EveryDev.ai
Subscribe
Home
Tools

3,245+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents2189
  • Coding1574
  • Infrastructure698
  • Marketing534
  • Projects498
  • Research456
  • Design416
  • Analytics389
  • Testing296
  • MCP290
  • Security286
  • Data262
  • Integration197
  • Prompts189
  • Communication183
  • Extensions173
  • Learning170
  • Voice151
  • Commerce135
  • DevOps123
  • Web86
  • Finance26
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. Kastra
    Kastra icon

    Kastra

    Access Control
    Featured

    Kastra is a runtime authorization platform that decides what AI agents, models, and tools are allowed to do — checking every prompt, tool call, shell command, and API request against policy in under a millisecond before execution.

    Visit Website

    At a Glance

    Pricing
    Free tier available

    Local AI runtime protection for solo developers. Forever free.

    Pro: $20/mo
    Team: $50/mo
    Enterprise: Custom/contact

    Engagement

    Available On

    Windows
    macOS
    Web
    API
    SDK

    Resources

    WebsiteDocsllms.txt

    Topics

    Access ControlAutonomous SystemsCompliance and Governance

    Alternatives

    OpenBox AIKYE ProtocolOasis Security
    Developer
    Kastra Labs Inc.Newark, DEEst. 2025

    Listed Jul 2026

    About Kastra

    Kastra is a runtime authorization layer for AI systems, built by Kastra Labs Inc. and headquartered in Newark, Delaware. It sits in the execution path of every AI action — shell commands, database queries, API requests, browser clicks, and tool calls — and issues an allow or deny verdict before the action runs, with a stated p99 latency under one millisecond. The platform is designed for teams deploying autonomous AI agents in regulated or production-critical environments who need to answer, in seconds, what each agent is allowed to do, which rule permitted a given action, and whether access can be revoked without redeployment.

    What It Is

    Kastra positions itself as the authorization layer for AI — a policy decision point (PDP) that intercepts AI-generated actions before they reach real systems. Unlike observability or monitoring tools that record what happened after the fact, Kastra evaluates each action against a versioned policy and returns a signed verdict in real time. The platform organizes its capabilities into three loops: Decide (runtime authorization and policy engine), Enforce (Kastra Edge for developer laptops, autonomous agent controls, OpenClaw browser agent integration, and endpoint governance), and Prove (signed append-only audit trail and flexible deployment architecture). Every decision is cryptographically signed with ed25519 and stored in an append-only audit vault that can be streamed to a SIEM, Datadog, Splunk, or S3.

    Core Architecture and Modules

    The platform ships nine modules across the three loops:

    • Runtime Authorization — the central PDP that checks every action against policy before execution.
    • Policy Engine — a typed, versioned domain-specific language for writing what AI can and cannot do, managed like code.
    • Post-Inference Validation — inspects model output before it touches a downstream system.
    • Kastra Edge — a local daemon (available as a macOS app or CLI via Homebrew) that governs coding agents such as Claude Code, Cursor, and Codex CLI on developer laptops.
    • Autonomous Agent Controls — scopes each step of multi-step workflows and gates sensitive steps behind human approval.
    • OpenClaw Integration — intercepts every click, form fill, navigation, and download from autonomous browser agents before the DOM event fires.
    • Endpoint Governance — controls AI tools across employee laptops, build agents, and engineering workstations.
    • Audit Trail — signed, append-only traces with configurable retention and export to external systems.
    • Deployment Control — supports cloud, hybrid, self-hosted, and air-gapped topologies with identical policy semantics across all.

    Kastra Recon and Shadow Mode

    Kastra Recon is a scan-first feature that lets teams audit their coding agent's existing history before enabling enforcement. It surfaces risky actions already taken — secret writes, force pushes, production database reads, piped shell downloads — and auto-drafts a self-verified policy for each finding. This supports a "shadow mode" rollout path: deploy Kastra without blocking anything, observe real AI runtime activity, validate policy fit against live traffic, then graduate to enforcement mode that blocks denied actions in real time and sends alerts to Slack or webhooks.

    Compliance and Deployment Posture

    The platform targets regulated industries including finance, healthcare, government, defense, legal, and retail. According to the Kastra website, the platform is SOC 2 Type II (in audit), ISO 27001 (Stage 2, targeting 2026), HIPAA (BAA available), GDPR (EU residency supported), EU AI Act (Article 9 mapped), and FedRAMP Moderate (in preparation). The enterprise tier adds single-tenant VPC deployment, customer-managed KMS keys, RBAC with SSO/SAML and SCIM provisioning, break-glass with dual approval, and a named technical account manager with a stated 15-minute incident response SLA. Air-gapped and on-premises deployments are supported for sovereign cloud and defense use cases.

    SDK and Integration Surface

    Kastra publishes SDKs for TypeScript, Python, Go, Rust, Java, and Swift, along with an OpenAI-compatible proxy for drop-in integration with any OpenAI-spec runtime. The platform natively supports Claude Code, Codex CLI, Cursor, OpenClaw browser agents, and custom in-house agent systems. An MCP integration and CLI are also documented. Control plane regions include us-east-1, eu-west-1, and ap-south-1.

    Who It Is Built For

    The platform targets a range of audiences from solo developers (free local enforcement with no account required) to platform teams running thousands of agents and enterprise security teams in regulated industries. The company describes itself as built by engineers, security researchers, and policy practitioners who believe execution governance is a precondition for autonomous AI deployment rather than an afterthought.

