or not yet assessed) with a note on how you meet it.
- New See at a glance how many obligations are met, how many have gaps, and which are still unassessed or missing an owner, so nothing an auditor asks about is a surprise.
Information asset register (Annex A 5.9 & 5.12)
- New An information asset register, the ISO 27001 Annex A 5.9 (inventory of information and other associated assets) and 5.12 (classification of information) requirement. Inventory each asset with a type, an accountable owner, and a classification (public, internal, confidential, restricted), then rate it for confidentiality, integrity, and availability. It’s the foundation the rest of your ISMS builds on: every risk, control, and Statement of Applicability decision traces back to the assets you’re protecting.
- New See at a glance how many assets are confidential or restricted, how many carry a high CIA rating, and which are still missing an owner, so gaps in your inventory are obvious before an auditor finds them.
Management reviews (Clause 9.3)
- New A management review module, the ISO 27001 / 9001 Clause 9.3 requirement. Keel pre-fills the agenda with the inputs the standard asks for, pulled live from your program: internal audit results, open nonconformities, security incidents, and per-framework readiness. Record attendees, minutes, and decisions, and track the action items that come out of the review to done.
- New Export branded, auditor-ready management-review minutes (PDF), with the agenda inputs, minutes, decisions, and actions, the record a certification auditor expects for Clause 9.3. This completes the run-and-prove-your-ISMS set: SoA, internal audit, nonconformities & CAPA, incidents, and management review.
Security incident register (Annex A 5.24–5.28)
- New A security incident register: the ISO 27001 Annex A 5.24–5.28 workflow, and the record SOC 2 auditors expect. Report an incident with a severity, then work it through its lifecycle: investigate, contain, find the root cause, and capture lessons learned, with an at-a-glance view of what’s open and how many high-severity incidents are still live.
- New Incidents feed corrective action: raise a nonconformity (CAPA) from any incident in one click, pre-filled from the incident and linked back, so the follow-up is tracked to closure with an effectiveness check.
Internal audits (Clause 9.2)
- New An internal audit module, the ISO 27001 / 9001 Clause 9.2 requirement. Plan an audit against any framework you’ve enabled, and Keel generates a clause-by-clause checklist straight from that framework’s requirements. Work through it recording a result for each clause (conforming, nonconformity, observation, or opportunity for improvement) with notes.
- New Findings flow into corrective action: promote any nonconformity finding into the CAPA register in one click, pre-filled and linked back to the audit. Export a branded, auditor-ready internal audit report (PDF) with the scope, conclusion, and every finding.
Nonconformities & corrective action (CAPA)
- New A nonconformity & corrective-action (CAPA) register, the ISO 27001 / 9001 Clause 10 loop. Log a nonconformity (from an audit, an incident, a risk, or a control gap), work a guided root-cause analysis (5 Whys or Fishbone), assign corrective actions with owners and due dates, and track each one to done.
- New A real closure gate: a nonconformity can only be closed once you’ve recorded and confirmed that the corrective action was effective, the effectiveness-verification step auditors look for, enforced by the workflow, not left to a checkbox in a spreadsheet.
Statement of Applicability: your ISO 27001 SoA, generated
- New A Statement of Applicability (SoA) generator, the mandatory ISO 27001 deliverable (Clause 6.1.3). Keel builds it from your program: every one of the 93 Annex A:2022 controls, whether it applies, a justification for inclusion or exclusion, and its live implementation status pulled from the controls you’ve already mapped. Export a branded, auditor-ready SoA PDF in a click.
- New Applicability stays in sync with your scope: excluding an Annex A control on the SoA (or on the Scope page) updates both, and your readiness score, from one place. Add document-control details (version, ISMS scope statement, approver and date) that print on the SoA header.
CIS Critical Security Controls v8.1 is live
- New CIS Critical Security Controls v8.1 is now available: all 18 Controls and 153 Safeguards, organized by Implementation Group (IG1–IG3). Apply it in one click and Keel seeds the recommended controls, crosswalked so evidence you collect for SOC 2, ISO 27001, NIST, PCI, or HIPAA counts toward CIS too.
- New A CIS-scoped “evidence to collect” guide: for each control CIS expects, see the concrete artifacts that satisfy it and which ones you still need. The reference doubles as a per-framework gap checklist.
A policy template library, continuous checks & bulletproof backups
- New A library of 50+ framework-mapped policy templates (ISO 27001, SOC 2, GDPR, CIS Controls, ISO 9001 and more). Search, filter by framework, and create an editable draft with your company details pre-filled, then version, approve, and export a branded PDF.
- Improved The Policies page is now a full register: search and status filters, per-policy owner and review-due dates, one-click bulk status and archive, and a coverage checklist that shows which recommended policies you still need. Create any gap straight from a template.
- New Reset any policy back to its template at any time. Your document-control fields are kept and the previous version is saved to the revision history first.
- New Continuous automated checks: credential-free monitors verify real-world controls over HTTPS and DNS (TLS/HTTPS, security headers, SPF, DMARC) on a schedule and record each pass/fail as living evidence.
- New Connect your own AI agents and tools to Keel through a Model Context Protocol (MCP) server over the Keel API: list controls, check readiness, and manage tasks and webhooks programmatically.
- Improved Reliability, hardened: nightly off-provider encrypted database backups with automated monthly restore drills, a deep health endpoint for external uptime monitoring, and a documented disaster-recovery / business-continuity runbook.
