Enterprise
For organizations whose regulatory or data-sovereignty requirements prohibit source code, findings, or AI inference traffic from leaving their environment.
Air-gapped deployments
also available.
Keygraph Enterprise deploys entirely within your cloud infrastructure. Source code, scan results, and AI inference stay inside your security perimeter. No Keygraph-managed control plane, no external data plane.
Architecture
Every component runs inside your cloud account.
Deployed in your cloud. Scans repos and infrastructure. Calls the LLM via your credentials.
Scheduling, workflow, and operator console all run on your compute.
Your Postgres. Your encryption. Your retention policy.
Integrates with your IdP via SAML 2.0 or OIDC, with any standards-compliant provider.
Air-gapped deployments
Run the Keygraph platform in a fully network-isolated environment. Designed for FedRAMP, ITAR, defense, classified networks, and financial-services environments where every byte of egress requires legal sign-off.
Platform images mirrored to your private registry, Docker Hub, ECR, GCR, Artifactory, or Harbor.
Models served from your own Amazon Bedrock, Vertex AI, or Azure OpenAI endpoint, or a fully self-hosted model, using credentials you hold.
No phone-home, no expiry-day surprises. Validation runs entirely inside your network.
Update bundles delivered as signed artifacts, applied on your schedule via your change-management process.
Integrations
Plugs into the tools your security and engineering teams already run. Native connectors for source control, identity, ticketing, and AI inference.
Source Control
SSO & Identity
Ticketing
AI Inference (BYOK)
Everything in Enterprise
The complete platform plus the support and services around it, in one license. Vulnerabilities are identified, validated with working exploits, prioritized by proven exploitability, and tracked through remediation in a single findings layer.
Source-aware static analysis with exploit validation: findings are confirmed against the running application, not just pattern matched.
Penetration testing of the running application with zero code access. Findings are validated by exploitation, not inferred from signatures.
Identifies workflow and authorization flaws traditional tools miss.
Open-source dependency risk with reachability analysis: only CVEs that are actually reachable from your code are surfaced for triage, covering supply-chain risk requirements.
Committed credentials, tokens, keys.
Fixes for confirmed findings, opened as reviewable pull requests. Patches are never auto-applied; your team reviews and merges.
Unified across all scanners. One queue, one triage model.
Tunable to your risk model and asset criticality.
Jira, GitHub, GitLab, Azure DevOps, Slack.
Granular permissions per project, scanner, and finding action. Inherit roles from your IdP groups.
Every scan, finding mutation, status change, suppression, role grant, and integration call recorded with actor, timestamp, source IP, and diff. Searchable, filterable, and exportable as JSON or CSV for SIEM ingestion or auditor evidence.
Provisioning, de-provisioning, and group mapping inherit from identity.
All scanners, all findings, no per-scan quotas.
Bring your own keys for infrastructure and AI providers.
A single point of contact, embedded with your team.
Usage, findings, and roadmap alignment, every quarter.
Custom SLAs written directly into your contract.
Typically 4 to 8 weeks, end to end.
JSON and CSV export for SIEM ingestion and audit evidence. Scan records and validated findings produce evidence for penetration testing and vulnerability scanning requirements.
No add-ons. All scanners, integrations, and service items are included in the base license. You do not buy modules.
Annual contracts. Net 30 standard. Procurement-friendly paper available: MSA, DPA, and security addendum templates ready for redline.
Ready to talk through an Enterprise deployment?
Schedule time with a solutions engineer. We will walk through your current AppSec architecture, identify coverage gaps, and map how Keygraph deploys into your environment.


