Watch Keystile decide, live
Start a scenario. A real agent sends each action through Keystile; the verdicts appear below as they happen.
No activity yet. Start a scenario above.
Waiting for approval
Escalated actions are held here until a person decides.
Nothing waiting.
Proof
Every verdict and every approval is written to a signed, tamper-evident log.
How Keystile connects
Same decisions, rules, approvals and signed log behind every connector. Pick by how easy to adopt and how hard to get around.
SDK hook
- Sits
- Inside the agent's code, one line per tool
- Protects
- Every tool call that agent makes
- Bypass
- Possible if the agent's code is altered
- Setup
- Minutes
- Best for
- Fintechs building their own agents
@guard(keystile, agent_id="ap-agent")
def send_payment(payee, amount): ...MCP gateway
- Sits
- Between the agent and its MCP tool servers
- Protects
- Every MCP tool call, no code changes
- Bypass
- Harder: separate process
- Setup
- One line in the agent's tool config
- Best for
- Any agent using MCP tools
python -m keystile.mcp_gateway --agent-id ap-agent -- <tool server>System gateway (Box)
- Sits
- In front of the system of record's API
- Protects
- The system, from every agent wherever it runs
- Bypass
- No, when the system accepts traffic only through it
- Setup
- Network routing by the firm's IT team
- Best for
- Banks and critical on-prem systems
agent → Keystile Box → core systemLive check API
- Sits
- Called by any software, any language
- Protects
- Whatever the caller sends
- Best for
- Custom integrations
POST /v1/checkPlug-ins
- Sits
- Inside self-hosted agents and coding assistants
- Protects
- Every tool call, before and after it runs
- Best for
- Teams running their own agents
python -m keystile.installReplay
- Sits
- Offline, on past agent logs
- Protects
- Nothing live; shows what would have been caught
- Best for
- Pilots with no install
Replay tab → upload logs → reportComing later
- Outbound proxy
- Everything an agent sends over the network
- Key (USB)
- Advisers' client data checked on a separate device
Run a demo
See a Replay report on synthetic data before using real logs.
Replay your logs
CSV or JSON lines. Columns Keystile reads: agent_id, action, target, ts, amount, payload. Other columns are kept as context.
Running…
Check one agent action
This is the live Gateway call. The verdict is written to the signed audit log.
Activity
Everything Keystile decided, from the signed record: what each agent tried, what happened, why, and who approved held actions.
| When | Agent | Action | Outcome | Why |
|---|
Verify the record
Recomputes every signature and link in the chain. Any edited or deleted record breaks it.
Protect your first agent in a few minutes
Each step ticks itself off as you go. Everything here uses your own agents; nobody else sees them.
-
See Keystile decide
Send four things an agent might do. Each goes through the same live check your agents will use.
-
Create your API key
Your agents use it to reach Keystile. It's shown once; keep it like a password.
-
Connect your agent
Pick how your agent runs. Your address and key are filled in.
-
Watch your agent here
Run your agent. Its first action shows up here, in Live demo, and in Activity.
Waiting for your agent…
Test a policy change before it goes live
Edit the rules or the tool policy, then re-run your recent agent actions under them. You see every decision that would change. Nothing is enforced or recorded.
Your API keys
Your agents use these to reach Keystile (set KEYSTILE_API_KEY). A new key is shown once; store it like a password.
| Name | Starts with | Created | Last used |
|---|
Invite people
For example from the waitlist. They get an email with a sign-in link, then sign in with their email any time.
| Name | Role | Status | Last sign-in |
|---|