AI governance for GitHub Copilot
GitHub Copilot at work: redaction and visibility
PromptWall redacts sensitive content in every Copilot completion and chat - VS Code, JetBrains, Neovim, and the Copilot Chat sidebar. NetLens shows how the team uses it.
Real usage
What people paste into GitHub Copilot
The patterns we see most often once a team adopts GitHub Copilot for real work.
Open editor tabs become context
Copilot sends nearby file content as context for completions - a .env file, a credentials fixture, or a customer-data seed file open in another tab included by default.
Selections sent to Copilot Chat
Right-clicking a block and asking Copilot to explain it sends the full selection, which can include hard-coded credentials or internal URLs.
Generated tests echo real seed data
"Generate a test for this" prompts often reuse the real data handed to Copilot moments earlier, landing it in a committed fixture.
What your employee typed
// Write a unit test for this refund job with PAYMENTS_DB_URL=postgres://svc:[email protected]:5432/payments and alert email [email protected]
What GitHub Copilot received
// Write a unit test for this refund job with PAYMENTS_DB_URL=[CREDENTIAL_1] and alert email [EMAIL_1]
Coverage
How NexusNest covers GitHub Copilot
PromptWall
- API keys, tokens and secrets appearing in code context
- Customer identifiers embedded in test data and seed scripts
- Internal URLs and connection strings
NetLens
NetLens shows how much of the team is using Copilot, in which IDEs, and how often PromptWall redacted something in a completion or chat - on redacted text only.
Learn moreFAQ
GitHub Copilot, common questions
Does it cover Copilot Chat as well as inline completions?
Yes. Both the autocomplete API and the chat endpoint are covered - PromptWall redacts the prompt text and the attached context.
Does PromptWall add noticeable latency to completions?
Typically under 200ms for a normal completion, mostly the redaction round-trip - shorter prompts add much less.
What if Copilot needs the literal credential to write correct code?
Copilot suggests a correctly-shaped completion using the placeholder, and the developer fills the real value back in locally at edit time.
Does this work with Copilot for Business or Enterprise?
Yes - coverage doesn't depend on the Copilot tier. Business and Enterprise add SSO and audit logs on GitHub's side; PromptWall covers what your code sends as context regardless.
Will my IDE warn about certificate issues?
No. The agent sets up a locally-trusted certificate during install, and VS Code, JetBrains and Neovim all honour the system trust store.
Start with one team. Prove control before you scale AI.
Start with one team. See exactly how your company uses AI.