Guardrails for AI agent actions

The checkpoint between AI agents and your money, data and systems.

Keystile checks every action an AI agent is about to take and decides: allow, redact, escalate or block. In real time, with a clear reason for every decision and a signed record auditors can trust.

Example · agent actions checked by Keystile

Pay invoice #2231, $1,240

Known vendor, normal amount

ALLOW
Send $40,000 to new payee

New payee, far above normal, after hours

ESCALATE
Email client statement to outside address

Account numbers removed before sending

REDACT
Wipe 2,000 managed devices

Brand-new admin, never-seen action, at 5 a.m.

BLOCK
35 / 35attacks stopped before they ran, in an outside test
94%+AUROC on every task tested
On-premclient data stays inside your walls
Patentpending since early 2026

Demo · 4 minutes

Watch Keystile stop a hijacked AI agent.

See it live in the console · 1:23 · real agents, a payment you reject with one click, and the signed record afterwards

Test report · October 2026

35 of 35 attacks stopped before they ran.

We ran Keystile against a public set of 56 test cases written by an outside open-source project: 35 attacks, 16 harmless actions and 5 borderline ones. Every attack was blocked or held for a person before it could run. One harmless action was held for a person; none was blocked.

25attacks blocked or masked outright
10attacks held for a person to decide
0attacks let through
15 / 16harmless actions let through, none blocked
What the test triedCasesBlocked or maskedHeld for a personLet through
Sending private data or files out10910
Destroying data, systems or access7070
Hidden instructions in an agent's request4310
Stealing passwords and keys3210
Hidden instructions in what a tool returns6600
Secrets in what a tool returns (masked)3300
Attacks hidden deep in very long text2200
All attacks3525100
Other casesCasesResult
Harmless actions and tool outputs1615 let through, 1 held for a person (an invoice email), none blocked
Borderline cases52 held for a person, 2 blocked, 1 masked
Tool descriptions with hidden instructions32 flagged, 1 missed
Harmless tool descriptions22 let through
Speed per check56Median 0.8 seconds, 95% under 4.7 seconds, on the default Balanced setting

Run on 5 October 2026 with Keystile's built-in rule packs and default settings, on our own decision model. We used this test set while building Keystile's checks, so we are now running a fresh set we have never seen; we will publish those results here too. Full case-by-case results are available to design partners.

The problem

AI agents now hold real keys. Nothing independent checks what they do with them.

On 11 March 2026 an attacker used one compromised admin account and a normal device-management command to wipe about 80,000 devices at Stryker in three hours. No malware. Every command was authorized. Now picture the same access in the hands of an AI agent, steered by a prompt injection instead of a stolen password.

Step 1

One admin account compromised

Step 2

New global admin created

05:00–08:00 UTC

Normal wipe command, at scale

Result

~80,000 devices erased

Agents are everywhere

Always-on agents from OpenAI, Microsoft, Google and Salesforce now act with their own credentials. Gartner expects 15% of day-to-day work decisions to be made by agents by 2028.

Today's checks miss it

Antivirus sees no malware. Access control sees valid credentials. Per-action rules see a normal command. The danger is in the pattern.

Regulators want proof

Financial firms must show which model decided, that it was not altered, and why. New SEC breach rules for advisers add a 30-day clock.

Sources: BleepingComputer · Gartner via WFTV · TechCrunch

Try it yourself

Pick what an AI agent is about to do.

Each scenario shows the action the agent submits, Keystile's checks, and the verdict it returned.

Sample scenarios. Verdicts, confidence and decision times were recorded from Keystile in October 2026.

How you use it

Connect it once. Write rules in plain English. Every agent action gets checked.

01 · CONNECT

Sit in front of your agents

Keystile goes between your AI agents and the tools they use: payments, email, client data, admin consoles. One line in Python, LangChain or the OpenAI Agents SDK; one setting for MCP; one command for Claude Code, Cursor or Hermes Agent; or the API from any language.

