Runtime enforcement
Put policy in the path of prompts, responses, model calls, and tool actions before consequence.
- Policy management
- Permission matrix
- Shadow mode
- Control simulator
Enterprise AI governance and runtime control
Kestrel evaluates identity, context, and policy before an AI request, response, or tool action can create impact, then preserves the evidence behind the decision.
ONE CONTINUOUS CONTROL PATH
Incoming operation
Principal resolved
Kestrel resolves the organisation, workspace, workload identity, AI system, and intended operation before policy evaluation begins.
CONTROL BEFORE CONSEQUENCE
Define and manage security policies to block or allow AI interactions
0Deny harmful instructionsHarm preventionBlocks high-risk real-world harm requests before execution.v1intent in harmful_instruction, violent_harmdenyenforceAll agents0Deny high threatHarm preventionStops interactions above the approved threat threshold.v1threat_score gt 0.70denyenforceAll agents1Block code executionPrevents agents from executing unapproved code.v1intent eq execute_codedenyenforceRuntime agents2Block non-admin escalationTool authorizationRequires administrator authority for privileged operations.v1intent in admin_access, config_changeagent_role neq admindenyenforceAll agents3Review restricted data accessRoutes restricted-data requests through a governed review path.v2data_label eq restrictedreviewshadowData agents4Block reader data exportStops reader-role agents from exporting organisational data.v1intent eq data_exportagent_role eq readerdenyenforceReader rolePut policy in the path of prompts, responses, model calls, and tool actions before consequence.
Maintain an accountable operating record of the agents, models, systems, owners, and workflows in use.
Make authority explicit across organisations, workspaces, departments, roles, owners, and delegated decisions.
Test whether controls continue to work as models, prompts, data, tools, and operating conditions change.
Give technical operators and accountable leaders a connected view of exposure, decisions, and evidence integrity.
Organisation and workspace scope stays explicit throughout authenticated data paths.
Role, scope, and permission are evaluated instead of inherited through ambient trust.
Uncertainty can be held for accountable review instead of becoming silent permission.
Material decisions stay linked to source context, policy version, and responsible actor.
A time-bound evaluation in a real operating environment.
Ongoing governance and runtime control for production AI.
Contracted terms for large-scale production estates.
Prices are stated in USD and exclude applicable taxes. Usage, billing cadence, and final fees are subject to the applicable order form.
EU and EEA availability: Kestrel is not currently available for deployment in the European Union or European Economic Area while applicable EU AI Act requirements are being addressed.
CONTROL BEFORE CONSEQUENCE