# Evaluate Kastra for your security program

A CISO's guide to the controls, evidence, and operating decisions needed to evaluate Kastra.

Updated: 2026-09-22

Canonical: https://docs.kastra.ai/security/overview

## The decision Kastra helps you make

Kastra gives security and engineering teams a shared way to decide which connected AI actions may proceed, which must stop, and which need human approval. Policies apply at supported integration points, and recorded decisions connect the action to its policy and outcome.

For a first evaluation, choose one action with a clear business consequence: changing deployment configuration, invoking a write-capable MCP tool, or dispatching a model-generated application command. Agree on the boundary before expanding to more agents or teams.

## Start with these six questions

| Security review question | What to inspect | Read next |
| --- | --- | --- |
| Where can Kastra stop an action? | The integration, pre-action check, and paths that bypass it | [Architecture and coverage](https://docs.kastra.ai/security/architecture) |
| What data reaches Kastra and other services? | Payloads, credentials, masking, retention, and analysis paths | [Data protection review](https://docs.kastra.ai/security/data-protection) |
| Who can change policy or approve an action? | Workspace roles, credential scope, and approver identity | [Access and responsibilities](https://docs.kastra.ai/security/access-control) |
| What happens when a dependency fails? | The actual client and server behavior, including non-enforcement | [Operations and incident response](https://docs.kastra.ai/security/operations) |
| How will we know the pilot worked? | Observed execution results, review effort, and evidence quality | [Pilot acceptance plan](https://docs.kastra.ai/security/evaluation) |
| What supports the vendor security review? | SOC 2 assurance, GDPR documentation, and deployment scope | [Assurance and Trust Center](https://docs.kastra.ai/security/assurance) |

## Separate three kinds of evidence

**Vendor assurance** helps assess Kastra as a supplier. Start with the [Kastra Trust Center](https://trust.oneleet.com/kastra) for SOC 2 and GDPR review material and its stated scope.

**Product evidence** shows how a connected action was evaluated and resolved. Inspect the policy revision, decision, approval history, and verification scope.

**Your evaluation results** establish whether the integration and operating model meet your requirements. Record the exact agent, platform, configuration, and failure cases tested. These results are the basis for a rollout decision.

## A useful outcome from the first review

Leave with a named control owner, one agreed integration boundary, a data-handling decision, a tested failure posture, and a pilot acceptance plan. Kastra's value is a repeatable permission decision at the point of action, supported by evidence your team can inspect.

[Plan a pilot](https://docs.kastra.ai/security/evaluation) · [Review the Trust Center](https://trust.oneleet.com/kastra) · [Discuss your security requirements](https://kastra.ai/book-demo)
