@meta
  v: 1
  route: /keelpin/
  generated: 2026-09-19T03:52:00Z
  ttl: 1d

@intent
  purpose:    Keelpin fuses SAST, SCA, secrets, IaC, container, and agentic pentest into one exploit-proven finding per vulnerability, every commit. Built by Titanium.
  audience:   visitor, prospective-client, ai-agent
  capability: learn, compare, contact, call, visit_product_site

@state
  business: Titanium Computing
  page: Keelpin. Hold the Line. Every Commit.
  phone: +1-512-623-9199
  address:
    street: "2013 Wells Branch Pkwy, Suite 310"
    city: Austin
    region: TX
    postal: 78728
  hours: 24/7
  product: Keelpin
  website: "https://keelpin.io"
  built_by: "Titanium Computing (Austin, TX)"
  parent_service: /cybersecurity/
  modules[8]{name,scope}:
    Hull,whitebox pentesting
    Tide,blackbox pentesting
    Weld,agentic SAST
    Compass,business logic
    Cargo,SCA + reachability
    Lockbox,secrets
    Drydock,IaC
    Hold,containers
  pipeline[4]: Scan, Prove, Mend, Hold
  deployment: "read-only by default; self-hosted in your AWS, GCP, or Azure account; air-gapped available"
  compliance_evidence[8]: PCI DSS, FedRAMP, GLBA, NYDFS Part 500, DORA TLPT, CMMC L3, SOC 2 Type II, ISO 27001
  integrations: "GitHub, GitLab, Azure DevOps, Jira, Slack, container registries"
  key_stats[4]{value,metric}:
    One record,"Per vulnerability, per repo, across every scanner"
    Exploit-proven,"Findings validated by autonomous exploits, not pattern matches"
    Every commit,"Continuous, not an annual pentest of six-month-old code"
    "Austin, TX",Forged in-house by Titanium Computing
  page_sections[5]:
    - Your Team Ships Code Daily. Your Scanners Disagree.
    - A Fleet of Pins. One Platform.
    - From Commit to Verified Weld
    - Your Code Stays in Your Hold
    - We Don't Report What Might Be Vulnerable. We Hold the Line on What Is.
  section_summaries[4]{section,summary}:
    A Fleet of Pins. One Platform.,"Continuous application security across every layer of your stack, from static analysis of your code to runtime pentesting of your apps."
    From Commit to Verified Weld,"Every finding follows the same four steps. Nothing is automated past the review gate, the pin holds because you decide it holds."
    Your Code Stays in Your Hold,"Keelpin is read-only by default. Source loads into ephemeral worker memory and is discarded when the scan completes, only the canonical finding record persists. Enterprise deployments run entirely inside your AWS, GCP, or Azure account: no managed control plane, no external egress, fully air-gapped if you need it."
    We Don't Report What Might Be Vulnerable. We Hold the Line on What Is.,"Schedule a structural review. We'll point Hull and Tide at a target you control, run a real exploit, and show you the canonical finding before the call ends."
  your_team_ships_code_daily_your_scanners_steps[3]{step,title,detail}:
    01,Scanner Sprawl,SAST says one thing. SCA says another. Your pentester said something else last March. Nobody trusts any of it.
    02,The 364-Day Gap,Your team merges 200 PRs a week. Your annual pentest tested code that's already six months gone.
    03,Unproven Findings,"Pattern-matchers flag the textbook patterns. Real exploits live in business logic, auth flows, and the seams between services."
  a_fleet_of_pins_one_platform[8]{category,title,detail}:
    PENTESTING,Hull · whitebox,"Agents read your source, model the architecture, and generate precise exploits validated against the live application."
    PENTESTING,Tide · blackbox,"Autonomous external pentesting against the running app. No code access. On-demand, per repository."
    CODE,Weld · agentic SAST,"Code Property Graph plus LLM reasoning. Real vulnerabilities with full data-flow context, never regex matches."
    LOGIC,Compass · business logic,"Authorization bypass, IDOR, state-machine flaws, race conditions, and workflow abuse. What pattern-matchers miss."
    DEPENDENCIES,Cargo · SCA + reachability,Know which CVEs in your dependencies are actually reachable from attacker-controlled input.
    CREDENTIALS,Lockbox · secrets,"Leaked credentials, tokens, and API keys across code and commit history. Validated, deduplicated, prioritized by blast radius."
    INFRA,Drydock · IaC,"Terraform, CloudFormation, Kubernetes manifests, and Helm charts, scanned for misconfigurations before they sail."
    BUILD,Hold · containers,"Container images scanned for vulnerable packages, exposed secrets, and misconfigurations across every layer."
  from_commit_to_verified_weld_steps[4]{step,title,detail}:
    01,SCAN,"Push triggers SAST, SCA, secrets, IaC, and container scans across the changed surface. Source loads into ephemeral memory; nothing persists."
    02,PROVE,An agent generates an exploit and runs it against the live app. Confirmed exploits are filed as canonical findings with full reproduction.
    03,MEND,You click a finding. An agent writes the patch and re-runs the original scanner. No patch is delivered unless the vulnerability is gone.
    04,HOLD,Patch lands as a clearly labeled bot PR in your normal workflow. You review. You merge. The pin holds. The finding closes.
  your_code_stays_in_your_hold_points[4]{title,detail}:
    Never used for training,Zero-retention enforced with every model vendor. Bring your own keys if you prefer.
    Self-hosted available,"Run the entire platform inside your VPC, air-gapped, zero outbound calls."
    One source of truth,"Canonical findings deduplicated across scanners, synced bidirectionally with Jira."
    Deep integrations,"GitHub, GitLab, Azure DevOps, Jira, Slack, and every major container registry."
  external_links[1]{label,url}:
    keelpin.io,"https://keelpin.io"

@actions
  - id: request_free_consultation
    method: GET
    href: /contact/
    inputs[1]{name,type,required}:
      need,string,false
  - id: call_titanium_computing
    method: GET
    href: tel:+15126239199
  - id: visit_product_site
    method: GET
    href: https://keelpin.io
  - id: view_pricing
    method: GET
    href: /pricing/
  - id: view_human_page
    method: GET
    href: /keelpin/

@context
  > Our application security monitoring platform, built in-house at Titanium. SAST, SCA, secrets, IaC, container, and pentest, fused into one canonical record per vulnerability and proven by an autonomous exploit before it reaches your inbox.
  > Keelpin fuses SAST, SCA, secrets, IaC, container, and agentic pentest into one exploit-proven finding per vulnerability, every commit. Built by Titanium.
  > Titanium Computing is an engineer-run managed IT, cybersecurity, and compliance provider in Austin, TX, serving Central Texas since 2016. Flat per-user monthly pricing, no setup fees, and a named engineer who knows your network.

@nav
  self: /keelpin.agent
  parents: [/.agent]
  peers: [/ai/private-ai-appliance.agent, /ai/ainode.agent, /formflows.agent, /callscrub.agent, /ai.agent, /cybersecurity.agent, /case-studies.agent, /contact.agent]
