Security documentation for enterprise procurement.
Every control is listed with its current status — available, in progress, or on the roadmap. We state what we have, not what we intend to have. For questionnaires, pen test summaries, or DPA templates, contact our security team.
Certifications & Compliance
Current certification status
We list the status of every certification rather than implying coverage we do not yet hold. Last reviewed: August 2025.
Certification
Scope
Current status
Timeline
SOC 2 Type II
Security, Availability, Confidentiality
Audit formally underway. Evidence collection in progress with a Big Four auditor.
Target: Q4 2025
ISO 27001
Information Security Management
Gap assessment complete. ISMS implementation scheduled to follow SOC 2 completion.
Target: 2026
GDPR Compliance
EU data processing & residency
Data processing agreements, DPA templates, and EU-region deployment options available now.
—
HIPAA Controls
US healthcare data handling
BAA available on Enterprise plans. Healthcare-specific deployment configuration on request.
—
CSA STAR Level 1
Cloud security self-assessment
Planned following SOC 2 Type II completion. Self-assessment to be published in the CSA registry.
Target: 2026
Penetration Testing
Third-party application & infrastructure
Annual external penetration test conducted. Summary report available to enterprise customers under NDA.
Annual cadence
Certification documentation, audit scope letters, and security questionnaire responses available to enterprise customers under NDA. Request documentation →
Infrastructure
Deployment model & data residency
Cloud-hosted (SaaS)
Keel-managed deployment on AWS. US East (Virginia) by default. No infrastructure required from the customer.
EU data residency
Data stored exclusively in AWS EU-West (Ireland). Required DPA template available. Suitable for GDPR-regulated workloads.
Private cloud (VPC deployment)
Keel deployed into your AWS, Azure, or GCP account. All data stays within your cloud boundary. No Keel egress of customer content.
On-premise / air-gapped
Full on-premise deployment for regulated industries or classified environments. No external network dependency.
Multi-region failover
Active-passive failover across two AWS availability zones. RTO < 4h, RPO < 1h for cloud-hosted deployments.
Dedicated tenancy
Single-tenant infrastructure with no shared compute or storage. Available for Enterprise plans requiring physical isolation.
Data Handling
Data handling, retention & deletion
No training on customer data
Customer content is never used to train, fine-tune, or improve Keel models or any third-party model. This is contractually guaranteed.
No cross-customer data sharing
Workspaces are fully isolated. No query, document, or embedding crosses workspace boundaries.
Configurable retention periods
Indexed content and log retention configurable per workspace: 30 days to 7 years. Default: 90 days for logs, indefinite for indexed content until deleted.
Granular deletion
Content can be deleted at document, connector, or workspace level. Deletions propagate through the vector index and knowledge graph within 24h.
Right to erasure (GDPR Article 17)
Deletion pipeline satisfies GDPR right-to-erasure requirements. Deletion receipts available. DPA templates provided to EU customers.
Data portability
Indexed metadata and configuration can be exported in JSON format. Raw document export from connectors requires source-system access.
Full portability export targeting Q1 2026
Access Controls
Permissions & inheritance
Workspace-level RBAC
Admin, Editor, and Viewer roles. Admins manage connectors and users. Editors configure context. Viewers query only.
API token scoping
Tokens scoped to a workspace. Can be restricted to read-only or specific operations. Token rotation and revocation available.
Source-system permission inheritance
Queries will only surface documents the querying user is authorised to see in the source system (e.g. SharePoint, Confluence). In active development.
Available in Enterprise preview — contact us to enable
Attribute-based access control (ABAC)
Fine-grained policies based on document classification, user attributes, or connector metadata.
Targeting H2 2026
IP allowlisting
Restrict API access to approved IP ranges. Available via workspace network policy configuration.
Encryption
Encryption & credential security
TLS 1.2+ in transit
All API communication uses TLS 1.2 minimum. TLS 1.3 preferred. Certificates managed via AWS ACM with automatic rotation.
AES-256 at rest
All indexed content, embeddings, and metadata encrypted at rest using AES-256. Encryption managed by AWS KMS.
Credential & secrets management
Connector OAuth tokens and API keys stored in an encrypted secrets store (AWS Secrets Manager). Never stored in plaintext.
Customer-managed encryption keys (CMEK)
Enterprise customers can supply their own KMS keys. Keel holds no plaintext access to customer data when CMEK is active.
AWS KMS CMEK targeting Q4 2025. Azure Key Vault on roadmap.
mTLS for connector communication
Mutual TLS for inbound connector webhooks and real-time sync channels.
Targeting Q1 2026
Auditability
Audit logs & observability
Query audit log
Every context query logged: user identity, timestamp, query text, confidence score, sources cited, and response metadata.
Ingestion audit log
All connector sync events, document additions, updates, and deletions logged with source, timestamp, and record count.
Access audit log
Login events, MFA outcomes, token creation and revocation, permission changes, and workspace configuration events.
Immutable log storage
Audit logs written to append-only storage. Logs cannot be modified or deleted by workspace admins.
Log export (JSON)
Audit logs exportable in structured JSON. Configurable retention: 90 days default, up to 7 years on Enterprise.
SIEM integration (webhook / Splunk)
Real-time audit log streaming to customer SIEM via webhook. Datadog Logs API and Elastic bulk API available via webhook now. Native Splunk HEC connector in development.
Webhook available now. Splunk HEC connector targeting Q1 2026.
