Coverage
AI Coding Tools
Your fastest-moving AI surface is engineering
Coding assistants read your entire codebase, run with developer credentials, and now make multi-file changes on their own. They are the highest-capability AI in most organisations and usually the least governed. SAF3AI inventories them, sees what they can reach, and gates what they produce.
What you see
The telemetry we pull
Coding assistant usage
Which assistants your developers use, how heavily, and on which repositories — Cursor, Claude Code, GitHub Copilot and the rest.
Repository and context reach
What each assistant is allowed to read: which repos, which files, and whether that includes the ones holding credentials or regulated data.
AI-authored code attribution
Which changes were machine-generated, by which tool and which session, so review effort can be aimed at the code that needs it most.
Local agent and MCP servers
Tool servers running on developer machines with production credentials, reaching internal systems from outside your managed estate.
Secrets in prompts and context
Credentials pulled into an assistant's context window from a local file or environment, detected by provider signature and entropy.
Token spend by team
Assistant cost attributed to teams and repositories, which is usually the first place engineering AI spend becomes visible at all.
How it connects
From zero to first signal
- 1
Inventory from what you already run
MDM and EDR connectors surface which assistants are installed across the fleet before you deploy anything new.
- 2
Connect the vendor tenant
Where the assistant has an enterprise tenant — Claude Code through the Anthropic connector, Cursor through its own — SAF3AI reads usage and telemetry directly from it.
- 3
Gate the output in CI
The SAF3AI CLI runs SAST and red-team scans in your pipeline and returns SARIF, so AI-generated code is reviewed by the same gate as everything else. Findings appear inline in the IDE through the extension.
- 4
Cover the local agent surface
The desktop agent inventories MCP servers and local runtimes, which is the part of the developer surface no cloud connector reaches.
What it catches
Risks specific to this surface
Secrets pulled into context windows
An assistant reading a .env file or credential store as part of "understanding the codebase", then carrying it into a prompt.
Vulnerable AI-generated code
Plausible-looking code with real flaws, merged because it read well. SAST scanning in CI catches it before it ships.
Proprietary source leaving the building
Whole repositories used as context by a personal-tier assistant with no enterprise data agreement behind it.
Local MCP servers with production access
Tool servers on laptops holding production credentials, invisible to every server-side control you have.
Prompt injection through dependencies
Instructions planted in a README, comment or package that an assistant reads and acts on while working in the repo.
Unreviewed autonomous changes
Agentic coding tools making multi-file changes faster than review can keep up, with no record of which changes were machine-authored.
See AI Coding Tools in your own tenant
Connect this surface in a pilot and get a mapped inventory, a scored risk list and the attack paths that actually reach your data.