Crosswalk-native GRC
Crosswalk-native GRC: author a control once, comply everywhere
In most GRC tools every framework is a separate checklist, so you re-do the same work for every audit. Keel inverts that. A control is the unit of work and each framework is a view over your controls, so a single control satisfies clauses across all the frameworks you have applied at once. Author your evidence once and it counts everywhere, on an open API you can automate and with data you can take with you.
One control, many frameworks · REST API, webhooks & MCP · keel-migrate (MIT) · public pricing.
What sets Keel apart
Built around one idea: reuse the control, not the busywork
Crosswalk-native is the foundation, and three principles build on it. Each one is something Keel does today, not a promise.
-
Crosswalk-native
One control, many frameworks
Controls are the atom, frameworks are views over them. Author a control once and it satisfies clauses across every framework you have applied at the same time. Collect the evidence once, comply everywhere.
-
Connected
Fits the stack you already run
A REST API, outbound webhooks (REST Hooks), a Model Context Protocol (MCP) server for AI agents, a Zapier app (private beta), and directory sync. Your program is data you can read, push, and automate.
-
Portable
Your data leaves as easily as it arrives
keel-migrate is an open-source (MIT), read-only tool that exports your registers, policies, and evidence to a neutral, documented bundle, into Keel or anywhere. Portability is a principle, not a favor.
-
Transparent
Self-serve, public pricing, start free
No mandatory sales call to see a price or start a program. Public pricing, a real free tier, and a product you can stand up yourself in an afternoon. What you see is what you pay.
Crosswalk-native
The crosswalk is the architecture, not a report
In checklist-based GRC, each framework is a separate list and you re-do the same work for every audit. Keel makes the control the unit of work, and every framework a view over your controls. Author a control once and it satisfies mapped clauses across all the frameworks you have applied at the same time. Apply your second framework and a large share of it is already covered by the controls you built for the first.
-
One control library
Apply a framework and one-click a curated, pre-mapped starter control set instead of starting from a blank page.
-
Collect evidence once
Attach evidence to a control once and it counts everywhere that control is mapped, no duplicated evidence per framework.
-
See the overlap
The crosswalk explorer shows how clauses in one framework line up with another, so you can see reuse before you commit.
Live frameworks in the crosswalk
-
ISO/IEC 27001
The international standard for an Information Security Management System (ISMS), including the Annex A control set. Keel’s flagship framework.
-
CIS Critical Security Controls
A prioritized set of safeguards to mitigate the most common cyber attacks, mapped to Implementation Groups.
-
PCI DSS
Payment Card Industry Data Security Standard - requirements for organizations that store, process, or transmit cardholder data.
-
SOC 2
Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) for service organizations. The report buyers ask for most.
-
SOX (Sarbanes-Oxley) Section 404
Internal control over financial reporting for a US issuer, modelled against the five components and seventeen principles of the COSO Internal Control—Integrated Framework (2013) — the framework management evaluates ICFR against to make the assessment SOX Section 404(a) requires. SOX itself is a statute of eleven titles that publishes no control list: 15 U.S.C. 7262(a) requires an assessment of effectiveness, 17 CFR 240.13a-15(c) requires it to rest on “a suitable, recognized control framework”, and 17 CFR 229.308(a)(2) requires management’s report to name the framework it used. The seventeen principles are that framework and are the complete, declared scope here: the control environment (integrity, board oversight, structure and authority, competence, accountability), risk assessment (financial reporting objectives, risk analysis, fraud including management override, change), control activities (control design and precision, general controls over technology, deployment through policy and procedure), information and communication (information quality, internal and external communication), and monitoring (evaluation of the other four components — built into daily operations, run separately, or both — and deficiency evaluation and reporting). Deliberately outside that scope, each for a stated reason: the §302 and §906 officer certifications, the §404(b) auditor attestation, process-level controls over revenue, procure-to-pay, payroll, the financial close and management estimates, and COSO’s points of focus. ITGCs are not a separate authored layer — they are the subject of Principle 11, with the access, change-management and operations detail carried by the crosswalked starter controls.