    Kastra - 1

    Community Discussions

    Be the first to start a conversation about Kastra

    Share your experience with Kastra, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Free

    Local AI runtime protection for solo developers. Forever free.

    • 1 developer · 1 machine
    • 50K authorization decisions / month
    • 7-day audit retention
    • Claude Code + Codex CLI support
    • Prebuilt safety packs

    Pro

    Professional AI governance for developers governing production AI workflows and advanced runtime behavior.

    $20
    per month
    • 1 developer · 1 machine
    • 1M authorization decisions / month
    • 90-day audit retention
    • Custom policies + versioning
    • Plain-English AI rule generation
    • YAML + UI-based policy management
    • Kastra Recon with auto-drafted policies
    • Kastra Edge on every machine
    • Slack + webhook alerts
    • CSV / JSON audit exports
    • Priority support

    Team

    Centralized runtime governance for engineering organizations deploying AI systems at scale. 3 seat minimum.

    $50
    per month
    • Pooled authorization infrastructure
    • 10M authorization decisions / month
    • Shared audit infrastructure
    • 1-year+ audit retention
    • Centralized policy management
    • Admin-enforced policies
    • Mandatory runtime enforcement
    • Cross-machine policy synchronization
    • Fleet-wide audit visibility
    • Team-wide Kastra Recon
    • Fleet-wide Kastra Edge enforcement
    • Usage analytics
    • Team onboarding + fast support

    Enterprise

    Enterprise runtime governance platform for organizations deploying autonomous AI systems across regulated and production-critical infrastructure.

    Custom
    contact sales
    • Unlimited authorization scale
    • Multi-region deployments
    • Self-hosted + private cloud
    • Advanced RBAC, SSO / SAML
    • Dedicated VPC infrastructure
    • Compliance + extended retention
    • Enterprise SLAs + incident response
    • Dedicated runtime governance architecture reviews
    • Custom Kastra Recon deployments
    • Custom Kastra Edge fleet rollouts
    • Custom integrations + regulatory support
    View official pricing

    Capabilities

    Key Features

    • Runtime authorization — allow/deny AI actions before execution
    • Sub-millisecond policy decisions (p99 < 1ms)
    • Policy Engine with typed, versioned DSL
    • Kastra Edge — local enforcement daemon for developer laptops (macOS app + CLI)
    • Kastra Recon — scan AI history and auto-draft policies before enforcing
    • Shadow mode for risk-free rollout and policy validation
    • OpenClaw browser agent integration — intercepts clicks, form fills, and navigation
    • Autonomous agent controls with human-approval checkpoints
    • Post-inference validation of model output
    • Signed, append-only audit trail (ed25519)
    • SIEM streaming to Datadog, Splunk, and S3
    • Multi-region control plane (us-east-1, eu-west-1, ap-south-1)
    • Cloud, self-hosted, and air-gapped deployment topologies
    • SDKs for TypeScript, Python, Go, Rust, Java, and Swift
    • OpenAI-compatible proxy for drop-in integration
    • MCP integration
    • RBAC, SSO/SAML, and SCIM provisioning (enterprise)
    • Customer-managed KMS keys (enterprise)
    • SOC 2 Type II, HIPAA BAA, GDPR EU residency, EU AI Act Article 9 mapping
    • Plain-English AI rule generation
    • YAML and UI-based policy management
    • Fleet-wide policy synchronization and audit visibility
    • Slack and webhook alerts

    Integrations

    Claude Code
    Codex CLI
    Cursor
    OpenClaw
    OpenAI-compatible runtimes
    Datadog
    Splunk
    S3
    Slack
    SAML/OIDC SSO
    SCIM
    Custom KMS
    API Available
    View Docs

    Ratings & Reviews

    No ratings yet

    Be the first to rate Kastra and help others make informed decisions.

    Developer

    Kastra Labs Inc.

    Kastra Labs builds runtime authorization infrastructure for AI systems, letting teams govern what every agent, model, and tool is allowed to do before actions execute. Founded by engineers, security researchers, and policy practitioners, the company operates remote-first across twelve time zones with documentation-first engineering practices. Kastra Labs targets regulated industries including finance, healthcare, government, and defense, and designs its platform to satisfy compliance frameworks such as SOC 2, HIPAA, GDPR, and the EU AI Act.

    Founded 2025
    Newark
    15 employees
    Read more about Kastra Labs Inc.
    Website
    1 tool in directory

    Similar Tools

    OpenBox AI icon

    OpenBox AI

    Enterprise AI Trust Platform providing runtime enforcement of identity, authorization, policy, and risk across every agent action and cross-system interaction.

    KYE Protocol icon

    KYE Protocol

    An open standard (Apache 2.0) that turns every AI-agent and automation action into signed, replayable evidence a regulator, auditor, or court can verify with public keys alone.

    Oasis Security icon

    Oasis Security

    Agentic Access Management platform that secures AI agents and non-human identities across cloud, SaaS, and on-prem environments.

    Browse all tools

    Related Topics

    Access Control

    AI-enhanced tools for managing authentication and authorization.

    26 tools

    Autonomous Systems

    AI agents that can perform complex tasks with minimal human guidance.

    347 tools

    Compliance and Governance

    AI-enhanced tools for ensuring regulatory compliance and project governance with automated monitoring, risk assessment, and policy enforcement across projects.

    63 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions