For consultants and assessors
Stop collecting the AI inventory by hand
The endpoint AI question shows up in every AI governance engagement, and the usual answer is a spreadsheet someone filled in from memory. KeepRails produces the same artifact from the machines themselves — dated, source-attributed, and honest about what it did not scan.
Who this is for
ISO 42001 implementers
Scope the management system against what is actually installed on the engineering fleet, instead of a self-reported spreadsheet collected in week one.
vCISOs
Answer the AI-inventory question across every client on the same evidence shape, with the coverage boundary stated per client rather than assumed.
Vanta and Drata service partners
Fill the endpoint AI gap in a programme you already run. KeepRails produces the evidence; the GRC platform stays the system of record.
Auditors and assessors
Receive a dated, source-attributed register with an integrity hash and a declared scan boundary, so the review argues about substance rather than provenance.
Where it sits in an engagement
01
Scope the run
Decide which machines are in scope and which surfaces are collected. What is excluded gets declared, not omitted.
02
Deploy and collect
A single static binary on macOS and Linux. No content leaves the device; the org sync carries sanitized tool identity only.
03
Review with the client
Owner, sanction and review decisions are recorded against register entries, so the artifact carries the client’s own judgement.
04
Hand over the evidence
Export the register, the framework report, the evidence JSON and the CycloneDX AI-BOM. Re-run it next period and diff it.
What your client keeps
The engagement ends. The evidence pipeline does not.
A hand-collected inventory is stale the week after you invoice. A KeepRails register re-runs on demand, produces the same artifact shape every period, and diffs against the previous one — which is what turns your assessment into something the client can maintain rather than repurchase.
Nothing you or your client runs through KeepRails sends prompts, source code or configuration content anywhere.
What it does not do yet
You will meet all four of these in your first engagement, so they belong here rather than in a support thread.
No multi-tenant console yet
One account maps to one client organization. Running five clients means five organizations and five logins today. A partner-facing view over several client orgs does not exist.
macOS and Linux only
Windows endpoints are not collected. A Windows-first engineering fleet is outside what KeepRails can evidence right now.
Not an assessment
KeepRails supplies inventory and tooling evidence. It is evidence, not certification. It does not assess a management system, and it does not replace the work you are being paid for.
No white-label
Reports carry KeepRails provenance fields, because a versioned rubric and KB snapshot are what make the artifact checkable. Removing that would remove the reason it is trusted.
Try it on your own machine
Judge the output before you put it in front of a client
Free, no account, nothing uploaded. Two minutes on your own laptop.
curl -fsSL https://staging.keeprails.dev/install.sh | sh Bring us a client
Run a scoped Sprint together
Thirty days, up to fifty endpoints, one review of the output with you in the room. Terms for repeat engagements are agreed directly — there is no partner portal to sign up to yet.
Talk to us