DocsSign inInstall Kastel
Solutions · Defence

Your company's knowledge,on a network you control.

Equipment makers, subcontractors, design offices: your value lives in knowledge you cannot pour into an AI service hosted outside your control. Kastel structures that knowledge - processes, responsibilities, programme memory, each prime contractor's requirements - and exposes it to the AI you choose, under access rules you set. The complete core is free, self-hosted, on your own infrastructure.

Request a demoSee the security posture
01

Knowledge that is precious, scattered, and forbidden to leave

In a company that works for defence, organisational knowledge is both the most valuable asset and the most constrained one: it cannot circulate just anywhere, and nobody structures it.

It is scattered, and it leaves with people

Processes, quality trade-offs, programme memory, each prime contractor's specific requirements: this knowledge lives in scattered documents and in the heads of engineers heading for retirement. Nothing structures it, nothing records who is allowed to see it.

A generic AI does not know your constraints

Without your company's context, an AI model answers beside the point, retries, escalates. The real cost is not the subscription price: it is the cost per useful result, and a wrong answer given with confidence costs more than no answer at all.

Pouring it into a third-party service is not an option

Your security officer, your CISO and your prime contractors' clauses all say the same thing: this knowledge does not go into an AI service hosted outside your control, without provable access rules or traceability.

Kastel's answer is a deployment architecture: self-host, on the infrastructure you already operate, with access control enforced at the database and traceability you can show.

02

The perimeter, stated before anything else

You know how to read a security promise. So here, before any argument, is what Kastel is not and does not claim to be.

No defence clearance

Neither Kastel nor Pharos EURL, the company that publishes it, holds any clearance under the French national defence secrecy regime, and no application is under way.

No classified information

Kastel does not handle classified information and is not accredited to handle information bearing the French Diffusion Restreinte protective marking. Its perimeter is your company's non-classified organisational knowledge.

No qualification, no certification

Kastel holds no SecNumCloud qualification, no ISO 27001, no SOC 2. No independent audit or third-party penetration test has been performed to date. What Kastel can show instead is in section 05.

The actual perimeter

Your company's organisation: its documented processes, its responsibilities, its decision memory, the requirements of each contract. You choose what enters your Kastel, and that perimeter stays under your access control.

With that frame set, what remains is the subject nobody takes care of: the mass of non-classified knowledge that runs your company, that your teams search for every day, and that no AI can use properly as long as it is neither structured nor governed.

03

The deployment, not the subscription

For a company of the defence industrial base, Kastel is first of all an architecture.

Self-hosted, on your infrastructure

Kastel runs on the network your company already operates. The complete core is free, without feature gating, without network licence checks, without expiry. No traffic to any Kastel infrastructure by default, telemetry disabled by default: this is verifiable by watching the network.

Exposed over MCP, to the model of your choice

Once structured, your context plugs into the AI you choose through a standard socket - including a model running on your own infrastructure, with no outbound call to any inference provider. That fully local configuration is a deployment choice that belongs to you.

Your own keys

Inference runs on your company's keys, with the provider you selected. Kastel never resells inference, takes no margin on it, and trains no model on your data.

You decide what each AI is allowed to see

A destination policy per sensitivity class refuses, fail-closed, to send content categorised as sensitive to a provider whose declared posture is insufficient. The refusal is sealed in the audit chain.

Under the hood, the content of your Kastel is versioned text: export is total, at any time, in a format published under Apache-2.0, readable without any Kastel tooling.

04

The objections, taken head-on

What a CISO or a security officer asks before going any further - in the order the questions actually come.

  1. 01

    “Are you cleared? Can you handle classified material?”

    No, and no. No clearance, no accreditation, no application under way, and this page tells you so rather than letting you find out. Kastel's perimeter is non-classified organisational knowledge, without protective markings. Whatever falls under national defence secrecy stays in your accredited systems, outside Kastel.

  2. 02

    “We handle Diffusion Restreinte. Can your tool host it?”

    Not as it stands. An information system handling material bearing the Diffusion Restreinte protective marking undergoes a formal accreditation process, and Kastel has been evaluated by no one for that purpose. Accreditation is a decision your authority takes about your system: it would be your process, not a Kastel promise, and we do not claim the product would satisfy it. A Kastel deployment lives outside that perimeter.

