keystoneDetect · Remediate · Prove

Your compliance tool can't fix anything... 
It never could.

Find it. Fix it.
Prove it.

Every tool in your stack can tell you a control failed. None of them can remediate it, and none of them can prove the fix happened. Keystone is the one platform where the scan, the Terraform run, the approval and the audit evidence are the same record.

AWS and Azure. Cross-account role, no agents on your devices.

Private beta. Design partner cohort opens Q4 2026 — 5 places.

13
Competing platforms researched
0
That run `terraform apply`
0
That manage Ansible state
4
Tools Keystone replaces

The gap isn't a capability. It's the join.

They detect.
They do not remediate.

Not our words. Theirs. 
Every quote below is published by the vendor or an independent analyst.

“The Green Agent itself doesn't execute infrastructure changes, run Terraform, or patch operating systems.”


Wiz, official product announcement, March 2026

“We export an Orca report, take a few screenshots, and paste it as evidence.”


An Orca customer, quoted approvingly in Orca's own compliance marketing

“These tools detect, they do not remediate.”


Independent technical comparison of Vanta, Drata, Secureframe and Sprinto

Compliance platforms connect over read-only APIs — they cannot change anything by architecture. Posture platforms open a pull request and hand off. Terraform Cloud executes but has never heard of a control. Somebody, somewhere in your team, is still taking the screenshot.

One record. Four steps.

Connect a cross-account role once. 
Keystone discovers everything and never lets go of the thread.

1

Discover

Cross-account IAM role on AWS, service principal on Azure. Every resource, every region, scoped by tag or type. No agents on your devices.

2

Scan

Continuous scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and Essential Eight — built on Security Hub, Inspector and Config conformance packs.

3

Remediate

Terraform plan / apply with policy scanning and approval gates by role. Ansible desired state against inventory built from what we discovered. Patch orchestration across EC2, RDS and EKS.

4

Prove

The finding, the run that fixed it, who approved it, the timestamp and the control it maps to — one record, exported as a PDF your assessor accepts.

See the record

The finding, the run, the approval, and the evidence — in one place.

Where you sit in this

Four people read this page. You are probably one of them.

CISO / VP Security

You will be asked what you did about it.

You own tools that find things. What you don't own is a defensible answer to *and then what happened?* — it lives in screenshots and ticket queues.

Four contracts, four renewals, and one person still assembling evidence by hand before the audit.

→One contract, one review, and an evidence chain you can hand the board.

GRC Analyst / Compliance Manager

The week before the audit is the tell.

You know which control failed. You just don't control whether it gets fixed, or have proof without asking an engineer for a screenshot.

Every new framework multiplies the same manual work because the evidence was never attached to the finding.

→Finding, fix, approver and control — one record, exported as a PDF your assessor accepts.

SOC Analyst / Security Operations

The same CVE, three sprints running.

Triage isn't the hard part. The hard part is the same vulnerability coming back because nobody closed the loop.

A finding that goes into a ticket and never comes back isn't resolved.

→Every finding carries its history: who found it, who approved the fix, and what the fix did.

Cloud / Platform Engineer

Read-only role. No agents. Your pipeline stays yours.

You've been handed a spreadsheet of findings by someone who doesn't know your infrastructure. Fair enough.

Keystone connects through a cross-account IAM role you create. Terraform runs where it always has, with an approval gate you configure.

→You'll see the exact IAM policy before you grant anything.

Different jobs. Same record.

Six modules. One data model.

Start with one. Grow into the platform. 
Ten roles, unlimited users, on every tier.

Required

Core

Foundation

Multi-tenant dashboard, workspaces, findings, ten distinct roles from TenantAdmin to Auditor, full audit log and alerting.

Compliance

Most common entry

Continuous scanning and scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and ACSC Essential Eight. Audit-ready PDF and JSON per framework.

Patch

Ops

Patch management and OS compliance across EC2, RDS, EKS nodes and containers — with the evidence that it ran.

IaC

Executes

GitHub App integration, Terraform plan / apply / destroy, tfsec and Checkov before every apply, approval gates by role, a validated compliance-ready module library, self-hosted runners.

Automation

Executes

Ansible desired state with inventory generated from discovered resources — no hand-maintained inventory files, no silently ungrouped hosts. Scheduling, approval gates, full run history.

Containers

Visibility

EKS and ECS discovery, Kubernetes workload visibility, ECR image inventory with Inspector findings linked per image, node health, rescan triggers.

Is this you?

Check what's true right now.

If you checked four or more, this was built for you.

What your current stack can't do

Every cell sourced to the vendor's own documentation. 
We'll send you the citations.

