PromptGuard
About
PromptGuard is a security layer that inspects application requests before they reach an LLM provider. It describes 15 detectors across six layers for risks such as prompt injection, jailbreaks, PII exposure, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. The product says it detects and redacts 43 PII types using reversible tokenization. Its SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. Listed integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM. Deployment choices include managed cloud, hybrid self-hosting, and air-gapped installations; air-gapped licenses validate offline with a signed key. Zero-retention mode does not store prompt or response content, while default security events include a truncated 500-character preview and content hash. The company says customer content is not used to train, fine-tune, or evaluate models. The permanent Free tier includes 20,000 scans monthly, one API key, one project, and 24-hour log retention. Paid plans include a 14-day money-back guarantee, not a trial.
Who it is for
It suits teams that want to inspect LLM requests across listed providers and deployment environments. Teams with strict data handling needs can assess its zero-retention and air-gapped options alongside its stated coverage gaps.
What is good
- Lists 15 detectors across six threat layers
- Detects and redacts 43 PII types
- Supports managed, hybrid, and air-gapped deployment
- Free tier includes 20,000 monthly scans
What to know first
- Hosted service has no EU region currently
- SOC 2 Type II certification is not yet achieved
- Five OWASP LLM Top 10 risks are only partially covered
Inferse review
PromptGuard: the full review
PromptGuard provides request inspection and multiple deployment patterns, with a permanent Free tier to start. Review its stated OWASP coverage gaps, hosted-region limits, and default event previews against your requirements.
Overview
PromptGuard sits between an application and its LLM provider to inspect requests before they reach a model. It suits teams that want security controls across several providers and deployment patterns; its appeal is tempered by incomplete OWASP coverage and US-only hosted residency.
Key features
Inspection and privacy
PromptGuard describes 15 detectors across six layers, covering threats such as prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware and tool injection. It also supports prompt-injection, jailbreak, data-leakage, unsafe-output and custom tests. This combination serves teams screening live traffic and checking application behavior, but it is not a complete OWASP LLM Top 10 solution: five risks are covered in full and five in part, with provenance verification and vector-store isolation among the gaps.
The product says it detects and redacts 43 PII types using reversible tokenization. Its SDK can instrument supported LLM calls with one initialization call while leaving provider code unchanged, which can reduce integration work for teams already using supported providers. Those include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM.
Deployment and data handling
Managed cloud, hybrid self-hosting and air-gapped deployment let teams choose between a hosted service and tighter infrastructure control. Air-gapped licences validate offline with a signed key. The hosted service runs on Google Cloud Run in us-central1, with no hosted EU region, so organizations requiring EU-hosted processing should look elsewhere or assess a self-hosted option.
Zero-retention mode does not store prompt or response content. By default, security events include a truncated 500-character preview and content hash, a meaningful distinction for teams setting logging policy. PromptGuard says customer prompts, completions and documents are not used to train, fine-tune or evaluate models. GDPR and CCPA are supported; SOC 2 Type II is not yet certified and ISO 27001 is planned.
Pricing
The permanent Free plan costs 0.00 USD per free and includes 20,000 scans a month, one API key, one project and 24-hour log retention. It is a practical starting point for a small evaluation, but the scan, project and key caps constrain broader use. There is no free trial; paid plans include a 14-day money-back guarantee.
Team costs 19.00 USD per month and provides 15,000 scans per seat, pooled, plus a browser extension, macOS and Windows agent, fleet enrollment, MDM and organization-wide policy. It fits teams managing employee-side usage, though its pooled allowance is seat-based rather than a single fixed monthly quota.
Pro costs 99.00 USD per month, with 100,000 scans a month, five API keys, five projects and seven-day log retention. It suits a small production setup that needs more capacity and separation than Free. Scale has custom pricing for 500,000 requests/month, unlimited API keys and projects, and 30-day log retention; overage is metered at $0.40 per 1,000 requests up to a spend cap. Its 48-hour email support on Pro gives way to priority support with a 24-hour response time on Scale.
Enterprise has custom pricing for custom volume, fully air-gapped deployment, SCIM, IP allowlisting, custom retention and dedicated support with a four-hour response SLA. It is the fit for organizations needing isolated deployment and enterprise access controls, rather than teams seeking a published per-seat price. Free includes community support.
Platforms
PromptGuard supports API, browser extension, Linux, macOS, self-hosted, web and Windows environments. That breadth helps teams combine backend inspection with desktop or browser controls, while air-gapped deployment addresses networks that cannot depend on a hosted connection.
Who it's for
PromptGuard is best suited to teams adding inspection to applications already connected to multiple LLM providers, particularly those that need self-hosting, air-gapped options or reversible PII tokenization. It is less suitable when complete OWASP LLM Top 10 coverage, hosted EU residency or an achieved SOC 2 Type II certification is a requirement.
Pros and cons
- Pros: Broad provider support and SDK auto-instrumentation can add a common inspection layer without changing existing provider code.
