Your compliance tool can't fix anything...
It never could.
Find it. Fix it.
Prove it.
Every tool in your stack can tell you a control failed. None of them can remediate it, and none of them can prove the fix happened. Keystone is the one platform where the scan, the Terraform run, the approval and the audit evidence are the same record.
AWS and Azure. Cross-account role, no agents on your devices.
Private beta. Design partner cohort opens Q4 2026 — 5 places.
The gap isn't a capability. It's the join.
They detect.
They do not remediate.
Not our words. Theirs.
Every quote below is published by the vendor or an independent analyst.
“The Green Agent itself doesn't execute infrastructure changes, run Terraform, or patch operating systems.”
Wiz, official product announcement, March 2026
“We export an Orca report, take a few screenshots, and paste it as evidence.”
An Orca customer, quoted approvingly in Orca's own compliance marketing
“These tools detect, they do not remediate.”
Independent technical comparison of Vanta, Drata, Secureframe and Sprinto
Compliance platforms connect over read-only APIs — they cannot change anything by architecture. Posture platforms open a pull request and hand off. Terraform Cloud executes but has never heard of a control. Somebody, somewhere in your team, is still taking the screenshot.
One record. Four steps.
Connect a cross-account role once.
Keystone discovers everything and never lets go of the thread.
Discover
Cross-account IAM role on AWS, service principal on Azure. Every resource, every region, scoped by tag or type. No agents on your devices.
Scan
Continuous scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and Essential Eight — built on Security Hub, Inspector and Config conformance packs.
Remediate
Terraform plan / apply with policy scanning and approval gates by role. Ansible desired state against inventory built from what we discovered. Patch orchestration across EC2, RDS and EKS.
Prove
The finding, the run that fixed it, who approved it, the timestamp and the control it maps to — one record, exported as a PDF your assessor accepts.
See the record
The finding, the run, the approval, and the evidence — in one place.
Where you sit in this
Four people read this page. You are probably one of them.
CISO / VP Security
You will be asked what you did about it.
You own tools that find things. What you don't own is a defensible answer to *and then what happened?* — it lives in screenshots and ticket queues.
Four contracts, four renewals, and one person still assembling evidence by hand before the audit.
→One contract, one review, and an evidence chain you can hand the board.
GRC Analyst / Compliance Manager
The week before the audit is the tell.
You know which control failed. You just don't control whether it gets fixed, or have proof without asking an engineer for a screenshot.
Every new framework multiplies the same manual work because the evidence was never attached to the finding.
→Finding, fix, approver and control — one record, exported as a PDF your assessor accepts.
SOC Analyst / Security Operations
The same CVE, three sprints running.
Triage isn't the hard part. The hard part is the same vulnerability coming back because nobody closed the loop.
A finding that goes into a ticket and never comes back isn't resolved.
→Every finding carries its history: who found it, who approved the fix, and what the fix did.
Cloud / Platform Engineer
Read-only role. No agents. Your pipeline stays yours.
You've been handed a spreadsheet of findings by someone who doesn't know your infrastructure. Fair enough.
Keystone connects through a cross-account IAM role you create. Terraform runs where it always has, with an approval gate you configure.
→You'll see the exact IAM policy before you grant anything.
Different jobs. Same record.
Six modules. One data model.
Start with one. Grow into the platform.
Ten roles, unlimited users, on every tier.
Core
FoundationMulti-tenant dashboard, workspaces, findings, ten distinct roles from TenantAdmin to Auditor, full audit log and alerting.
Compliance
Most common entryContinuous scanning and scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and ACSC Essential Eight. Audit-ready PDF and JSON per framework.
Patch
OpsPatch management and OS compliance across EC2, RDS, EKS nodes and containers — with the evidence that it ran.
IaC
ExecutesGitHub App integration, Terraform plan / apply / destroy, tfsec and Checkov before every apply, approval gates by role, a validated compliance-ready module library, self-hosted runners.
Automation
ExecutesAnsible desired state with inventory generated from discovered resources — no hand-maintained inventory files, no silently ungrouped hosts. Scheduling, approval gates, full run history.
Containers
VisibilityEKS and ECS discovery, Kubernetes workload visibility, ECR image inventory with Inspector findings linked per image, node health, rescan triggers.
Is this you?
Check what's true right now.
If you checked four or more, this was built for you.
What your current stack can't do
Every cell sourced to the vendor's own documentation.
