PromptGuard is a security layer that checks application requests before they reach an LLM provider. Its 15 detectors across six layers are described as covering prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. It can detect and redact 43 PII types with reversible tokenization. The SDK can instrument supported LLM calls with one initialization call, without changing existing provider code. Listed integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM. Deployment choices include managed cloud, hybrid self-hosting, and air-gapped installations. Zero-retention mode avoids storing prompt and response content; default security events retain a shortened 500-character preview and content hash. The free tier includes 20,000 monthly scans, one API key, one project, and 24-hour log retention. Paid plans start at 19.00 USD per month. The hosted service runs in us-central1 and has no hosted EU region listed.
Who it is for
It suits teams adding request screening to LLM applications, including those needing self-hosted or air-gapped deployment. The free tier may suit smaller projects that fit its monthly scan, key, project, and retention limits.
What is good
- 15 detectors cover threats across six layers.
- Detects and redacts 43 PII types.
- SDK instrumentation can leave provider code unchanged.
- Offers managed, hybrid, and air-gapped deployment.
- Free tier includes 20,000 scans monthly.
What to know first
- Free tier has one API key and one project.
- Free logs are retained for 24 hours.
- No hosted EU region is currently offered.
- SOC 2 Type II certification is not yet achieved.
Freedom251 review
PromptGuard: the full review
PromptGuard combines LLM request screening with deployment choices from managed cloud to air-gapped operation. Check scan limits, data residency, retention, and stated coverage gaps before choosing a plan.
PromptGuard is an inspection layer for applications that send requests to large language models. It best suits teams that need to screen LLM traffic while choosing between managed, self-hosted, and air-gapped deployment; its main trade-off is incomplete stated coverage and a hosted service limited to a US region.
Overview
PromptGuard sits between an application and its LLM provider to inspect requests before they reach the model. It describes 15 detectors across six layers, covering threats such as prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. That breadth makes it relevant to teams building security controls into LLM applications, but it is not a complete answer to every LLM risk: five OWASP LLM Top 10 risks are covered in full and five only partially, with provenance verification and vector-store isolation among the stated gaps.
Key features
Inspection, testing, and data handling
PromptGuard says it detects and redacts 43 types of PII, with reversible tokenization. That can help teams mask sensitive values while retaining a path to restore them. Tests cover prompt injection, jailbreaks, data leakage, unsafe outputs, and custom cases, giving security teams a way to check more than incoming requests alone.
The SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. That is useful for teams seeking to add screening without rewriting provider code, though support is limited to supported calls. Integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM.
Deployment and trust
Managed cloud, hybrid self-hosting, and air-gapped deployment offer meaningful choices for organizations with different infrastructure constraints. Air-gapped licences validate offline with a signed key, a practical fit where network access is restricted. Hosted service runs on Google Cloud Run in us-central1, and the company does not offer a hosted EU region, so European teams requiring EU-hosted service should consider self-hosting or another option.
Zero-retention mode does not store prompt or response content. By default, security events include a truncated 500-character preview and content hash, so teams handling sensitive traffic should weigh that default against their retention requirements. The company says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models. GDPR and CCPA are supported, but SOC 2 Type II is not yet certified and ISO 27001 is planned.
Pricing
PromptGuard is freemium. Free is a permanent tier, not a timed trial; paid plans include a 14-day money-back guarantee. There is no free trial.
- Free — 0.00 USD per free: 20,000 scans a month, one API key, one project, 24-hour log retention, and community support. It is a sensible way to start, but the short retention and single-key, single-project limits constrain ongoing or multi-environment use.
- Team — 19.00 USD per month: 15,000 scans per seat, pooled, plus browser extension, macOS/Windows agent, fleet enrollment, MDM, and organization-wide policy. It suits teams needing endpoint and fleet controls; the pooled per-seat quota should be checked against expected traffic.
- Pro — 99.00 USD per month: 100,000 scans a month, five API keys, five projects, and seven-day log retention. This is better suited to teams managing several integrations or projects, though the fixed quota and key cap remain meaningful constraints.
- Scale — custom pricing: 500,000 requests/month, unlimited API keys and projects, 30-day log retention, and overage metered at $0.40 per 1,000 requests up to a spend cap. It fits higher-volume deployments that need longer retention and room to scale; the overage rate makes usage monitoring important.
- Enterprise — custom pricing: custom volume, fully air-gapped deployment, SCIM, IP allowlist, custom retention, and dedicated support with a four-hour response SLA. It is the fit for organizations with isolation, access-control, or support requirements that exceed the lower tiers.
Support steps up with the plans: Free has community support, Pro email support with a 48-hour response time, Scale priority support with a 24-hour response time, and Enterprise dedicated support with a four-hour response SLA. Team support terms are not given.
Platforms
PromptGuard supports API, browser extension, Linux, macOS, self-hosted, web, and Windows. Its deployment modes span managed cloud, hybrid self-hosting, and air-gapped operation, making it more flexible than a cloud-only screening layer.
Who it's for
Choose PromptGuard if you need request screening, PII controls, and deployment options that can extend to air-gapped environments. It is less suitable if you need complete coverage of the stated OWASP risk set, a hosted EU region, or SOC 2 Type II certification today.
Pros and cons
- Pro: Managed, hybrid, and air-gapped deployment accommodate organizations with distinct hosting and network constraints.
- Pro: Reversible tokenization and zero-retention mode provide useful controls for sensitive prompts and responses.
- Pro: SDK auto-instrumentation can add screening without changing existing provider code.
- Con: Hosted service is in us-central1 with no hosted EU region, limiting the fit for EU-residency requirements.
- Con: Stated coverage leaves some OWASP risks partial, including gaps such as provenance verification and vector-store isolation.
- Con: SOC 2 Type II certification has not yet been achieved, which may matter to buyers with formal assurance requirements.
Alternatives
Consider Enkrypt AI Guardrails for a freemium API, self-hosted, or web option with a free tier that starts with 500 credits, then 50 credits per month and seven-day data retention.
Fiddler Guardrails is another freemium API, self-hosted, and web alternative; its free plan targets harmful exposure including hallucinations, toxicity, PII/PHI, prompt injection, and jailbreak attempts, with latency under 80ms.
Openlayer Guardrails may suit teams prioritizing a free testing-oriented tier: Basic includes one member, five projects, one inference pipeline per project, 20,000 inferences per month, 20 tests per project, and three months of data retention.
OpenSecureAI Prompt Firewall is a freemium self-hosted and web option whose free plan includes in-browser tools and npm packages, 2,000 API requests per month, and 30 requests per minute per key.
Oracle Mobile Authenticator is a free alternative for Android, iOS, and Windows.
Pangea AI Guard is a freemium alternative across API, extension, and self-hosted platforms.
CyberSecEval is a free alternative.
HiddenLayer AI Runtime Security is a paid alternative for API, Linux, self-hosted, and web deployments.
Browse AI Guardrail Software, LLM Security Tools, and AI Security Testing Tools for more options.
Verdict
PromptGuard is a strong candidate for teams that need broad request screening with deployment flexibility, especially when hybrid or air-gapped operation matters. Its principal reasons to look elsewhere are the stated coverage gaps and the lack of a hosted EU region or current SOC 2 Type II certification.
PromptGuard plans and pricing
All plansCompared on AI security testing tools
- Free plan
- Yes


