CUSTOMER CASE STUDY
Securing AI Coding Assistants for 15,000+ Developers at a Fortune 500 Financial Services Firm
A Fortune 500 financial services firm sanctioned modern AI coding assistants for its 15,000+ developers, but existing tools could not enforce policy inline without breaking the user experience. Aurascape deployed alongside the incumbent, enforcing tenant, data, and threat policy in the interaction path, without interrupting developers.
Enterprise account access enforced
Developers reach coding assistants through approved enterprise accounts. Personal accounts stay separated from source code.
Developers secured
Developers work inside sanctioned AI coding assistants with Aurascape in the interaction path.
Sanctioned AI Tools
AI coding assistants and enterprise AI clients run as designed, from Claude Code to Codex to Google Antigravity, with policy enforced in real time.
AURASCAPE
Customer Journey
Challenges
Existing security tools could not inspect AI coding assistant traffic without disrupting the user experience, and business pressure could have led to exceptions routing traffic around security policy.
Solution
Aurascape deployed alongside the existing security stack, decoding AI traffic inline and enforcing tenant and data policy without interfering with the developer experience.
Results
15,000+ developers secured across 8 targeted AI tools, with source code and client data governed inside the interaction.
CUSTOMER CONTEXT
Fortune 500 Financial Services Firm
Under CIO and board pressure to speed development and improve productivity with AI, the firm targeted a modern AI stack for its 15,000+ developers and other business teams. Security and IT needed those tools governed without exposing source code or client data, while restricting access to unsanctioned AI tools.
About the Customer
- Industry
- Financial Services
- Developers Secured
- 15,000+
- Targeted AI Tools
- Claude Code, Cowork, & Desktop; Codex, ChatGPT, Google Antigravity, Gemini, Windsurf
- Deployment Model
- Alongside existing SASE, AI traffic only
CHALLENGES
What the Firm Needed to Solve
Inspection that disrupted developer workflows
The targeted coding assistants stream over server-sent events (SSE), streamable HTTP, and Protobuf, and hold long-lived sessions. Inspecting that traffic caused buffering that interrupted developer workflows.
Pressure to route around security
Disruption to developer productivity pushed development leadership toward requesting a bypass. Granting one would mean unmonitored AI traffic potentially carrying source code. Refusing would mean slower development and a stalled AI mandate.
Control AI account access & utilization
Coding assistants accept source code by design. Security needed developers on enterprise accounts, because personal accounts might expose code to training, retention, or storage that violates the firm’s data residency requirements.
Protect client data across the business
Business and operations teams use AI for daily work. Client data and personally identifiable information (PII) needed the same protection as source code.
OBJECTIVES
- Maintain full developer productivity in the targeted AI coding assistants under security control, with no buffering or degraded experience inside the tools.
- Enforce enterprise tenant access for coding assistant use, redirecting developers away from personal accounts toward the accounts the firm sanctioned.
- Keep source code and secrets under policy across prompts, files, and generated code, with redaction and blocking applied in real time.
- Protect client data and PII as more teams adopt AI across the firm, using the same architecture that secures the developer organization.
- Preserve interaction-level evidence for audit and investigation, so policy decisions can be explained after the fact.
OUTCOMES
15,000+ developers work at full speed inside sanctioned AI coding assistants, with policy enforced inside the interaction.
Aurascape runs alongside the firm’s existing SASE stack, steering only AI traffic and decoding and governing it inline. Enterprise tenant policy, data protection, and audit evidence now apply inside the tools themselves, and the pressure for a security exception went away.
WHY AURASCAPE
Inline security for AI workflows that preserves user experience.
The firm chose Aurascape because the architecture matched the problem: Aurascape understands the AI traffic its existing controls could not decode, adding stronger security for the AI tools the business had already committed to.
Modern Protocol Support
Aurascape decodes SSE, Protobuf, and long-lived streaming sessions inline. These are the traffic patterns that break traditional proxies built for web and SaaS.
Complement, Not Replace
Aurascape deploys alongside the existing SASE stack and steers only AI traffic. Nothing else in the security architecture changes.
Entitlement Enforcement
Aurascape distinguishes approved enterprise tenants from personal accounts inside the same application, and redirects users to the correct account.
AI-Native Protection
Real-time classifiers detect source code, secrets, client data, and threats like prompt injection, across prompts, responses, files, and generated code, with inline redaction and blocking.
Full Conversation Context
Policy decisions draw on the prompt, the response, and the accumulated exchange, so a safe interaction and a risky one can be told apart inside the same approved tool.
Govern Agentic AI
As coding assistants take on agent capabilities, Aurascape governs the tool calls they make before actions reach external systems.
Secure AI Coding Without Slowing Down Developers
Aurascape secures the AI coding assistants your developers already rely on, with no degraded experience inside the tools. See it on your own traffic.