Roadmap
What we’re building next
A look at where Keel is headed. Want to shape it? Sign in and vote or suggest an idea on the live roadmap, and see what we’ve already shipped on What’s new.
In progress 4
-
Integrations
Zapier integration
A Zapier app connecting Keel to thousands of tools. In private beta — request access — the Zap editor offers triggers for a control status change and a new task, a Create Task action, and a search for your ISO 27001 readiness summary. Risks, vendors, evidence, policies and readiness changes are built on Keel’s API but not selectable in a Zap yet.
-
Trust Center
Publish your trust center on a custom domain
Serve your public trust center from your own domain (e.g. trust.yourcompany.com) with your branding and an automatically provisioned certificate, instead of a Keel-hosted URL. The in-app flow (add host, verify by TXT, provision certificate) is built; finishing platform enablement.
-
Onboarding
Migrate from another GRC tool
Live: export your vendors, risks and people from Vanta, Drata, Hyperproof, Oneleet or Secureframe with the open-source keel-migrate tool, then import them into Keel (large exports split across files automatically). Policies and evidence files travel only where the source platform’s API documents them. A OneTrust source is in beta (users and risks today). Coming next: more sources and direct-to-storage streaming for very large libraries.
-
Platform
Keel mobile app (iOS & Android)
A companion app for the on-the-go moments: approve access reviews and policies, complete assigned training, clear task reminders, and check readiness, with push notifications.
Planned 5
-
Automation
Continuous evidence integrations
Auto-collect evidence from cloud and SaaS tools (AWS, GitHub, Google Workspace, and more) so controls stay current without manual uploads.
-
Frameworks
Framework version-to-version gap analysis
When a framework publishes a new revision, see a clause-level diff of what was added, changed, merged, or retired, and a report of the delta work to re-certify. Built for migrations like ISO 27001:2013 → 2022 and CIS Controls v8.0 → v8.1.
-
Frameworks
NIS2 & DORA (EU cyber & operational-resilience regulations)
Authored coverage for the EU NIS2 Directive (Directive (EU) 2022/2555) and the Digital Operational Resilience Act (Regulation (EU) 2022/2554), crosswalked to the ISO 27001 and SOC 2 controls you already run so most of the evidence carries over. Listed in the framework catalog now; content is being authored and IP-reviewed.
-
Frameworks
OSCAL export: System Security Plan & POA&M
Export your program as NIST OSCAL — a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M) — generated from the controls, evidence, and gaps you already track in Keel, so teams working toward FedRAMP or federal frameworks can hand assessors machine-readable artifacts instead of rebuilding them by hand.
-
Integrations
Slack & Microsoft Teams notifications
Route review reminders, control changes, and readiness digests to your team’s chat.
Considering 13
-
AI
AI compliance agent (computer use)
An AI agent that can actually operate Keel and your connected tools on your behalf, gather evidence, draft controls and policies, chase down gaps, and prep an audit package, working through tasks step by step while you stay in control and approve the results. Early idea: vote if you’d want it.
-
Reporting
Customizable dashboard widgets
Rearrange your program dashboard and show or hide widgets, pin the charts and posture cards that matter most to your team, saved per user.
-
Integrations
Push remediation tasks to Jira & GitHub Issues
Two-way sync so a control gap in Keel becomes a ticket in the tracker your team already lives in, and closing it there marks the control remediated here.
-
Risk
Risk quantification in dollars
Layer a FAIR-style quantitative model onto the risk register so you can express exposure as a probable financial range, not just a heat-map color, the language executives and boards fund against.
-
Enterprise
SCIM directory provisioning
Beyond SSO: auto-provision and deprovision Keel users from your identity provider (Okta, Entra, Google) via SCIM, so joiners and leavers flow through without manual seat management.
-
Frameworks
Custom frameworks & controls
Bring your own framework or add custom controls and crosswalk them alongside the built-in catalog.
-
Audit
Find-an-auditor marketplace
A curated directory of independent auditors and assessors who already know Keel: request quotes and share a read-only audit workspace, so getting from “ready” to “certified” is one less scramble.
-
Trust Center
Publisher approval for document requests
Hold each gated-document request for the publisher to approve or decline before any access link is issued, instead of emailing the requester automatically.
-
Trust Center
Subprocessor & vendor logos
Show vendor and subprocessor logos on the trust center, pulled automatically via AI vendor enrichment or added by hand.
-
Automation
More continuous checks
Expand the credential-free monitors beyond TLS, security headers, SPF, and DMARC (think DNSSEC, CAA, and certificate-expiry), each recorded as living evidence.
-
Policies
Bring your own policy templates
Save and reuse your own policy templates alongside Keel’s 50+ library, so your team can standardize on its house wording and structure.
-
Audit
Auditor collaboration workspace
Beyond today’s free read-only auditor seat, give your auditor a place to leave evidence requests and track fieldwork in-app.
-
Reporting
Gap analysis & evidence-index reports
One-click reports that list every unaddressed requirement and index all evidence by control.