Trust

Security at Keel

We run our own security program inside Keel, on the same control & evidence graph our customers use, and hold ourselves to the frameworks we support. Here's how your data is protected today.

Data protection

  • Tenant isolation. Every workspace's data is isolated at the database level with Postgres row-level security - enforced in the database, not just in application code. Your data is never reachable from another workspace.
  • Encryption. All traffic is served over HTTPS/TLS. Data at rest is encrypted by our infrastructure providers (Neon Postgres and Cloudflare R2).
  • Least privilege. The application connects to the database as a non-superuser role, so isolation holds even at the connection layer.
  • Auditability. Changes in a workspace are recorded to an audit log, and Enterprise customers can export it in full.

Infrastructure

  • Runs on Cloudflare's global edge network, with Postgres (Neon) and object storage on Cloudflare R2.
  • Authentication is handled by Clerk, with SSO / SCIM available to Enterprise customers.
  • Application errors are monitored so issues are caught and resolved quickly.

For how we keep the platform available and recover from incidents - global edge delivery, point-in-time recovery, and our DR/BCP runbooks - see Reliability.

Data residency

Keel stores and processes customer data in the United States. The third-party services we rely on are listed on our Subprocessors page.

Our own program

Keel isn't just the tool - it's how we run compliance ourselves. Our controls, policies, evidence, and vendor reviews live in Keel, mapped to SOC 2, ISO 27001, and NIST CSF.

To be clear about where we stand today: Keel does not yet hold a third-party attestation or audit report (such as a SOC 2 report or an ISO 27001 certificate). Pursuing formal attestation is on our roadmap, and we will publish the report here once it is complete. We would rather tell you exactly where we are than imply a certificate we do not have.

Reporting a vulnerability

Found a security issue? Please report it to [email protected]. See our vulnerability disclosure policy for what to include and what to expect. For general questions, email [email protected].

Third-party framework names (e.g. SOC 2, ISO 27001) are the property of their respective owners; Keel is not affiliated with or endorsed by them.