Skip to main content

New: Malicious MCP server caught in the wild!

Find the Right Plan for You

Secure your AI coding agents with Kirin and the skills, MCP servers, and extensions they install with AgentMesh. Both start free.

Kirin

Security for AI coding agents and IDEs. Learn more

Free

$0 /mo

For individual developers / small teams (1 - 5 users)

Start Free Today
  • Continuous scanning across projects
  • Granular policies control
  • Configuration enforcement
  • Extensions scanning
  • Rules and Generated Code scanning
  • MCP scanning
  • Standard Support
Team

$15 /mo, per user

For growing teams (5+ users)

Talk to Sales

Includes everything in Free, plus:

  • Unified dashboard
  • Organizational policy
  • Role-based access control
  • Audit logs
  • Cross-org MCP, rules, hooks visibility
  • Priority support
  • Advanced contextual detection: add-on
Enterprise

Contact Us

For engineering managers (10+ users)

Talk to Sales

Includes everything in Team, plus:

  • Policy groups
  • Advanced contextual detections (add-on included)
  • Enterprise SSO
  • Integrations (SIEM, Slack)
  • Compliance Ready Reporting
  • Dedicated enterprise support

Both Team and Enterprise plans come with a 14-day free trial so you can evaluate advanced features before committing.

AgentMesh

Supply chain security for agent skills, MCP servers, and extensions. Learn more

Free

$0 /mo

No time limit · login required

Start Browsing
  • 300 items per category (fixed set)
  • Web UI + limited API access
Premium

$15 /mo, per user

Full catalog · Kirin included

Upgrade Now
  • Full catalog - all categories
  • Up to 300 API calls per month (20/day)
  • Kirin IDE security included
Pro

$850 /mo, per user

Unlimited API · Kirin included

Go Pro
  • Full catalog - all categories
  • Unlimited API access
  • Kirin IDE security included

Every paid AgentMesh plan includes Kirin IDE security. Need 11 or more users? Contact sales for enterprise pricing.

FAQs

Kirin has three tiers, designed to scale from individual developers to enterprise-wide rollouts.

  • Free - $0/month. For individual developers and teams up to five users. Includes Kirin's core scanning and enforcement: continuous project scans, granular policy controls, configuration enforcement, extensions scanning, rules and generated-code scanning, MCP scanning, and standard support.
  • Team - $15 per user per month. For growing teams (5+ users). Everything in Free, plus the things you need when more than a handful of developers are using Kirin: a unified dashboard, organizational policy, role-based access control, audit logs, cross-org visibility into MCP servers, rules, and hooks, and priority support. Advanced contextual detection is available as an add-on.
  • Enterprise - custom pricing. For organizations rolling Kirin out at scale. Everything in Team, plus policy groups, advanced contextual detection bundled in by default, Enterprise SSO, SIEM and Slack integrations, compliance-ready reporting, and dedicated enterprise support.

Today, we support Claude Code CLI, Claude Desktop and Cowork, Cursor, Windsurf, and VS Code + GitHub Copilot, on macOS and Windows. Linux is in beta.

IntelliJ IDEA, and an additional VS Code + Claude Code integration are in near-term roadmap; WebStorm, Amazon Kiro, OpenAI Codex, and Gemini CLI follow shortly after.

Knostic Kirin deploys in minutes. Managers provision the console, push the endpoint client to the endpoints (directly or via your existing MDM), and start in Monitor mode. Policy configuration can be fine-tuned over a matter of hours.

Both. Knostic’s Kirin endpoint client sits on the operating system (in user-space) and watches network traffic for connections to AI services, picking up shadow AI use like browser chatbots, local LLMs, or unsanctioned LLM APIs. For telemetry, protection, and prevention on the agents themselves, Kirin's IDE extension sits inside the coding agent only (e.g., VS Code Copilot, Cursor, Windsurf), detecting prompts, tool calls, file actions, and MCP traffic.

Other agents, such as Claude Code and Cowork, require the endpoint client, operating in combination with agent hooks and other functionality.

Value-wise:

  • Controls coverage: Knostic’s Kirin complements your existing stack: EDR watches the endpoint OS, network detection watches the wire, and Kirin watches inside the applications themselves - the prompts, tool calls, and configs flowing through the agent, where EDR and network tools can't see.
  • Extending CI/CD capabilities to the developer's machine: Kirin additionally implements controls on the endpoint and inside the developer's environment, which currently run only in the CI/CD and the agent often bypasses, such as secrets leakage detection and prevention.

Deployment-wise, we provide scripts for your internal MDM system(s). Direct installation by the developer is also available.

Supporting your security stack:

  • Audit logs and per-endpoint activity logs are available in-product on Team and above. On Enterprise, those streams pipe into your SIEM, alerts route into Slack or Teams, and Enterprise SSO is included.
  • Enforcement is scoped to the agent layer (i.e., Kirin can block a secret before it leaves the IDE) while Shadow AI Discovery is visibility-only by design.

For compliance purposes, we provide a package with SOC 2, pen test reports, data flow diagram, and whatever else you may need in our trust center.

Knostic’s Kirin installs in different ways depending on what you're trying to protect. For Claude Code and Claude Cowork, Kirin installs as a lightweight client, which includes shadow AI visibility functionality. For Cursor and VS Code, Kirin deploys as an extension, but requires the light-weight client for shadow AI visibility. The client runs in user-space (does not require admin).