Keel
Trust Center

Security documentation for enterprise procurement.

Every control is listed with its current status — available, in progress, or on the roadmap. We state what we have, not what we intend to have. For questionnaires, pen test summaries, or DPA templates, contact our security team.

Certifications & Compliance

Current certification status

We list the status of every certification rather than implying coverage we do not yet hold. Last reviewed: August 2025.

SOC 2 Type II

Security, Availability, Confidentiality

In Progress

Audit formally underway. Evidence collection in progress with a Big Four auditor.

Target: Q4 2025

ISO 27001

Information Security Management

Roadmap

Gap assessment complete. ISMS implementation scheduled to follow SOC 2 completion.

Target: 2026

GDPR Compliance

EU data processing & residency

Available

Data processing agreements, DPA templates, and EU-region deployment options available now.

—

HIPAA Controls

US healthcare data handling

Enterprise

BAA available on Enterprise plans. Healthcare-specific deployment configuration on request.

—

CSA STAR Level 1

Cloud security self-assessment

Roadmap

Planned following SOC 2 Type II completion. Self-assessment to be published in the CSA registry.

Target: 2026

Penetration Testing

Third-party application & infrastructure

Available

Annual external penetration test conducted. Summary report available to enterprise customers under NDA.

Annual cadence

Certification documentation, audit scope letters, and security questionnaire responses available to enterprise customers under NDA. Request documentation →

Infrastructure

Deployment model & data residency

Cloud-hosted (SaaS)

Keel-managed deployment on AWS. US East (Virginia) by default. No infrastructure required from the customer.

Available

EU data residency

Data stored exclusively in AWS EU-West (Ireland). Required DPA template available. Suitable for GDPR-regulated workloads.

Available

Private cloud (VPC deployment)

Keel deployed into your AWS, Azure, or GCP account. All data stays within your cloud boundary. No Keel egress of customer content.

Enterprise

On-premise / air-gapped

Full on-premise deployment for regulated industries or classified environments. No external network dependency.

Enterprise

Multi-region failover

Active-passive failover across two AWS availability zones. RTO < 4h, RPO < 1h for cloud-hosted deployments.

Available

Dedicated tenancy

Single-tenant infrastructure with no shared compute or storage. Available for Enterprise plans requiring physical isolation.

Enterprise

Data Handling

Data handling, retention & deletion

No training on customer data

Customer content is never used to train, fine-tune, or improve Keel models or any third-party model. This is contractually guaranteed.

Available

No cross-customer data sharing

Workspaces are fully isolated. No query, document, or embedding crosses workspace boundaries.

Available

Configurable retention periods

Indexed content and log retention configurable per workspace: 30 days to 7 years. Default: 90 days for logs, indefinite for indexed content until deleted.

Available

Granular deletion

Content can be deleted at document, connector, or workspace level. Deletions propagate through the vector index and knowledge graph within 24h.

Available

Right to erasure (GDPR Article 17)

Deletion pipeline satisfies GDPR right-to-erasure requirements. Deletion receipts available. DPA templates provided to EU customers.

Available

Data portability

Indexed metadata and configuration can be exported in JSON format. Raw document export from connectors requires source-system access.

Full portability export targeting Q1 2026

In Progress

Access Controls

Permissions & inheritance

Workspace-level RBAC

Admin, Editor, and Viewer roles. Admins manage connectors and users. Editors configure context. Viewers query only.

Available

API token scoping

Tokens scoped to a workspace. Can be restricted to read-only or specific operations. Token rotation and revocation available.

Available

Source-system permission inheritance

Queries will only surface documents the querying user is authorised to see in the source system (e.g. SharePoint, Confluence). In active development.

Available in Enterprise preview — contact us to enable

In Progress

Attribute-based access control (ABAC)

Fine-grained policies based on document classification, user attributes, or connector metadata.

Targeting H2 2026

Roadmap

IP allowlisting

Restrict API access to approved IP ranges. Available via workspace network policy configuration.

