Policy-as-Code
for EU Regulation
Kestura translates complex EU regulatory requirements — GDPR, NIS2, DORA, AI Act — into verifiable, automated policy code for the Mittelstand.
Explore Services Get in TouchWhat We Do
-
GDPR & ePrivacy Compliance
Automated data protection controls, consent management, and audit trails.
-
NIS2 & DORA Readiness
Policy-as-Code implementations aligned to critical infrastructure directives.
-
AI Act & Governance
Risk classification and conformity workflows for AI systems under the EU AI Act.
-
DevSecOps Integration
CI/CD security gates, dependency scanning, and compliance-as-pipeline for GitHub & GitLab.
AI Security Research
AI × Cybersecurity — Defending AI, Defending with AI
Kestura's Policy-as-Code practice extends into securing AI/ML systems and using AI-driven automation to strengthen security operations. Selected applied projects and research below — updated as work progresses (last updated August 2026).
Defending AI — Securing AI/ML Systems
Hardening AI agents, AI coding pipelines, and AI transparency records so they stay auditable and governable by default.
-
Private Repository
Tideline
Human-in-the-loop approval cockpit for AI agents. Surfaces the policy/delegation chain behind each paused agent action, enforces a browser-signed Tier-3 structural lock for high-risk actions, and generates one-click EU AI Act Annex IV-style evidence packs.
-
Private Repository
CodePilot
Multi-agent coding system (Planner / Coder / Reviewer / Security / QA / Releaser) where every consequential action routes through Tideline for single-named-human approval — not an unreviewed PR merge.
-
Private Repository
atrs-as-code
Governance-to-policy compiler turning the UK Algorithmic Transparency Recording Standard into YAML records, validated in CI, cross-walked to BSI Bausteine and ISO/IEC 42001, and diffed against deployed Terraform so an AI system's transparency record can't drift from what's running.
-
Private Repository
ai-security-labs
Hands-on OWASP ML Top 10 labs, including an FGSM adversarial-attack implementation against a CNN plus gradient-norm / confidence-based defense evaluation with ROC-curve analysis.
Defending with AI — AI-Enhanced Security Operations
Using AI and automation to replace manual audits and strengthen continuous compliance and threat governance.
-
Private Repository
DevSecOps PaC Pipeline
Policy-as-Code/DevSecOps pipeline (Terraform + OPA/Conftest + GitHub Actions) that evaluates every infrastructure change against BSI C5, NIST SP 800-53, and ISO 27001-mapped Rego policies pre-merge, blocks violations, and emits signed compliance evidence — replacing manual audits.
-
Private Repository
nis2-compliance-as-code
NIS2 automation for German SMEs, combining IaC policy enforcement with an AI-adaptive training platform.
-
Research in Progress
Agent Runtime Governance
Ongoing research extending Policy-as-Code into AI-agent runtime governance: each agent tool call is evaluated as a JSON payload against Rego policies by an OPA proxy before execution — governing agent behavior continuously, not just static infrastructure.
About Kestura
Kestura UG (haftungsbeschränkt) is a German-based advisory and engineering firm specialising in EU regulatory compliance automation. We help small and medium enterprises navigate complex legal requirements through executable, verifiable policy code.
Kestura works with an independent international network of cooperation partners, including legal counsel in East Africa. See our cooperation partners.
Headquartered in Germany · Registered under German law · Impressum
Contact
Interested in working with Kestura or have a question about EU regulatory compliance automation? Get in touch — we typically respond within two business days.
- Email info@kestura.com
- Phone (Management) +49 711 34063747
- Phone (Advisory) +49 711 49094952
- Location Filderstadt, Germany
- Availability By appointment only