An asset that lives in no system, and retires with people.
Why this setting, why we never do it that way for this customer, how that non-conformity was resolved eight years ago: none of it is written anywhere, and the company knows it.
It leaves with the people who hold it
Decades of settings, resolved non-conformities and quality trade-offs walk out of the company with every retirement. What is not structured does not get passed on.
It cannot go just anywhere
Your competitive edge sits entirely in your processes, and they are, more often than not, unpatented - by choice, since a patent publishes. Pouring that knowledge into an AI service hosted outside your control is not a tooling decision: it is an industrial-property decision.
Its legal protection has to be earned
Trade-secret law only protects your know-how on the condition that you have taken reasonable protection measures. Knowledge that circulates with no access control and no traceability weakens your own position in a dispute.
Kastel's answer: a structured, governed, traceable context, on infrastructure you operate. An asset that can be passed on, and tangible elements for your protection file.
A software layer, on your business IT
For a manufacturer, Kastel is first a deployment architecture, before it is a commercial offer.
Self-hosted, on your infrastructure
Kastel runs on your site's or your group's infrastructure, as containers, with a hardening guide for the operator. No traffic to any Kastel infrastructure by default, telemetry off by default: verifiable by watching the network. The complete core is free, with nothing held back.
Exposed over MCP, to the model of your choice
Once structured, your context plugs into the AI you choose through a standard socket - Claude, another provider, or a model running on your own infrastructure, with no inference traffic leaving at all. That last profile exists because Kastel is model-agnostic: it is a configuration made by your IT department, not an option you buy.
Your own keys
Inference runs on your company's keys, with the provider you selected. Kastel never resells inference and takes no margin on it: the spend stays under your control.
Your business IT, not your PLCs
Kastel structures the company's knowledge: methods, quality, engineering office, industrial management. It does not connect to your programmable controllers or your shop-floor supervision, and nothing in the product belongs to industrial-systems security.
Under the hood, the content of your Kastel is versioned markdown: export is total, at any time, in a format published under Apache-2.0. A managed mode also exists, hosted in Europe on one isolated instance per client, for companies that prefer to operate nothing.
The objections, taken head-on
What an industrial director, a CIO or a CISO asks before going further - in the order the questions actually come.
- 01
"Our routings and processes will not leave the plant?"
Self-hosted, the context layer lives on your infrastructure, with no traffic to any Kastel infrastructure by default - verifiable by watching the network. The moment an external model is plugged in, what you send for inference does reach that provider, under your keys: it has to be said. You decide what each AI is allowed to see, and the only configuration with no inference traffic at all is the one where the model runs on your own infrastructure - it exists, as a configuration made by your IT department.
- 02
"What does your AI provider do with our data?"
Kastel maintains a declarative register of what each provider publishes about retention and training, with its caveats, and a destination policy by sensitivity class: content classified confidential does not go to an insufficient posture, the refusal fails closed and is sealed in the audit chain. The register is declarative: it guarantees nothing on the provider's behalf.
- 03
"Do you train a model on our know-how?"
No. Kastel trains no model, and training is not a Kastel product. It is a clear-cut answer, and one of the few on this page.
- 04
"Could a subcontractor or a temp worker see what they should not?"
The access filter is enforced in the database, on every read path, including those of AI agents. A denial is indistinguishable from a resource that does not exist: the absence of information cannot be deduced from an error message. Access tokens are issued per consumer and revocable.
- 05
"What proves who consulted what?"
A sealed audit chain, re-verified on every read, and any break in it is disclosed. Honest limit: nothing is tamper-proof against the owner of the instance itself - that is the flip side of self-hosting.
- 06
"Do you hold ISO 27001?"
No. Neither ISO 27001, nor SOC 2, nor any certification, nor an independent audit, nor a third-party penetration test to date. What exists: a pre-filled security questionnaire that writes down its own gaps, invariants tested in continuous integration, and a signed release manifest, verifiable without any Kastel tooling.
- 07
"If you shut down, do we lose our company memory?"
Your data, no: total export at any time, markdown readable without any Kastel tool, published format. Self-hosted, the instance keeps running with no network link to Kastel. The live system, though, is a real weak point: no escrow deposit has been made to date - a programme is being put in place - and no continuity plan is written.
Tangible elements for your protection file
Trade-secret law protects your know-how on the condition that you have taken reasonable protection measures. Kastel does not protect your secret for you: it gives you tangible elements you add to your file, and it is for your counsel to assess whether they are sufficient.
Access control enforced in the database
On every read path, including those of AI agents. A denial is byte-for-byte indistinguishable from a resource that does not exist.
Sealed audit chain
Every governed action is recorded in it, re-verified on every read. A break would be disclosed, never hidden.
Destination policy by sensitivity
Content classified confidential never goes to an AI provider whose declared posture is insufficient: the refusal fails closed, sealed in the audit chain.
Employee GDPR kit
Structuring the company's memory touches privacy at work: an employee notice template, a processing register, a private-content filtering procedure, an erasure procedure - each to be reviewed by your counsel.
Sovereignty and reversibility
The ownership question, last - after the architectural answer has been heard.
Content exportable, at any time
Versioned markdown, in a format published under Apache-2.0, readable without any Kastel tool.
Standard MCP interface
The protocol AIs plug into is open. Changing AI provider rebuilds nothing.
The complete core, free, forever
Self-hosted, with nothing held back, no size cap, no network licence check and no expiry.
What is not yet true
No escrow deposit has been made to date: a programme is being put in place. No business continuity plan is written. These are real weak points, not details: we state them as they are.
Kastel is not exempt from its own rule: total export at any time, free self-hosting for life. Proof, not promise.
See Kastel EnterpriseLet's build your fortress.
The complete core is free, self-hosted. If your company wants support deploying it, let's talk.
Prefer to be guided? Our partner integrators will take it from here.