ProofKeel

ProofKeel Steward

Keep your servers hardened, patched, and backed-up — no security team required.

ProofKeel Steward is a preventive, posture-and-remediation-first control plane for self-managed infrastructure.

Backup test-restore proof
Weekly
Patch success, verified by probes
Health-gated
Signed attestation freshness
This week

The gap

Deployment got easy. Security stayed on you.

The PaaS wave left security as an exercise for the user. Coolify and Dokploy deploy beautifully — but hardening, patching, and backups are still “on you”.

The incumbents sit at the wrong end of the market: Wiz, Aikido, and Vanta assume you already have a security team. Everyone running their own servers without one is left to stitch it together alone.

What the PaaS wave solved

Push-to-deploy, previews, and dashboards. Standing up a server has never been easier.

What it left behind

Hardening the box, keeping it patched without breaking production, and proving backups actually restore. That part is still yours.

What it does

Outcomes, on a recurring schedule

CVE response, while you sleep

CVE dropped at 2am — know your blast radius; auto-fix the safe majority, one-click approval for the rest.

Consent-based patching

Every patch triaged with a disruption-risk assessment, applied inside your maintenance windows, and confirmed healthy by your own probes — with one-click rollback.

Backup verification

From sample file restores to a database dump restored into an ephemeral container and smoke-queried — “test-restore succeeded this week”, fresh proof, weekly.

Attestation, always current

A signed, audit-ready trust artifact — “as of this week”, not 8 months old.

How it works

From install to proof in four steps

  1. Install the agent

    One lightweight agent per server, minutes per box. Onboarding starts observe-only: it watches and reports, and changes nothing until you say so.

  2. Assess

    Continuous posture baseline — hardening drift, patch state, backup health, proxy TLS, default credentials — rolled into a per-host trust score.

  3. Remediate

    Safe fixes applied automatically in your windows; the rest wait for one click.

  4. Prove

    A signed, current attestation of posture you can hand to anyone.

Deep dive

Safe patching, by construction

The differentiator is not “we patch automatically” — it is that every patch is triaged for disruption risk, every change is reversible, and apply-or-defer is a one-click decision instead of a research project.

Consent tiers, not blind automation

Auto-apply is opt-in per server and reserved for low-risk, high-urgency fixes. Approve-first is the default. Test-then-promote rolls a canary host before the fleet. Kernel patches never auto-apply.

Success means healthy, not just installed

A patch is done when your declared health probes pass — the service answers again and no new critical finding appears — not when the package manager exits 0. A canary that fails its probes halts the rollout.

Approve the exact change

Dry-run runs the same plan computation as apply, with download-and-write steps replaced by reads. The plan you approve — validated with the service's own config checks — is the plan that gets applied.

Interlocks that assume failure

Maintenance windows are enforced on the agent itself, even if the control plane errs. SSH and firewall changes carry an automatic revert timer. A fix that starts rolling back across the fleet is paused fleet-wide.

Freezes and exceptions, first-class

Declare a change freeze and nothing moves — it outranks windows, consent tiers, and rollout waves. Grant a patch exception with a reason and an expiry, disclosed on your attestation.

Honest about rollback

Auto-tier eligibility requires a verified reversal path. Where rollback is limited, the host defaults to human approval instead of pretending otherwise.

Assurance

Trust you can show, not just claim

Compliance-mapped attestation

Every attestation maps your posture to CIS, ISO/IEC 27001:2022, SOC 2, and PCI DSS v4.0 control IDs — full, partial, or supporting, stated as it is.

Trust pages & auditor access

Publish a public trust page for your customers, and give auditors revocable, token-gated access to compliance reports, evidence, and attestations.

Fleet trust scores

Every host earns a 0–100 trust score across posture, exposure, patch health, backup, and drift — with component drill-down and a fleet-wide rollup.

An agent you can trust

Agents self-update only signed releases through canary, early, and stable rings, with a control-plane kill switch. Opt in to TPM-resident identity (ECC P-256) for hardware-backed machine identity.

Who it's for

Built for the long tail of self-managed infrastructure

Indie SaaS & solo operators

You run 1–5 servers that are the business. You need them hardened, patched, and backed-up without becoming a part-time security engineer.

Small agencies

You operate 10–200 client servers. ProofKeel Steward turns upkeep into a recurring-value service you can show clients — with project-scoped access keeping each client's fleet separate.

PaaS refugees

You left the big platforms for cost and control — and inherited the ops burden. ProofKeel closes the gap you traded away.

Pricing

Explore early-access pricing

These indicative prices are research only: not a quote, offer, or final pricing decision. Choosing a tier below tells us which price point to build toward; it does not charge you anything today. Paid server capacity follows purchased slots, starting at the minimum shown for each tier.

FreeFree

Prove it on the one box that matters.

Up to 5 servers · 3 seats

  • Continuous posture baseline
  • Approve-first patching
  • Weekly backup test-restore proof

Pro$29/mo

For the fleet that is the business.

From 50 server slots · 25 seats

  • Everything in Free
  • Auto-apply for low-risk, high-urgency fixes
  • Staged rollouts across the fleet
  • Trust portal for customers

Team$99/mo

For agencies running client infrastructure.

From 200 server slots · 100 seats

  • Everything in Pro
  • Audit export for client-facing reporting
  • Priority support

Early access

Join the waitlist

No spam. We’ll email you exactly once when early access opens. Prefer email? hello@proofkeel.com

By joining, you agree to how we handle your information — see our privacy notice.