A People page, smarter evidence & finer AI controls
- New Dedicated People page: manage your whole employee directory in one place: search, add, edit, and offboard, with each person’s training status at a glance. It feeds access reviews and training.
- New Questionnaire assist now takes a file: upload a Word, Excel, or CSV security questionnaire and Keel detects the questions and drafts answers grounded in your own controls and policies.
- Improved The Evidence page’s “evidence to collect” guide is now scoped to your enabled frameworks and marks, per control, whether you’ve already linked evidence, a running per-framework gap checklist.
- New Turn all AI off for a workspace with a single switch in Settings → AI credits; every AI button then disables until you switch it back on. AI credit activity also shows which user ran each action.
- Improved Training catalog filters (by topic and framework) and illustrated courses.
- Improved Program polish: a ⌘K command palette, teaching empty states, controls grouped by domain, evidence freshness tracking, and readiness-over-time trend charts on Reports.
New frameworks on the way
- New Three more frameworks are landing on a rolling schedule - CIS Controls v8.1, GDPR, and NIST 800-171 (CMMC-aligned). See their launch dates in the Frameworks catalog.
- Improved The Frameworks catalog now shows a launch month for scheduled frameworks instead of a bare "Coming soon".
Ten new AI tools & a dedicated MSP plan
- New Control implementation guidance: for any control, get plain-English steps and the exact evidence to collect.
- New One-click remediation tasks from a not-yet-met control, and AI-drafted risks straight from a vendor profile.
- New Questionnaire assist: draft answers to inbound security questionnaires from your own controls and policies.
- New Policy-gap analysis, audit-readiness executive summaries, evidence summaries, plain-language rewrites, trust-center narratives, and access-review anomaly notes - each an optional, credit-metered click.
- New MSP / Partner is now a dedicated plan with the multi-client console, white-label, and per-client partner pricing - separate from Enterprise.
Welcome AI credits & promo codes
- New New workspaces start with a one-time welcome bonus of AI credits to try every AI feature - the unused remainder expires after a short window.
- New Redeem promo codes for bonus AI credits from Settings → AI credits.
AI drafting for risks & policies
- New Draft risk-register entries with AI - tailored to your framework and company profile, scored, and ready to edit.
- New Draft a full policy from scratch with AI: name a topic and get a clean, framework-mapped first version in your editor.
MSP client provisioning & guided-setup checklist
- New Create a new, isolated client workspace right from the MSP multi-client console (Enterprise) - you become its owner and can run guided setup for them immediately.
- Improved The dashboard getting-started checklist is now progress-driven and dismissible, linking straight to each remaining setup step.
- Fixed Support and Help links now resolve reliably to the in-app Help page and contact.
Weekly digest
- New Opt-in weekly readiness digest email: readiness, gaps to close, open risks and tasks, vendors due for review, and outstanding training - summarized every week. Turn it on in Settings.
- Improved The on-demand "email me a digest" summary is now far more comprehensive.
Training, governance & vulnerability monitoring
- New Security-awareness training: assign framework-mapped courses to your team, track completion, and auto-collect certificates as evidence.
- New RACI matrix across controls, policies, and risks - assign Responsible / Accountable / Consulted / Informed, with a printable export.
- New Executive board pack: a one-click management-review (ISO 27001 Clause 9.3) / steering-committee deck.
- New CISA Known Exploited Vulnerabilities (KEV) catalog with search and ransomware filtering, refreshed from CISA’s feed.
- New Risk heat map - a 5×5 likelihood × impact view of your register.
- Improved Vendor questionnaire portal: the vendor contact can invite colleagues to help answer, and any of them can submit.
- New Opt-in domain-based workspace join, so teammates on your company domain land in the same workspace.
Vendor assessments & questionnaire builder
- New Send security questionnaires to vendors via a secure, no-login portal - with a library of 100+ curated questions.
- New AI questionnaire builder assembles a scored, structured questionnaire from your concerns in seconds.
- New Vendors can upload evidence files (SOC 2 reports, certs) directly in the portal.
- New Admin-managed global questionnaire catalog available in every workspace.
- Improved Automatic vendor risk scoring on submission, with reviewer flagging and findings.
AI, embedded
- New AI policy & document import - drop in a Word doc and get a clean, framework-mapped policy.
- New AI vendor profiles: paste a website and Keel drafts the vendor’s risk profile.
- New Metered AI credits included on every paid plan, with pay-as-you-go top-ups.
- Improved Monthly AI credit allotment is now granted automatically.
Risk register & reporting
- New First-class risk register with inherent/residual scoring, treatments, owners, and control links.
- New Branded, print-ready compliance readiness report.
- New Readiness digest you can email yourself.
Team, trust center & integrations
- New Shared team workspaces with invites and owner/member roles.
- New Public, branded trust center to share your posture with prospects.
- New Directory sync (Microsoft Entra / Google) and periodic access reviews.
- New REST API and outbound webhooks (REST Hooks).
Frameworks & evidence
- New One control library crosswalked across SOC 2, ISO 27001, PCI DSS, HIPAA, ISO 9001, NIST CSF, and ESG.
- New One-click starter control sets per framework.
- New Evidence library with control linkage and branded policy PDF export.
Keel launch
- New Self-serve GRC: stand up a real compliance program in an afternoon - controls, evidence, policies, and readiness, no sales call.