Security for AI coding tools

Secure every AI prompt across your engineering team.

Rye sits between your developers' AI coding tools (Cursor, Windsurf, Claude Code) and LLM providers. Review every prompt, block secrets from leaking, enforce policies, and keep audit trails for compliance.

$ rye status --workspace acme-eng
12 devs active · 3,841 prompts today
secret-scanning: 2 blocked today
model-allowlist: enforced
token-budget: eng-platform at 87%
tools: cursor (8) · claude-code (3) · windsurf (1)
<4ms
Median policy eval
99.9%
Enforcement uptime
1 yr
Audit retention

Architecture

One control plane for every AI coding tool

Cursor
Cursor
AI-first code editor
Windsurf
Windsurf
Agentic IDE by Codeium
Claude Code
Claude Code
Anthropic's CLI coding agent
GitHub Copilot
GitHub Copilot
AI pair programmer
rye.ai
Secret scanningPolicy enginePrompt monitorDevice authAudit log
Dashboard
Alerts
SIEM export
Webhooks

Features

Security and visibility for AI-assisted development

See what your developers are prompting, stop sensitive code from reaching LLM providers, and maintain the audit trail your compliance team needs.

Prompt visibility

See every prompt your developers send

Full-text search across all AI coding interactions. Filter by developer, tool, model, repository, or risk score. Know exactly what code context is leaving your org.

>jchen · cursor → claude-42.3s
>akim · windsurf → gpt-41.1s
!mrodriguez · claude-code → claude-4flagged
>slee · cursor → gpt-40.8s
xjchen · windsurf → claude-4blocked

Policy engine

Stop secrets and proprietary code from leaking

Block API keys, credentials, and sensitive source files from reaching LLM providers. Enforce model allow-lists and scope what each team can access.

-block: secrets_in_prompt
-block: proprietary_code_paths
-alert: large_context_window
-allow_models: [claude-4, gpt-4]

Device authorization

Only approved machines talk to LLM providers

Register developer laptops and CI runners that can access AI coding tools. Revoke access instantly when someone leaves. See every active device.

macbook-eng-042 · cursor3m ago
macbook-eng-118 · claude-code1m ago
desktop-contract-017 · windsurfrevoked
ci-runner-prod-0912s ago

Audit trail

Compliance-ready logs, zero extra work

Every AI interaction logged with developer identity, device, tool, model, policy evaluation, and full prompt/response. Export to your SIEM or pull via API.

14:03:22ALLOW jchen cursor:claude-4
14:03:24ALERT secret detected in prompt
14:03:25BLOCK policy:no_proprietary_code
14:03:27ALLOW akim windsurf:gpt-4

How it works

Deployed in minutes. No workflow changes.

1

Connect your coding tools

Install the Rye agent on developer machines. It sits between your AI coding tools and LLM providers, capturing every prompt and completion without changing your workflow.

2

Set security policies

Define what developers can send to LLMs. Block secrets, credentials, and proprietary code from leaving your network. Set model allow-lists and token budgets per team.

3

Monitor, investigate, comply

See what every developer is prompting in real time. Trace code suggestions back to the original prompt. Export audit trails for SOC 2, ISO 27001, or incident response.

Your devs are already using AI. Now secure it.

Free for up to 1,000 requests per month. No credit card required. Installs in under five minutes.