Kastra

Kastra

A permission gate that sits in front of your AI coding agent and blocks it from running a dangerous command or deleting a file before it happens — instead of hoping the agent behaves.

🔗 Visit Kastra
📁 Security & Privacy🗣️ English

Description

Letting an AI agent run shell commands, hit APIs, or query a database on its own is powerful and a little terrifying — one bad instruction and it can do real damage before anyone notices. Kastra is built to close that gap: it sits between the agent and the outside world, checking every action against a policy in under a millisecond, and can revoke access instantly if something looks wrong.

Kastra is a runtime authorization layer for agents built on Claude, Cursor, Codex and OpenClaw, providing policy decision points, signed append-only audit trails, and both cloud and self-hosted (including air-gapped) deployment. It supports SDKs across TypeScript, Python, Go, Rust, Java and Swift, and controls shell commands, API requests, database queries and browser actions specifically — not just a generic firewall. It's SOC 2 Type II, ISO 27001, HIPAA and GDPR compliant, aimed squarely at teams running agents in regulated or production environments.

💬 Our review

The short version: if you're letting AI coding agents touch production systems and haven't thought about what stops them from doing something catastrophic, Kastra is the missing safety layer, not an optional nice-to-have.

The sub-millisecond policy decision claim (p99 <0.8ms) is the right design goal — a permission layer that adds noticeable latency to every agent action would get bypassed or disabled in practice, so speed here isn't a vanity metric. Compliance certifications (SOC 2, HIPAA) matter because this is exactly the kind of tool a security or compliance team needs to sign off on before agents touch anything real. The free tier (50K decisions/month) is generous enough to actually evaluate it on a real project, not just a toy demo. The honest caveat: this is a young, unproven category — "agent governance" barely existed a year ago, so there's no long track record, and pricing per developer seat ($19.99–$49.99) can add up fast for larger teams running many agents in parallel.

💰 Pricing

FreemiumGratuit 50K décisions/mois, puis par développeur

📊 Global score

45Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile75/100Bien

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Freemium

Gratuit (50K décisions/mois) ; Pro 19,99$/dev/mois (1M décisions) ; Team 49,99$/dev/mois (10M décisions) ; Enterprise sur devis

👥 Target audienceÉquipes dev/plateforme qui déploient des agents IA (Claude, Cursor, Codex) avec accès à des systèmes de production
🗣️ Languagesen
🌍 Target countriesMonde
👍

Pros

Décisions sub-milliseconde, n'ajoute pas de latence perceptible

SOC 2/ISO 27001/HIPAA/GDPR

SDK multi-langages

Déploiement air-gap possible

👎

Cons

Catégorie très jeune, peu de recul terrain

Prix par développeur peut grimper vite en équipe nombreuse

Pas de clients nommés publiquement

❓ Frequently asked questions

What is Kastra in one sentence?
Which agent frameworks does it support?
Does it slow down my agent?
Can I self-host it?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?