Knowledge Security Platform for Prod & Engineering | Knostic

SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain

24 August 2026

CodeRelay: 12 VS Code Extensions Disguised as Developer Tools

4 August 2026

Introducing AgentMesh Access Tiers: Building Together, Growing Together

27 July 2026

Lessons Learned from the Hugging Face Security Team

24 July 2026

Knostic for Product & Engineering Teams

Don’t Put Your Company Secrets in Jeopardy

Engineers love LLMs for instant code reviews. But those same chats can reveal unreleased features, API tokens, or partner NDA content—especially when documents are mis-tagged or stored in public team drives.

Knostic Locks Down Innovation Secrets

Confidential road-map firewall

allows for need-to-know access to any mention of unreleased products

Secrets scanner

prevents LLMs from exposing API keys or credentials in responses, unless the user has a verified need-to-know

The right users, the right privileges

Knostic applies contextual access policies to LLM usage without slowing down dev cycles

Mis-permission alerts

Notify owners if restricted docs become publicly readable

Explore our latest Security Tools

Test your LLM for oversharing

Ever wonder what your Copilot or internal LLM might accidentally reveal? We help you test for real-world oversharing risks with role-specific prompts that mimic real workplace questions.

RAG Security Training Simulator

RAG Security Training Simulator is a free, interactive web app that teaches you how to defend AI systems — especially those using Retrieval-Augmented Generation (RAG) — from prompt injection attacks.

Made for Product & Engineering Teams

Ship faster with Copilot while keeping competitive intel from unauthorized access.

Latest research and news

SaassyCode Repackaged: Four New VS Code Extensions and a New ...

Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package was republished almost ...

CodeRelay: 12 VS Code Extensions Disguised as Developer Tools

CodeRelay is the name we gave to a coordinated campaign involving 13 malicious VSIX packages across 12 VS Code extensions. Most look like compiler, code-runner, or 'timeline' ...

What’s next?

Want to solve oversharing in your enterprise AI search? Let's talk.

Knostic is the comprehensive impartial solution to stop data leakage.

Knostic offers visibility into how LLMs expose your data - fast.