Cybersecurity
DeepKeep Adds Runtime Guardrails for AI Coding Agents With AI Lens for Developers

DeepKeep has introduced AI Lens for Developers, a security layer designed to give CISOs visibility and policy control over AI coding agents operating on developer machines. The product extends DeepKeep’s existing AI usage-control and runtime-protection capabilities to tools such as Cursor and Claude Code, with support for GitHub Copilot, OpenAI Codex, Lovable, Windsurf and additional coding agents planned.
The launch addresses a security problem created by the growing autonomy of developer tools. Modern coding agents can inspect and modify local files, execute shell commands and invoke external services through the Model Context Protocol (MCP). Those permissions make the tools useful, but they also allow an agent to expose credentials, change sensitive code or interact with systems outside the controls security teams traditionally apply to cloud applications.
The result is a widening visibility gap. A company may approve a coding assistant as a product while having little evidence of what an individual agent did during a particular session. As Unite.AI recently explored, security teams increasingly need to trace agent tool calls, command execution and system-changing events, not simply maintain a list of approved AI services.
Inspecting agent actions before and after execution
AI Lens for Developers is built as a lightweight plug-in rather than a full endpoint agent. DeepKeep says it hooks into the coding-agent workflow to inspect prompts, file reads, shell commands and MCP tool calls before and after they run. Each activity can be routed through the company’s policy system for an allow, block or audit decision.
The distinction between pre-execution and post-execution monitoring is important. An audit trail can explain why an incident occurred, but it cannot prevent a destructive command or stop a secret from leaving a developer’s environment. DeepKeep is positioning AI Lens as both a preventive control and a source of evidence for incident response and compliance.
The product can flag credentials, access tokens and passwords included in prompts or attached files. It also examines agent-generated code for insecure patterns, such as functions that omit authentication. Commands judged to be destructive can be held for human approval, while administrators can create custom key-phrase rules to identify references to sensitive repositories, code sections or internal projects.
DeepKeep says each session generates a detailed audit record that can include the device ID, prompt content and user ID. That gives security teams a way to reconstruct an agent’s activity even if a developer modifies a blocked request and attempts it again.
Central policy for developer-facing AI
Administrators manage rules through DeepKeep’s Policy Hub. Policies can be applied by role or across an organization and can cover categories including personally identifiable information, credentials and destructive commands. The approach is intended to let companies set a consistent security posture while allowing engineering teams to keep using agentic development workflows.
The product’s focus on MCP is especially timely. The protocol gives AI applications a standard way to connect with tools and enterprise data, but every server and callable action can expand an agent’s reachable attack surface. Unite.AI’s guide to the Model Context Protocol notes that MCP hosts and servers form distinct security boundaries, including exposure to prompt injection and untrusted tool output. Monitoring the model alone is therefore insufficient when the model can take action through other systems.
Ofer Rotberg, DeepKeep’s vice president of product, argues that coding agents inherit unusually powerful developer access while acting with increasing autonomy. From his perspective, CISOs need continuous visibility into agent behavior and the ability to stop harmful actions in real time rather than waiting to investigate the next incident.
Part of a broader AI security platform
AI Lens for Developers sits within DeepKeep’s wider AI security platform. The company also offers an AI Firewall, automated and human-guided AI red teaming, AI usage controls, agent scanning and model scanning. DeepKeep says its controls can be applied across the AI lifecycle, from development and testing to production use of applications and agents.
The company was founded in 2021 and describes its platform as model-agnostic, with support for deployment in SaaS, private-cloud, on-premises and air-gapped environments. Its broader pitch is that enterprises need a common policy language for models, applications, employees and autonomous agents rather than separate controls for every AI tool.
For CISOs, developer-facing agents are becoming an urgent test of that idea. Traditional application security focuses heavily on the code that reaches production. Coding agents add another layer of risk: the process that reads the repository, creates the code and runs commands may itself be autonomous. Products such as AI Lens are attempting to make that process observable and enforceable without removing the speed gains that led developers to adopt agents in the first place.












