AI Governance Platform

Your AI Agents Have the Keys to Your Kingdom. Who's Watching the Door?

Kestra Labs is the security checkpoint between AI assistants and your enterprise SaaS. Control who can do what, with which credentials, under what conditions and audit every interaction.

🛂
Think TSA for AI traffic. Every request gets an identity check, permission validation, a temporary credential, and a full audit log. No boarding pass, no access.
0
SaaS Connectors
0
Governed Actions
5-Layer
Security Gateway
<500ms
End-to-End Latency

Two Products, One Architecture

Both products share identity validation, device posture, Key Management integration, session management, and policy engine. The only difference is what gets proxied.

🛡

MCP Fortress

Secure AI-to-SaaS Gateway

Let AI assistants use Salesforce, Slack, GitHub and 245+ other SaaS tools while your security team controls every credential, permission, and data flow.

Protocol
MCP (JSON-RPC 2.0 over HTTP)
For
Non-technical users via Claude connectors
Gateway
gateway.kestralabs.com
Protects
SaaS credentials (API keys, OAuth)
Key features
245+ connectors, PII redaction, kill switch
EXPLORE MCP FORTRESS
🔑

PAT Fortress

Secure Claude API Proxy

Your developers call Claude through your proxy, not Anthropic's endpoint directly. You set the spend caps, model allowlists, and log every prompt and response. PAT = Personal Access Token.

Protocol
REST API proxy (Claude Messages API)
For
Developers and power users
Gateway
pat.kestralabs.com
Protects
Claude API keys (Personal Access Tokens)
Key features
Model allowlists, spend caps, full logging
EXPLORE PAT FORTRESS

The 5-Layer Gateway

Every request passes through 5 security layers in under 500ms. If any layer fails, credentials are never touched.

1

Entry Point (~10ms)

Global CDN + API Gateway. TLS encryption, DDoS shield, organization key validation.

2

Identity & Policy (~5-15ms)

Entra ID validation, device posture (Zero Trust), role resolution, policy evaluation. Shared between both products.

3

Credential Resolution (~15-100ms)

Three paths by tier: SOHO (our key), Bank (your key + our key), Zero Trust (session-scoped, memory only).

4

Proxy (~100-300ms)

MCP Fortress: calls SaaS APIs + PII redaction. PAT Fortress: proxies to Claude API + response logging.

5

Observability (async)

Audit logging, platform metrics, alerts. PAT Fortress logs full request+response for SOC 2 compliance.

MCP Fortress

Secure AI-to-SaaS Gateway

245+ SaaS Connectors

Connect to any SaaS platform with pre-built, regularly updated connectors. Manage credentials in our secure vault with automatic rotation, health monitoring, and breach detection. No more storing API keys in CI/CD systems or spreadsheets.

Live Connectors (21):

Zendesk
Salesforce
HubSpot
ServiceNow
Jira
GitHub
GitLab
Linear
Monday.com
Notion
AWS
Azure
Cloudflare
Heroku
Grafana
Elastic/ELK
MongoDB Atlas
Box
CrowdStrike
Jenkins
CircleCI

VIEW ALL CONNECTORS

Role-Based Access Control

Define granular policies that control exactly what each user can do. Rules are evaluated in real-time using a deny-by-default architecture:

  • Time-based rules: Allow access only during business hours or specific time windows
  • IP-based rules: Restrict to corporate network or specific geolocations
  • Rate limiting: Cap API calls per user, per connector, per hour
  • Conditional rules: Combine multiple conditions with AND/OR logic

Every policy evaluation is logged and can be audited in real-time.

Immutable Audit Trail

Every request, decision, and policy change is logged to an immutable audit trail. Export evidence for SOC 2 Type II, ISO 27001, PCI DSS, and HIPAA audits.

  • Request logging: Timestamp, user, connector, action, policy decision, result
  • Change tracking: All policy modifications logged with who, what, when
  • Retention: 90 days (SOHO), 1 year (Bank), 7 years (Zero Trust)
  • Export: Download evidence in standard format for auditors

PAT Fortress

Secure Claude API Proxy

PAT (Personal Access Token), the API key your developers use to call Claude. PAT Fortress makes sure your organization controls it, not individual developers.

Drop-in Replacement

Change your base URL from api.anthropic.com to pat.kestralabs.com. Everything else stays the same. Your developers never see the real Claude API key.

Granular Controls

Restrict to specific Claude models, set per-request token limits, enforce monthly spend caps per PAT, and apply rate limiting per user. All policies are evaluated in real-time.

Full Audit Trail

Every prompt sent to Claude AND every response is logged. Archived to encrypted storage with server-side encryption. Critical for SOC 2 Type II compliance. MCP Fortress only logs decisions; PAT Fortress logs everything.

Developer sends request → Kestra Labs validates identity
→ Policy check (model, tokens, spend) → Decrypt PAT
→ Proxy to Claude API → Log response → Return to developer
0+
Connectors Available
<0ms
End-to-End Latency
0.00%
Uptime SLA
0 min
Setup Time

Three Tiers of Credential Trust

Choose how much you trust Kestra Labs with your keys.

SOHO

Managed Vault

"Giving your house key to a trusted neighbor"

We hold encrypted credentials and decrypt per request. Fastest setup.

Setup: 5 minutes

Bank

Safety Deposit Box

"Your key + our key required"

Customer Key Management key required for decryption. You maintain control.

Setup: 30 minutes

Zero Trust

No Keys Stored

"Credentials never leave your building"

Entra ID + device posture + session-scoped keys. Maximum security.

Setup: 2-4 hours

SOC 2 Type II
ISO 27001
NIST 800-53
PCI DSS 4.0
GDPR
HIPAA

Simple, Transparent Pricing

Pick one product or bundle both and save. No free trial: we're infrastructure, not a toy.

SOHO

$5/user/month

Both products: save $1/user vs. individual

  • 2–5 users (self-serve)
  • 245+ MCP connectors
  • Claude API proxy with spend caps
  • 90-day audit retention
  • SLA: 99.5%
  • No SSO or device posture
$10/month
GET STARTED
RECOMMENDED

Bank

$8/user/month

Both products: save $2/user vs. individual

  • 5–150 users (self-serve)
  • 245+ MCP connectors
  • Claude API proxy with spend caps
  • 1-year audit retention
  • SLA: 99.9%
  • SSO: Entra ID / Okta + SCIM
  • PII redaction & kill switch
  • Model allowlists & token limits
$40/month
GET STARTED

Zero Trust

Custom

150+ users · enterprise contract

  • 150+ users (custom contract)
  • 245+ MCP connectors
  • Claude API proxy with spend caps
  • 7-year audit retention
  • SLA: 99.95%
  • SSO: Entra ID + SCIM
  • Device posture (4 MDM providers)
  • BAA/DPA included

Contact our sales team for pricing and custom setup.

CONTACT SALES
💡 Bundle & save: Get both MCP Fortress + PAT Fortress together. SOHO saves $1/user/mo · Bank saves $2/user/mo.

No free trial. No demo required. No sales call for SOHO and Bank. Overage: 1.25x base rate. Claude API token costs are billed directly by Anthropic; Kestra Labs only charges for platform access.

Ready to Secure Your AI?