Where should we begin?
What is Kastron?
Kastron is a governance gateway that makes your AI applications follow your policies.
Your business wants to put AI to work. You are expected to help, but you are also responsible for keeping it within the rules. That means protecting customer information, restricting what applications can say and do, and keeping adoption moving.
The difficulty is that an AI model can understand a rule and still break it. Telling it what’s allowed doesn’t give you reliable control.
Kastron sits between your applications and their AI models, checking requests, responses, and tool calls before they proceed. It applies the policies you define: removing sensitive information, blocking prohibited responses, and stopping unauthorized tool calls.
That gives you a way to keep AI within policy without depending on the model to follow instructions or discovering a violation after the harm is done. You can support AI adoption with policies you own and controls you can stand behind.
Can’t I just put our policies in the AI’s instructions?
You can, and you should. But telling the AI a rule doesn’t guarantee it will follow it.
Whether you put the rule in every prompt or in an instructions file the AI reads, it is still just an instruction for the model to interpret. It is not a control that prevents a prohibited response or action.
You have probably seen an AI do something you explicitly told it not to do, then reply:
“You’re absolutely right! I shouldn’t have done that.”
That’s the problem. It can recognize the rule when you point out the mistake, yet fail to follow it when it matters.
If you are responsible for compliance, you need more than an apology after customer information has been shared or an unauthorized action taken.
Kastron checks what the AI is about to send or do against your policies and blocks what isn’t allowed. Your instructions still guide the model, but enforcement no longer depends on the model following them.
OK, but what if our AI does something it shouldn’t?
Some mistakes can be reversed. Others can’t.
If a customer-service AI issues a refund it was only authorized to discuss, you may be able to reverse the transaction. But if it shares someone’s personal information with the wrong person, you can not take that information back.
Your organization has to deal with the consequences. And if you’re responsible for governance, you may be asked:
What controls were in place? Why was this allowed? What prevents it from happening again?
You need to be able to show how your policies were enforced, beyond pointing to instructions the model was supposed to follow.
Kastron gives you controls that act before a prohibited response or tool call proceeds, and records which policies applied, what decision it made, and why. You have a way to prevent the violation and the evidence to explain the decision.
So how does Kastron actually control AI?
Kastron sits between your application and the AI models and tools it uses. It acts as a Gateway, checking what is being sent to the model, what comes back, and what the AI tries to do.
You set the rules. Some may apply to every app in your enterprise. Others may apply only to a particular business line or jurisdiction. An app-specific rule does not replace your enterprise-wide policies. Kastron applies both, along with any additional rules for the business line and jurisdiction.
Suppose one of those rules says:
“The customer-support application is not allowed to use the refund tool.”
If the AI tries to call that tool, Kastron blocks the call before it executes. You’re not relying on the model to remember its instructions. The prohibited action can not proceed.
Other rules can remove sensitive information or block a prohibited response, while permitted activity continues. The control sits outside the model, so changing models or providers does not mean giving up your rules. Kastron enforces them across all interactions routed through the Gateway.
Who on my team would run Kastron?
Your governance team can create and manage the rules. Your technical team connects the applications, but you do not need developers to write code every time a policy requirement changes.
You define what a rule should check and what should happen when it applies. Then you test it before submitting it for approval.
You also decide who can write, approve, and audit policies, and which parts of the organization each person can access. If your process requires a second person to approve a rule, Kastron keeps those responsibilities separate.
Once the rules are active, your dashboard shows how much AI activity is governed and the potential violations prevented. You can show leadership what your controls are accomplishing.
When someone needs to examine a particular decision, tamper-evident records show which policies applied, what Kastron did, and why. Policy changes, approvals, and administrative activity are recorded too, so you can trace how a rule reached production as well as how it was enforced.
What about security, privacy, and performance?
You shouldn’t create a new privacy problem in order to control an existing one. Kastron can inspect prompts, responses, and tool calls in memory, apply your policies, and discard the underlying content. By default, it retains evidence of what was decided and why, not the prompts and responses themselves.
That approach limits what Kastron keeps. Encryption and isolation protect the information it does handle: data is encrypted in transit, retained information and credentials are encrypted at rest, and each customer’s data and configuration are kept separate. You can also choose the Gateway and evidence-storage regions to support your data-residency requirements.
Protecting those interactions shouldn’t make your applications feel slower. Passing through a Gateway adds processing time, but Kastron keeps that additional latency low enough to be imperceptible to users in most cases.
Your technical team can review the Kastron Technical Overview for details on architecture, security controls, data handling, performance, and how to connect your applications.
Can I see Kastron in action?
Yes. The video below gives you a quick look at the platform and how it works.
If you would like a closer look, you can request a demo. Kastron will show you how your team can manage your policies, control what AI applications are allowed to do, and see how those controls are working.