COPilot is EDR for AI coding agents. Agents now run with real credentials, often with approvals off, so a prompt injection hidden in a web page, README or tool output can make them leak secrets. The model can't be trusted to notice, so COPilot makes the decision outside the agent.
How it works: COPilot is a local daemon. Claude Code's hooks send every tool call through it before the call runs and after it returns, and it decides allow, ask the developer, or deny/block. It never auto-allows. Decoy "honeytools" (e.g. read_aws_credentials) are denied on any call. Touching a secret, reading an injection and sending data out in one session triggers an ask.
ClickHouse: the org-wide memory of every event, factor and developer answer. Lookups take 8.6–12.4 ms across 4.0M events from 501 developers. If 3 developers decline an ask, the next agent is denied.
Semgrep: Guardian runs unmodified on every Write, Edit and Bash. Findings go back to Claude, and git commit/push is held until the flagged file is fixed (tested on leaked AWS keys).
Akash: hosts lev, our self-hosted Qwen3.5-4B + LoRA model on an H100, so code and secrets never reach a vendor API. It answers: is this text a prompt injection, and does this action serve the user's request? It caught 10/10 injections and 10/10 drift actions at 130–160 ms per call.
Works end to end on Claude Code today.