Your compliance tool can't fix anything. It never could.
Find it. Fix it.
Prove it.
Every tool in your stack can tell you a control failed. None of them can remediate it, and none of them can prove the fix happened. Keystone is the one platform where the scan, the Terraform run, the approval and the audit evidence are the same record.
AWS and Azure. Cross-account role, no agents on your devices.
Private beta. Design partner cohort opens Q4 2026 — 5 places.
The gap isn't a capability. It's the join.
They detect.
They do not remediate.
Not our words. Theirs.
Every quote below is published by the vendor or an independent analyst.
“The Green Agent itself doesn't execute infrastructure changes, run Terraform, or patch operating systems.”
Wiz, official product announcement, March 2026
“We export an Orca report, take a few screenshots, and paste it as evidence.”
An Orca customer, quoted approvingly in Orca's own compliance marketing
“These tools detect, they do not remediate.”
Independent technical comparison of Vanta, Drata, Secureframe and Sprinto
Compliance platforms connect over read-only APIs — they cannot change anything by architecture. Posture platforms open a pull request and hand off. Terraform Cloud executes but has never heard of a control. Somebody, somewhere in your team, is still taking the screenshot.
One record. Four steps.
Connect a cross-account role once.
Keystone discovers everything and never lets go of the thread.
Discover
Cross-account IAM role on AWS, service principal on Azure. Every resource, every region, scoped by tag or type. No agents on your devices.
Scan
Continuous scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and Essential Eight — built on Security Hub, Inspector and Config conformance packs.
Remediate
Terraform plan / apply with policy scanning and approval gates by role. Ansible desired state against inventory built from what we discovered. Patch orchestration across EC2, RDS and EKS.
Prove
The finding, the run that fixed it, who approved it, the timestamp and the control it maps to — one record, exported as a PDF your assessor accepts.
Is this you?
Check what's true right now.
Most people on the waitlist check four or more.
Six modules. One data model.
Start with one. Grow into the platform.
Ten roles, unlimited users, on every tier.
Core
FoundationMulti-tenant dashboard, workspaces, findings, ten distinct roles from TenantAdmin to Auditor, full audit log and alerting.
Compliance
Most common entryContinuous scanning and scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and ACSC Essential Eight. Audit-ready PDF and JSON per framework.
Patch
OpsPatch management and OS compliance across EC2, RDS, EKS nodes and containers — with the evidence that it ran.
IaC
ExecutesGitHub App integration, Terraform plan / apply / destroy, tfsec and Checkov before every apply, approval gates by role, a validated compliance-ready module library, self-hosted runners.
Automation
ExecutesAnsible desired state with inventory generated from discovered resources — no hand-maintained inventory files, no silently ungrouped hosts. Scheduling, approval gates, full run history.
Containers
VisibilityEKS and ECS discovery, Kubernetes workload visibility, ECR image inventory with Inspector findings linked per image, node health, rescan triggers.
What your current stack can't do
Every cell sourced to the vendor's own documentation.
We'll send you the citations.
| Capability | Vanta / Drata | Wiz / Orca | Terraform Cloud | Rapid7 | Keystone |
|---|---|---|---|---|---|
| Cloud compliance scanning | Yes | Yes | Plan-time, AWS only | Removed 2025 | Yes |
| Runs `terraform apply` | No | No | Yes | No | Yes |
| Ansible desired state | No | No | No | No | Yes |
| OS patch orchestration | No | No | No | Hands off to SCCM | Yes |
| Container image scanning | No | Yes | No | No | Yes |
| Audit-ready evidence package | Yes | Dashboard only | No | PCI ASV only | Yes |
| Serves cloud engineers | Barely | Yes | Yes | Yes | Yes |
| Serves GRC analysts | Yes | No | No | No | Yes |
| All of the above | No | No | No | No | Yes |
Thirteen platforms researched in August 2026. Not one has a Yes in more than five rows.
Four renewals.
One platform.
A 300-person AWS shop: ~1,000 resources, two frameworks, 100 patched instances — priced from published rate cards.
What you pay today
- Compliance automation$30,000
- Cloud security posture$40,000
- IaC orchestration$20,000
- Patch + vulnerability$22,400
$112,400
Four contracts. Four security reviews. Four renewals.
Keystone, full platform
- Core Growth$30,000
- All five modules, two frameworks$62,700
- Bundle discount −25%−$15,675
- 3-year term −15%−$11,554
$65,471/yr
42% less. One contract. Price locked three years.
Priced in public.
Locked for three years.
Platform fee plus modules. Unlimited users on every tier. Commit to three years and your price never moves — no annual escalator, no headcount-tier surprise, in writing.
Team
up to 250 resources · 2 cloud accounts
$10,200/yr
List $12,000 · 3-year total $30,600
- All ten roles, unlimited users
- Findings, workspaces, alerting
- 90-day audit log
- Email support
Growth
up to 1,000 resources · 5 cloud accounts
$25,500/yr
List $30,000 · 3-year total $76,500
- Everything in Team
- SSO
- 1-year audit log retention
- API access and scheduled reporting
- Business-hours support
Scale
up to 3,000 resources · 15 cloud accounts
$51,000/yr
List $60,000 · 3-year total $153,000
- Everything in Growth
- SCIM and custom roles
- 3-year audit log with export
- Private runners
- Priority support
Add modules à la carte — all five together, 25% off
Compliance
$15,000
first framework, +$6,000 each
Patch
$2.25
per instance / month
IaC
$12,000
flat, unlimited resources
Automation
$12,000
flat, unlimited nodes
Containers
$15,000
up to 1,000 containers
Above 3,000 resources, or need something the tiers don't cover?
Enterprise, MSSP and multi-entity pricing is quoted. Volume, education and non-profit discounts beyond the published rates are available on request.
Who this is for
Regulated teams running real infrastructure, with a date on the calendar.
Regulated scale-ups
Primary200–1,200 people, AWS-native, holding SOC 2 and adding ISO 27001, PCI DSS or HIPAA. B2B SaaS, fintech, healthtech, insurtech.
CMMC and FedRAMP
Federal & defenceNIST 800-53 Rev 5, CMMC Level 2, FedRAMP Moderate. Continuous monitoring is a recurring evidence problem — that's exactly what Keystone is.
MSSPs and AWS partners
Channel15–80 client environments. True multi-tenancy with data-layer isolation, per-client reporting, white-label and aggregated billing.
Built by someone who's been on the other side of the audit
Kenio Shirley
Founder, Keystone
I spent seventeen years in enterprise technology, across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and ISM IRAP. I watched teams buy a compliance tool, a CSPM, a patch scanner, an IaC orchestrator, and an automation platform — and still spend their nights taking screenshots and praying the evidence matched the fix. They detect. They do not remediate. They do not prove. So I built Keystone: one place where the finding, the fix, and the evidence live in the same loop.
“Compliance is a business enabler, not a checkbox. But only if the fix and the proof live in the same place.”
Also running hireken.io — fractional CTO for high-stakes teams.
Get on the list.
Be first in the room.
Keystone is in private beta. Join the waitlist and you'll get early access, the thirteen-vendor comparison with every citation, and first refusal on the five design-partner places when the cohort opens in Q4.
Work email, thirty seconds. No sales sequence — you'll hear from me, not a tool.
Design partner cohort opens Q4 2026 — 5 places