PromptGuard

Input—per 1M tokens
Output—per 1M tokens
Context—tokens
WeightsClosed

About

PromptGuard is a security layer that inspects application requests before they reach an LLM provider. It describes 15 detectors across six layers for risks such as prompt injection, jailbreaks, PII exposure, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. The product says it detects and redacts 43 PII types using reversible tokenization. Its SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. Listed integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM. Deployment choices include managed cloud, hybrid self-hosting, and air-gapped installations; air-gapped licenses validate offline with a signed key. Zero-retention mode does not store prompt or response content, while default security events include a truncated 500-character preview and content hash. The company says customer content is not used to train, fine-tune, or evaluate models. The permanent Free tier includes 20,000 scans monthly, one API key, one project, and 24-hour log retention. Paid plans include a 14-day money-back guarantee, not a trial.

Who it is for

It suits teams that want to inspect LLM requests across listed providers and deployment environments. Teams with strict data handling needs can assess its zero-retention and air-gapped options alongside its stated coverage gaps.

What is good

  • Lists 15 detectors across six threat layers
  • Detects and redacts 43 PII types
  • Supports managed, hybrid, and air-gapped deployment
  • Free tier includes 20,000 monthly scans

What to know first

  • Hosted service has no EU region currently
  • SOC 2 Type II certification is not yet achieved
  • Five OWASP LLM Top 10 risks are only partially covered

Inferse review

PromptGuard: the full review

PromptGuard provides request inspection and multiple deployment patterns, with a permanent Free tier to start. Review its stated OWASP coverage gaps, hosted-region limits, and default event previews against your requirements.

Overview

PromptGuard sits between an application and its LLM provider to inspect requests before they reach a model. It suits teams that want security controls across several providers and deployment patterns; its appeal is tempered by incomplete OWASP coverage and US-only hosted residency.

Key features

Inspection and privacy

PromptGuard describes 15 detectors across six layers, covering threats such as prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware and tool injection. It also supports prompt-injection, jailbreak, data-leakage, unsafe-output and custom tests. This combination serves teams screening live traffic and checking application behavior, but it is not a complete OWASP LLM Top 10 solution: five risks are covered in full and five in part, with provenance verification and vector-store isolation among the gaps.

The product says it detects and redacts 43 PII types using reversible tokenization. Its SDK can instrument supported LLM calls with one initialization call while leaving provider code unchanged, which can reduce integration work for teams already using supported providers. Those include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM.

Deployment and data handling

Managed cloud, hybrid self-hosting and air-gapped deployment let teams choose between a hosted service and tighter infrastructure control. Air-gapped licences validate offline with a signed key. The hosted service runs on Google Cloud Run in us-central1, with no hosted EU region, so organizations requiring EU-hosted processing should look elsewhere or assess a self-hosted option.

Zero-retention mode does not store prompt or response content. By default, security events include a truncated 500-character preview and content hash, a meaningful distinction for teams setting logging policy. PromptGuard says customer prompts, completions and documents are not used to train, fine-tune or evaluate models. GDPR and CCPA are supported; SOC 2 Type II is not yet certified and ISO 27001 is planned.

Pricing

The permanent Free plan costs 0.00 USD per free and includes 20,000 scans a month, one API key, one project and 24-hour log retention. It is a practical starting point for a small evaluation, but the scan, project and key caps constrain broader use. There is no free trial; paid plans include a 14-day money-back guarantee.

Team costs 19.00 USD per month and provides 15,000 scans per seat, pooled, plus a browser extension, macOS and Windows agent, fleet enrollment, MDM and organization-wide policy. It fits teams managing employee-side usage, though its pooled allowance is seat-based rather than a single fixed monthly quota.

Pro costs 99.00 USD per month, with 100,000 scans a month, five API keys, five projects and seven-day log retention. It suits a small production setup that needs more capacity and separation than Free. Scale has custom pricing for 500,000 requests/month, unlimited API keys and projects, and 30-day log retention; overage is metered at $0.40 per 1,000 requests up to a spend cap. Its 48-hour email support on Pro gives way to priority support with a 24-hour response time on Scale.

Enterprise has custom pricing for custom volume, fully air-gapped deployment, SCIM, IP allowlisting, custom retention and dedicated support with a four-hour response SLA. It is the fit for organizations needing isolated deployment and enterprise access controls, rather than teams seeking a published per-seat price. Free includes community support.

Platforms

PromptGuard supports API, browser extension, Linux, macOS, self-hosted, web and Windows environments. That breadth helps teams combine backend inspection with desktop or browser controls, while air-gapped deployment addresses networks that cannot depend on a hosted connection.

