Keystile Cloud
We host it for you. Available on request for teams that prefer it.
Guardrails for AI agent actions
Keystile checks every action an AI agent is about to take and decides: allow, redact, escalate or block. In real time, with a clear reason for every decision and a signed record auditors can trust.
Example · agent actions checked by Keystile
Known vendor, normal amount
New payee, far above normal, after hours
Account numbers removed before sending
Brand-new admin, never-seen action, at 5 a.m.
Demo · 4 minutes
Demo video
Coming this week.
Meanwhile, try the live scenarios below. They show real verdicts from Keystile.
Try it yourselfTest report · October 2026
We ran Keystile against a public set of 56 test cases written by an outside open-source project: 35 attacks, 16 harmless actions and 5 borderline ones. Every attack was blocked or held for a person before it could run. One harmless action was held for a person; none was blocked.
| What the test tried | Cases | Blocked or masked | Held for a person | Let through |
|---|---|---|---|---|
| Sending private data or files out | 10 | 9 | 1 | 0 |
| Destroying data, systems or access | 7 | 0 | 7 | 0 |
| Hidden instructions in an agent's request | 4 | 3 | 1 | 0 |
| Stealing passwords and keys | 3 | 2 | 1 | 0 |
| Hidden instructions in what a tool returns | 6 | 6 | 0 | 0 |
| Secrets in what a tool returns (masked) | 3 | 3 | 0 | 0 |
| Attacks hidden deep in very long text | 2 | 2 | 0 | 0 |
| All attacks | 35 | 25 | 10 | 0 |
| Other cases | Cases | Result |
|---|---|---|
| Harmless actions and tool outputs | 16 | 15 let through, 1 held for a person (an invoice email), none blocked |
| Borderline cases | 5 | 2 held for a person, 2 blocked, 1 masked |
| Tool descriptions with hidden instructions | 3 | 2 flagged, 1 missed |
| Harmless tool descriptions | 2 | 2 let through |
| Speed per check | 56 | Median 0.8 seconds, 95% under 4.7 seconds, on the default Balanced setting |
Run on 5 October 2026 with Keystile's built-in rule packs and default settings, on our own decision model. We used this test set while building Keystile's checks, so we are now running a fresh set we have never seen; we will publish those results here too. Full case-by-case results are available to design partners.
The problem
On 11 March 2026 an attacker used one compromised admin account and a normal device-management command to wipe about 80,000 devices at Stryker in three hours. No malware. Every command was authorized. Now picture the same access in the hands of an AI agent, steered by a prompt injection instead of a stolen password.
Step 1
One admin account compromised
Step 2
New global admin created
05:00–08:00 UTC
Normal wipe command, at scale
Result
~80,000 devices erased
Always-on agents from OpenAI, Microsoft, Google and Salesforce now act with their own credentials. Gartner expects 15% of day-to-day work decisions to be made by agents by 2028.
Antivirus sees no malware. Access control sees valid credentials. Per-action rules see a normal command. The danger is in the pattern.
Financial firms must show which model decided, that it was not altered, and why. New SEC breach rules for advisers add a 30-day clock.
Sources: BleepingComputer · Gartner via WFTV · TechCrunch
Try it yourself
Each scenario shows the action the agent submits, Keystile's checks, and the verdict it returned.
Sample scenarios. Verdicts, confidence and decision times were recorded from Keystile in October 2026.
How you use it
01 · CONNECT
Keystile goes between your AI agents and the tools they use: payments, email, client data, admin consoles. One line in Python, LangChain or the OpenAI Agents SDK; one setting for MCP; one command for Claude Code, Cursor or Hermes Agent; or the API from any language.
02 · SET RULES
"Payments over $10k to a new payee need a human." "Client account numbers never leave the firm."
03 · DECIDE
Each action gets a verdict in real time, with the reason. Anything high-stakes waits for a person.
04 · PROVE
Compliance and auditors see what was checked, what was decided and why.
Products
Available now
Send us a few weeks of agent or AI-tool logs and your rules. We show you every action Keystile would have escalated or blocked, and why. Nothing to install.
Available for pilots
Live, real-time protection in front of every agent, on your own servers or run by us in your cloud. Blocks data leaks, prompt-injection exfiltration and abnormal agent behavior. PATENT PENDING
Coming later
The same protection on dedicated hardware the protected systems cannot modify: an inline box for on-prem systems of record, and a USB key for financial advisers. PATENT PENDING
For developers
Your admin runs Keystile on your own servers, or we run it for you. Developers get two settings and connect the same way, whichever it is.
Your IT team runs the Keystile server on your own servers or cloud account, under a license. Client data never leaves you.
We run Keystile for you, inside your own cloud account. Client data still never leaves you.
We host it for you. Available on request for teams that prefer it.
Plans
To try it
IT teams, university departments, startups
Mid-size companies and fintechs
Banks, hospitals, large universities
Paid plans run on your own servers under a license agreement, managed by us in your cloud, or on Keystile Cloud. Claude Code and Cursor protection: $10 per developer a month. Managed (we run it in your cloud): +$750 a month. Education and nonprofits: 40% off. Design partners: free for 90 days.
Who it's for
Universities and growing companies, where AI agents already run computers, accounts and help desks every day.
Banks, credit unions, wealth managers, advisors and fintechs. Payments held for a person, client data kept inside, and a signed record for examiners. Where one wrong payment or leaked file costs the most.
Hospitals, online stores and software teams: anywhere an AI agent can move money, touch private data or change systems.
Team
Founder, Live AI Dream
Design partner program
A Keystile Replay report on your own logs, and live protection for one agent or system, set up with you.
A short feedback call every two weeks, and permission to mention the pilot.
Covered by a mutual NDA. Anonymized logs are fine to start.
chhavi.jain@ieee.org
Email us