Your institution's knowledge is scattered, and not everyone is allowed to see it.
Credit procedures, validation workflows, delegations of authority, committee memory: this knowledge exists, but it lives in office tools, with access rules that nothing enforces on the AI side.
A bare AI does not know your institution
Without context, a model knows neither your procedures, your vocabulary nor your delegations. It answers off the mark, with confidence - and an AI that answers wrong with confidence is worse than no AI at all.
Information sharing is regulated internally
A credit committee note, a claims file and market data do not share the same audience. An AI tool that does not enforce those rules on every read path will not pass your permanent control.
Every added vendor must be supervisable and replaceable
Since January 2025, DORA requires your institution to record its IT vendors in a register, to frame them contractually and, for critical or important functions, to know how to exit them. An AI vendor unable to answer those questions cleanly wastes your time.
Kastel's answer: a structured, governed context that makes the AI competent on your real cases - built by a vendor designed, from the architecture up, to be supervised and replaced.
Built to fit inside your regulatory frame
DORA applies to your institution, not to your software. Kastel will never call itself "DORA compliant": it provides precise, verifiable answers that you file into your own dossier.
Self-hosted: the processing locations are yours
Kastel's complete core is free when self-hosted, on the infrastructure your institution operates. Your team runs the instance: the information-register answer fits on one line, and the operational dependency on the vendor largely disappears from the picture.
Managed: an isolated instance, in Europe, with a named host
In managed mode, Kastel operates one isolated instance per client, on Kubernetes, hosted at Scaleway SAS, fr-par region (France). Honest disclosure: the service's control plane (accounts, billing, console) is shared and hardened; only the engine and each client's context are isolated.
Your own AI keys
Inference runs on your institution's own keys, with the provider you pick - or on a model running on your own infrastructure. Kastel never resells inference and takes no margin on it. You decide what each AI is allowed to see.
For a regulated account, the paid plan is Kastel Enterprise
Self-hosted or managed. The core itself stays free, complete and without a size cap, for everyone - including a regulated entity that wants to start by evaluating the architecture on its own infrastructure.
Under the hood, your Kastel's content is versioned markdown: export is total, at any time, in a format published under Apache-2.0, readable without any Kastel tool.
Your risk department's questions, met head-on
What a risk department, a CISO or a permanent-control team asks before going further - with the exact answers, including the ones that do not flatter us.
- 01
"How do I record you in my information register?"
With short answers. The legal entity is Pharos EURL, France. The service is a context layer exposed over MCP. Self-hosted, the processing locations are yours and there is no subcontracting on our side. Managed, the host is Scaleway SAS, fr-par region (France), and the inference providers are the ones you choose.
- 02
"What is your exit strategy?"
The strongest answer in the file. Total export at any time, content in markdown readable without any Kastel tool, an export format published under the Apache-2.0 licence, a standard MCP interface: the AIs you have plugged in survive a change of vendor. In managed mode, destruction is never finalised without verifying a checksum of the export.
- 03
"Who is allowed to see what, and how do you prove it?"
The access filter is enforced in the database, on every read path, including AI agents'. A denial is indistinguishable from a resource that does not exist, and every governed request seals a replayable trace your permanent control can verify.
- 04
"Do your AIs train on our data?"
Kastel trains no model. What you send for inference reaches the provider you chose, under your keys and under that provider's policy. Kastel keeps a declarative registry of what each provider publishes about retention and training, and a destination policy refuses - fail-closed - to send confidential content to an insufficient posture. That registry guarantees nothing on the provider's behalf: for a regulated dossier, attach the agreements you have signed with them.
- 05
"I have a contractual audit right. What do I audit?"
A defined perimeter, identical for everyone: the specifications, the invariant test suites, and a black-box penetration test on your own instance. The engine's source code is never shown, including under NDA. That is a deliberate trade-off, not a negotiating position.
- 06
"Do you have ISO 27001, SOC 2, a third-party pentest?"
None of the three, and we would rather say so before you ask. What exists: a pre-filled security questionnaire where every positive answer cites its evidence and every gap is written as such, invariants tested in continuous integration, a signed release manifest verifiable without Kastel tooling, and a hardening guide for the operator.
- 07
"What if you disappear?"
The data survives: total export, published format, markdown readable anywhere. The live system does not survive the same way: no escrow deposit has been made to date - a program is being put in place - and no continuity plan is written. A self-hosted instance, however, keeps running with no network link to Kastel at all: that is the real mitigation we offer.
What your permanent control can verify itself
Not commitments on paper: mechanisms your teams can test on your own instance.
Access control enforced in the database, on every read path
Including agents'. A denial is byte-for-byte indistinguishable from a resource that does not exist.
Sealed audit chain
Every governed action is traced there, re-verified on every read. A break would be disclosed, never hidden. The audit trail you can rely on in front of an auditor is this chain.
Fail-closed destination policy
Confidential content never leaves for an AI provider whose declared posture is insufficient: the send is refused, and the refusal is sealed into the audit chain.
Security log exportable to your tools
A signed feed into your security event management system, without one byte of business content, disabled by default: you switch it on, you control it.
Sovereignty and reversibility
The dependency question, last - after the register and audit answers have been heard.
Exportable content, at any time
Versioned markdown, in a format published under Apache-2.0, readable without any Kastel tool.
Standard MCP interface
The protocol AIs plug into is open. Switching AI provider rebuilds nothing, and reading your data back requires no proprietary tool.
The complete core, free, forever
Self-hosted, with no restrictions, no size cap.
What is not yet true
Kastel holds no certification: no ISO 27001, no SOC 2, no third-party pentest. No escrow deposit has been made to date - a program is being put in place - and no business continuity plan is written. These are real weaknesses, not details: we say so plainly.
Kastel is not exempt from its own rule: total export at any time, free self-host for life. Proof, not promise.
See Kastel EnterpriseLet's build your fortress.
The complete core is free when self-hosted. If your institution wants to evaluate Kastel against its own requirements - register, clauses, exit strategy - let's talk.
Prefer to be guided? Our partner integrators will take it from here.