Deploy KeenSafe the way your environment requires. Same control plane in every mode.
Four deployment modes share one engine, one evidence chain and one set of integrations. Move workloads between modes as governance evolves — without re-platforming and without losing your audit history.
Four deployment modes. One product.
Same orchestrator. Same evidence model. Same integrations. Pick the mode that fits your governance — then change your mind without re-platforming.
Hosted by KeenSafe with cryptographic tenant isolation. Onboarding in days, not quarters. Used by the majority of our enterprise customers.
- · Enterprises with vendor-onboarding approval for cloud security tooling
- · MSSPs running multi-tenant programs
- · Mid-market and growth-stage security teams
- · Cryptographic tenant isolation · per-tenant KMS
- · BYOK supported via AWS / Azure / GCP KMS
- · Region pinning across 14 supported regions
- · Egress filtering · operator zero-trust gateway
A dedicated KeenSafe control plane in the cloud region of your choice. Same product, same evidence chain — no shared compute with other customers.
- · Financial services with regional regulator requirements
- · Healthcare groups requiring PHI residency
- · Government suppliers and defense primes
- · Single-tenant compute + storage in your region
- · HSM-backed keys · HYOK supported
- · IP allow-listing · private connectivity (PrivateLink / Private Endpoint)
- · Customer-managed encryption key rotation
Customer-operated KeenSafe control plane inside your own datacenter or private cloud. Used by organizations where data-residency mandates prohibit any vendor-hosted control plane.
- · Operators with strict data-residency mandates
- · Sovereign-cloud customers (Bleu · Delos · GCC-High)
- · Organizations with existing on-prem K8s footprint
- · Customer-operated · KeenSafe ships signed releases
- · Runs on RHEL 9 / Ubuntu 22.04 / OpenShift 4.x / RKE2
- · Internal CA support · enterprise PKI integration
- · No telemetry to vendor — local-only observability
Fully disconnected installation with signed offline content and signature updates. Used by classified defense programs and critical-infrastructure operators that cannot egress to a vendor cloud.
- · Classified defense programs
- · Critical-infrastructure operators (energy · water · transport)
- · Air-gapped financial-trading networks
- · Offline content packs · signed update bundles via WORM media
- · No outbound network calls — verified by network ACLs
- · Operator access via local zero-trust gateway
- · Local FIPS 140-3 validated cryptography
How KeenSafe actually sits in your environment.
Whether KeenSafe runs in our cloud or yours, the topology is the same: an orchestration layer reaches your scope through authorized boundaries, evidence flows back via a signed chain, and telemetry streams to your SIEM / SOAR / ITSM.
Six layers, each with a single responsibility.
- · mTLS to operator gateway
- · Per-tenant API gateway
- · WAF + DDoS protection
- · Authorization manifest engine
- · Scope-bound run scheduler
- · Crown-jewel boundary checks
- · External / internal recon primitives
- · Identity + cloud graph builder
- · Attack-path synthesizer
- · Read-only primitives
- · Sandboxed payload replay
- · Per-step signed evidence
- · Signed per-event evidence
- · WORM storage · 7y default retention
- · Cryptographic deletion on request
- · Splunk · Sentinel · Chronicle · QRadar
- · XSOAR · Splunk SOAR · Tines
- · ServiceNow · Jira · PagerDuty
Native integrations across SIEM, SOAR, ITSM, identity, cloud and OT.
KeenSafe is not the system of record for your security operations — your SIEM and ticketing stack are. The platform meets you where you live, with native sinks and pre-built content for the platforms below.
- Splunk Enterprise / CloudNative HEC sink + detection-content pack
- Microsoft SentinelCEF + Logic Apps · Analytics rules pack
- Google Chronicle / SecOpsUDM-formatted feed
- Elastic SecurityECS-formatted feed · pre-built dashboards
- IBM QRadarCustom DSM · LEEF events
- Exabeam · Securonix · Sumo LogicGeneric syslog + JSON sinks
- Palo Alto XSOARNative playbook pack · 14 actions
- Splunk SOAR (Phantom)App pack · attack-path → ticket auto-flow
- TinesAPI-first integration · evidence-bundle delivery
- Microsoft Logic AppsSentinel-native automation
- Swimlane · Torq · ThreatConnectREST + webhook integration
- ServiceNow ITSM / SecOpsBidirectional ticket sync · evidence attached
- Jira / Jira Service ManagementProject + queue mapping
- Zendesk · FreshserviceTicket creation + status sync
- PagerDuty · OpsgenieCritical-path paging
- Okta · Entra ID · PingSAML + SCIM · group-to-role mapping
- CyberArk · BeyondTrust · DelineaPrivileged-access enumeration
- Active Directory · LDAPRead-only enumeration via service account
- AWS IAM · Azure AD · GCP IAMCloud identity graph ingestion
- AWS OrganizationsCross-account role · read-only · org-wide enumeration
- Azure SubscriptionsReader role · Graph API · multi-tenant supported
- Google CloudOrg-level service account · Cloud Asset Inventory
- Kubernetes (EKS / AKS / GKE / on-prem)Read-only kubeconfig · audit-log ingestion
- Tenable.io · Tenable.scAsset and finding ingestion · re-validation feedback
- Qualys VMDRAsset + finding sync · attack-path enrichment
- Rapid7 InsightVMAsset + finding sync
- Snyk · Wiz · Orca SecurityCloud-finding ingestion
- CrowdStrike FalconDetection-coverage validation · OAuth API
- SentinelOneDetection-coverage validation · API token
- Microsoft Defender for EndpointGraph API · ATP integration
- Cortex XDR · Sophos · CybereasonREST API integration
- Claroty xDome / CTDOT-asset graph ingestion · passive observation
- Dragos PlatformOT-asset + threat-intel sync
- Nozomi NetworksOT-asset graph ingestion
- Tenable.otOT-asset + IT-OT bridge mapping
No agents required — but a lightweight collector is available where it helps.
KeenSafe runs agentless against authorized scope by default. For deep segmentation and OT environments, an optional lightweight collector (~38 MB, no kernel hooks) can be deployed to extend reach without changing the security posture.
Get a deployment design tailored to your environment
Bring your network topology, your SIEM, your identity stack and your regulatory constraints — we'll respond with a deployment design, scope authorization plan and timeline within one business day.