Black
Runtime Guardrails

Prevent Source Code Leaks Through AI

Prevent proprietary code and secrets from leaking through AI coding tools. Protect prompts, files, responses, and agent workflows.

Use Case

AI coding assistants accelerate development, but they also create a direct channel between proprietary code and external or internal models. PointGuard AI helps security teams inspect those interactions and enforce data-protection policy without blocking developer productivity.

Challenges

The AI environment creates several recurring security and governance challenges:

  • Developers paste proprietary code into AI prompts
  • Files and repositories expose code through retrieval workflows
  • Credentials and API keys become embedded in model context
  • Coding agents can exfiltrate content through downstream tools

Solution

PointGuard AI provides a comprehensive solution for protecting source code across coding prompts, files, responses, and agent interactions:

1. Inspect coding interactions. Use AI Intelligent Guardrails and MCP Security Gateway to monitor prompts and responses from AI coding tools to identify proprietary code, secrets, and restricted technical information.

2. Scan retrieved content. Inspect source files and other retrieved content before they are passed into models or agent workflows.

3. Enforce code protection policies. Block, mask, or redact protected code and secrets when an interaction violates enterprise data policies.

4. Protect connected coding agents. Extend runtime DLP to MCP and agent tool calls so code cannot be exfiltrated through downstream workflows.

This allows development teams to benefit from AI coding tools while keeping proprietary code and technical secrets inside approved boundaries.

Risks Addressed

Applicable framework risks and controls include:

OWASP Top 10 for LLMs
  • LLM02:2026 Sensitive Information Disclosure
  • LLM04:2026 Supply Chain
  • LLM08:2026 Hidden Context Exposure
OWASP Top 10 for Agentic Applications
  • ASI02: Tool Misuse and Exploitation
  • ASI04: Agentic Supply Chain Vulnerabilities
  • ASI05: Unexpected Code Execution (RCE)
NIST AI Risk Management Framework
  • GOVERN 1.4: Transparent risk policies, procedures, and controls are established
  • GOVERN 6.1: Policies and procedures address third-party AI risks
  • MEASURE 2.7: AI system security and resilience are evaluated and documented
  • MANAGE 4.1: Post-deployment monitoring and change management are implemented