Scans · Controls
Evidence for your security controls, straight from the repo.
Keelen's Controls scan is a gap review for security controls. It reads your repo. Stack facts you declare, like cloud and identity provider, are read too. It looks for evidence against three frameworks. One is Cyber Essentials (NCSC requirements v3.3). The next is CMMC Level 1, with the fifteen FAR 52.204-21 safeguards. The last is CMMC Level 2, with NIST SP 800-171 Rev. 2. For every control it reports what evidence exists and how strong it is. It also says what a repo scan cannot see.
This does not decide if you get certified. It sets no maturity level. It shortens the distance from “we should look at Cyber Essentials” to an evidence list for each control. Your team can act on it. Selected gaps that code can fix can become remediation Requests.
Updated
- Three frameworks in one pass. Cyber Essentials v3.3, CMMC Level 1 (fifteen safeguards), CMMC Level 2 (NIST SP 800-171 Rev. 2, all 110 requirements tracked).
- Each control shows its source reference. It shows an evidence class. It shows a confidence level. The class runs from repo-observable to organisational.
- Each entry states what stays outside a repository's view. That way you know what still needs a human.
- Some gaps need code fixes. You can pick them and send them as remediation Requests. A pull request then follows the project's settings. Those settings cover review, verification and merge.
- Run each cycle again. Evidence updates. Dismissals stick. Reports stay comparable, so you can line them up.
Three frameworks, one evidence pass
Cyber Essentials entries track the NCSC v3.3 requirements. CMMC Level 1 entries track the fifteen safeguards of FAR 52.204-21. CMMC Level 2 entries keep all 110 NIST SP 800-171 Rev. 2 references. The repo-observable subset maps to evidence channels the product collects. The rest have no automated check. They say so plainly. Every entry names its source document and version. A version printed beside your evidence has to be the publisher's own.
Report the evidence
Each control has a class. The class shows where its evidence can come from. The classes are repo-observable, infrastructure-observable, a policy document, and organisational context. Infrastructure-observable needs a declared stack. Organisational context is one no scanner can reach. The report never makes that a pass mark. It never gives a readiness percentage. It lists evidence and gaps, with a confidence level for each item.
From gap to remediation Request
Some findings call for code changes. Send those to Keelen's development loop as Requests. Review the pull requests and checks. The project's merge settings apply. Other findings need a policy, legal or operational decision. Those stay with people.
Run it on your cadence
Use the Run action on the project tab for a review on demand. For repeated reviews, set your own agent or scheduler to call run_control_gap_review for this project, for example monthly during a remediation push, or before each assessment cycle. Keelen has no built in scan scheduler. Set up the project context and access first. Respect running reviews and limits. Read the result before you pick the next step.
Trigger it from any agent
claude mcp add --transport http keelen https://keelen.ai/mcp
Then the run_control_gap_review MCP tool starts a run. It works from Claude Code, Cursor, a cron job, or any other tool that speaks MCP.
What it is not
This automated engineering review records observations from the sources it names. It cannot determine an organisation's standing under a security framework. A missing observation does not establish anything about a control.
Included on every paid plan
From $29 / month on Indie
FAQ
Can I get Cyber Essentials certified with this?
No tool certifies you. A licensed certification body does that. The Controls scan builds an evidence list for each control. It uses the NCSC v3.3 requirements. It shows where the gaps are. You can turn selected gaps that code can fix into remediation Requests. The project's settings then apply. They cover review, verification and merge. You act on the evidence after that.
What is the difference between CMMC Level 1 and Level 2 here?
Level 1 covers the fifteen FAR 52.204-21 safeguards. Every one is reviewed. Level 2 tracks all 110 NIST SP 800-171 Rev. 2 requirements. The repo-observable subset maps to evidence the product collects. The rest carry no automated check, and the report says which is which. CMMC Level 2 review is a feature of the Enterprise plan.
Does it connect to my cloud account?
No. You declare stack facts in a short profile. Those facts are your cloud provider, your identity provider, and your data location. The scan reads your repo. Some evidence would need live access to your infrastructure. The report marks that evidence as such. It never overstates what was observed.
Is this a SOC 2 tool?
Not today. The frameworks covered are Cyber Essentials v3.3, CMMC Level 1, and CMMC Level 2 (NIST SP 800-171 Rev. 2). If you need a list of evidence for each control under one of those three, this is built for it.
Which plans include the Controls scan?
Included on every paid plan, from Indie at $29/month. CMMC Level 2 controls are an Enterprise feature.
Does Keelen include a scan scheduler?
No. Start a review from the dashboard. Or set up an external agent or scheduler that calls the scan's MCP tool. Daily, weekly and release driven cadences are examples. You set those up outside Keelen.
Does every finding become an automatic fix?
No. Read the evidence first. Then send the code fixes you pick to the loop. Some findings need a policy decision. Some need an operational one. Others need a legal one. Development follows the project's normal approval and merge controls.