It should live with you. The AI model can be rented; the company’s memory has to be owned. Owning means three things you can verify: being able to host it on your own infrastructure, being able to export it in full at any time in an open format, and deciding what each AI is allowed to see.
A dependence nobody signed up for
Every day, your organisation teaches its trade to an intelligence hosted somewhere else. A salesperson explains how you sell, a lawyer has it review your standard contracts, an executive runs decisions past it. The provider hosting that intelligence can cut off access, change the prices or shut the service down whenever it chooses.
Nobody signed up for this. No board ever approved the decision to deposit the company’s knowledge with a third party that commits to nothing. It happened one use at a time, because every use taken on its own was reasonable. That is how digital dependence settles in, without a single decision ever having been made.
The model is rented, the memory is owned
The right answer is not to give up hosted AIs. The best models change regularly, and running them yourself costs a great deal for a result that is often worse. Renting the model is a sound choice, and one Kastel encourages.
The model and the memory simply do not have the same status. The model is interchangeable: the one you use today will be overtaken, and you will want the freedom to swap it. Your company’s memory is unique and it accumulates: your organisation, your processes, your decisions and their history. If that memory lives with the model’s provider, switching means teaching everything again from scratch, and the provider knows it. That is exactly what makes the dependence so comfortable for them.
What owning means, and what it does not mean
Owning your company’s memory comes down to three concrete gestures you can check. You can host it on your own infrastructure: the Kastel core is free to self-host, with no size limit, operated through the command line and MCP. You can export it in full, at any time, in an open and documented format. And you connect the AIs of your choice with your own keys, which means you decide what each AI is allowed to see, and that you can switch AI providers without rebuilding everything.
Owning your memory does not mean owning the recipe of the engine that structures it. The Kastel engine is proprietary and closed; its interface is open and standard. The protocol, the schema and the export format are public, and that is what matters to you: your ability to leave does not depend on our goodwill. The sovereignty Kastel sells you is the ownership of your data, and it does not rest on reading our code.
What leaves, and what stays
It is worth saying precisely what happens when a connected AI does its work, because this is where a lot of sovereignty talk goes vague. When an AI handles a request, it receives the slice of context it is allowed to read, and that slice does go to the model, on your keys. That is the whole point of the product: an AI cannot reason about what it has not read.
What stays in the fortress is everything else: the structured memory as a whole, its history, and the rules that decide who is allowed to see what. No AI reads more than the slice of the person it works for. Each one receives its slice, defined by context governance, and nothing more. How those rules are enforced and recorded is described in our security posture.
The proof happens on your machine
This page can be verified on your own infrastructure. Install the free core, load a piece of your context into it, connect your own keys, and watch what each AI receives. Then export the whole thing and confirm the result reads without us. Once the product is running, the distinction between company context and a personal AI memory becomes very tangible.
Kastel is not exempt from its own rule: full export at any time, free self-hosting for life. You can check every one of these claims yourself.