We'll send you the citations.
| Capability | Vanta / Drata | Wiz / Orca | Terraform Cloud | Rapid7 | Keystone |
|---|---|---|---|---|---|
| Cloud compliance scanning | Yes | Yes | Plan-time, AWS only | Removed 2025 | Yes |
| Runs `terraform apply` | No | No | Yes | No | Yes |
| Ansible desired state | No | No | No | No | Yes |
| OS patch orchestration | No | No | No | Hands off to SCCM | Yes |
| Container image scanning | No | Yes | No | No | Yes |
| Audit-ready evidence package | Yes | Dashboard only | No | PCI ASV only | Yes |
| Serves cloud engineers | Barely | Yes | Yes | Yes | Yes |
| Serves GRC analysts | Yes | No | No | No | Yes |
| All of the above | No | No | No | No | Yes |
Thirteen platforms researched in August 2026. Not one has a Yes in more than five rows.
Four renewals.
One platform.
A 300-person AWS shop: ~1,000 resources, two frameworks, 100 patched instances — priced from published rate cards.
What you pay today
- Compliance automation$30,000
- Cloud security posture$40,000
- IaC orchestration$20,000
- Patch + vulnerability$22,400
$112,400
Four contracts. Four security reviews. Four renewals.
Keystone, full platform
- Compliance (2 frameworks)$21,000
- Patch (100 instances)$2,700
- IaC$12,000
- Automation$12,000
- Containers$15,000
- All five modules$62,700
- Bundle discount −25%−$15,675
- Core Growth$30,000
- 3-year term −15%−$11,554
$65,471/yr
42% less. One contract. Price locked for the full 3-year term.
Who this is for
Regulated teams running real infrastructure, with a date on the calendar.
Regulated scale-ups
Primary200–1,200 people, AWS-native, holding SOC 2 and adding ISO 27001, PCI DSS or HIPAA. B2B SaaS, fintech, healthtech, insurtech.
CMMC and FedRAMP
Federal & defenceNIST 800-53 Rev 5, CMMC Level 2, FedRAMP Moderate. Continuous monitoring is a recurring evidence problem — that's exactly what Keystone is.
MSSPs and AWS partners
Channel15–80 client environments. True multi-tenancy with data-layer isolation, per-client reporting, white-label and aggregated billing.
Priced in public.
Locked for three years.
Platform fee plus modules. Unlimited users on every tier. The term discount applies to your whole contract, platform fee and modules alike. Commit to three years and your price never moves — no annual escalator, no headcount-tier surprise, in writing.
Team
up to 250 resources · 2 cloud accounts
$10,200/yr
List $12,000 · 3-year total $30,600
- All ten roles, unlimited users
- Findings, workspaces, alerting
- 90-day audit log
- Email support
Growth
up to 1,000 resources · 5 cloud accounts
$25,500/yr
List $30,000 · 3-year total $76,500
- Everything in Team
- SSO
- 1-year audit log retention
- API access and scheduled reporting
- Business-hours support
Scale
up to 3,000 resources · 15 cloud accounts
$51,000/yr
List $60,000 · 3-year total $153,000
- Everything in Growth
- SCIM and custom roles
- 3-year audit log with export
- Private runners
- Priority support
Add modules à la carte — all five together, 25% off, then your term discount on top
Compliance
$15,000
first framework, +$6,000 each
$9,563 with all five on 3 years
Patch
$2.25
per instance / month
$1.43 with all five on 3 years
IaC
$12,000
flat, unlimited resources
$7,650 with all five on 3 years
Automation
$12,000
flat, unlimited nodes
$7,650 with all five on 3 years
Containers
$15,000
up to 1,000 containers
$9,563 with all five on 3 years
Above 3,000 resources, or need something the tiers don't cover?
Enterprise, MSSP and multi-entity pricing is quoted. Volume, education and non-profit discounts beyond the published rates are available on request.
Built by someone who's been on the other side of the audit
Kenio Shirley
Founder, Keystone
I spent seventeen years in enterprise technology, across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and ISM IRAP. I watched teams buy a compliance tool, a CSPM, a patch scanner, an IaC orchestrator, and an automation platform — and still spend their nights taking screenshots and praying the evidence matched the fix. They detect. They do not remediate. They do not prove. So I built Keystone: one place where the finding, the fix, and the evidence live in the same loop.
“Compliance is a business enabler, not a checkbox. But only if the fix and the proof live in the same place.”
Also running hireken.io — fractional CTO for high-stakes teams.
Get on the list.
Be first in the room.
Keystone is in private beta. Join the waitlist and you'll get early access, the thirteen-vendor comparison with every citation, and first refusal on the five design-partner places when the cohort opens in Q4.
Work email, thirty seconds. No sales sequence — you'll hear from me, not a tool.
Design partner cohort opens Q4 2026 — 5 places