Skip to main content

New: Malicious MCP server caught in the wild!

Enforce your AI policies in real time

Written policy does not stop an agent. Knostic turns your rules for AI use into controls enforced inside every agent, with the evidence trail auditors ask for.

Critical High Medium by Dashboard Inventory Alerts Shadow AI Agents Activity Policies AI AppSec Users Security Groups Settings Audit Logs Attack Demonstrations Get Started Dashboard Security Overview for Knostic Knostic Organization General Usage A high-level view of organization-wide alerts, coverage, and MCP usage. Top Alerts TitleSeverityScoreUsers Malicious package 94 3 AI-instruction file classifi… 92 7 MCP server tool descripti… 92 6 Prompt injection 64 8 Alerts Last 7 days Total: 62 13 10 5 0 Sep 30, 2026 Oct 1, 2026 Oct 2, 2026 Oct 3, 2026 Oct 4, 2026 Oct 5, 2026 Oct 6, 2026 Latest Alerts TitleSeverityDescriptionLast Seen Prompt injection A file the agent read tried tooverride its rules. October 6, 2026 at04:20:51 UTC AI-instructionfile… An instruction file tells the agent toskip code review. October 6, 2026 at04:14:35 UTC Command FileThreat A command file, a reusable set ofinstructions for the agent, hides… October 6, 2026 at04:11:04 UTC Shadow AIextension An unsanctioned AI extension wasinstalled in VS Code. October 6, 2026 at04:01:10 UTC Rule filechanged .cursorrules changed outside ofcode review. October 6, 2026 at03:50:17 UTC Kirin User Coverage Over Time Total Users 1684 Active Users 1520 Active Users Total Users Last 30 days Policies Coverage 89% Detection Policies Detects active attacks, malicious content, and security threats. These policies are enabled by default to provide immediate protection. 8 enabled out of 9 100% AI Agent Instructions Your rules for how AI coding agents should behave. Kirin audits instruction files (such as CLAUDE.md and .cursorrules) against this catalog and reports… 58 enabled out of 60 100% Allow/Block Lists Manage Allow and Block lists. 2 enabled out of 2 Top MCP Servers by Usage atlassian 1627 sentry 1149 supabase 599 notion 551 stripe 226

Moratoriums stall work. Manual review cannot keep pace.

A blanket ban on AI agents puts the business months behind, and a policy PDF cannot inspect a tool call. Knostic encodes the policy once, applies it to every agent in use, and records every decision, so compliance keeps up with adoption instead of blocking it.

How Knostic makes policy enforceable

Consistent controls

Before Knostic

Each AI tool has its own configuration for autonomy, secrets, and connectors. The policy you wrote is applied differently, or not at all, in each one.

After Knostic

One policy mapped to every tool. Any deviation is flagged as drift, so what the document says and what the agents do stay the same.

Scope you can attest to

Before Knostic

Audit asks which AI systems are in use. The honest answer is that nobody knows.

After Knostic

A continuously updated inventory of agents, models, and plugins by team, ready for the register and the regulator.

Evidence of control

Before Knostic

An agent's action is only visible in its consequences. There is no record of what was allowed or why.

After Knostic

Every allowed, blocked, or escalated action is logged with the matching policy, timestamped for the audit trail.

Key capabilities

Policy as code

Express your acceptable-use rules as enforceable guardrails and apply them per team or regulation.

Drift detection

Configuration changes that take an agent out of policy are flagged and can be reverted.

Audit-ready logs

Decision logs map every agent action to the control that governed it, exportable as ISO 27001, SOC 2, PCI, HIPAA, and CMMC evidence.

AI system inventory

Know every agent and model in use, who runs it, and what it can reach.

Fine-grained exemptions

Allow a research team more autonomy while keeping regulated data teams locked down, from one policy set.

Monitor before enforce

Run any rule in Monitor mode to measure impact before it blocks anything.

Frequently asked questions

Knostic provides the inventory, control enforcement, and decision logs that ISO 27001, SOC 2, PCI DSS, HIPAA, CMMC, and the EU AI Act all expect for AI systems. It is evidence for your controls, not a certification.

Yes. Policies are assigned per team or group, so marketing's agents and finance's agents run under different allowances.

The decision log shows every action an agent attempted, the rule that applied, and the outcome. Coverage dashboards show which users and tools the policy reaches.

It is designed to speed it up. With enforceable guardrails in place, the business can approve agents it would otherwise have to ban.