Skip to content
Scan one machine free. No account. Nothing leaves your machine.
KeepRails

For consultants and assessors

Stop collecting the AI inventory by hand

The endpoint AI question shows up in every AI governance engagement, and the usual answer is a spreadsheet someone filled in from memory. KeepRails produces the same artifact from the machines themselves — dated, source-attributed, and honest about what it did not scan.

Who this is for

ISO 42001 implementers

Scope the management system against what is actually installed on the engineering fleet, instead of a self-reported spreadsheet collected in week one.

vCISOs

Answer the AI-inventory question across every client on the same evidence shape, with the coverage boundary stated per client rather than assumed.

Vanta and Drata service partners

Fill the endpoint AI gap in a programme you already run. KeepRails produces the evidence; the GRC platform stays the system of record.

Auditors and assessors

Receive a dated, source-attributed register with an integrity hash and a declared scan boundary, so the review argues about substance rather than provenance.

Where it sits in an engagement

01

Scope the run

Decide which machines are in scope and which surfaces are collected. What is excluded gets declared, not omitted.

02

Deploy and collect

A single static binary on macOS and Linux. No content leaves the device; the org sync carries sanitized tool identity only.

03

Review with the client

Owner, sanction and review decisions are recorded against register entries, so the artifact carries the client’s own judgement.

04

Hand over the evidence

Export the register, the framework report, the evidence JSON and the CycloneDX AI-BOM. Re-run it next period and diff it.

What your client keeps

The engagement ends. The evidence pipeline does not.

A hand-collected inventory is stale the week after you invoice. A KeepRails register re-runs on demand, produces the same artifact shape every period, and diffs against the previous one — which is what turns your assessment into something the client can maintain rather than repurchase.

Nothing you or your client runs through KeepRails sends prompts, source code or configuration content anywhere.

What it does not do yet

You will meet all four of these in your first engagement, so they belong here rather than in a support thread.

No multi-tenant console yet

One account maps to one client organization. Running five clients means five organizations and five logins today. A partner-facing view over several client orgs does not exist.

macOS and Linux only

Windows endpoints are not collected. A Windows-first engineering fleet is outside what KeepRails can evidence right now.

Not an assessment

KeepRails supplies inventory and tooling evidence. It is evidence, not certification. It does not assess a management system, and it does not replace the work you are being paid for.

No white-label

Reports carry KeepRails provenance fields, because a versioned rubric and KB snapshot are what make the artifact checkable. Removing that would remove the reason it is trusted.

Try it on your own machine

Judge the output before you put it in front of a client

Free, no account, nothing uploaded. Two minutes on your own laptop.

curl -fsSL https://staging.keeprails.dev/install.sh | sh

Bring us a client

Run a scoped Sprint together

Thirty days, up to fifty endpoints, one review of the output with you in the room. Terms for repeat engagements are agreed directly — there is no partner portal to sign up to yet.

Talk to us