Enterprise

Encryption

Encryption & credential security

TLS 1.2+ in transit

All API communication uses TLS 1.2 minimum. TLS 1.3 preferred. Certificates managed via AWS ACM with automatic rotation.

Available

AES-256 at rest

All indexed content, embeddings, and metadata encrypted at rest using AES-256. Encryption managed by AWS KMS.

Available

Credential & secrets management

Connector OAuth tokens and API keys stored in an encrypted secrets store (AWS Secrets Manager). Never stored in plaintext.

Available

Customer-managed encryption keys (CMEK)

Enterprise customers can supply their own KMS keys. Keel holds no plaintext access to customer data when CMEK is active.

AWS KMS CMEK targeting Q4 2025. Azure Key Vault on roadmap.

In Progress

mTLS for connector communication

Mutual TLS for inbound connector webhooks and real-time sync channels.

Targeting Q1 2026

In Progress

Auditability

Audit logs & observability

Query audit log

Every context query logged: user identity, timestamp, query text, confidence score, sources cited, and response metadata.

Available

Ingestion audit log

All connector sync events, document additions, updates, and deletions logged with source, timestamp, and record count.

Available

Access audit log

Login events, MFA outcomes, token creation and revocation, permission changes, and workspace configuration events.

Available

Immutable log storage

Audit logs written to append-only storage. Logs cannot be modified or deleted by workspace admins.

Available

Log export (JSON)

Audit logs exportable in structured JSON. Configurable retention: 90 days default, up to 7 years on Enterprise.

Available

SIEM integration (webhook / Splunk)

Real-time audit log streaming to customer SIEM via webhook. Datadog Logs API and Elastic bulk API available via webhook now. Native Splunk HEC connector in development.

Webhook available now. Splunk HEC connector targeting Q1 2026.

In Progress

Example audit event — query.executed

application/json
{
  "event_id":    "evt_01HXYZ9M3KQT",
  "timestamp":   "2026-08-27T14:32:01.882Z",
  "event_type":  "query.executed",
  "workspace_id":"ws_claims_prod",
  "actor": {
    "type":  "api_key",
    "id":    "key_7a3bc",
    "label": "ClaimsBot-Prod"
  },
  "request": {
    "question":       "What is the deductible for policy P-8821?",
    "top_k":          5,
    "min_similarity": 0.75
  },
  "response": {
    "confidence":      0.91,
    "chunks_returned": 4,
    "abstained":       false
  },
  "latency_ms": 187,
  "source_ip":  "10.0.4.22"
}

All fields present on every event. abstained: true events also include abstain_reason and available chunks.

AI Model Controls

Model-provider data handling

Zero-day retention with cloud providers

When cloud embedding models are used, Keel enforces zero-retention API agreements with providers. Content is not logged or stored beyond the inference call.

Available

Self-hosted embedding models

Run embedding models (e.g. sentence-transformers, BGE) inside your VPC. No content leaves your environment. Supported on private cloud and on-premise deployments.

Available

Configurable model provider

Enterprise customers can designate their approved embedding provider. Keel supports OpenAI, Cohere, Azure OpenAI, and self-hosted models.

Available

Model provider audit trail

All model inference calls logged with provider, model version, and token count. Verifiable evidence that no unexpected provider is used.

Available

No LLM access to raw documents

Keel surfaces context chunks and citations to the calling application. The LLM (in your stack) receives structured context — Keel does not route prompts through a shared LLM.

Available

Identity & Access

SSO, MFA & provisioning

SAML 2.0 SSO

SP-initiated and IdP-initiated flows. Any SAML 2.0-compliant IdP works. Verified providers listed below.

Enterprise

OIDC / OAuth 2.0

OpenID Connect login for organisations using OIDC-compatible identity providers.

Enterprise

SCIM 2.0 user provisioning

Automated provisioning and deprovisioning. Attribute mapping: userName, emails[primary], displayName, groups. Group→role: Admin / Editor / Viewer / Read-only.

