TRUST CENTER
Don't just trust us. Verify us.
Certifications, with scope and validity.
| CERTIFICATION | SCOPE | ISSUER | VALID UNTIL | Evidence |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | SOC, IR, Managed IT, Console | Accredited CB [placeholder] | 2028-03-14 | Certificate |
| BSI-qualified APT response provider | Incident response | BSI [placeholder] | 2027-11-30 | Listing |
| TISAX AL3 | Kiel HQ, SOC | ENX [placeholder] | 2027-06-02 | Label |
| SOC 2 Type II | Keel Console | Audit firm [placeholder] | Period 2025-10 → 2026-09 | Report (NDA) |
| CREST | Penetration testing | CREST [placeholder] | 2027-01-31 | Member page |
All certifications are illustrative placeholders for the fictional Keel Security.
Data location & sovereignty.
Your telemetry, tickets and reports are processed and stored in Germany. Support and SOC staff are EU-based employees.
- Telemetry & SIEM
- Frankfurt am Main, DE · ISO/IEC 27001 data center
- Backups
- Nuremberg, DE · immutable, offline copy
- SOC operations
- Kiel, DE · Keel employees only
- Encryption
- AES-256 at rest, TLS 1.3 in transit, customer-managed keys optional
Subprocessors.
Get notified of changes (30 days ahead) →| SUBPROCESSOR | PURPOSE | LOCATION |
|---|---|---|
| Data center operator A | Colocation, Frankfurt | DE |
| Data center operator B | Backup storage, Nuremberg | DE |
| EDR vendor (per contract) | Endpoint telemetry | EU |
| Ticketing SaaS | Helpdesk tickets | DE |
Responsible disclosure.
Found a vulnerability in our systems? Thank you. We acknowledge within one business day, keep you updated, credit you in our hall of fame and won't take legal action against good-faith research.
- 01Report encrypted to security@example.com
- 02Acknowledgement ≤ 1 business day
- 03Fix, coordinated publication, credit
Contact: mailto:security@example.com Contact: tel:+49-431-555-0000 Expires: 2027-09-24T00:00:00.000Z Encryption: https://example.com/pgp-key.txt Acknowledgments: https://example.com/hall-of-fame Preferred-Languages: en, de Canonical: https://example.com/.well-known/security.txt Policy: https://example.com/disclosure-policy
PGP 4A1F 9C0E 22B7 51D3 8E6A 0C4B 7F19 D2E8 3B55 91AC
Status · last 90 days.
Full status page →Keel Console99.98%
Alert pipeline99.99%
Hotline100%
Security documentation.
Public policies are free to download. Audit reports and pentest summaries need a click-through NDA.
- Information security policyPDF · public
- Privacy notice & DPA templatePDF · public
- Business continuity summaryPDF · public
- ISO/IEC 27001 certificatePDF · public
- SOC 2 Type II reportNDA
- Annual pentest summaryNDA
✓ NDA accepted · 2026-09-24 03:12 UTC
Partner & insurer ecosystem.
- CYBER INSURERLogo · with permission
- CYBER INSURERLogo · with permission
- MSP PARTNERLogo · with permission
- MSP PARTNERLogo · with permission
- EDR VENDORLogo · with permission
- CLOUDLogo · with permission
- RESELLERLogo · with permission
- CERT NETWORKLogo · with permission