Keel was built for security reviews from day one. Here is what we do, in plain words.
A separate database for each companyYour data is never in the same file as another company's. A mistake in one query cannot show you someone else's plan.
Single sign-onMicrosoft Entra ID, Okta, Google Workspace, any OpenID Connect provider, and SAML through a bridge. You can make sign-on the only way in.
Two-factor sign-inAdmins must use an authenticator app. You can require it for everyone.
Three clear rolesViewers read. Editors change the plan. Admins manage users, settings and the audit log.
An audit log you can checkEach entry is chained to the one before it. If anyone edits or removes an entry, the check fails.
Secrets are encryptedAI keys and tool connections are stored encrypted, with a key for each company.
Private by default with AICustomer names are replaced with codes before any text goes to an AI provider.
Backups we testSealed backups every night. Each month a backup is restored to prove it works.
For your security team
We map our controls to ISO 27001. Ask us for the control map and our answers to your questionnaire.