Knostic
Need-to-know access control platform stopping enterprise AI assistants like Copilot from oversharing sensitive internal data.
Visit Website ↗ + Add to CompareOverview
Knostic sits between employees and enterprise AI assistants such as Microsoft 365 Copilot, Glean and Google Gemini to enforce need-to-know access controls on what those assistants are allowed to answer — addressing cases where an AI tool has technical access to a document or dataset but a specific user should not see its contents. This is a distinct problem from traditional data loss prevention or model-level guardrails, which generally don’t account for identity-based need-to-know policy when an AI assistant surfaces information it can technically reach.
Founded in 2023 by Gadi Evron, a former CISO of the Israeli National Digital Authority, and Sounil Yu, former Bank of America chief security scientist and creator of the widely used Cyber Defense Matrix framework, Knostic has raised roughly $19.3 million, including an $11 million round in March 2025 and a $5 million investment tied to winning RSA Conference’s 2025 Innovation Sandbox competition.
Knostic is the only startup to have swept both the RSA Conference Launch Pad and Black Hat Startup Spotlight competitions in the same year (2024), an independently judged signal of early technical credibility, though as a very early-stage company it has limited real-world deployment history to draw on.
Innovation Matrix Assessment
Sweeping both RSA Conference Launch Pad and Black Hat Startup Spotlight in the same year, plus winning the 2025 RSAC Innovation Sandbox, reflects fast, independently judged technical progress for a two-year-old company.
Directly addresses a widely reported enterprise fear — Copilot-style assistants surfacing sensitive documents to users who shouldn't see them — with identity-based need-to-know controls.
Early-stage funding ($19.3M total) and competition wins are real but modest signals; per this matrix's methodology, small/early companies are scored honestly on momentum even when the underlying technology is promising.
Addresses a genuinely new problem category — AI oversharing/need-to-know for enterprise copilots — that did not meaningfully exist before 2023-2024, though it is too early to call it a proven category redefinition.
Too early-stage for independent real-world efficacy evidence beyond competition judging and founder credibility; scored conservatively pending customer case studies.
AI oversharing and access governance is very likely to grow in importance as Copilot-style enterprise AI tools spread further into daily workflows.
Why CISOs Should Care
Prevents enterprise AI assistants from surfacing sensitive documents to users who technically have no need to know their contents, closing a gap neither DLP nor model guardrails address.
What Makes It Different
Applies identity- and need-to-know-based governance specifically to what an AI assistant is permitted to answer, rather than filtering the underlying data or model outputs generically.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
An Incremental Innovator: Knostic addresses a real and growing problem with credible, independently judged early recognition, but as a very young, seed-stage company it lacks the market momentum and efficacy track record needed for a higher tier yet.
Editorial Note: Claims vs. Verified Findings
Competition wins (RSAC, Black Hat) are independently judged; funding and customer-impact figures are company-disclosed and the company is too early-stage for independent efficacy benchmarks.
Sources
Alternatives to Knostic
Adaptive Security
AI-driven platform that simulates deepfake, voice, and multichannel social-engineering attacks to train and test organizations against next-generation phishing.
Quilr
Early-stage agentic AI security startup building a 'Service-as-Software' platform to guard against human-related breaches and secure AI agent…
Zenity
Governance and security platform for AI agents and low-code/no-code development, securing agent identity, permissions and behavior across the…
Tenzai
An agentic AI penetration testing startup building autonomous 'AI hackers' to find and validate exploitable vulnerabilities at a…
Reco
Reco secures the "agentic ecosystem" — mapping what AI agents can access across SaaS and enterprise apps, detecting…
Charm Security
Agentic AI workforce that investigates and intervenes on scams and fraud in real time, reading manipulation and intent…