Keel GRC
GRC for SMBs & MSPs. Get audit-ready, and prove it.
6 followers
GRC for SMBs & MSPs. Get audit-ready, and prove it.
6 followers
Keel helps growing organizations manage risk, meet their obligations, and prove their work through one connected, practical GRC platform. One workspace covers controls, evidence, policies, access reviews, and a trust center, so you collect evidence once, comply everywhere. Frameworks include ISO/IEC 27001, CIS Critical Security Controls, PCI DSS, SOC 2.







Curious how the AI piece actually works in practice — does it just draft policies from prompts, or is it pulling in evidence from your stack and flagging gaps automatically? Also wondering what integrations you support out of the box, since that usually decides whether something like this saves time or adds busywork.
@nazlcan1332465 Hello and thank you for the great questions!
On the AI: it's grounded in your Keel workspace, not blank-prompt drafting. Today it drafts policies from a topic using your industry + active framework as context, analyzes your existing policy set against that framework to flag what's missing or thin, summarizes and gap-checks the evidence you've attached to controls, and drafts things like vendor risks, questionnaire answers, and a trust-center narrative from your real posture. So it both drafts and flags gaps over the data in your workspace. To be straight about the boundary: it doesn't yet crawl your cloud/SaaS stack to auto-collect evidence in the background... you add evidence (upload or link) and the AI reasons over it. Automated stack-based evidence collection is on our roadmap, not something I'll claim we do today.
On integrations out of the box: employee-directory sync with Microsoft Entra ID and Google Workspace (plus CSV import) powering access reviews, offboarding, and training assignment; a REST API + webhooks (works with Zapier) to push events into your other tools; and GitHub for content publishing. Evidence today is upload/link rather than auto-pulled from cloud providers.
We're still early, so I'd genuinely love to hear which integrations would save you the most time. That feedback is helping shape our roadmap.
finally tried this out for our soc 2 prep and the evidence mapping across frameworks saved me from hours of duplicate work. vendor risk module felt a little bare, but the ai questionnaires were surprisingly useful.
@mzeyyenb78a Thanks! Really appreciate you taking the time to try it out. Hearing that the evidence mapping saved you hours is exactly what we were hoping for.
I also agree on the vendor risk module. It’s still early and has a lot more planned. We’ve got several enhancements and AI capabilities on the roadmap that will make it much more powerful over the next few releases.
Thanks again for the honest feedback. It’s incredibly helpful.