Targeting Q1 2026. Admin API available as interim.

In Progress

Multi-factor authentication (MFA)

TOTP-based MFA enforced for all users on cloud-hosted deployments. Hardware key (FIDO2 / WebAuthn) support in progress.

Available

Session management

Configurable session timeout (default 8h). Force-logout available to admins. Concurrent session limits on Enterprise plans.

Available

Just-in-time (JIT) provisioning

Users provisioned automatically on first SSO login. Role assigned from IdP group mapping.

Enterprise

Verified identity providers

Okta

SAML 2.0 · OIDC · SCIM

Azure AD / Entra ID

SAML 2.0 · OIDC · SCIM

Google Workspace

SAML 2.0 · OIDC

PingFederate

SAML 2.0

PingOne

SAML 2.0 · OIDC

OneLogin

SAML 2.0 · OIDC · SCIM

Auth0

SAML 2.0 · OIDC

ADFS (on-prem)

SAML 2.0

Duo Security

MFA overlay

Any SAML 2.0-compliant IdP works. The list above is verified and regression-tested.

Status key

AvailableLive and verifiable
In ProgressUnder active development
RoadmapPlanned — not yet started
EnterpriseEnterprise plan only

Security FAQ

Common procurement questions

Does Keel train AI models using our data?

No. Your enterprise data is used exclusively to serve context queries within your workspace. It is never used to train, fine-tune, or improve Keel's models or any third-party model. This applies to both cloud-hosted and on-premise deployments.

Can access permissions from source systems be inherited?

Source-system permission inheritance is in active development. Today, access is controlled at the workspace and role level within Keel (Admin, Editor, Viewer). Connector-level permission scoping — where a query only surfaces content the querying user is authorised to see in the source system — is on the roadmap and available for preview in our Enterprise plan.

Where is our data stored, and can we control residency?

Cloud-hosted deployments run on AWS infrastructure in the US East (Virginia) region by default. EU-West (Ireland) is available for organisations requiring EU data residency. Private cloud and on-premise deployments give you full control over data location and do not require data to leave your environment.

What data does Keel send to model providers (e.g. OpenAI)?

Query content is sent to the configured embedding model for vectorisation. Keel supports self-hosted embedding models (e.g. sentence-transformers running in your VPC) so that no content leaves your environment. For cloud embedding, we use providers with zero-day retention policies — content is not stored or logged beyond the immediate inference call. Enterprise customers can configure the provider and verify the retention policy in writing.

Is SOC 2 Type II certification available?

Our SOC 2 Type II audit is formally underway with a Big Four auditor, targeting completion in Q4 2025. In the interim, we can provide our security controls documentation, completed security questionnaires, and a summary of the audit scope under NDA.

Do you support SSO and SCIM?

SAML 2.0-based SSO (Okta, Azure AD, Google Workspace) is available on Enterprise plans. SCIM 2.0 for automated user provisioning and deprovisioning is in development, targeting Q1 2026. In the interim, workspace membership can be managed via the admin API.

Can we deploy Keel in our own cloud or on-premise?

Yes. Private cloud deployment (into your AWS, Azure, or GCP account) and on-premise deployment are available on Enterprise plans. In this model, all data remains within your environment and Keel never touches your indexed content.

How are audit logs structured and how long are they retained?

Audit logs cover four event classes: query events (user, timestamp, query, confidence score, sources cited), ingestion events (connector sync, documents added/removed), access events (login, token creation, permission changes), and admin events (workspace configuration). Default retention is 90 days; configurable up to 2 years for Enterprise. Logs can be exported in JSON or streamed to your SIEM via webhook.

Procurement support

Need documentation for your security review?

We can provide security questionnaire responses, penetration test summaries, our controls documentation, and DPA templates — all under NDA, usually within 2 business days.

Security questionnaire response
On request
Penetration test executive summary
On request
SOC 2 audit scope letter
On request
Data Processing Agreement (DPA)
On request
SOC 2 Type II report
Available Q4 2025
Request security documentation