Skip to main content

New: Malicious MCP server caught in the wild!

Let agents work the data without putting it at risk

Analysts hand agents database access, notebooks, and warehouse credentials to move faster. Knostic makes sure the agent reads what it should, never drops what it should not, and never carries a credential or a PII row out the door.

One careless instruction can undo months of governance.

An agent asked to clean up a table will clean up the wrong one. An agent with a connection string will paste it into a prompt. Knostic checks each action against your data policy before it runs, and catches sensitive values before they leave.

How Knostic protects data teams

Destructive queries

Before Knostic

Asked to tidy stale orders data, the agent drops the live orders table. 'Command completed.' Then checkout throws 500s and errors climb.

After Knostic

Kirin recognises the table-deletion rule, denies the command before it executes, and alerts the data owner with the exact query.

Who is querying with what

Before Knostic

Analysts connect notebooks, assistants, and desktop agents to the warehouse on their own. Nobody has the list.

After Knostic

Every AI tool touching data is discovered and attributed to a user and team, with usage trends over time.

Consistent access rules

Before Knostic

Each tool has its own idea of what an agent may read, write, or delete. Policy is enforced differently in each.

After Knostic

One policy for read, write, and destructive operations across every agent, with drift flagged.

Key capabilities

Destructive operation guardrails

DROP, DELETE, TRUNCATE, and bulk writes against protected sources are blocked or routed for approval.

Credential and PII detection

Connection strings, keys, and personal data in prompts and outputs are caught before they leave the agent.

Query attribution

See which user, agent, and tool ran what against which source.

Scoped data access

Allow analysts' agents to read curated schemas while keeping raw PII and finance tables off-limits.

Owner alerts

Data owners are notified when an agent attempts a blocked action on their source.

Audit log

Every agent action against data is logged for governance review.

Frequently asked questions

It sits inside the agent. Kirin evaluates the tool call, including the SQL or command, before the agent executes it. No proxy in the data path.

Yes. Policies distinguish read, write, and destructive operations and can be scoped to specific sources or schemas.

Kirin covers coding agents such as Cursor and Claude Code and non-coding agents such as Claude Cowork, which is where most analyst workflows now run.

Kirin's secret and sensitive-data detection inspects prompts, retrieved context, and outputs in real time, in Monitor or Enforce mode.