02 · SET RULES

Say it in plain English

"Payments over $10k to a new payee need a human." "Client account numbers never leave the firm."

03 · DECIDE

Allow, redact, escalate or block

Each action gets a verdict in real time, with the reason. Anything high-stakes waits for a person.

04 · PROVE

A signed record of every decision

Compliance and auditors see what was checked, what was decided and why.

Products

Start with a no-install pilot. Grow into live protection.

Available now

Keystile Replay

Send us a few weeks of agent or AI-tool logs and your rules. We show you every action Keystile would have escalated or blocked, and why. Nothing to install.

Available for pilots

Keystile Gateway

Live, real-time protection in front of every agent, on your own servers or run by us in your cloud. Blocks data leaks, prompt-injection exfiltration and abnormal agent behavior. PATENT PENDING

Coming later

Keystile Box and Key

The same protection on dedicated hardware the protected systems cannot modify: an inline box for on-prem systems of record, and a USB key for financial advisers. PATENT PENDING

For developers

No server to run. An address, a key, and one line.

Your admin runs Keystile on your own servers, or we run it for you. Developers get two settings and connect the same way, whichever it is.

# KEYSTILE_URL and KEYSTILE_API_KEY come from your admin from keystile.client import KeystileClient, guard ks = KeystileClient() @guard(ks, agent_id="payments-agent") # checked before every call def send_payment(payee: str, amount: float): ...
Python SDK and API · 1:45 · one line per tool, spending limits, approvals, LangChain and OpenAI Agents SDK, REST
MCP, Claude Code and Hermes Agent · 1:32 · no code changes

Self-hosted

Your IT team runs the Keystile server on your own servers or cloud account, under a license. Client data never leaves you.

Managed

We run Keystile for you, inside your own cloud account. Client data still never leaves you.

Keystile Cloud

We host it for you. Available on request for teams that prefer it.

Plans

Priced per protected agent. Start free.

Developer

Free

To try it

  • On our Keystile sandbox
  • 2 agents, test data only
  • Every integration

Team

$500 a month

IT teams, university departments, startups

  • 10 agents
  • 250,000 checks a month
  • Console, approvals, signed record, alerts

Business

$2,000 a month

Mid-size companies and fintechs

  • 50 agents
  • 2 million checks a month
  • Named approvers, audit export, support

Enterprise

From $50k a year

Banks, hospitals, large universities

  • Unlimited agents
  • Fully offline option, custom rules
  • Our model tuned on your data, SLA

Paid plans run on your own servers under a license agreement, managed by us in your cloud, or on Keystile Cloud. Claude Code and Cursor protection: $10 per developer a month. Managed (we run it in your cloud): +$750 a month. Education and nonprofits: 40% off. Design partners: free for 90 days.

Who it's for

For IT teams, financial firms and any company that lets AI agents act.

IT teams first

Universities and growing companies, where AI agents already run computers, accounts and help desks every day.

Financial firms

Banks, credit unions, wealth managers, advisors and fintechs. Payments held for a person, client data kept inside, and a signed record for examiners. Where one wrong payment or leaked file costs the most.

And any company with AI agents

Hospitals, online stores and software teams: anywhere an AI agent can move money, touch private data or change systems.

Team

Built by someone who ran payment systems inside wealth management.

Chhavi Jain

Founder, Live AI Dream

  • VP of Software, Payment Systems, LPL Financial. Learned the exact nuances of wealth management from the inside and saw its pain points first-hand.
  • AI and edge devices at Qualcomm, Nokia and Intel. Built intelligence that runs on the device itself, where speed and trust matter most. Several granted patents worldwide.
  • Five US patent-pending applications in AI security.

Design partner program

We are taking three design partners for a free 90-day pilot.

You get

A Keystile Replay report on your own logs, and live protection for one agent or system, set up with you.

We ask

A short feedback call every two weeks, and permission to mention the pilot.

Your data

Covered by a mutual NDA. Anonymized logs are fine to start.

chhavi.jain@ieee.org Email us