One platform for your whole GRC program
Controls crosswalked across every framework, a living risk register, a policy builder, vendor risk, access reviews, a public trust center, and AI woven through all of it, so you collect evidence once and comply everywhere. Explore each capability below.
Compliance & controls
A library of 50+ framework-mapped policy templates you fill in, approve, and export as branded PDFs, or draft from scratch with AI. A register tracks owners, review dates, and coverage gaps.
Learn more → Controls & crosswalkOne control library, crosswalked across every framework, so you collect evidence once and comply everywhere.
Learn more → Information asset registerInventory your information and associated assets with an owner, a classification, and a CIA rating, the ISO 27001 Annex A 5.9 and 5.12 register your whole ISMS is built on.
Learn more → Nonconformities & CAPALog a nonconformity, find its root cause, correct it, and verify the fix worked before you close it, the ISO 27001 / 9001 Clause 10 loop.
Learn more → Internal auditsPlan an internal audit, work a clause-by-clause checklist generated from the framework, record findings, and export an auditor-ready report, the ISO 27001 / 9001 Clause 9.2 requirement.
Learn more → Security incident registerReport, triage, contain, and learn from security incidents, the ISO 27001 Annex A 5.24–5.28 workflow, and the record a SOC 2 auditor expects.
Learn more → Management reviewsRun the ISO 27001 / 9001 Clause 9.3 management review with the agenda pre-filled from your program (audit results, nonconformities, incidents, and readiness), plus minutes, decisions, and a branded PDF.
Learn more → Legal & regulatory requirements registerTrack the legal, statutory, regulatory, and contractual obligations that apply to you, the ISO 27001 Annex A 5.31 register, each with an owner and a compliance status.
Learn more → Business continuity & BIAA business impact analysis and continuity register, the ISO 27001 Annex A 5.29 and 5.30 requirement, with RTO, RPO, recovery strategy, and continuity-test tracking on every critical process.
Learn more → Security objectives & KPIsSet measurable information security objectives and track them to target, the ISO 27001 Clause 6.2 requirement, with a metric, a baseline, a target, and a live status on each.
Learn more → Competence & training-gap matrixShow the people doing security work are competent for it, the ISO 27001 Clause 7.2 requirement, with a per-person competence matrix, evidence, and expiry tracking.
Learn more → Documented information registerThe controlled master list of every document your ISMS depends on, the ISO 27001 Clause 7.5 requirement, with owners, versions, classification, review cadence, and retention.
Learn more → Nonconforming outputs (NCR)Control nonconforming product and outputs, the ISO 9001 Clause 8.7 requirement, with disposition, quarantine, and a one-click bridge to CAPA.
Learn more → Audit programme & calendarPlan and maintain your internal-audit programme, the ISO 27001 / 9001 Clause 9.2.2 requirement, on a cadence, with a calendar that shows what’s due.
Learn more → Quality dashboardYour whole quality-management system on one surface: nonconforming outputs, CAPA, audits, objectives, competence, and document control, with a live “needs attention” roll-up.
Learn more → Complaints & customer feedbackCapture, investigate, and resolve customer complaints, the ISO 9001 Clause 9.1.2 / 10.2 requirement, and escalate systemic ones to a root-cause CAPA.
Learn more → Change controlPlan and control changes to processes, products, documents, and systems, the ISO 9001 Clause 6.3 / 8.5.6 requirement, through impact assessment, approval, and verification.
Learn more →Vendor & questionnaires
Track third parties by criticality, send security questionnaires, and profile a vendor from just its URL with AI.
Learn more → Security questionnaire automationAnswer inbound security questionnaires with AI grounded in your own controls, and send auto-scored ones to your vendors.
Learn more → Supplier quality & SCARsControl your externally provided products and services, the ISO 9001 Clause 8.4 requirement, with an approved-supplier list, quality scores, and supplier corrective actions (SCARs).
Learn more →Proof & reporting
Attach evidence to a control once and reuse it across every framework that control satisfies.
Learn more → Trust centerA branded, public proof page (posture, policies, and documents) that helps you close deals without a security call.
Learn more → Readiness reportsBranded, auditor-ready readiness reports and a posture digest you can email yourself in a click.
Learn more → Statement of ApplicabilityGenerate the mandatory ISO 27001 Statement of Applicability from your program: every Annex A control, its applicability, justification, and status, exported as a branded PDF.
Learn more →AI, built in
AI woven through every module: draft policies and risks, profile vendors, answer questionnaires, and summarize evidence.
Learn more → AI InsightsOne rundown of your whole compliance program: readiness gaps, policy and vendor issues, stale evidence, and where to focus next, each with a link to act.
Learn more →Platform
Directory sync, a REST API, and webhooks (REST Hooks) connect Keel to the tools you already run.
Learn more → Tasks & remediationTurn gaps and findings into tracked work items: created in-app, from a failing control with AI, via the API, or over webhooks.
Learn more → Public roadmap & changelogA public roadmap you can vote on and a changelog of what shipped, so you can see the product is moving and shape where it goes.
Learn more → RACI matrixMake ownership explicit across your program with a Responsible / Accountable / Consulted / Informed matrix.
Learn more →No credit card. A working program in an afternoon.