AppSecNews
AI Security Commercial Emerging

Knostic

by Knostic

Detects where enterprise AI assistants expose data users should not reach, and maps the permission mistakes behind each exposure.

Visit knostic.ai (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Knostic in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 3 points in this profile are not yet confirmed against vendor documentation.
  • Coverage for AI assistants beyond Microsoft 365 Copilot, confirm with vendor
  • Whether remediation is advisory or applied directly to the tenant, confirm
  • Permissions and connectors required for deployment, confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Knostic addresses a specific failure that enterprise AI assistants made visible. Copilot-style tools answer questions using whatever a user is technically permitted to open, and in most large tenants that permission set is far wider than anyone intended: legacy SharePoint sites shared organization-wide, inherited folder permissions, links that were never revoked. Before an assistant existed, that overexposure was latent because nobody browsed to those files. A natural language interface makes them reachable in one question.

The product works by probing what the assistant actually returns. Rather than reading permission tables alone, it asks questions as different user personas and records what comes back, producing evidence that a given role can surface salary data, deal terms or unreleased plans. That output is then tied back to the underlying cause, the specific site, label or inheritance chain, so the finding arrives with a remediation target rather than a warning. The framing the vendor uses is need-to-know: authorization should reflect what a role should see, not just what an access control list has not gotten around to denying.

Where it fits

This runs pre-rollout and then continuously, owned by security or identity teams rather than developers. It assumes you have already deployed or are about to deploy an enterprise assistant over a real corporate data estate, and that someone can act on permission findings, which usually means cooperation from the collaboration platform owners. The value is highest in the window before a broad assistant rollout, when the findings can still change the plan.

Strengths

  • Testing by observed assistant behavior produces evidence that is hard to argue with, which moves permission cleanup up the priority list.
  • Ties each exposure to the underlying misconfiguration, so remediation is actionable rather than a generic instruction to review permissions.
  • Addresses a risk that conventional data security posture tools were not built to reason about.

Limitations

  • Narrow by design. It solves knowledge access exposure and does not address prompt injection, model supply chain or agent behavior.
  • Depth outside the Microsoft ecosystem is the main thing to verify, since that is where the problem was first acute.
  • Discovery requires broad read access across the tenant, which is itself a privilege that needs review.

Who it suits

Right for enterprises rolling out an AI assistant across a large, messy collaboration estate, where the real risk is not the model but what the model can reach. Not relevant to a team building a customer-facing LLM product, where the threat model is injection and abuse rather than internal oversharing.

Used Knostic? Recommend it under your own name and title.

Recommend this tool