-
NIST Cybersecurity Framework
Outcome-based framework organized by the Govern, Identify, Protect, Detect, Respond, and Recover functions.
-
NIST SP 800-53
Security and privacy controls for information systems and organizations, scoped to the 800-53B Moderate baseline.
-
NIST SP 800-171
Protecting Controlled Unclassified Information (CUI) in nonfederal systems (CMMC-aligned).
-
HIPAA
US regulation for protected health information, modeled to 45 CFR Part 164 leaf level: the Security Rule’s administrative, physical and technical safeguards with every required and addressable implementation specification, the Breach Notification Rule, and the Privacy Rule’s individual rights and administrative duties (§164.520-§164.530). The Privacy Rule’s permitted-use and disclosure provisions (§164.502-§164.514) are freestanding permissions - each authorises a disclosure a covered entity is free never to make, so no duty attaches to it - and are deliberately not scored. Permissions that attach to a duty the entity already has, such as the joint notice at §164.520(d) and the termination of an agreed restriction at §164.522(a)(2), are scored. Applicability paragraphs that only state who the section binds, such as §164.530(k), are not requirements and are not scored.
-
GDPR
EU General Data Protection Regulation - every obligation the Regulation places on a controller or processor, modelled at its own numbered-paragraph level: principles and lawful basis, data-subject rights, accountability, processor contracting, records, security, breach handling, DPIAs, the DPO and international transfers. Provisions addressed to Member States, the Commission, supervisory authorities and the Board, and the remedies and penalties of Chapter VIII, are cited but not scored.
-
COPPA
The FTC’s Children’s Online Privacy Protection Rule (16 CFR Part 312), as amended in 2025, modelled to the Rule’s own paragraph level: notice to parents and on the service, verifiable parental consent with its recognised methods and its exceptions, the parent’s right to review and delete, the ban on conditioning a child’s participation on excess collection, the written children’s information security programme, and the retention-and-deletion duty. It binds operators of websites and online services directed to children under 13, and any operator with actual knowledge it collects personal information from a child. Scope (§312.1), definitions (§312.2), enforcement (§312.9), safe harbor programmes (§312.11), the Commission’s voluntary approval processes (§312.12) and severability (§312.13) are cited but not scored: they impose no implementable operator duty, or they bind the Commission or a safe harbor programme rather than an operator.
-
Google Play Families
Google Play’s Families Policies, modelled requirement by requirement: the Play Console target-audience and data-safety declarations; the Families Policy Requirements covering child-appropriate content, disclosure of what is collected from children, the persistent identifiers a child-only app may not transmit (AAID, SIM serial, Build serial, BSSID, MAC, SSID, IMEI, IMSI) and the wider mixed-audience rule that also covers users of unknown age, the AD_ID permission on API 33 and above, precise location, Companion Device Manager for Bluetooth, SDK approval for child-directed services, augmented-reality safety warnings, online-safety reminders and adult controls on social features, and compliance with COPPA and the GDPR; and the Families Ads and Monetization requirements - ads to children or unknown-age users only from Families Self-Certified Ads SDK versions, no interest-based advertising or remarketing, age-appropriate creative, and the ad format rules on ad walls, five-second closeability, launch interstitials, multiple placements and virtual currency. Google publishes no version number or clause numbering, so this carries the date Keel retrieved the policy and uses Keel’s own reference scheme. A replacement Families policy takes effect on 2026-08-26; Keel models the policy in force as at retrieval and does not author the preview. Requirements Google places on ads SDK vendors and mediation platforms bind those parties rather than the developer, and are cited but not scored.
