Skip to content

Incident status portal

Incident response in Keel

When a security incident affects a client, they want to know what happened, what you are doing about it, and when it is resolved. Keel’s incident status portal lets you share a live status page for a single incident with exactly the people who need it, over a private link protected by email verification, without giving anyone an account or exposing your internal incident record. The page carries your own logo and brand color, reused from your Trust Center, so it reads as yours, not a generic Keel page.

You are reading this because a company that uses Keel shared the status of a security incident with you. The link you were sent opens a private page for one incident, meant only for you.

The first time you open the link, Keel emails a 6-digit verification code to your address and asks you to enter it before any incident details are shown. The code is single-use, expires after 10 minutes, and is limited to a few attempts. Once you verify, your browser is remembered for 7 days, so you will not be asked again during that window. Because the code is sent only to the address the link was issued to, the link cannot be used by anyone else, even if it is forwarded.

On the page itself you can:

  • See the current status at a glance — a severity badge, a phase stepper (Investigating → Contained → Resolved), a “last updated” time, and, when the owner sets one, a “next update expected by” time.
  • Follow the timeline as the incident owner posts updates and the status progresses.
  • Acknowledge receipt so the sender knows you have seen the update.
  • Subscribe an email address to be notified when a new update is published (a quick bot check keeps the form clean).
  • Contact the incident owner using the details they provided.
  • Save a PDF — a clean, branded summary of the incident and its timeline for your own records.

The page shows only the plain-language summary and updates the sender chose to publish. It never exposes their internal notes. Please treat the link as confidential and do not forward it; the link is personal to you, and in any case the verification code is only ever sent to your address.

Sharing is off by default. Nothing about an incident reaches a client until a team member turns it on. When you share an incident you decide:

  • Whether it is shared at all (the client-visible toggle).
  • The client-facing summary the reader sees, written in plain language, separate from your internal description, root cause, and lessons learned, which never leave your workspace.
  • A point of contact (email and phone) shown on the page.
  • Who gets a link. Each recipient gets their own private, revocable link, optionally with an expiry date. You can resend a recipient their existing link at any time (it does not change), revoke any link immediately, and see a read-receipt roll-up of how many recipients have viewed and acknowledged.
  • What each update says, whether it is published to clients or kept internal, and an optional “next update expected by” time shown to recipients.

When you publish a client-visible update, everyone with an active link is emailed a notification with their own link to the page. Recipients can also subscribe additional colleagues, and the page refreshes itself while an incident is live so a reader watching it sees new updates without reloading.

  1. Open the incident in Incidents and write a plain-language client-facing impact statement.
  2. Turn on Allow sharing this incident with clients and, optionally, add a contact email and phone.
  3. Add each client’s email to create their private link (it is emailed to them automatically).
  4. Post updates as the incident progresses. Tick published on the ones you want clients to see, that is what triggers the email notification and updates the page.
  5. When the incident is resolved, a closing summary is shown at the top of the page.

Every link is a scoped, revocable, expiring token that resolves to one incident under your workspace. There is no universal or public status page, only these per-recipient links. Readers see only published, client-visible content. Revoke a link and it stops working immediately.