Assess a client, keep their risk register updated, and give their board a report they'll actually read. The same way, every client, every quarter.
Plain-language questions, written by a cyber consultant, that a practice manager or ops lead can answer without an interpreter. Every answer scores their capability and can be filed into the risk register.
Each client keeps their own inventory and register. You get one dashboard across the lot, with every risk ranked, owned and tracked until it's closed.
Assessments provide technical roadmaps for your teams to follow. Gaps and risks can be easily added to an exec report so a board, auditor or insurer can follow without a translator. Benchmark against ACSC, Essential Eight, NIST, CIS and more with a posture score you can use for trending and showing improvement over time.
Risk reduced by 12 points this quarter. Two high risks remain, both with owners and due dates.

Domain scores, quick wins and regulatory gaps, benchmarked against industry, generated straight from an assessment.

Every risk owned, prioritised and tracked to resolution, per client.

Scores, activity and workload across your entire client book in one view.
Toggle the controls below: watch the score update, just like a client assessment would in Keystone.
Gaps are identified and added to the recommendations automatically.
Get some basic details in, add some asset information or create the IT service manual. Where you start is up to you.
Work through the questions with your client. The risk register, posture score and reporting can be built from there.
Produce the board report in a click, then work through the priority risks with your client. The remediation and support work is yours to quote.
Keystone wasn't built by a product team guessing at what security delivery looks like. It's built and used by Community Cyber's own advisory practice. Every assessment we run for our own clients runs through Keystone first, so the assessment content, the risk scoring and the reporting are all field-tested on real engagements, not theorised in a roadmap meeting.
Essential Eight and ACSC guidance are baked in, so what you deliver stands up to the funders, insurers and auditors your clients answer to.
Designed for providers serving not-for-profits, charities and small businesses: fast to run, easy to hand over, and priced for that market, not for enterprise GRC budgets.
Keystone doesn't summarise a client's risk for you, doesn't guess at their answers, and doesn't generate their board report out of thin air. The questions are written by a cyber security consultant. The judgement stays with you and your client. What lands in front of the board has been reviewed and discussed rather than generated.
Per-vendor and per-app risk tiering, with shared-credential and SSO gaps flagged automatically.
Create a document that can be printed and stored onsite in case of an outage or issue.
Essential Eight, ACSC, NIST CSF, CIS Controls, NIST 800-53 and SOC 2, scored from the same assessment.
A plain-language reference you can hand straight to a non-technical board or client.
Cross-client rollups, industry benchmarks and team workload in one dashboard.
Shared client access across your whole team, no per-user linking required.
Passkey sign-in and SSO for everyone on your team, no shared passwords.
Every report, every format, ready to send to a client or a board.
We consult. We don't do implementation or ongoing support. So when our advisory clients need the work done and kept running, we hand it to partners we trust — real clients, already assessed, ready to go.
Partners can lean on our expertise for the security questions clients raise, rather than fielding them alone.
We list partner services and point organisations their way when the fit is right, and vice versa — we only ever consult, so there's no overlap on delivery work.
Log in if you use Keystone already. Otherwise, happy to answer questions.