Integrations and automated evidence are typically managed by workspace admins.
See Evidence & audits for how automated evidence fits
alongside manual evidence.
What it’s used for
Keldyn uses the data it reads from Vercel to keep the evidence for your hosting and deployment controls current. Each nightly refresh updates the evidence and the freshness status shown on the integration’s Controls covered table. The integration contributes evidence to these ISO 27001 controls:Full coverage means the data is the artifact the control asks for.
Partial coverage means the data usefully contributes but does not, on its
own, replace everything the control requires (for example, A.8.32 also needs
change authorization, impact assessment, and rollback records that live in your
change-management process). Keldyn labels partial coverage in the
auto-generated evidence so it isn’t mistaken for complete coverage.
Before you begin
1
Install as a Vercel team admin
You connect by installing the Keldyn integration on your Vercel team. This
is a connect once flow — after install, Keldyn refreshes evidence on its
own with no further action from you. Installing requires permission to add
integrations to the team.
2
Know which features your plan includes
The Vercel Firewall (WAF) and Log Drains are available on higher
Vercel plans (Pro/Enterprise). On plans that don’t include them, the
firewall and logging controls show Access required instead of failing —
the rest of the evidence still refreshes normally.
3
Keldyn only ever reads
The integration is granted read access only. Keldyn never deploys, changes
configuration, or writes to your Vercel team.
Set up the integration
1
Open Integrations
In the Keldyn web app, go to Integrations and select Vercel.
2
Connect
Select Connect. You’re redirected to Vercel to install the Keldyn
integration on your team. Review the requested read access and approve it;
Vercel returns you to Keldyn once the install completes.
3
Run the first sync
After connecting, select Sync now to pull evidence immediately, or wait
for the next scheduled refresh. The Controls covered and Evidence
sources tables then show what was collected and how fresh it is.
What data Keldyn collects and why
Keldyn requests read-only access and never writes to your Vercel team. It collects only the data below, and only to build control evidence.Authentication
Keldyn authenticates as a Vercel integration installation. Installing the integration returns a long-lived, team-scoped access token that Keldyn stores encrypted, so there is no password to rotate and no repeated re-authorization. The integration’s read scopes are configured on the integration itself in Vercel. Removing the integration in Vercel, or selecting Disconnect in Keldyn, immediately severs access.Troubleshooting “Access required”
A control shows Access required when the connected team can’t read the underlying data — most often because the feature isn’t included in your Vercel plan. For example:- The Vercel Firewall (WAF) is required for the networks-security control.
- Log Drains are required for the logging control.
Keeping evidence current
Keldyn refreshes Vercel evidence automatically each day. Evidence that hasn’t refreshed within its expected cadence is marked stale, and failed pulls are marked failed so you can spot gaps. You can also trigger an immediate refresh at any time with Sync now.Next steps
Evidence & audits
Learn how automated integration evidence works alongside manual evidence and
audits.