What is the latency overhead of authorizing responses and tool inputs at runtime?

Kastra evaluates blocking secret and credential exposure policy in a p50 of 0.3 ms and a p99 under 1 ms. The decision engine uses partial evaluation, cached ASTs, and vectorized rule matching on a Rust runtime. For most responses and tool inputs the authorization step is invisible end-to-end.