New The reliability layer for production AI

Your AI tells you what happened. Astriel keeps it
from going wrong.

Observability records the disaster. Astriel redacts the leak, blocks the attack, and pauses the risky action — in real time — then proves it in an audit trail.

Open-core · self-hostable · drop-in for your existing stack

Live firewall feed enforce
1,284 decisions today0 leaks shipped
01 — The stakes

Three ways your AI can hurt you tonight

Modern agents don’t just answer questions — they move money, send email, touch data. A single bad action stopped being an embarrassing screenshot and became a real loss. Observability tools watch all three happen and do nothing.

Data leaks

A customer pastes their SSN into chat. It sails straight to your model vendor and lands in their logs. You find out during the audit.

SSN sitting in the vendor’s logs

Manipulation

“Ignore your instructions.” The bot obeys — leaking its system prompt, its tools, the data behind them.

System prompt & tools, exposed

Runaway actions

An agent misreads a $95 dispute and fires a $9,500 refund. Fast, error-free — and completely wrong.

$9,500 out the door

Observability watches. Astriel acts. It sees the risk — and steps in.

02 — The reliability loop

One connected loop, not four disconnected tools

Every other platform stops at the first verb. Astriel closes the loop — and each stage feeds the next.

01

Observe

Full tracing of every call, tool, and turn.

02

Evaluate

Multi-turn, trajectory & simulation scoring.

03

Protect

Redact, block & approve in real time.

04

Prove

Tamper-evident, policy-versioned audit trail.

03 — A day at Acme Bank

Watch it happen, in one afternoon

Acme pointed their support agent at Astriel — one line of code. Here’s what the gate did while nobody was watching.

Moment 01 · The invisible seatbelt

An SSN, redacted in 8ms

A customer types their Social Security number into chat. Astriel catches it, masks it, and forwards the clean message. The model vendor never sees it. The customer notices nothing.

Moment 02 · The blocked attack

An injection, stopped cold

An attacker tries “ignore previous instructions.” The request scores 0.94 and is blocked before the model is ever called. No tokens spent. No prompt leaked.

Moment 03 · The $9,500 that didn’t move

A risky action, held for a human

The agent tries to refund $9,500 on a $95 dispute. Policy pauses it. A support lead sees the full conversation, spots the mistake, and clicks deny.

04 — The product

Four surfaces. One data model.

Every guardrail decision, eval score, and simulation run lands in the same trace you already use to debug. Protection and observability, not two products.

Protect

Runtime Guardrails

An OpenAI-compatible gate in front of your model. Redacts PII & secrets, blocks injections, pauses risky tool calls — with six actions, not two.

  • PII redaction
  • Injection blocking
  • Tool approval
  • Shadow mode
Evaluate

Agent Evals & Simulation

Persona-driven users run multi-turn conversations against your agent before real ones do. Trajectory X-rays catch loops and dead-ends. CI gates block bad deploys.

  • Multi-turn judges
  • Trajectory metrics
  • Adversarial sims
  • CI exit codes
Observe

Insights & Root-Cause

Ask your trace data structured questions — cost, latency, failing tools — with automatic anomaly hints that tell you what moved before you thought to look.

  • Cost & latency
  • Failing tools
  • Anomaly hints
  • Guardrail activity
Prove

Compliance Evidence

Every decision is timestamped and policy-versioned. Export tamper-evident evidence packages — the answer to “show me your AI controls.”

  • Audit trail
  • Policy versioning
  • Evidence export
  • On-prem
05 — Turn it on without fear

Shadow mode measures first. You enforce when you’re ready.

0
PII leaks that would have shipped
0
injection attempts headed for your model
0
false positives on normal traffic

Every policy starts in shadow mode — scoring 100% of real traffic, changing nothing, showing exactly what it would have done. One week later, one click promotes it to enforce. The numbers above are one customer’s first week — quantified prevented damage, in their own data.

06 — Why Astriel

“Isn’t this just observability?”

No. Observability is where the market is crowded. The control plane in front of your AI is where it isn’t.

Open-source observability

Records everything, prevents nothing

Beautiful traces of three disasters — after they happened. You migrate to us in one line and keep your instrumentation.

Closed protection vendors

Blocks, but bolted on

Code changes at every checkpoint, two crude actions, GPU-heavy, and their guardrail logs live apart from your traces.

Astriel

Protection, in the trace, in one line

Six actions including human approval. Runs on CPU. Open-core and self-hostable. Every decision lands where you already debug.

Observe. Protect. Prove.

Start recording like everyone else. Then get the layer no one else ships — the one that keeps your AI from going wrong.