keystoneDetect · Remediate · Prove

Your compliance tool can't fix anything. It never could.

Find it. Fix it.
Prove it.

Every tool in your stack can tell you a control failed. None of them can remediate it, and none of them can prove the fix happened. Keystone is the one platform where the scan, the Terraform run, the approval and the audit evidence are the same record.

AWS and Azure. Cross-account role, no agents on your devices.

Private beta. Design partner cohort opens Q4 2026 — 5 places.

0
Competing platforms researched
0
That run `terraform apply`
0
That manage Ansible state
0
Tools Keystone replaces

The gap isn't a capability. It's the join.

They detect.
They do not remediate.

Not our words. Theirs. 
Every quote below is published by the vendor or an independent analyst.

The Green Agent itself doesn't execute infrastructure changes, run Terraform, or patch operating systems.


Wiz, official product announcement, March 2026

We export an Orca report, take a few screenshots, and paste it as evidence.


An Orca customer, quoted approvingly in Orca's own compliance marketing

These tools detect, they do not remediate.


Independent technical comparison of Vanta, Drata, Secureframe and Sprinto

Compliance platforms connect over read-only APIs — they cannot change anything by architecture. Posture platforms open a pull request and hand off. Terraform Cloud executes but has never heard of a control. Somebody, somewhere in your team, is still taking the screenshot.

One record. Four steps.

Connect a cross-account role once. 
Keystone discovers everything and never lets go of the thread.

1

Discover

Cross-account IAM role on AWS, service principal on Azure. Every resource, every region, scoped by tag or type. No agents on your devices.

2

Scan

Continuous scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and Essential Eight — built on Security Hub, Inspector and Config conformance packs.

3

Remediate

Terraform plan / apply with policy scanning and approval gates by role. Ansible desired state against inventory built from what we discovered. Patch orchestration across EC2, RDS and EKS.

4

Prove

The finding, the run that fixed it, who approved it, the timestamp and the control it maps to — one record, exported as a PDF your assessor accepts.

Is this you?

Check what's true right now.

Most people on the waitlist check four or more.

Six modules. One data model.

Start with one. Grow into the platform. 
Ten roles, unlimited users, on every tier.

Required

Core

Foundation

Multi-tenant dashboard, workspaces, findings, ten distinct roles from TenantAdmin to Auditor, full audit log and alerting.

Compliance

Most common entry

Continuous scanning and scoring against PCI DSS, SOC 2, NIST 800-53 Rev 5, FedRAMP Moderate and ACSC Essential Eight. Audit-ready PDF and JSON per framework.

Patch

Ops

Patch management and OS compliance across EC2, RDS, EKS nodes and containers — with the evidence that it ran.

IaC

Executes

GitHub App integration, Terraform plan / apply / destroy, tfsec and Checkov before every apply, approval gates by role, a validated compliance-ready module library, self-hosted runners.

Automation

Executes

Ansible desired state with inventory generated from discovered resources — no hand-maintained inventory files, no silently ungrouped hosts. Scheduling, approval gates, full run history.

Containers

Visibility

EKS and ECS discovery, Kubernetes workload visibility, ECR image inventory with Inspector findings linked per image, node health, rescan triggers.

What your current stack can't do

Every cell sourced to the vendor's own documentation. 
We'll send you the citations.

CapabilityVanta / DrataWiz / OrcaTerraform CloudRapid7Keystone
Cloud compliance scanningYesYesPlan-time, AWS onlyRemoved 2025Yes
Runs `terraform apply`NoNoYesNoYes
Ansible desired stateNoNoNoNoYes
OS patch orchestrationNoNoNoHands off to SCCMYes
Container image scanningNoYesNoNoYes
Audit-ready evidence packageYesDashboard onlyNoPCI ASV onlyYes
Serves cloud engineersBarelyYesYesYesYes
Serves GRC analystsYesNoNoNoYes
All of the aboveNoNoNoNoYes

Thirteen platforms researched in August 2026. Not one has a Yes in more than five rows.

Four renewals.
One platform.

A 300-person AWS shop: ~1,000 resources, two frameworks, 100 patched instances — priced from published rate cards.

What you pay today

  • Compliance automation$30,000
  • Cloud security posture$40,000
  • IaC orchestration$20,000
  • Patch + vulnerability$22,400

$112,400

Four contracts. Four security reviews. Four renewals.

vs

Keystone, full platform

  • Core Growth$30,000
  • All five modules, two frameworks$62,700
  • Bundle discount −25%−$15,675
  • 3-year term −15%−$11,554

$65,471/yr

42% less. One contract. Price locked three years.

Priced in public.
Locked for three years.

Platform fee plus modules. Unlimited users on every tier. Commit to three years and your price never moves — no annual escalator, no headcount-tier surprise, in writing.

Team

up to 250 resources · 2 cloud accounts

$10,200/yr

List $12,000 · 3-year total $30,600

  • All ten roles, unlimited users
  • Findings, workspaces, alerting
  • 90-day audit log
  • Email support
Most common

Growth

up to 1,000 resources · 5 cloud accounts

$25,500/yr

List $30,000 · 3-year total $76,500

  • Everything in Team
  • SSO
  • 1-year audit log retention
  • API access and scheduled reporting
  • Business-hours support

Scale

up to 3,000 resources · 15 cloud accounts

$51,000/yr

List $60,000 · 3-year total $153,000

  • Everything in Growth
  • SCIM and custom roles
  • 3-year audit log with export
  • Private runners
  • Priority support

Add modules à la carte — all five together, 25% off

Compliance

$15,000

first framework, +$6,000 each

Patch

$2.25

per instance / month

IaC

$12,000

flat, unlimited resources

Automation

$12,000

flat, unlimited nodes

Containers

$15,000

up to 1,000 containers

Above 3,000 resources, or need something the tiers don't cover?

Enterprise, MSSP and multi-entity pricing is quoted. Volume, education and non-profit discounts beyond the published rates are available on request.

Who this is for

Regulated teams running real infrastructure, with a date on the calendar.

Regulated scale-ups

Primary

200–1,200 people, AWS-native, holding SOC 2 and adding ISO 27001, PCI DSS or HIPAA. B2B SaaS, fintech, healthtech, insurtech.

CMMC and FedRAMP

Federal & defence

NIST 800-53 Rev 5, CMMC Level 2, FedRAMP Moderate. Continuous monitoring is a recurring evidence problem — that's exactly what Keystone is.

MSSPs and AWS partners

Channel

15–80 client environments. True multi-tenancy with data-layer isolation, per-client reporting, white-label and aggregated billing.

Built by someone who's been on the other side of the audit

Kenio Shirley, founder of Keystone

Kenio Shirley

Founder, Keystone

CISSPCISMMSITMMCITPAzure Solutions Architect

I spent seventeen years in enterprise technology, across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and ISM IRAP. I watched teams buy a compliance tool, a CSPM, a patch scanner, an IaC orchestrator, and an automation platform — and still spend their nights taking screenshots and praying the evidence matched the fix. They detect. They do not remediate. They do not prove. So I built Keystone: one place where the finding, the fix, and the evidence live in the same loop.

“Compliance is a business enabler, not a checkbox. But only if the fix and the proof live in the same place.”

Also running hireken.io — fractional CTO for high-stakes teams.

Get on the list.
Be first in the room.

Keystone is in private beta. Join the waitlist and you'll get early access, the thirteen-vendor comparison with every citation, and first refusal on the five design-partner places when the cohort opens in Q4.

Work email, thirty seconds. No sales sequence — you'll hear from me, not a tool.

Design partner cohort opens Q4 2026 — 5 places