NexusNest

AI governance for GitHub Copilot

GitHub Copilot at work: redaction and visibility

PromptWall redacts sensitive content in every Copilot completion and chat - VS Code, JetBrains, Neovim, and the Copilot Chat sidebar. NetLens shows how the team uses it.

Start your trial

Real usage

What people paste into GitHub Copilot

The patterns we see most often once a team adopts GitHub Copilot for real work.

  • Open editor tabs become context

    Copilot sends nearby file content as context for completions - a .env file, a credentials fixture, or a customer-data seed file open in another tab included by default.

  • Selections sent to Copilot Chat

    Right-clicking a block and asking Copilot to explain it sends the full selection, which can include hard-coded credentials or internal URLs.

  • Generated tests echo real seed data

    "Generate a test for this" prompts often reuse the real data handed to Copilot moments earlier, landing it in a committed fixture.

GitHub Copilot
Redacted by PromptWall

What your employee typed

// Write a unit test for this refund job with PAYMENTS_DB_URL=postgres://svc:[email protected]:5432/payments and alert email [email protected]

What GitHub Copilot received

// Write a unit test for this refund job with PAYMENTS_DB_URL=[CREDENTIAL_1] and alert email [EMAIL_1]

FAQ

GitHub Copilot, common questions

Does it cover Copilot Chat as well as inline completions?

Yes. Both the autocomplete API and the chat endpoint are covered - PromptWall redacts the prompt text and the attached context.

Does PromptWall add noticeable latency to completions?

Typically under 200ms for a normal completion, mostly the redaction round-trip - shorter prompts add much less.

What if Copilot needs the literal credential to write correct code?

Copilot suggests a correctly-shaped completion using the placeholder, and the developer fills the real value back in locally at edit time.

Does this work with Copilot for Business or Enterprise?

Yes - coverage doesn't depend on the Copilot tier. Business and Enterprise add SSO and audit logs on GitHub's side; PromptWall covers what your code sends as context regardless.

Will my IDE warn about certificate issues?

No. The agent sets up a locally-trusted certificate during install, and VS Code, JetBrains and Neovim all honour the system trust store.

Start with one team. Prove control before you scale AI.

Start with one team. See exactly how your company uses AI.

Start your trial