Scans
Review your software. Keep selected fixes moving.
Keelen runs security, legal and controls scans. Security checks code risks, secrets, dependencies and infrastructure. Legal checks possible exposure the code may show. It reads the project profile as well. Controls checks the evidence for gaps. It works against supported frameworks. All three help teams review software as it changes. Read the findings. Pick the code fixes to send to the development loop. Check the pull requests before the next review.
Start a review from the project dashboard. Or set your own agent or scheduler to trigger it through MCP each day, each week or after a release. Keelen has no built in scan scheduler. A review needs the right project setup and access. It also depends on plan availability, billing and run limits. Included on every paid plan, from Indie at $29/month. CMMC Level 2 controls are an Enterprise feature.
Updated
Security scan
Keelen's Security scan is a deep security audit of your whole repo.
About the Security scan →Choose a review rhythm
These are example cadences for your external scheduler. They are not required frequencies, and they do not promise that a scan runs all the time. Pick one based on how your software changes and how much time you have to read findings.
- After a release or material change
- After a release, check the changed repo. Also check the project context. The trigger sits in your external workflow.
- Daily for a fast changing project
- Choose a daily review when your changes call for it and someone can read the results. Respect running jobs and limits.
- Weekly or after remediation
- Review the changes that built up. Pick the next fixes, then run another review after the work is accepted.
From review to the next change
Prepare the context
Connect your repo. Save the profile. Save the framework context. The review needs one or both.
Run the review
Use the dashboard. Or use an external scheduler that calls the right MCP tool.
Triage findings
Read the evidence and the coverage. Pick the code changes for the roadmap. Other questions go to the right people. They may be policy, legal or operational.
Review the pull request
Look at the proposed change and the checks. Your project's approval and merge settings apply.
Run another review
Read the new evidence and the status of prior findings. A clear report is not proof that no risks remain.
FAQ
What are Keelen's scans?
Keelen has three read only reviews. Each one runs in an isolated VM. It reads your repo. Security audits code and secrets. It also checks dependencies. It checks infrastructure too. Legal maps what the code shows to commonly cited legal obligations. Controls records evidence against Cyber Essentials and CMMC. Send the findings you pick to the development loop as Requests. Send one only when a code change is needed. Review the pull requests and the checks. Your merge settings still apply. Some findings need a policy, legal or operational decision. Those findings stay with the right people.
Are the scans read only?
Yes. Every scan runs in an isolated single use VM. Its token is read only and scoped to one repository. Nothing runs against your live systems, and nothing is written. Changes happen only when you send a finding to the loop. Then they arrive as normal pull requests through Keelen's verification gates.
How often should I run them?
These are example cadences for your external scheduler. They are not required frequencies, and they do not promise that a scan runs all the time. Base the choice on how your software changes and how much time you have to read findings. Pick the next review from the scan's own scope and the changes in your project.
Does Keelen include a scan scheduler?
No. Start a review from the dashboard. Or set an external agent or scheduler to call the scan's MCP tool. Daily, weekly and release driven cadences are examples you set up outside Keelen.
Does every finding become an automatic fix?
No. Read the evidence first. Then pick the code fixes to send into the development loop. Some findings need a person. The call may be policy, legal or operational. The project's normal approval and merge controls still apply.