Skip to content
Policy Engine

Write the Policy Once. Every Endpoint Enforces It Instantly.

Author policy in the dashboard, stream it to every agent in under a second, and evaluate it locally on the endpoint - with no latency cost to the developer.

The Problem

Proxy-Based Enforcement Taxes Every Request

The common approach to AI policy is a cloud proxy: route every model call through a gateway and inspect it there. That adds a network hop to every request, creates a single point of failure for developer productivity, and stops working the moment a tool talks to a provider the proxy does not front.

Kraitos AIDR evaluates policy where the activity happens. Rules stream to the agent and are enforced locally in sub-millisecond time, whether the endpoint is on the corporate network, on a home connection, or offline.

How It Works

Watch Quietly or Block Outright - Your Call

Monitor mode - see everything, interrupt nothing

Monitor mode - see everything, interrupt nothing
RuleWhat it catches
Blocked tool useUse of a tool that policy designates as blocked
Usage limitsA user exceeding token limits per day, week, or month
Sensitive file accessAn AI agent reading a path flagged as sensitive
New tool detectedAn unapproved AI tool appearing on an endpoint
Data volume anomaliesUnusual spikes in AI data transfer
Endpoint gone quietAn endpoint that stopped reporting
Off-hours activityAI activity outside defined business hours
Model restrictionsUse of an unapproved model
Sensitive data in promptsPotential data-leakage patterns in prompts
Unapproved MCP serversConnection to an unauthorized external tool server
Budget thresholdsSpend exceeding a budget threshold

Enforce mode - stop it before it happens

Enforce mode - stop it before it happens
RuleWhat it prevents
Block tool actionsSpecific tool invocations, such as shell access for AI agents
Block MCP serversConnections to unauthorized external tool servers
Block an AI toolA specific AI tool from running at all
Block shell commandsSpecific shell commands from AI execution
Restrict file accessAI agents reading protected directories
Require approvalGates an action behind a human approval workflow

Dependency audit

Dependency audit
RuleEffect
Vulnerable packagesBlock installs of packages with known CVEs
Package auditLog every package install performed by an AI agent

Scoping and lifecycle

  • Hierarchical scoping - policies scope to org, team, device, or user, and priority-based evaluation means the most specific applicable policy wins
  • Versioned history - every policy change is recorded, and exceptions are first-class and audited
  • Compliance templates - one-click policy sets for SOC 2, ISO 27001, NIST 800-53, HIPAA, and PCI-DSS, each mapped to specific controls
  • Distribution - policy changes reach every agent in under one second
What You See

Policy Authoring and Enforcement Log

Policy list showing rule types, monitor or enforce mode, mapped compliance frameworks, scope, and priority
Policy engine - each rule with its type, enforcement mode, mapped compliance controls, scope, and priority.
Policy editor dialog with policy name, rule type, enforcement mode toggle, scope, priority, and JSON rule configuration
Policy editor - rule type, monitor or enforce toggle, scope, priority, and the raw rule configuration.
Compliance Mapping

Controls This Evidences

SOC 2 CC6.1
Logical access controls - policy enforcement records and MCP allowlist enforcement
NIST AC-6
Least privilege - restricting what AI agents may execute and read
NIST CM-5
Access restrictions for change - command and package controls
ISO A.8.22
Segregation of networks and services by policy scope

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io