Services AI Security About Impressum Datenschutz

Policy-as-Code
for EU Regulation

Kestura translates complex EU regulatory requirements — GDPR, NIS2, DORA, AI Act — into verifiable, automated policy code for the Mittelstand.

Explore Services Get in Touch

What We Do

AI × Cybersecurity — Defending AI, Defending with AI

Kestura's Policy-as-Code practice extends into securing AI/ML systems and using AI-driven automation to strengthen security operations. Selected applied projects and research below — updated as work progresses (last updated August 2026).

Defending AI — Securing AI/ML Systems

Hardening AI agents, AI coding pipelines, and AI transparency records so they stay auditable and governable by default.

  • Private Repository

    Tideline

    Human-in-the-loop approval cockpit for AI agents. Surfaces the policy/delegation chain behind each paused agent action, enforces a browser-signed Tier-3 structural lock for high-risk actions, and generates one-click EU AI Act Annex IV-style evidence packs.

    Agent Governance · EU AI Act Annex IV

  • Private Repository

    CodePilot

    Multi-agent coding system (Planner / Coder / Reviewer / Security / QA / Releaser) where every consequential action routes through Tideline for single-named-human approval — not an unreviewed PR merge.

    Multi-Agent Systems

  • Private Repository

    atrs-as-code

    Governance-to-policy compiler turning the UK Algorithmic Transparency Recording Standard into YAML records, validated in CI, cross-walked to BSI Bausteine and ISO/IEC 42001, and diffed against deployed Terraform so an AI system's transparency record can't drift from what's running.

    Rego · Terraform · CI

  • Private Repository

    ai-security-labs

    Hands-on OWASP ML Top 10 labs, including an FGSM adversarial-attack implementation against a CNN plus gradient-norm / confidence-based defense evaluation with ROC-curve analysis.

    Python · Adversarial ML

Defending with AI — AI-Enhanced Security Operations

Using AI and automation to replace manual audits and strengthen continuous compliance and threat governance.

  • Private Repository

    DevSecOps PaC Pipeline

    Policy-as-Code/DevSecOps pipeline (Terraform + OPA/Conftest + GitHub Actions) that evaluates every infrastructure change against BSI C5, NIST SP 800-53, and ISO 27001-mapped Rego policies pre-merge, blocks violations, and emits signed compliance evidence — replacing manual audits.

    OPA · Rego · Terraform

  • Private Repository

    nis2-compliance-as-code

    NIS2 automation for German SMEs, combining IaC policy enforcement with an AI-adaptive training platform.

    IaC · AI-Adaptive Training

  • Research in Progress

    Agent Runtime Governance

    Ongoing research extending Policy-as-Code into AI-agent runtime governance: each agent tool call is evaluated as a JSON payload against Rego policies by an OPA proxy before execution — governing agent behavior continuously, not just static infrastructure.

    OPA Proxy · Runtime PaC

About Kestura

Kestura UG (haftungsbeschränkt) is a German-based advisory and engineering firm specialising in EU regulatory compliance automation. We help small and medium enterprises navigate complex legal requirements through executable, verifiable policy code.

Kestura works with an independent international network of cooperation partners, including legal counsel in East Africa. See our cooperation partners.

Headquartered in Germany · Registered under German law · Impressum

Contact

Interested in working with Kestura or have a question about EU regulatory compliance automation? Get in touch — we typically respond within two business days.

Send us an email