Like IcePanel. On your servers. And it runs your traffic.
IcePanel made model-based C4 diagrams easy. Keystone keeps the same ideas, runs inside your network, and adds a simulator so you can test a design before you build it.

What feels familiar
If your team knows IcePanel, you'll be at home. One shared model of objects and connections, with diagrams as views onto it. Objects nested inside each other, C4 style. Flows with alternate and parallel paths, drafts for proposed changes, and snapshots to freeze the landscape in time.
Tags, team ownership, comments, decision records and a dependencies view are all there too.
What's different
| Keystone | IcePanel | |
|---|---|---|
| Where it runs | Your servers (Docker and Postgres) | IcePanel's cloud |
| Single sign-on | SAML and OIDC in every install | On higher plans |
| Features by plan | Every feature in every install | Some features depend on plan |
| Traffic simulation | Built in, with per-message traces | Not offered |
| Custom object types | Your own names, icons, colours and shapes | Built-in set of types |
| Server upkeep | You run it | Handled for you |
Based on IcePanel's public docs and pricing page as of September 2026. Spot something out of date? Email support@keystone-app.io.
Which should you pick?
IcePanel, if…
- you'd rather nobody on your team ever runs a server for it;
- putting your architecture map in a vendor cloud is fine for your company.
Keystone, if…
- your architecture data must stay on your own infrastructure;
- you want SSO and every feature without moving up a plan;
- you want to test designs with simulation, not just draw them.