Source-code leak at a large enterprise
Thousands of developers, each running a coding agent that reads the repository and sends what it needs to a model.
The policy took a minute. The detection was the hard part.
"Our source code does not go to an external model" is one sentence. Knowing that this block of text is theirs is the part nobody had solved.
A developer runs a coding agent — Claude Code, Codex, Cursor — and the agent decides what to send: the file being edited, the three other files it opened to understand it, a function it has already half-rewritten. The developer never chose to share any of it and never sees it go. Matching strings against a repository finds nothing, because what the agent sends is never exactly what is committed. A secret scanner finds an API key and misses the pricing engine.
So we built the detector
It fingerprints their own code and recognizes it at the moment the agent is about to send it. It runs in the same gateway as every other control, and its verdicts go into the same decision records. How it works.
The alternative they had
They could ban the agent outright, which is what companies in this position do. That is worse for the business than governing it: the tool gets used anyway, on personal accounts, where nothing is recorded.