Skip to main content

Enterprise AI governance and runtime control

Control AI before it acts.

Kestrel evaluates identity, context, and policy before an AI request, response, or tool action can create impact, then preserves the evidence behind the decision.

ONE CONTINUOUS CONTROL PATH

01Identity02Policy03Enforcement04Evidence

The decision path AI systems run through.

From declared intent to an enforceable outcome and a durable record.

Incoming operation

Agent requests access to restricted supplier data

Source
procurement-agent
Tool
vendor-records.read
Classification
confidential
Requested scope
organisation
01

Principal resolved

Know exactly what is acting.

Kestrel resolves the organisation, workspace, workload identity, AI system, and intended operation before policy evaluation begins.

Live readout
Principal
agent.procurement
Workspace
operations
Purpose
supplier review
OutcomeIDENTITY VERIFIED
Policy boundary activeACTOR + CONTEXT + POLICY + OUTCOME

CONTROL BEFORE CONSEQUENCE

AI can move quickly. Its authority should move deliberately.

See how Kestrel connects governance to operation

The operating picture stays connected to the control.

Explore how Kestrel turns policy into an enforceable decision, then carries the result into evidence, assurance, review, and executive oversight.

Policy Management

Define and manage security policies to block or allow AI interactions

Active0Deny harmful instructionsHarm preventionBlocks high-risk real-world harm requests before execution.v1intent in harmful_instruction, violent_harmdenyenforceAll agents
Active0Deny high threatHarm preventionStops interactions above the approved threat threshold.v1threat_score gt 0.70denyenforceAll agents
Active1Block code executionPrevents agents from executing unapproved code.v1intent eq execute_codedenyenforceRuntime agents
Active2Block non-admin escalationTool authorizationRequires administrator authority for privileged operations.v1intent in admin_access, config_changeagent_role neq admindenyenforceAll agents
Active3Review restricted data accessRoutes restricted-data requests through a governed review path.v2data_label eq restrictedreviewshadowData agents
Active4Block reader data exportStops reader-role agents from exporting organisational data.v1intent eq data_exportagent_role eq readerdenyenforceReader role

The full operating system for governed AI.

From runtime enforcement to executive oversight, Kestrel connects the AI estate, the people accountable for it, and the evidence that proves control.

Runtime enforcement

Put policy in the path of prompts, responses, model calls, and tool actions before consequence.

  • Policy management
  • Permission matrix
  • Shadow mode
  • Control simulator

AI estate governance

Maintain an accountable operating record of the agents, models, systems, owners, and workflows in use.

  • Agent inventory
  • AI model catalogue
  • AI system registry
  • Governance workflows

Accountability and access

Make authority explicit across organisations, workspaces, departments, roles, owners, and delegated decisions.

  • People and organisation access
  • Ownership and authorities
  • Risk acceptance
  • Escalation management

Continuous assurance

Test whether controls continue to work as models, prompts, data, tools, and operating conditions change.

  • Control evidence
  • Broader assurance
  • Behaviour baselines
  • Review queue

Oversight and audit

Give technical operators and accountable leaders a connected view of exposure, decisions, and evidence integrity.

  • Executive oversight
  • Transaction log
  • Evidence verification
  • Decision history

Trust is explicit at every boundary.

Kestrel is designed around constrained authority, isolated scope, and evidence that can withstand review.
Control surfacePrincipleOperating posture
BoundaryTenant isolation

Organisation and workspace scope stays explicit throughout authenticated data paths.

AuthorityLeast privilege

Role, scope, and permission are evaluated instead of inherited through ambient trust.

DecisionFail-safe enforcement

Uncertainty can be held for accountable review instead of becoming silent permission.

RecordEvidence integrity

Material decisions stay linked to source context, policy version, and responsible actor.

Start with a real control problem. Scale from there.

Every plan includes Kestrel's core governance and runtime control capabilities.
01

Pilot

A time-bound evaluation in a real operating environment.

$500per month
Usage
100,000 requests included
Term
Maximum 3 months
All capabilities
02

Production

Ongoing governance and runtime control for production AI.

$2,500per month
Usage
$1.00 per 1K requests
Term
Ongoing
All capabilities
03

Enterprise Volume

Contracted terms for large-scale production estates.

Customannual agreement
Usage
Contracted volume pricing
Term
Annual contract
All capabilities

Prices are stated in USD and exclude applicable taxes. Usage, billing cadence, and final fees are subject to the applicable order form.

EU and EEA availability: Kestrel is not currently available for deployment in the European Union or European Economic Area while applicable EU AI Act requirements are being addressed.

CONTROL BEFORE CONSEQUENCE

Put governance where AI becomes action.

Book a demo