CUSTOMER CASE STUDY

At a Fortune 500 Insurer, Securing Data and Agents Made AI Adoption Faster

A global Fortune 500 insurer used Aurascape to keep PII out of unsanctioned AI tools, redact it inline on sanctioned ones, and see how data moves between the tools its AI agents call. Adoption sped up because security could control how sensitive data flows in AI apps and agents.

PII Protected Inline

Sensitive data redacted or blocked before it could leave, across 30,000+ users

60%

Faster AI tool adoption

Automated discovery and risk scoring replaced manual tool-by-tool security review

3x

AI agent integrations

Tripled with no unauthorized data access, governed through the Zero-Bypass MCP Gateway

AURASCAPE

Customer Journey

01

Challenges

Protect PII under strict regulation while employees, developers, and business units adopt AI tools and agents.

02

Solution

Deploy a platform that discovers the AI in use, redacts PII inline, and governs agent tool calls end to end.

03

Results

Faster AI adoption, tripled agent integrations, and no unauthorized data access.

CUSTOMER CONTEXT

Regulated Fortune 500 Insurance Company

Insurers run on sensitive data: policyholder personally identifiable information (PII), nonpublic personal information (NPI), claims files, and medical and financial records across every line of business. Strict regulation, including state insurance data security laws, meant this security-focused insurer had to balance the business need to adopt AI with compliance concerns.

About the Customer

Industry
Insurance
Number of Users
30,000+
Commercial AI Agent Adoption
60% of users
Distribution
Global
Target AI Agents
Claude Code, Claude Cowork, Claude Design, and others

CHALLENGES

What the Insurer Needed to Secure

Keep PII Secure

For a highly regulated insurer, PII came first. Sensitive data could not reach unsanctioned tools, and any PII sent to a sanctioned AI model had to be redacted in real time.

Secure AI Coding Assistants

Developers wanted AI coding assistants. That put source code and secrets one prompt away from an unsanctioned tool. The company needed to protect code inline, without making security review a gate on the development pipeline.

Safely Adopt AI Agents

Developers and business units wanted to adopt AI agents including Claude Code, Claude Cowork, and Claude Design. The business wanted more of that, not less, without losing control of its data.

Safeguard MCP Adoption

The team needed visibility into the Model Context Protocol (MCP) tools in use across the organization, and needed to understand how data flowed between them. Every new agent integration widened the blind spot.

OBJECTIVES

  • Enforce PII-protection policy inline: block sensitive data from entering unsanctioned tools, and redact sensitive data when working with sanctioned AI tools.
  • Add security guardrails to AI coding assistant usage, without disrupting developers' user experience.
  • Expand Commercial AI agent use for developers and business units, while governing every interaction.
  • Build a live inventory of MCP servers and tools in use across teams. See and control the data moving between them.
  • Prove it all: keep audit-ready records of every AI interaction, showing what data was involved, what policy applied, and what happened next.

OUTCOMES

The customer protected PII across 30,000+ users, adopted new AI tools 60 percent faster, and tripled its agent integrations with no unauthorized data access.

Developers delivered code 40 percent faster because policy ran inline instead of in a review queue. MCP went from zero visibility to a governed inventory, with every tool call inspected before it executed. Security reviews for new AI tools now start from an AI catalog with live risk scores.

WHY AURASCAPE

Aurascape helps you protect data at the speed AI moves.

Aurascape secures how employees and agents use AI. It discovers the AI in use, understands each interaction in context, protects sensitive data inline, and governs the tool calls behind agent integrations. Controls run where the interaction happens, so users keep working and security keeps evidence.

Complete AI Discovery

Finds known and long-tail AI applications and agents, and risk-scores each on behavior, permissions, and data handling.

AI-Native Data Protection

Real-time data classifiers identify PII, NPI, and source code inline. Redact before data reaches a sanctioned AI model, or block it from leaving for an unsanctioned tool.

Entitlement Enforcement

Distinguishes sanctioned enterprise tenants from personal accounts, so policy follows how a tool is used, not just where the traffic goes.

Inline Enforcement & User Coaching

Allow, coach, warn, block, or redact as the interaction happens. Coaching reaches users in the browser and beyond it, including development environments and the command line.

Zero-Bypass MCP Gateway

Discovers MCP servers and tools, inspects prompts, responses, and tool calls, and enforces policy on the actions agents take and the data they reach. Calls that try to route around it arrive unsigned and are blocked by default.

Audit-Ready Evidence

Interaction records show who used AI, what data was involved, what policy applied, and what happened next. Role-based access control governs who can review them.

Make the Safe Path the Easy Path

See how Aurascape protects PII, governs agent tool calls, and speeds up AI adoption.