Kastra favicon

Kastra

Kastra: The Comprehensive Runtime Authorization Layer and Security Infrastructure for AI Systems

Introduction:

Kastra is the industry-leading runtime authorization platform designed specifically for AI systems and autonomous agents. Unlike traditional monitoring tools that observe actions after the fact, Kastra sits directly in the execution path, deciding what your AI is allowed to do before it happens. With sub-millisecond decision latency (p99 <1ms), Kastra checks every prompt, tool call, shell command, and API request against cryptographically signed policies. Kastra provides a complete execution control plane featuring three core modules: Decide, Enforce, and Prove. Whether governing coding agents like Claude Code and Cursor or securing browser-based agents via OpenClaw, Kastra ensures enterprise-grade security and compliance (SOC 2, ISO 27001, HIPAA). Its unique 'Recon' feature allows teams to scan historical AI activity to draft self-verified policies, moving from audit to enforcement seamlessly. Kastra supports diverse deployment models including Cloud, Self-hosted, and Air-gapped environments across major programming languages like Python, TS, and Go.

Added On:

2026-07-24

Monthly Visitors:

--K

Kastra - AI Tool Screenshot and Interface Preview

Kastra Product Information

Kastra: The Runtime Authorization Layer for AI Systems

In the rapidly evolving landscape of artificial intelligence, a critical gap has emerged in AI infrastructure: the lack of a real-time decision layer. While AI agents are increasingly tasked with shipping code, moving money, and querying sensitive data, most tools only monitor these actions after they have occurred. Kastra fills this void as the first dedicated runtime authorization platform that decides what your AI is allowed to do — before it does it.

What is Kastra?

Kastra is the missing authorization layer for AI infrastructure. It acts as a Policy Decision Point (PDP) that sits in the path of every AI-generated action. Every prompt, tool call, shell command, and API request is evaluated against your organization's specific policies in under a millisecond.

Unlike generic AI safety filters or post-hoc logging tools, Kastra is a proactive governance system. It ensures that only authorized actions reach their intended targets, such as databases, shell environments, or third-party APIs. By providing a centralized control plane, Kastra allows developers and security teams to govern what models, agents, and copilots are allowed to execute in real production environments.

Kastra is NOT:

  • A post-hoc logging or observability tool.
  • Simple chatbot moderation or content filtering.
  • Generic AI safety monitoring.
  • A feature bolted onto a monitoring product.

Kastra IS:

  • The definitive authorization layer for AI.
  • A sub-millisecond decision engine for AI actions.
  • A system that sits in the execution path to allow or deny actions in real-time.
  • A cryptographically signed, append-only audit trail for compliance.

Key Features of the Kastra Platform

Kastra provides a comprehensive execution control plane built around three core pillars: Decide, Enforce, and Prove.

1. Decide: Sub-Millisecond Policy Evaluation

Every AI action undergoes a rigorous policy check before it can execute. Kastra's Policy Engine (POLICY.DSL) allows you to write typed, versioned policies as code.

  • Runtime Authorization (PDP.EVAL): Checks every tool call and request against active policies with a p99 latency of <1ms.
  • Post-Inference Validation (INFER.GUARD): Inspects model returns before they touch real systems, preventing harmful outputs from triggering unintended actions.

2. Enforce: Consistent Governance Everywhere

Kastra ensures that the same policy language is enforced across all environments, from developer laptops to cloud-scale agent runtimes.

  • Kastra Edge (EDGE.DAEMON): Governs coding agents such as Claude Code, Cursor, and Codex CLI locally on developer machines.
  • Autonomous Agent Controls (AGENT.SCOPE): Scopes each step of multi-step workflows and mandates human approval for sensitive actions.
  • OpenClaw Integration (BROWSER.INTERCEPT): Intercepts and checks every click, navigation, and form fill from autonomous browser agents.

3. Prove: Audit and Compliance

For industries like finance and healthcare, proving compliance is non-negotiable. Kastra ensures every decision is signed and replayable.

  • Audit Trail (AUDIT.VAULT): Provides signed, append-only traces that can be streamed to SIEMs like Datadog or Splunk.
  • Deployment Flexibility (DEPLOY.ANY): Deploy via Cloud, Hybrid, Self-hosted, or Air-gapped models with consistent policy enforcement.

Use Cases for Kastra

Governing Coding Agents

Developers using AI tools like Claude Code or Cursor often face risks of destructive shell commands (e.g., rm -rf) or accidental pushes to production. Kastra Edge checks these commands locally, blocking high-risk actions before they hit the terminal.

Securing Browser Agents via OpenClaw

Browser agents are autonomous, but their actions should not be. Kastra governs OpenClaw sessions by intercepting DOM events. For example, an agent might be allowed to navigate an internal banking portal but denied the ability to click the "Approve Wire Transfer" button without a human-in-the-loop sign-off.

Database and Infrastructure Protection

Kastra prevents research agents from querying PII (Personally Identifiable Information) without residency checks and stops operations agents from deleting production deployments in Kubernetes without authorization.

"If you cannot cut off an agent's access in seconds without redeploying it, you do not have an authorization layer. Kastra provides that control."

Kastra Recon: See Before You Enforce

If you aren't ready to enforce strict policies yet, Kastra Recon allows you to scan your AI's history. It surfaces risky behavior—such as writing API keys to disk or force-pushing to Git—and automatically drafts self-verified policies based on that history. This allows teams to move from "Audit first" to "Enforce next" with confidence.

How to Use Kastra

Setting up Kastra is designed to take minutes, not quarters. Below are the primary ways to get started with the platform.

Installation

For developers looking to govern coding agents on macOS, you can install the CLI using Homebrew:

brew install kastra-labs/tap/kastra-edge

Scanning Historical Actions

To audit what your local AI agents have already done, use the Recon scan command:

kastra-edge scan

This command will redact information on-device and surface risks like hardcoded secrets, production database reads, or destructive commands.

Integration Path

  1. User Request: A user asks a question or starts a workflow.
  2. AI Action: The AI picks a tool call or shell command.
  3. Kastra Check: Kastra evaluates the action against the policy (e.g., identity verified, scope evaluated).
  4. Execution: Only allowed actions reach the target API or database. Everything else is blocked and logged.

FAQ

Q: What is AI agent governance? A: It is the practice of defining and enforcing what autonomous AI agents are permitted to do within your digital infrastructure to mitigate security and operational risks.

Q: How does Kastra compare to LLM guardrails? A: LLM guardrails typically focus on content filtering or safety at the model level. Kastra is an infrastructure-level authorization layer that controls the actual tools and systems the AI attempts to use.

Q: What deployment models are supported? A: Kastra supports Cloud, Self-hosted, and Air-gapped deployments to meet the needs of global banks, federal agencies, and AI labs.

Q: Which programming languages does Kastra support? A: Kastra offers SDKs and support for TypeScript, Python, Go, Rust, Java, and Swift.

Q: Is Kastra compliant with industry standards? A: Yes, Kastra is SOC 2 Type II (in audit), ISO 27001 (2026), HIPAA compliant, and mapped to Article 9 of the EU AI Act.

Loading related products...