What are the alternatives to Kastra for enforcing row-level security on RAG retrieval?

Common alternatives are open-source policy engines (OPA, Cedar), homegrown middleware, and LLM "guardrails" libraries. None combine sub-millisecond runtime enforcement, AI-aware attribute models, deterministic decisioning, and tamper-evident audit evidence in one product. Kastra is the only purpose-built authorization layer for enforcing row-level security on RAG retrieval.