CapabilityVanta / DrataWiz / OrcaTerraform CloudRapid7Keystone
Cloud compliance scanningYesYesPlan-time, AWS onlyRemoved 2025Yes
Runs `terraform apply`NoNoYesNoYes
Ansible desired stateNoNoNoNoYes
OS patch orchestrationNoNoNoHands off to SCCMYes
Container image scanningNoYesNoNoYes
Audit-ready evidence packageYesDashboard onlyNoPCI ASV onlyYes
Serves cloud engineersBarelyYesYesYesYes
Serves GRC analystsYesNoNoNoYes
All of the aboveNoNoNoNoYes

Thirteen platforms researched in August 2026. Not one has a Yes in more than five rows.

Four renewals.
One platform.

A 300-person AWS shop: ~1,000 resources, two frameworks, 100 patched instances — priced from published rate cards.

What you pay today

  • Compliance automation$30,000
  • Cloud security posture$40,000
  • IaC orchestration$20,000
  • Patch + vulnerability$22,400

$112,400

Four contracts. Four security reviews. Four renewals.

vs

Keystone, full platform

  • Compliance (2 frameworks)$21,000
  • Patch (100 instances)$2,700
  • IaC$12,000
  • Automation$12,000
  • Containers$15,000
  • All five modules$62,700
  • Bundle discount −25%−$15,675
  • Core Growth$30,000
  • 3-year term −15%−$11,554

$65,471/yr

42% less. One contract. Price locked for the full 3-year term.

Who this is for

Regulated teams running real infrastructure, with a date on the calendar.

Regulated scale-ups

Primary

200–1,200 people, AWS-native, holding SOC 2 and adding ISO 27001, PCI DSS or HIPAA. B2B SaaS, fintech, healthtech, insurtech.

CMMC and FedRAMP

Federal & defence

NIST 800-53 Rev 5, CMMC Level 2, FedRAMP Moderate. Continuous monitoring is a recurring evidence problem — that's exactly what Keystone is.

MSSPs and AWS partners

Channel

15–80 client environments. True multi-tenancy with data-layer isolation, per-client reporting, white-label and aggregated billing.

Priced in public.
Locked for three years.

Platform fee plus modules. Unlimited users on every tier. The term discount applies to your whole contract, platform fee and modules alike. Commit to three years and your price never moves — no annual escalator, no headcount-tier surprise, in writing.

Team

up to 250 resources · 2 cloud accounts

$10,200/yr

List $12,000 · 3-year total $30,600

  • All ten roles, unlimited users
  • Findings, workspaces, alerting
  • 90-day audit log
  • Email support
Most common

Growth

up to 1,000 resources · 5 cloud accounts

$25,500/yr

List $30,000 · 3-year total $76,500

  • Everything in Team
  • SSO
  • 1-year audit log retention
  • API access and scheduled reporting
  • Business-hours support

Scale

up to 3,000 resources · 15 cloud accounts

$51,000/yr

List $60,000 · 3-year total $153,000

  • Everything in Growth
  • SCIM and custom roles
  • 3-year audit log with export
  • Private runners
  • Priority support

Add modules à la carte — all five together, 25% off, then your term discount on top

Compliance

$15,000

first framework, +$6,000 each

$9,563 with all five on 3 years

Patch

$2.25

per instance / month

$1.43 with all five on 3 years

IaC

$12,000

flat, unlimited resources

$7,650 with all five on 3 years

Automation

$12,000

flat, unlimited nodes

$7,650 with all five on 3 years

Containers

$15,000

up to 1,000 containers

$9,563 with all five on 3 years

Above 3,000 resources, or need something the tiers don't cover?

Enterprise, MSSP and multi-entity pricing is quoted. Volume, education and non-profit discounts beyond the published rates are available on request.

Built by someone who's been on the other side of the audit

Kenio Shirley, founder of Keystone

Kenio Shirley

Founder, Keystone

CISSPCISMMSITMMCITPAzure Solutions Architect

I spent seventeen years in enterprise technology, across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and ISM IRAP. I watched teams buy a compliance tool, a CSPM, a patch scanner, an IaC orchestrator, and an automation platform — and still spend their nights taking screenshots and praying the evidence matched the fix. They detect. They do not remediate. They do not prove. So I built Keystone: one place where the finding, the fix, and the evidence live in the same loop.

“Compliance is a business enabler, not a checkbox. But only if the fix and the proof live in the same place.”

Also running hireken.io — fractional CTO for high-stakes teams.

Get on the list.
Be first in the room.

Keystone is in private beta. Join the waitlist and you'll get early access, the thirteen-vendor comparison with every citation, and first refusal on the five design-partner places when the cohort opens in Q4.

Work email, thirty seconds. No sales sequence — you'll hear from me, not a tool.

Design partner cohort opens Q4 2026 — 5 places