DocumentationSecurity review

Evaluate Kastra for your security program

A CISO's guide to the controls, evidence, and operating decisions needed to evaluate Kastra.

Updated 2026-09-22 Read as Markdown
On this page

The decision Kastra helps you make

Kastra gives security and engineering teams a shared way to decide which connected AI actions may proceed, which must stop, and which need human approval. Policies apply at supported integration points, and recorded decisions connect the action to its policy and outcome.

For a first evaluation, choose one action with a clear business consequence: changing deployment configuration, invoking a write-capable MCP tool, or dispatching a model-generated application command. Agree on the boundary before expanding to more agents or teams.

Start with these six questions

Security review questionWhat to inspectRead next
Where can Kastra stop an action?The integration, pre-action check, and paths that bypass itArchitecture and coverage
What data reaches Kastra and other services?Payloads, credentials, masking, retention, and analysis pathsData protection review
Who can change policy or approve an action?Workspace roles, credential scope, and approver identityAccess and responsibilities
What happens when a dependency fails?The actual client and server behavior, including non-enforcementOperations and incident response
How will we know the pilot worked?Observed execution results, review effort, and evidence qualityPilot acceptance plan
What supports the vendor security review?SOC 2 assurance, GDPR documentation, and deployment scopeAssurance and Trust Center

Separate three kinds of evidence

Vendor assurance helps assess Kastra as a supplier. Start with the Kastra Trust Center for SOC 2 and GDPR review material and its stated scope.

Product evidence shows how a connected action was evaluated and resolved. Inspect the policy revision, decision, approval history, and verification scope.

Your evaluation results establish whether the integration and operating model meet your requirements. Record the exact agent, platform, configuration, and failure cases tested. These results are the basis for a rollout decision.

A useful outcome from the first review

Leave with a named control owner, one agreed integration boundary, a data-handling decision, a tested failure posture, and a pilot acceptance plan. Kastra’s value is a repeatable permission decision at the point of action, supported by evidence your team can inspect.

Plan a pilot · Review the Trust Center · Discuss your security requirements