Roadmap

What we’re building next

A look at where Keel is headed. Want to shape it? Sign in and vote or suggest an idea on the live roadmap, and see what we’ve already shipped on What’s new.

In progress 4

  1. Integrations

    Zapier integration

    A Zapier app connecting Keel to thousands of tools. In private beta — request access — the Zap editor offers triggers for a control status change and a new task, a Create Task action, and a search for your ISO 27001 readiness summary. Risks, vendors, evidence, policies and readiness changes are built on Keel’s API but not selectable in a Zap yet.

  2. Trust Center

    Publish your trust center on a custom domain

    Serve your public trust center from your own domain (e.g. trust.yourcompany.com) with your branding and an automatically provisioned certificate, instead of a Keel-hosted URL. The in-app flow (add host, verify by TXT, provision certificate) is built; finishing platform enablement.

  3. Onboarding

    Migrate from another GRC tool

    Live: export your vendors, risks and people from Vanta, Drata, Hyperproof, Oneleet or Secureframe with the open-source keel-migrate tool, then import them into Keel (large exports split across files automatically). Policies and evidence files travel only where the source platform’s API documents them. A OneTrust source is in beta (users and risks today). Coming next: more sources and direct-to-storage streaming for very large libraries.

  4. Platform

    Keel mobile app (iOS & Android)

    A companion app for the on-the-go moments: approve access reviews and policies, complete assigned training, clear task reminders, and check readiness, with push notifications.

Planned 5

  1. Automation

    Continuous evidence integrations

    Auto-collect evidence from cloud and SaaS tools (AWS, GitHub, Google Workspace, and more) so controls stay current without manual uploads.

  2. Frameworks

    Framework version-to-version gap analysis

    When a framework publishes a new revision, see a clause-level diff of what was added, changed, merged, or retired, and a report of the delta work to re-certify. Built for migrations like ISO 27001:2013 → 2022 and CIS Controls v8.0 → v8.1.

  3. Frameworks

    NIS2 & DORA (EU cyber & operational-resilience regulations)

    Authored coverage for the EU NIS2 Directive (Directive (EU) 2022/2555) and the Digital Operational Resilience Act (Regulation (EU) 2022/2554), crosswalked to the ISO 27001 and SOC 2 controls you already run so most of the evidence carries over. Listed in the framework catalog now; content is being authored and IP-reviewed.

  4. Frameworks

    OSCAL export: System Security Plan & POA&M

    Export your program as NIST OSCAL — a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M) — generated from the controls, evidence, and gaps you already track in Keel, so teams working toward FedRAMP or federal frameworks can hand assessors machine-readable artifacts instead of rebuilding them by hand.

  5. Integrations

    Slack & Microsoft Teams notifications

    Route review reminders, control changes, and readiness digests to your team’s chat.

Considering 13

  1. AI

    AI compliance agent (computer use)

    An AI agent that can actually operate Keel and your connected tools on your behalf, gather evidence, draft controls and policies, chase down gaps, and prep an audit package, working through tasks step by step while you stay in control and approve the results. Early idea: vote if you’d want it.

  2. Reporting

    Customizable dashboard widgets

    Rearrange your program dashboard and show or hide widgets, pin the charts and posture cards that matter most to your team, saved per user.

  3. Integrations

    Push remediation tasks to Jira & GitHub Issues

    Two-way sync so a control gap in Keel becomes a ticket in the tracker your team already lives in, and closing it there marks the control remediated here.

  4. Risk

    Risk quantification in dollars

    Layer a FAIR-style quantitative model onto the risk register so you can express exposure as a probable financial range, not just a heat-map color, the language executives and boards fund against.

  5. Enterprise

    SCIM directory provisioning

    Beyond SSO: auto-provision and deprovision Keel users from your identity provider (Okta, Entra, Google) via SCIM, so joiners and leavers flow through without manual seat management.

  6. Frameworks

    Custom frameworks & controls

    Bring your own framework or add custom controls and crosswalk them alongside the built-in catalog.

  7. Audit

    Find-an-auditor marketplace

    A curated directory of independent auditors and assessors who already know Keel: request quotes and share a read-only audit workspace, so getting from “ready” to “certified” is one less scramble.

  8. Trust Center

    Publisher approval for document requests

    Hold each gated-document request for the publisher to approve or decline before any access link is issued, instead of emailing the requester automatically.

  9. Trust Center

    Subprocessor & vendor logos

    Show vendor and subprocessor logos on the trust center, pulled automatically via AI vendor enrichment or added by hand.

  10. Automation

    More continuous checks

    Expand the credential-free monitors beyond TLS, security headers, SPF, and DMARC (think DNSSEC, CAA, and certificate-expiry), each recorded as living evidence.

  11. Policies

    Bring your own policy templates

    Save and reuse your own policy templates alongside Keel’s 50+ library, so your team can standardize on its house wording and structure.

  12. Audit

    Auditor collaboration workspace

    Beyond today’s free read-only auditor seat, give your auditor a place to leave evidence requests and track fieldwork in-app.

  13. Reporting

    Gap analysis & evidence-index reports

    One-click reports that list every unaddressed requirement and index all evidence by control.