Example audit event — query.executed
application/json{
"event_id": "evt_01HXYZ9M3KQT",
"timestamp": "2026-08-27T14:32:01.882Z",
"event_type": "query.executed",
"workspace_id":"ws_claims_prod",
"actor": {
"type": "api_key",
"id": "key_7a3bc",
"label": "ClaimsBot-Prod"
},
"request": {
"question": "What is the deductible for policy P-8821?",
"top_k": 5,
"min_similarity": 0.75
},
"response": {
"confidence": 0.91,
"chunks_returned": 4,
"abstained": false
},
"latency_ms": 187,
"source_ip": "10.0.4.22"
}All fields present on every event. abstained: true events also include abstain_reason and available chunks.
AI Model Controls
Model-provider data handling
Zero-day retention with cloud providers
When cloud embedding models are used, Keel enforces zero-retention API agreements with providers. Content is not logged or stored beyond the inference call.
Self-hosted embedding models
Run embedding models (e.g. sentence-transformers, BGE) inside your VPC. No content leaves your environment. Supported on private cloud and on-premise deployments.
Configurable model provider
Enterprise customers can designate their approved embedding provider. Keel supports OpenAI, Cohere, Azure OpenAI, and self-hosted models.
Model provider audit trail
All model inference calls logged with provider, model version, and token count. Verifiable evidence that no unexpected provider is used.
No LLM access to raw documents
Keel surfaces context chunks and citations to the calling application. The LLM (in your stack) receives structured context — Keel does not route prompts through a shared LLM.
Identity & Access
SSO, MFA & provisioning
SAML 2.0 SSO
SP-initiated and IdP-initiated flows. Any SAML 2.0-compliant IdP works. Verified providers listed below.
OIDC / OAuth 2.0
OpenID Connect login for organisations using OIDC-compatible identity providers.
SCIM 2.0 user provisioning
Automated provisioning and deprovisioning. Attribute mapping: userName, emails[primary], displayName, groups. Group→role: Admin / Editor / Viewer / Read-only.
Targeting Q1 2026. Admin API available as interim.
Multi-factor authentication (MFA)
TOTP-based MFA enforced for all users on cloud-hosted deployments. Hardware key (FIDO2 / WebAuthn) support in progress.
Session management
Configurable session timeout (default 8h). Force-logout available to admins. Concurrent session limits on Enterprise plans.
Just-in-time (JIT) provisioning
Users provisioned automatically on first SSO login. Role assigned from IdP group mapping.
Verified identity providers
Okta
SAML 2.0 · OIDC · SCIM
Azure AD / Entra ID
SAML 2.0 · OIDC · SCIM
Google Workspace
SAML 2.0 · OIDC
PingFederate
SAML 2.0
PingOne
SAML 2.0 · OIDC
OneLogin
SAML 2.0 · OIDC · SCIM
Auth0
SAML 2.0 · OIDC
ADFS (on-prem)
SAML 2.0
Duo Security
MFA overlay
Any SAML 2.0-compliant IdP works. The list above is verified and regression-tested.
Status key
Security FAQ
Common procurement questions
Does Keel train AI models using our data?
No. Your enterprise data is used exclusively to serve context queries within your workspace. It is never used to train, fine-tune, or improve Keel's models or any third-party model. This applies to both cloud-hosted and on-premise deployments.
Can access permissions from source systems be inherited?
Source-system permission inheritance is in active development. Today, access is controlled at the workspace and role level within Keel (Admin, Editor, Viewer). Connector-level permission scoping — where a query only surfaces content the querying user is authorised to see in the source system — is on the roadmap and available for preview in our Enterprise plan.
Where is our data stored, and can we control residency?
Cloud-hosted deployments run on AWS infrastructure in the US East (Virginia) region by default. EU-West (Ireland) is available for organisations requiring EU data residency. Private cloud and on-premise deployments give you full control over data location and do not require data to leave your environment.
What data does Keel send to model providers (e.g. OpenAI)?
Query content is sent to the configured embedding model for vectorisation. Keel supports self-hosted embedding models (e.g. sentence-transformers running in your VPC) so that no content leaves your environment. For cloud embedding, we use providers with zero-day retention policies — content is not stored or logged beyond the immediate inference call. Enterprise customers can configure the provider and verify the retention policy in writing.
Is SOC 2 Type II certification available?
Our SOC 2 Type II audit is formally underway with a Big Four auditor, targeting completion in Q4 2025. In the interim, we can provide our security controls documentation, completed security questionnaires, and a summary of the audit scope under NDA.
Do you support SSO and SCIM?
SAML 2.0-based SSO (Okta, Azure AD, Google Workspace) is available on Enterprise plans. SCIM 2.0 for automated user provisioning and deprovisioning is in development, targeting Q1 2026. In the interim, workspace membership can be managed via the admin API.
Can we deploy Keel in our own cloud or on-premise?
Yes. Private cloud deployment (into your AWS, Azure, or GCP account) and on-premise deployment are available on Enterprise plans. In this model, all data remains within your environment and Keel never touches your indexed content.
How are audit logs structured and how long are they retained?
Audit logs cover four event classes: query events (user, timestamp, query, confidence score, sources cited), ingestion events (connector sync, documents added/removed), access events (login, token creation, permission changes), and admin events (workspace configuration). Default retention is 90 days; configurable up to 2 years for Enterprise. Logs can be exported in JSON or streamed to your SIEM via webhook.
Procurement support
Need documentation for your security review?
We can provide security questionnaire responses, penetration test summaries, our controls documentation, and DPA templates — all under NDA, usually within 2 business days.