This knowledge is scattered, and it cannot go just anywhere.
Department organisation, care pathways, quality procedures, who decides what, meeting minutes: this knowledge exists, but it lives in office tools, not in a system an AI can reliably consult.
This knowledge is scattered and never structured
Department organisation, care pathways, quality procedures, meeting minutes: scattered across office tools, with no structure an AI can reliably consult.
An AI service hosted outside your control cannot receive it
For a healthcare institution, pouring this knowledge into a third-party service hosted elsewhere is not an option a CISO or IT director can sign off on without a prior architectural answer.
The question is settled before the demo
"Where does the data live" is the first question asked, not the last. A vendor with no architectural answer to it loses the meeting before the product is even shown.
Kastel's answer is a deployment architecture, not a label or a certification: self-hosted, on the infrastructure your institution already operates.
The deployment, not the subscription
For a healthcare institution, Kastel is first an architecture, before it is a commercial offer.
Self-hosted, on your infrastructure
Kastel runs on the infrastructure your institution already operates, or that of its hosting provider. The complete core is free, with no restrictions.
Exposed over MCP, to the model you choose
Once structured, your context plugs into the AI you choose - Claude, another provider, or a model running on your own infrastructure - through a standard socket.
Your own keys
Inference runs on your institution's own keys, with the provider you pick. Kastel never resells inference and takes no margin on it.
This is not the patient record
What Kastel structures is your institution's organisation: its departments, its pathways, its procedures, its decision memory. It is the perimeter you choose to connect that determines whether health-data rules apply.
Under the hood, your Kastel's content is versioned markdown: export is total, at any time, in a format published under Apache-2.0.
The objections, met head-on
What a CISO, an IT director or a DPO asks before going further - in the order the question actually comes up.
- 01
"Are you HDS certified?"
No. Kastel holds no HDS certification - neither Pharos EURL, the entity that publishes Kastel, nor a service operated by Kastel. Self-hosted, on your institution's infrastructure, there is no hosting on behalf of a third party: no certification requirement is triggered by Kastel.
- 02
"Where does our data live?"
On the infrastructure you operate. Your Kastel's content is versioned markdown; the accompanying database holds only the search index, which is rebuildable, and governance state.
- 03
"Does the AI model see our data?"
Yes, and it needs to be said. Kastel runs on BYOK: you plug in your own keys, and what you send for inference does reach the chosen provider, under that provider's policy. A declarative registry of each provider's posture, and a destination policy by sensitivity class, refuse - fail-closed - to send confidential content to a provider whose posture is insufficient, and the refusal is sealed into the audit chain.
- 04
"Who is allowed to see what, and how do you prove it?"
The access filter is enforced in the database, on every read path, including agents'. A denial is indistinguishable from a resource that does not exist. Every governed request seals a replayable trace.
- 05
"What happens if you shut down?"
The data survives: total export at any time, a format published under Apache-2.0, content in markdown readable without any Kastel tool. The live system, on the other hand, does not survive the same way: to date, no escrow deposit has been made, and no continuity plan is written. That is a real weakness, and we say so plainly.
- 06
"Can you prove an erasure?"
Yes, through a replayable proof on your own instance: ingest a marker, erase it, reindex, demonstrate it cannot be found. Four limits are systematically disclosed: the versioned history, backups held by the operator, the source system, and the inference provider that has already seen the content.
What you can prove to your auditor
Not promises: replayable proofs your DPO or your CISO can verify themselves.
Access control enforced in the database, on every read path
Including agents'. A denial is byte-for-byte indistinguishable from a resource that does not exist.
Sealed audit chain
Every governed action is traced there, re-verified on every read. A break would be disclosed, never hidden.
Demonstrable erasure
Replayable proof by your DPO, on your own instance, with its four disclosed limits (previous section).
GDPR compliance kit
Deployer-institution data processing agreement template, processing register, staff notice, personal-data screening procedure, erasure procedure - each one meant to be reviewed by your own counsel.
Sovereignty and reversibility
The question of ownership, last - after the architectural answer has been heard.
Exportable content, at any time
Versioned markdown, in a format published under Apache-2.0, readable without any Kastel tool.
Standard MCP interface
The protocol AIs plug into is open. Switching AI provider rebuilds nothing.
The complete core, free, forever
Self-hosted, with no restrictions, no size cap.
What is not yet true
No escrow deposit has been made to date: a program is being put in place. No business continuity plan is written. These are real weaknesses, not details: we say so plainly.
Kastel is not exempt from its own rule: total export at any time, free self-host for life. Proof, not promise.
See Kastel EnterpriseLet's build your fortress.
The complete core is free when self-hosted. If your institution wants help deploying it, let's talk.
Prefer to be guided? Our partner integrators will take it from here.