Knowledge Security Platform for Prod & Engineering | Knostic
SaassyCode Repackaged: Four New VS Code Extensions and a New Delivery Chain
24 August 2026
CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
4 August 2026
Introducing AgentMesh Access Tiers: Building Together, Growing Together
27 July 2026
Lessons Learned from the Hugging Face Security Team
24 July 2026
Knostic for Product & Engineering Teams
Don’t Put Your Company Secrets in Jeopardy
Engineers love LLMs for instant code reviews. But those same chats can reveal unreleased features, API tokens, or partner NDA content—especially when documents are mis-tagged or stored in public team drives.
Knostic Locks Down Innovation Secrets
Confidential road-map firewall
allows for need-to-know access to any mention of unreleased products
Secrets scanner
prevents LLMs from exposing API keys or credentials in responses, unless the user has a verified need-to-know
The right users, the right privileges
Knostic applies contextual access policies to LLM usage without slowing down dev cycles
Mis-permission alerts
Notify owners if restricted docs become publicly readable
Explore our latest Security Tools
Test your LLM for oversharing
Ever wonder what your Copilot or internal LLM might accidentally reveal? We help you test for real-world oversharing risks with role-specific prompts that mimic real workplace questions.
RAG Security Training Simulator
RAG Security Training Simulator is a free, interactive web app that teaches you how to defend AI systems — especially those using Retrieval-Augmented Generation (RAG) — from prompt injection attacks.
Made for Product & Engineering Teams
Ship faster with Copilot while keeping competitive intel from unauthorized access.
Latest research and news
SaassyCode Repackaged: Four New VS Code Extensions and a New ...
Knostic identified four VS Code extensions that reuse malicious code from the SaassyCode family. They reveal two distinct forms of reuse: one package was republished almost ...
CodeRelay: 12 VS Code Extensions Disguised as Developer Tools
CodeRelay is the name we gave to a coordinated campaign involving 13 malicious VSIX packages across 12 VS Code extensions. Most look like compiler, code-runner, or 'timeline' ...
What’s next?
Want to solve oversharing in your enterprise AI search? Let's talk.
Knostic is the comprehensive impartial solution to stop data leakage.
Knostic offers visibility into how LLMs expose your data - fast.