FAQs
Deployment
Knostic’s Kirin installs in different ways depending on what you're trying to protect. For Claude Code and Claude Cowork, Kirin installs as a lightweight client, which includes shadow AI visibility functionality. For Cursor and VS Code, Kirin deploys as an extension, but requires the light-weight client for shadow AI visibility. The client runs in user-space (does not require admin).
Today, we support Claude Code CLI, Claude Desktop and Cowork, Cursor, Windsurf, and VS Code + GitHub Copilot, on macOS and Windows. Linux is in beta.
IntelliJ IDEA, and an additional VS Code + Claude Code integration are in near-term roadmap; WebStorm, Amazon Kiro, OpenAI Codex, and Gemini CLI follow shortly after.
Knostic Kirin deploys in minutes. Managers provision the console, push the endpoint client to the endpoints (directly or via your existing MDM), and start in Monitor mode. Policy configuration can be fine-tuned over a matter of hours.
Both. Knostic’s Kirin endpoint client sits on the operating system (in user-space) and watches network traffic for connections to AI services, picking up shadow AI use like browser chatbots, local LLMs, or unsanctioned LLM APIs. For telemetry, protection, and prevention on the agents themselves, Kirin's IDE extension sits inside the coding agent only (e.g., VS Code Copilot, Cursor, Windsurf), detecting prompts, tool calls, file actions, and MCP traffic.
Other agents, such as Claude Code and Cowork, require the endpoint client, operating in combination with agent hooks and other functionality.
Value-wise:
- Controls coverage: Knostic’s Kirin complements your existing stack: EDR watches the endpoint OS, network detection watches the wire, and Kirin watches inside the applications themselves - the prompts, tool calls, and configs flowing through the agent, where EDR and network tools can't see.
- Extending CI/CD capabilities to the developer's machine: Kirin additionally implements controls on the endpoint and inside the developer's environment, which currently run only in the CI/CD and the agent often bypasses, such as secrets leakage detection and prevention.
Deployment-wise, we provide scripts for your internal MDM system(s). Direct installation by the developer is also available.
Supporting your security stack:
- Audit logs and per-endpoint activity logs are available in-product on Team and above. On Enterprise, those streams pipe into your SIEM, alerts route into Slack or Teams, and Enterprise SSO is included.
- Enforcement is scoped to the agent layer (i.e., Kirin can block a secret before it leaves the IDE) while Shadow AI Discovery is visibility-only by design.
For compliance purposes, we provide a package with SOC 2, pen test reports, data flow diagram, and whatever else you may need in our trust center.
Developer Impact
No. Policies run in the background without impact on the developer's environment. You can decide whether a developer sees alerts directly at all, and from what level of severity.
It depends on the mode and on what the policy is protecting. Detection and Hardening policies each run in Off, Monitor, or Enforce modes. In Monitor, the action proceeds and the event is logged and reported. In Enforce, Kirin steps in line, and how it intervenes depends on the policy:
- Secrets. If an agent tries to read a file containing a secret, Kirin blocks the read or sanitizes the secret before it reaches the model, and logs the attempt.
- MCP servers. Unverified or risky servers are quarantined and pulled from the system configuration so the agent can't connect to them, but held for admin review.
- Extensions. Allow/block lists are enforced against installed components, with anything outside the list quarantined rather than removed.
In every case, once configured, the developer can see a clear message about which policy fired and what to do next.
Plan Differences
Kirin has three tiers, designed to scale from individual developers to enterprise-wide rollouts.
- Free - $0/month. For individual developers and teams up to five users. Includes Kirin's core scanning and enforcement: continuous project scans, granular policy controls, configuration enforcement, extensions scanning, rules and generated-code scanning, MCP scanning, and standard support.
- Team - $15 per user per month. For growing teams (5+ users). Everything in Free, plus the things you need when more than a handful of developers are using Kirin: a unified dashboard, organizational policy, role-based access control, audit logs, cross-org visibility into MCP servers, rules, and hooks, and priority support. Advanced contextual detection is available as an add-on.
- Enterprise - custom pricing. For organizations rolling Kirin out at scale. Everything in Team, plus policy groups, advanced contextual detection bundled in by default, Enterprise SSO, SIEM and Slack integrations, compliance-ready reporting, and dedicated enterprise support.
Kirin secures agents and coding assistants at the endpoint. Shadow AI Spotlight provides visibility across the whole organization, surfacing AI tools in use across employees, sanctioned or not, with risk scored and mapped to the teams using it. AgentMesh secures the supply chain (extensions, skills, and MCP servers) before they reach an agent. OpenAnt is the leading LLM-based open-source vulnerability scanner for the code agents generate. OpenAnt is free for everyone, although we do offer a managed version. The others share a single Knostic console.
Every alert carries a severity and a risk score, so the highest-impact findings surface first by default. You can tune that: set severity on the policies you add, and create exclusions to mute alerts that aren't relevant to your environment. Shadow AI usage is also mapped, which points to the fastest path to a high-leverage first policy. Most customers go live with enforcement on a handful of well-scoped policies, then expand from there.