-
Amazon Appstore Child-Directed Apps
The Amazon Appstore’s Child-Directed App (COPPA) Policy, modelled requirement by requirement: the child-directed determination and the factors behind it, age-appropriate content, compliance with COPPA and other applicable children’s privacy law, the bar on serving ads through any Amazon Advertising or Amazon Associates programme to a known child or in a child-directed area of the app - which parental consent does not lift - the complete bar on those programmes in an app directed only at children, and the rules on which SDKs may collect personal information from children. Note the scope: Amazon treats a multi-audience app as child-directed unless the developer confirms children are not using it, and defines children as under 13, or under 16 in the European Union, Australia and Japan - a wider band than COPPA’s. Amazon publishes no version number or clause numbering, so this carries the date Keel retrieved the policy alongside Amazon’s own last-updated date of 2020-06-01, and uses Keel’s own reference scheme. Amazon’s separate Advertising ID, User Data Privacy and Appstore Advertising policies are different documents and are not modelled here.
-
Apple App Store Kids Category
The App Store rules whose duties are triggered by a child, a minor, an underage user, or by the Kids Category - the stated scope rule this framework is complete against, with every excluded guideline enumerated by number in the framework file. Guideline 1.3 (the Kids Category: the App Store Connect age band, parental gates on links out and purchases and the adult-level task a gate must be, requirements that persist after the category is deselected, no personally identifiable or device information sent to third parties even from adult-facing sections, human review of any advertising displayed, and third-party analytics and advertising excluded by default with narrow carve-outs), plus Guidelines 1.2.1(a) and 4.7.5 (age restriction for creator content and for mini apps, games, chatbots and emulators), 1.4.3 (encouraging minors to consume tobacco, drugs or alcohol), 2.3.8’s reservation of “For Kids” and “For Children” metadata, 2.5.13 (an alternative to facial-recognition sign-in for under-13s), 2.5.18 (no targeted or behavioural advertising on data from kids), 5.1.3(iii) (parent or guardian consent for a minor in health research), 5.1.4 (kids’ personal data, reaching apps intended primarily for kids and apps merely capable of sharing a minor’s information), and 5.1.1(i) for the contents of the privacy policy 5.1.4(b) requires. This is NOT a model of the App Store Review Guidelines as a whole and does not predict App Review outcomes: all 125 numbered guidelines still bind the app. Apple publishes no delimited Kids requirements document and no version number, so this carries the date Keel retrieved the two source pages.
-
ISO 9001
Quality Management System (QMS) requirements - consistent quality and continual improvement.
-
AI Governance Essentials
A Keel-authored baseline for responsible-AI governance - plain-language expectations across governance, risk, data, transparency, human oversight, security, lifecycle, and third parties, ready to evidence today and later map to a formal AI standard.
-
ISO/IEC 42001
AI Management System (AIMS) - governance for responsible development and use of AI. Management clauses 4-10 plus the Annex A reference controls (nine objective groups).
-
NIST AI Risk Management Framework
Voluntary framework for managing AI risks, organized around the Govern, Map, Measure, and Manage functions, modeled to the seventy-two subcategories of the Core.
-
EU AI Act
EU regulation on artificial intelligence (Regulation (EU) 2024/1689), setting obligations by risk tier: prohibited practices, high-risk requirements and obligations, transparency, and general-purpose AI models.
-
ESG Essentials
A Keel-authored baseline ESG program (Environmental, Social, Governance) for SMBs - plain-language expectations you can evidence today and later map to a formal standard. Its social-responsibility coverage was checked against the seven core subjects of ISO 26000:2010, which is guidance and cannot be certified against.
-
US Employment Law - Federal Baseline
The federal floor for US employment compliance - wage and hour, leave, anti-discrimination, safety, benefits, classification, labor relations, and required notices - that applies nationwide, with state-delta overlays for all 50 states and DC applied to the states you employ in.
Frameworks are added as data, not code. See the full, current list on the frameworks page, or open the crosswalk explorer. Framework names are referenced factually; Keel is not affiliated with their owners.