Who it's for

PromptGuard is best suited to teams adding inspection to applications already connected to multiple LLM providers, particularly those that need self-hosting, air-gapped options or reversible PII tokenization. It is less suitable when complete OWASP LLM Top 10 coverage, hosted EU residency or an achieved SOC 2 Type II certification is a requirement.

Pros and cons

  • Pros: Broad provider support and SDK auto-instrumentation can add a common inspection layer without changing existing provider code.
  • Pros: Cloud, hybrid and air-gapped choices, plus zero-retention mode, give security teams meaningful deployment and data-handling controls.
  • Pros: A permanent Free tier offers 20,000 monthly scans, making initial evaluation possible without a time-limited trial.
  • Cons: Partial OWASP coverage leaves provenance verification and vector-store isolation among the stated gaps.
  • Cons: Hosted processing is limited to us-central1, which rules out the service for teams requiring a hosted EU region.
  • Cons: Default event previews retain up to 500 characters, so teams wanting no prompt or response content in storage must enable zero-retention mode.

Alternatives

For a broader shortlist, compare LLM Security Tools, AI Security Testing Tools and AI Guardrail Software.

Lasso AI Security Platform is a paid API, extension and web option to consider if those deployment surfaces fit your stack better. WitnessAI is another paid API, web and Windows option, with custom enterprise pricing and no published tiers.

Prisma AIRS AI Gateway may fit teams already working with Software NGFW credits: its consumption-based gateway licensing is billed in credits based on token usage, with required credits determined through sales. SecureAI Guard is a paid API, self-hosted and web alternative without a free plan; its Startup plan is 2999.00 USD per month.

GuardionAI is worth considering when a free trial matters; it offers API, Linux, macOS, self-hosted, web and Windows platforms, with custom enterprise pricing. Amazon Nova Reel is a paid API alternative.

GLACIS is a freemium API, self-hosted and web alternative with a free account at 0.00 USD per free. HiddenLayer AI Guardrails is a paid self-hosted and web option at 5000000.00 USD per year on a 12-month contract; additional AWS infrastructure costs may apply.

Verdict

Choose PromptGuard if your team needs a provider-spanning inspection layer, flexible deployment and controls for sensitive data, with a permanent free tier to begin. Look elsewhere if hosted EU residency or complete OWASP LLM Top 10 coverage is essential; its US-only hosted service and stated coverage gaps are material constraints.

Compared on AI security testing tools

Free plan
Yespromptguard.co

Facts

Product
PromptGuard is a security layer between an application and its LLM provider that inspects requests before they reach the model.promptguard.co · 30 Sept 2026
Threat detection
The product describes 15 detectors across six layers for threats including prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection.promptguard.co · 30 Sept 2026
PII controls
PromptGuard says it detects and redacts 43 PII types, with reversible tokenization.promptguard.co · 30 Sept 2026
Deployment
The product offers managed cloud, hybrid self-hosting, and air-gapped deployment; air-gapped licences validate offline with a signed key.promptguard.co · 30 Sept 2026
Integrations
The site lists integrations/providers including OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM.promptguard.co · 30 Sept 2026
SDK behavior
Its SDK can auto-instrument supported LLM calls with one initialization call while leaving existing provider code unchanged.promptguard.co · 30 Sept 2026
Security data handling
Zero-retention mode does not store prompt or response content, while default security events record a truncated 500-character preview and content hash.promptguard.co · 30 Sept 2026
Training
PromptGuard says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models.promptguard.co · 30 Sept 2026
Certifications
The trust page says SOC 2 Type II is not yet certified, ISO 27001 is planned, and GDPR and CCPA are supported.promptguard.co · 30 Sept 2026
Residency
The hosted service runs on Google Cloud Run in us-central1, and the company says it does not currently offer a hosted EU region.promptguard.co · 30 Sept 2026
Support
Pricing lists community support for Free, email support with a 48-hour response time for Pro, priority support with 24 hours for Scale, and dedicated support with four hours for Enterprise.promptguard.co · 30 Sept 2026
Trial
The pricing FAQ says Free is a permanent tier rather than a time-limited trial; paid plans include a 14-day money-back guarantee.promptguard.co · 30 Sept 2026
Notable limits
The product says five OWASP LLM Top 10 risks are covered in full and five are partial, with stated gaps including provenance verification and vector-store isolation.promptguard.co · 30 Sept 2026
Company
PromptGuard is the trading name of PG Tech Ltd, registered in England and Wales, with a registered office in London.promptguard.co · 30 Sept 2026

Best PromptGuard alternatives

See all 12

Where it ranks on Inferse

Sources