Knostic
World's first need-to-know access control for LLMs. Prevents AI oversharing by enforcing role-based knowledge boundaries at inference time.
What it does
Knostic (Herndon, VA / Tel Aviv, founded 2023) provides need-to-know access controls for enterprise LLMs like Microsoft Copilot and Glean. Co-founded by Gadi Evron and Sounil Yu (former Chief Security Scientist at Bank of America). Won RSA Conference 2024 Launch Pad and Black Hat 2024 Startup Spotlight. Raised $14.3M. Monitors LLM queries and responses in real time, applying context-aware response rewriting — from obfuscation to complete blocking — based on user roles and enterprise need-to-know boundaries.
Security relevance
Addresses the inference-time data leakage problem that traditional DLP and file permissions cannot solve. LLMs can infer sensitive information by synthesising fragments across repositories even when file-level permissions are valid. Knostic detects and prevents this oversharing at the knowledge layer. Also provides Copilot Readiness Assessment to surface exposure before rollout.
When to use it
Use before or during enterprise Copilot/Glean deployment to prevent sensitive data exposure through AI-generated responses. Critical for regulated industries where need-to-know boundaries must be enforced.
OWASP coverage
Risks addressed — mapped to both OWASP Top 10 standards. 2 in LLM, 1 in Agentic.
The raw record
What Yuntona stores. Single source of truth — fork it on GitHub.
name: Knostic slug: knostic type: Mixed category: AI Guardrails & Firewalls url: https://www.knostic.ai reviewed: 2026-04 added: 2026-04 updated: 2026-04 risks: llm: [LLM02, LLM06] asi: [ASI06] complexity: Plug & Play pricing: — audience: CISO · GRC lifecycle: [deploy] tags: [Access Control, Commercial, Copilot Security, Data Leakage, Oversharing]