CBOM at
Enterprise Scale
Deploy KeyLens across your organization with SSO, role-based access, audit logging, and air-gapped installations. Built for compliance-driven teams that need cryptographic visibility without compromise.
Deployment Architecture
KeyLens runs entirely within your infrastructure. No data ever leaves your network.
Enterprise Capabilities
Everything in the open source CLI, plus the controls compliance teams require.
SSO / SAML
Integrate with your identity provider — Okta, Azure AD, PingFederate, or any SAML 2.0 / OIDC compliant IdP. Single sign-on for every team.
Role-Based Access Control
Granular permissions per team, project, and repository. Enforce least-privilege access for scan configurations and policy management.
Audit Logging
Tamper-proof, immutable audit logs for every scan, policy evaluation, and configuration change. Exportable to SIEM (Splunk, Elastic, Datadog).
Air-Gapped Deploy
Single static binary — no JVM, no Docker, no internet required. Deploy in classified, air-gapped, and SCIF environments.
Custom Policies
Author organization-specific Rego policies for algorithm allowlists, key size minimums, certificate requirements, and CI/CD gating rules.
Priority Support & SLA
Dedicated support channel with guaranteed response times. Direct access to the engineering team for integration assistance and custom requirements.
Open Source vs Enterprise
KeyLens is free and open source. Enterprise adds the controls organizations need at scale.
| Feature | Open Source | Enterprise |
|---|---|---|
| CLI Scanner (20+ languages) | ✓ | ✓ |
| CycloneDX 1.6 CBOM Output | ✓ | ✓ |
| Rego Policy Engine | ✓ | ✓ |
| GitHub Action | ✓ | ✓ |
| CBOM Diff (CI gating) | ✓ | ✓ |
| SSO / SAML Integration | — | ✓ |
| Role-Based Access Control | — | ✓ |
| Audit Logging (SIEM export) | — | ✓ |
| Air-Gapped Installation | — | ✓ |
| Custom Policy Packs | — | ✓ |
| Compliance Datasheets (PDF) | — | ✓ |
| Priority Support + SLA | Community | ✓ Dedicated |
| Unlimited Users | Up to 3 | ✓ Unlimited |
Talk to Us
Get a tailored demo, discuss deployment options, or request a compliance datasheet. We typically respond within one business day.