Pluto Security provides an AI‑aware endpoint protection platform that monitors and controls the use of AI tools across corporate devices. By automatically detecting unauthorized AI applications and enforcing policy‑driven blocks or supervised access, it reduces blind‑spot attack surfaces while allowing legitimate AI workflows to continue, and integrates with existing security stacks for seamless deployment.
Funding
Funding not disclosed
Founders
Product
Problem
Enterprises face increasing risk from malicious extensions, AI‑assisted code tools, and supply‑chain attacks that infiltrate developers’ primary environments such as VS Code and CI/CD platforms. These threats are hard to detect because they blend into normal development workflows, leading to hidden exposure across every endpoint.
Solution
Pluto Security delivers an AI‑driven endpoint protection platform that monitors developer tools and code repositories in real time. By integrating directly with environments like VS Code and GitLab, the system identifies and blocks malicious extensions, unauthorized AI tool usage, and supply‑chain compromises before they can execute. The platform provides continuous visibility into hidden AI activity across the organization, allowing security teams to enforce granular access controls without disrupting developer productivity. Alerts and policy actions are delivered through a unified console, enabling rapid response to emerging threats while maintaining a seamless development experience.
Target Audience
Primary customers are security and DevSecOps teams in mid‑size to large enterprises that need to protect developer endpoints and CI/CD pipelines while preserving engineering velocity.
Features
- AI‑based detection of malicious VS Code extensions and remote code execution attempts
- Real‑time monitoring of AI‑assisted coding tools and hidden usage across developer workstations
- Integration with GitLab and other CI/CD pipelines to block supply‑chain attacks at the repository level
- Granular, policy‑driven access controls that can block or allow specific tools per user or team
- Centralized dashboard offering continuous visibility and actionable alerts for security operators
- Low‑friction deployment that operates alongside existing development workflows without requiring major changes