- Pros: Cloud, hybrid and air-gapped choices, plus zero-retention mode, give security teams meaningful deployment and data-handling controls.
- Pros: A permanent Free tier offers 20,000 monthly scans, making initial evaluation possible without a time-limited trial.
- Cons: Partial OWASP coverage leaves provenance verification and vector-store isolation among the stated gaps.
- Cons: Hosted processing is limited to us-central1, which rules out the service for teams requiring a hosted EU region.
- Cons: Default event previews retain up to 500 characters, so teams wanting no prompt or response content in storage must enable zero-retention mode.
Alternatives
For a broader shortlist, compare LLM Security Tools, AI Security Testing Tools and AI Guardrail Software.
Lasso AI Security Platform is a paid API, extension and web option to consider if those deployment surfaces fit your stack better. WitnessAI is another paid API, web and Windows option, with custom enterprise pricing and no published tiers.
Prisma AIRS AI Gateway may fit teams already working with Software NGFW credits: its consumption-based gateway licensing is billed in credits based on token usage, with required credits determined through sales. SecureAI Guard is a paid API, self-hosted and web alternative without a free plan; its Startup plan is 2999.00 USD per month.
GuardionAI is worth considering when a free trial matters; it offers API, Linux, macOS, self-hosted, web and Windows platforms, with custom enterprise pricing. Amazon Nova Reel is a paid API alternative.
GLACIS is a freemium API, self-hosted and web alternative with a free account at 0.00 USD per free. HiddenLayer AI Guardrails is a paid self-hosted and web option at 5000000.00 USD per year on a 12-month contract; additional AWS infrastructure costs may apply.
Verdict
Choose PromptGuard if your team needs a provider-spanning inspection layer, flexible deployment and controls for sensitive data, with a permanent free tier to begin. Look elsewhere if hosted EU residency or complete OWASP LLM Top 10 coverage is essential; its US-only hosted service and stated coverage gaps are material constraints.
Compared on AI security testing tools
- Free plan
- Yespromptguard.co
Facts
- Product
- PromptGuard is a security layer between an application and its LLM provider that inspects requests before they reach the model.promptguard.co · 30 Sept 2026
- Threat detection
- The product describes 15 detectors across six layers for threats including prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection.promptguard.co · 30 Sept 2026
- PII controls
- PromptGuard says it detects and redacts 43 PII types, with reversible tokenization.promptguard.co · 30 Sept 2026
- Deployment
- The product offers managed cloud, hybrid self-hosting, and air-gapped deployment; air-gapped licences validate offline with a signed key.promptguard.co · 30 Sept 2026
- Integrations
- The site lists integrations/providers including OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM.promptguard.co · 30 Sept 2026
- SDK behavior
- Its SDK can auto-instrument supported LLM calls with one initialization call while leaving existing provider code unchanged.promptguard.co · 30 Sept 2026
- Security data handling
- Zero-retention mode does not store prompt or response content, while default security events record a truncated 500-character preview and content hash.promptguard.co · 30 Sept 2026
- Training
- PromptGuard says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models.promptguard.co · 30 Sept 2026
- Certifications
- The trust page says SOC 2 Type II is not yet certified, ISO 27001 is planned, and GDPR and CCPA are supported.promptguard.co · 30 Sept 2026
- Residency
- The hosted service runs on Google Cloud Run in us-central1, and the company says it does not currently offer a hosted EU region.promptguard.co · 30 Sept 2026
- Support
- Pricing lists community support for Free, email support with a 48-hour response time for Pro, priority support with 24 hours for Scale, and dedicated support with four hours for Enterprise.promptguard.co · 30 Sept 2026
- Trial
- The pricing FAQ says Free is a permanent tier rather than a time-limited trial; paid plans include a 14-day money-back guarantee.promptguard.co · 30 Sept 2026
- Notable limits
- The product says five OWASP LLM Top 10 risks are covered in full and five are partial, with stated gaps including provenance verification and vector-store isolation.promptguard.co · 30 Sept 2026
- Company
- PromptGuard is the trading name of PG Tech Ltd, registered in England and Wales, with a registered office in London.promptguard.co · 30 Sept 2026
Best PromptGuard alternatives
See all 12
7.3 AgentScan $29/mo first paid tier Free plan
7.3 OpenSecureAI Scanner $49/mo first paid tier Free plan
7.3 Project Moonshot Free free plan, no paid price published Free plan
7.2 Giskard Free free plan, no paid price published Free plan
7.2 Promptfoo Free free plan, no paid price published Free plan
7.2 PyRIT Free free plan, no paid price published Free plan Where it ranks on Inferse
Sources
- promptguard.co/about· checked 30 Sept 2026
- promptguard.co/features· checked 30 Sept 2026
- promptguard.co· checked 30 Sept 2026
- promptguard.co/security· checked 30 Sept 2026
- promptguard.co/pricing· checked 30 Sept 2026



