Keel is a governance, risk and compliance (GRC) platform for small and mid-sized companies doing compliance for the first time. It is built for the founder, IT lead, or fractional CISO who has to pass a first SOC 2 or ISO 27001 audit without a dedicated compliance team.
Keel stores controls and evidence in a single graph and crosswalks them across frameworks, so a policy you approve or a piece of evidence you upload counts toward every framework that requires it. Thirteen frameworks are live today: SOC 2, ISO/IEC 27001:2022, HIPAA, PCI DSS 4.0.1, CIS Controls v8.1, NIST CSF 2.0, NIST SP 800-53 Rev. 5, ISO 9001:2015, ISO/IEC 42001:2023, NIST AI RMF 1.0, the EU AI Act, AI Governance Essentials, and ESG Essentials.
The platform includes a risk register with likelihood and impact scoring, more than 50 framework-mapped policy templates with AI drafting and PDF export, vendor risk management, automated security questionnaires, evidence collection, access reviews, readiness reports, a Statement of Applicability, and a public trust center for sharing your security posture with customers. MSPs can manage multiple client programs from one console, with each client in an isolated, white-label workspace.
The free plan requires no credit card and includes NIST CSF 2.0 and AI Governance Essentials. Paid plans start at $99 per month.