  3. 03

    “Can our data stay on our network?”

    Yes. Self-hosted, the context layer lives entirely on your infrastructure. No traffic to any Kastel infrastructure by default, telemetry disabled by default, which you can verify by watching the network. As soon as an external model is plugged in, what you send for inference reaches that provider, on your own keys: that has to be said. The only configuration with no inference leaving at all is the one where the model runs on your own infrastructure, and that is a configuration you choose.

  4. 04

    “We export under licence. What stops controlled information from reaching an AI provider outside the European Union?”

    A destination policy per sensitivity class: content categorised as sensitive in your Kastel is not sent to a provider whose declared posture is insufficient, and the refusal is fail-closed and sealed in the audit chain. It is a tool for enforcing your policy, never a guarantee of export compliance: qualifying what is controlled and deciding what may go where remains your compliance officer's job.

  5. 05

    “Our prime contractor assesses our cyber maturity. What do you bring to that file?”

    Material elements about how your information circulates: access control enforced at the database on every read path, revocable per-consumer tokens, a sealed audit chain, a pre-filled security questionnaire, a hardening guide for your operator. Kastel is not labelled and does not do your compliance work: it gives you documented answers to the questions about who has access to what, who approved what, and what trace remains.

  6. 06

    “Could a subcontractor or a temp see what they should not?”

    The access filter is enforced at the database, on every read path, including those of AI agents. A refusal is indistinguishable from a resource that does not exist: the absence of information cannot be inferred from an error message. Access tokens are issued per consumer and revocable one by one.

  7. 07

    “Part of our site is a restricted-access area (zone à régime restrictif).”

    Deployment happens outside that area's perimeter, for your company's general organisational knowledge. Integrating a tool into the information system of a zone à régime restrictif is a matter for your own protection procedures, which you know better than we do: we do not ask for it, and we have no accreditation file to contribute to it.

  8. 08

    “What happens if you disappear?”

    Your data survives: total export at any time, text readable without any Kastel tooling, format published under Apache-2.0. Self-hosted, your instance keeps running with no network link to Kastel, which you can observe. The live system, however, is not guaranteed: no escrow deposit has been made to date, and no continuity plan is written. That is a real weak point, and we say it as it is.

05

What you can show your auditor

Not labels: mechanisms verifiable on your own instance, by your CISO or your security officer.

Access control at the database, on every read path

Including those of AI agents. A refusal is byte-for-byte indistinguishable from a resource that does not exist.

Sealed audit chain

Every governed action is recorded there and re-verified on every read. A break would be disclosed, never hidden.

Fail-closed destination policy

Content categorised as sensitive in your Kastel is not sent to an AI provider whose declared posture is insufficient: the refusal is fail-closed. The categorisation is your policy, enforced by the system, and the refusal itself is sealed in the audit chain.

A file that states its own gaps

A pre-filled security questionnaire, a hardening guide for the operator, a signed release manifest verifiable without Kastel tooling. Each says what exists and what is missing, so your security review starts from the facts.

Read the security posture
06

Sovereignty and reversibility

The ownership question, last - after the architectural answer has been heard.

Content exportable, at any time

The content of your Kastel is versioned text, in a format published under Apache-2.0, and it reads without any Kastel tooling.

Standard MCP interface

The protocol AIs plug into is open. Changing AI provider rebuilds nothing.

The complete core, free, forever

It deploys self-hosted, without feature gating, without a size cap, without network licence checks.

An asset you put on file

Structural access control, sealed logging and self-hosting are material elements your company can add to the file of its protective measures. Assessing their weight is your counsel's call.

What is not yet true

No escrow deposit has been made to date: a programme is being put in place. No business continuity plan is written. Content is not encrypted at the application level at rest: disk and backup encryption is your operator's responsibility. These are real weak points, not details: we say them as they are.

Kastel is not exempt from its own rule: total export at any time, free self-host for life. Proof, not promise.

See the plans

Let's build your fortress.

The complete core is free, self-hosted, on your network. If your company wants support deploying it, let's talk.

Request a demoSee pricing

Prefer to be guided? Our partner integrators will take it from here.