← News

DeepKeep AI Lens product UI — policy hub and prompt redaction/block for coding and chat agents

1 Oct 2026

DeepKeep

DeepKeep ships AI Lens for Developers to watch coding agents like Cursor and Claude Code

DeepKeep announced AI Lens for Developers, extending its AI usage-control and runtime-protection modules so security teams can monitor and govern coding agents that read files, run shell commands, and invoke MCP tools on developer machines — with Cursor and Claude Code supported at launch.

Coding agents now sit on the same machine privileges as the engineers who run them. Seeing what those agents prompt, which files they read, and which commands they send is becoming basic work for a chief information security officer, not an optional sidebar in how software gets built.

On Thursday, 1 October 2026, DeepKeep said it was shipping AI Lens for Developers. The release is datelined Tel Aviv-Yafo, Israel. PR Newswire carries it and stamps Oct 01, 2026, 09:00 ET. DeepKeep calls itself an end-to-end AI security platform. The new piece extends the company’s AI usage-control and runtime-protection modules. Usage control is the set of rules for what people and tools may send into an AI system. Runtime protection is the check while that work is actually running, not only a review after the fact. The release says the point is to secure software developers and the coding agents that can write, modify, and execute code on their behalf. A coding agent, here, is software that takes a next step in a programming task — read a file, change code, run a command — rather than only suggesting the next line. Those lines are DeepKeep’s.

What the release says a security team gets. Policy enforcement, an audit record, and runtime security over coding agents such as Cursor and Claude Code. Policy enforcement means a rule can allow an action, block it, or record it. An audit record is the log of what happened. The line under the headline says these tools can read files, run shell commands, and invoke MCP tools. A shell command is an instruction to the computer, the kind that can delete files or change a system. MCP is the Model Context Protocol, a connector an agent uses to call a tool or pull in data. The release uses the letters MCP and does not spell them out. It says that access is a gap most security programs have not had to cover before. That “most” is the company’s framing. The page does not name the programs it has in mind.

The company’s adoption figure, kept as its own. The release says 90 percent of developers use AI coding agents at work at least weekly. Ninety percent is nine in ten. The release calls that a growing security problem, because those agents can read local files, run shell commands, and call MCP tools on the developer’s own machine. It says security teams have no way to see what the agents do with that access, or to stop it. It says code is moving from a prompt to production with less human review at each step. A prompt is the instruction a person, or an agent, sends. Production is the software customers actually run. The software development life cycle, often shortened to SDLC, is that path from an idea to the software that ships. Those lines are DeepKeep’s. The release does not name a survey, a sample size, or the year of the count.

How the product is built, as the release states it. AI Lens is a light plug-in, not a full endpoint agent. An endpoint agent is security software installed across the whole computer. A plug-in hooks the coding tool itself. The release says that lets a team get coverage without adding a new client on the developer’s machine. Hooks inside the coding agent intercept prompts, shell commands, file reads, and MCP tool calls before and after they run, and send each one to DeepKeep for an allow, block, or audit decision. Intercept means the action is caught on the way through, so a rule can apply before it finishes. Those lines are DeepKeep’s.

What the release says the plug-in flags. Credentials, tokens, and passwords that can leak through prompts and through files a person attaches. A credential is a login. A token is a secret string a program uses in place of a password. The same paragraph says it catches insecure code an agent writes, and the example is a function missing authentication. Authentication is the check that a caller is allowed in. Destructive commands are flagged and sent for a person to approve before they run. Teams can also set custom key-phrase detection, so a sensitive stretch of code, or an internal code repository named in the rule, gets flagged. A repository is the stored project. Those lines are DeepKeep’s. The release does not print a list of the commands it treats as destructive.

The log, and who sets the rules. Every session produces a full audit log, including a device ID, the prompt content, and a user ID. A device ID identifies the computer. A user ID identifies the person. The release says the log still holds a record if a developer changes a blocked request and tries again. Administrators set policy in a Policy Hub, by role or across the organization. A role is a job type, such as a developer or an administrator. The categories the release names for blocking are personally identifiable information, credentials, and destructive commands. Personally identifiable information, often shortened to PII, is data that can point to a particular person. Those lines are DeepKeep’s.

Ofer Rotberg, vice president of product at DeepKeep, is quoted on the release. “Developers have more permissions and access than almost anyone else in the organization, and coding agents now act with full autonomy and responsibility,” he said. “The risk is real, as the recent OpenAI and Hugging Face incident showed, where AI agents were able to access and exploit external systems during testing.” He said it is essential for chief information security officers to see what is happening inside these tools, not only whether the tools are approved on paper, and that security teams must monitor every agent action and block harmful behaviour in real time, instead of waiting for the next incident. A chief information security officer, often shortened to CISO, is the executive in charge of a company’s security. That quotation is his, in the release. The release spells behaviour with a u. It describes the OpenAI and Hugging Face incident in that one sentence. It does not say AI Lens was part of that incident, and it does not say the plug-in would have stopped it.

Who it supports on day one. The release says AI Lens for Developers supports Cursor and Claude Code today. GitHub Copilot, OpenAI Codex, Lovable, Windsurf, and more are coming soon. Coming soon is the release’s wording. It does not say those other agents are covered now. It says the product is available now as part of DeepKeep’s wider AI security platform. The page does not print a price, and it does not name a customer.

Who the about box says DeepKeep is. The company says it provides AI security and trustworthiness across the life of an AI system. The platform, the box says, protects systems that include large language models and computer vision, so enterprises can deploy and use AI in line with security and privacy standards. A large language model is the kind of AI that reads and writes text. Computer vision is AI that reads images. The capabilities the box names are an AI Firewall, vibe and automated AI red teaming, AI usage control, and model scanning. Red teaming, here, is a test that tries to break the system on purpose. The box says the work is meant to defend against vulnerabilities, data leakage, hallucinations, and bias. A hallucination, in that sentence, is an answer the model states that is not grounded in the material it was given. DeepKeep was founded in 2021. The site the box prints is www.deepkeep.ai. The media contact is Mike Katznelson at Headline Media. Those lines are the about box. They are the company’s description of the wider platform, not a measured result of Thursday’s plug-in at a named company.

The picture is DeepKeep’s AI Lens product screen, on the Policies view. A dark window carries the DeepKeep mark. The side rail is labeled AI Lens, with Prompts, Coding agents, Chat agents, Policies, Integrations, and Logs. The header reads AI Lens for Developers, with a line about configuring guardrails for coding agents and chat agents. A guardrail, here, is a rule that stops or marks an action. A Policy Hub panel sits beside a form for a new policy: a name, a scope of coding agents or chat agents, an action of block, redact, or audit, and a trigger for credentials, a destructive command, or a key phrase. Redact means the sensitive part is hidden, rather than the whole prompt thrown out. A live preview shows a prompt held back, with a credential covered, and a shell command waiting on approval. The screen does not print a calendar date. The release does not say the preview is a named customer’s session.

In plain terms, DeepKeep said on Thursday that security teams can plug AI Lens into coding agents so prompts, file reads, shell commands, and MCP tool calls can be allowed, blocked, or logged. At launch the release names Cursor and Claude Code. GitHub Copilot, OpenAI Codex, Lovable, and Windsurf are listed as coming soon. The release says the plug-in flags leaked credentials and weak code, holds destructive commands for a person to approve, and writes an audit log with the device, the prompt, and the user. The 90 percent weekly-use figure is DeepKeep’s. The page does not name a customer, a price, or a survey behind that figure.

RELATED

ONLINE…

Comments

guidelines

Loading…

Loading…

Sources