What we’re building next
A look at where Keel is headed. Want to shape it? Sign in and vote or suggest an idea on the live roadmap, and see what we’ve already shipped on What’s new.
Grounded questionnaire answering engine
AITurn questionnaire assist into an auditable engine: reuse the answers you’ve already approved, retrieve from your own policies, controls, and evidence, and draft each answer only from cited snippets, flagging anything it can’t support for review instead of guessing. Upload a PDF/Excel/Word questionnaire and get your file back filled in; every answer you accept is saved and reused, so accuracy compounds and repeat questionnaires get faster and cheaper.
Zapier integration
IntegrationsA Zapier app (in private beta — request access) so you can connect Keel to thousands of tools with no code: trigger automations when a control, evidence item, task, or risk changes, and create tasks, log evidence, or open risks from wherever your team already works.
Publish your trust center on a custom domain
Trust CenterServe your public trust center from your own domain (e.g. trust.yourcompany.com) with your branding and an automatically provisioned certificate, instead of a Keel-hosted URL. The in-app flow (add host, verify by TXT, provision certificate) is built; finishing platform enablement.
Migrate from another GRC tool
OnboardingLive: export your vendors, risks, people, policies, and the actual policy and evidence document files from Vanta or Drata with the open-source keel-migrate tool, then import them into Keel (large exports are split across files automatically). A OneTrust source is in beta. Coming next: more source platforms and direct-to-storage streaming for very large libraries.
Keel mobile app (iOS & Android)
PlatformA companion app for the on-the-go moments: approve access reviews and policies, complete assigned training, clear task reminders, and check readiness, with push notifications.
Continuous evidence integrations
AutomationAuto-collect evidence from cloud and SaaS tools (AWS, GitHub, Google Workspace, and more) so controls stay current without manual uploads.
Framework version-to-version gap analysis
FrameworksWhen a framework publishes a new revision, see a clause-level diff of what was added, changed, merged, or retired, and a report of the delta work to re-certify. Built for migrations like ISO 27001:2013 → 2022 and CIS Controls v8.0 → v8.1.
NIS2 & DORA (EU cyber & operational-resilience regulations)
FrameworksAuthored coverage for the EU NIS2 Directive (Directive (EU) 2022/2555) and the Digital Operational Resilience Act (Regulation (EU) 2022/2554), crosswalked to the ISO 27001 and SOC 2 controls you already run so most of the evidence carries over. Listed in the framework catalog now; content is being authored and IP-reviewed.
OSCAL export: System Security Plan & POA&M
FrameworksExport your program as NIST OSCAL — a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M) — generated from the controls, evidence, and gaps you already track in Keel, so teams working toward FedRAMP or federal frameworks can hand assessors machine-readable artifacts instead of rebuilding them by hand. Builds on the OSCAL catalog and crosswalk export Keel already produces.
Slack & Microsoft Teams notifications
IntegrationsRoute review reminders, control changes, and readiness digests to your team’s chat.
AI compliance agent (computer use)
AIAn AI agent that can actually operate Keel and your connected tools on your behalf, gather evidence, draft controls and policies, chase down gaps, and prep an audit package, working through tasks step by step while you stay in control and approve the results. Early idea: vote if you’d want it.
Customizable dashboard widgets
ReportingRearrange your program dashboard and show or hide widgets, pin the charts and posture cards that matter most to your team, saved per user.
Push remediation tasks to Jira & GitHub Issues
IntegrationsTwo-way sync so a control gap in Keel becomes a ticket in the tracker your team already lives in, and closing it there marks the control remediated here.
Risk quantification in dollars
RiskLayer a FAIR-style quantitative model onto the risk register so you can express exposure as a probable financial range, not just a heat-map color, the language executives and boards fund against.
Subscribe to trust center updates
Trust CenterLet prospects and customers subscribe to be notified when your trust center posts a new update or your posture changes.
SCIM directory provisioning
EnterpriseBeyond SSO: auto-provision and deprovision Keel users from your identity provider (Okta, Entra, Google) via SCIM, so joiners and leavers flow through without manual seat management.
Gated & requestable downloads
Trust CenterPublish sensitive reports (e.g. a SOC 2) as request- or invite-only: visitors see it exists and ask for access, which the publisher approves, instead of a public link.
Upload trust center documents
Trust CenterUpload files for download on the trust center (policies, certificates, reports) instead of only linking out to them.
Custom frameworks & controls
FrameworksBring your own framework or add custom controls and crosswalk them alongside the built-in catalog.
Find-an-auditor marketplace
AuditA curated directory of independent auditors and assessors who already know Keel: request quotes and share a read-only audit workspace, so getting from “ready” to “certified” is one less scramble.
Subprocessor & vendor logos
Trust CenterShow vendor and subprocessor logos on the trust center, pulled automatically via AI vendor enrichment or added by hand.
More continuous checks
AutomationExpand the credential-free monitors beyond TLS, security headers, SPF, and DMARC (think DNSSEC, CAA, and certificate-expiry), each recorded as living evidence.
Bring your own policy templates
PoliciesSave and reuse your own policy templates alongside Keel’s 50+ library, so your team can standardize on its house wording and structure.
Auditor collaboration workspace
AuditBeyond today’s free read-only auditor seat, give your auditor a place to leave evidence requests and track fieldwork in-app.
Gap analysis & evidence-index reports
ReportingOne-click reports that list every unaddressed requirement and index all evidence by control.