Connected
Built to connect, and to hand to your AI agents
A control program is more useful when your other systems can reach it. Keel exposes your compliance data through standard, documented interfaces, so you can automate the busywork and let the tools (and AI agents) you already run do the reading and the writing.
-
REST API
Read and write your controls, evidence, risks, and more programmatically. Your program is queryable, not trapped behind a UI.
-
Outbound webhooks (REST Hooks)
Subscribe your systems to events in Keel and get pushed the moment something changes, so your stack reacts in real time.
-
MCP server
A Model Context Protocol server lets the AI agents you already use read from and act in Keel through a standard interface.
-
Zapier app (private beta)
No-code automation across 6,000+ apps: trigger tasks and alert your team. In private beta today.
-
Directory sync
Sync staff from Microsoft Entra or Google Workspace (or CSV) so access reviews and people data stay current automatically.
-
keel-migrate (open source)
An MIT-licensed CLI that exports your data from other platforms using their official APIs, read-only, running on your own machine.
Portable, no lock-in
Your data leaves as easily as it arrives
Lock-in is the quiet cost of closed GRC: the harder it is to leave, the less a vendor has to earn your renewal. Keel rejects that. Your registers, policies, and evidence are yours, and keel-migrate is a real open-source (MIT), read-only tool that runs on your own machine and exports them to a neutral, documented bundle, to bring into Keel, or to take anywhere. We built it on official, supported APIs precisely because your right to your own data should not depend on anyone’s permission.
-
Open source, auditable
The exporter is public under the MIT license. Read exactly what it does before you run it, no black box, no account required.
-
A neutral bundle format
It writes documented bundle files in a neutral format. Import them into Keel, or just keep them. Your data is not tied to any one destination.
Transparent
Self-serve, public pricing, start free
There is no mandatory sales call to see a price or to start a program. Keel has public pricing and a genuine free tier, so you can stand up a real program yourself, apply a framework, and watch how much of the next one your controls already cover.
FAQ
Common questions about crosswalk-native GRC
-
What does "crosswalk-native" mean?
- It means the crosswalk is the architecture, not a report bolted on afterward. In Keel a control is the unit of work and each framework is a view over your controls, so a single control satisfies mapped clauses across many frameworks at once. Apply a second framework and much of it is already covered by controls you authored for the first.
-
How is Keel different from other GRC tools?
- Four things: it is crosswalk-native (one control covers many frameworks), it connects to your stack through a REST API, webhooks, and an MCP server, your data is portable with the open-source keel-migrate exporter, and it is self-serve with public pricing. In short, less duplicated work and no lock-in.
-
Which frameworks can Keel crosswalk today?
- Live frameworks are ISO/IEC 27001, CIS Critical Security Controls, PCI DSS, SOC 2, SOX (Sarbanes-Oxley) Section 404, NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, HIPAA, GDPR, COPPA, Google Play Families, Amazon Appstore Child-Directed Apps, Apple App Store Kids Category, ISO 9001, AI Governance Essentials, ISO/IEC 42001, NIST AI Risk Management Framework, EU AI Act, ESG Essentials and US Employment Law - Federal Baseline. Frameworks are added as data, so the catalog on the frameworks page is always the current, accurate list.
-
How does Keel avoid vendor lock-in?
- Data portability is a first-class principle. keel-migrate is an open-source (MIT) tool that exports your registers, policies, and evidence to a neutral, documented bundle you can keep or import anywhere. Combined with the REST API and webhooks, your compliance program is never trapped in one vendor.
-
Do I have to talk to sales to start?
- No. Keel is self-serve with public pricing and a free tier. You can start a real program yourself, apply a framework, and see how much of the next one your controls already cover, no demo gate required.
Framework names are referenced factually; Keel is not affiliated with, endorsed by, or sponsored by their owners. Third-party product and standard names are trademarks of their respective owners. See our legal and trademarks page.
Run every framework off one control library
Author once, comply everywhere, and take your data with you. Start free, apply a framework, and see the reuse for yourself.