Tech riderRev. 30 Sept 2026
  1. 1Runs onAPI, Browser, Linux, Mac, self-hosted, Web, Windows
  2. 2CostsFree plan · paid from $19/mo
2 lines stated Written from the maker's own pages: promptguard.co
The PromptGuard homepage

Overview

PromptGuard is a security layer between an application and its LLM provider, inspecting requests before they reach the model. It describes 15 detectors across six layers for risks such as prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware and tool injection. The product says it detects and redacts 43 PII types using reversible tokenization. Its SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. Listed providers include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM. Deployment options include managed cloud, hybrid self-hosting and air-gapped installations. In zero-retention mode, prompt and response content is not stored; default security events include a shortened preview and content hash. PromptGuard says customer prompts, completions and documents are not used to train, fine-tune or evaluate models. The Free tier is permanent and includes 20,000 scans a month, one API key, one project and 24-hour log retention. Paid plans include a 14-day money-back guarantee, not a trial.

Who it is for

PromptGuard suits teams adding request inspection and data-protection controls to applications that use LLM providers. Its deployment options include self-hosted and air-gapped environments.

What is good

  • Detects and redacts 43 PII types.
  • Supports managed cloud, hybrid and air-gapped deployment.
  • SDK can instrument supported calls with one initialization.
  • Zero-retention mode does not store prompt or response content.

What to know first

  • No free trial; paid plans have a money-back guarantee instead.
  • Hosted service does not offer an EU region.
  • SOC 2 Type II certification is not yet in place.
  • Five OWASP LLM Top 10 risks are only partially covered.

Specifiction review

PromptGuard: the full review

PromptGuard offers request inspection across many providers and deployment modes, with specific controls for PII and content retention. Consider the stated risk-coverage gaps and hosted region limits against your requirements.

PromptGuard is an inspection layer for applications that send requests to large language models. It suits teams that need to screen LLM traffic and control sensitive data across cloud and self-managed deployments. Its breadth is useful, but incomplete risk coverage and US-only hosted residency rule it out for some requirements.

Overview

PromptGuard sits between an application and its LLM provider, inspecting requests before they reach the model. It describes 15 detectors across six layers, addressing threats such as prompt injection, jailbreaks, data exfiltration, PII, toxicity, fraud, secrets, malware and tool injection. The product also supports tests for prompt injection, jailbreaks, data leakage, unsafe outputs and custom cases, making it relevant to both live traffic screening and application checks.

Coverage is not comprehensive: PromptGuard says it covers five OWASP LLM Top 10 risks in full and five partially. Provenance verification and vector-store isolation are among the gaps, so teams with those controls as requirements should look elsewhere or plan additional safeguards.

Key features

Inspection and privacy controls

PromptGuard says it detects and redacts 43 PII types using reversible tokenization. That can help teams mask sensitive values while retaining the ability to restore them. Its SDK can auto-instrument supported LLM calls with one initialization call, leaving existing provider code unchanged; this is a practical advantage for teams adding inspection to an established application.

Zero-retention mode avoids storing prompt or response content. In the default mode, security events retain a truncated 500-character preview and a content hash, a meaningful distinction for organizations setting log policies. PromptGuard says customer prompts, completions and documents are never used to train, fine-tune or evaluate models.

Deployment and integrations

Managed cloud, hybrid self-hosting and air-gapped deployment accommodate different operational constraints. Air-gapped licences validate offline with a signed key, which is relevant to isolated environments. Integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM, giving teams several provider choices without making the product itself a model provider.

The hosted service runs on Google Cloud Run in us-central1, and PromptGuard does not offer a hosted EU region. Organizations that require hosted EU residency should not assume self-hosted options resolve that requirement without checking their deployment needs. GDPR and CCPA are supported; SOC 2 Type II is not yet certified, and ISO 27001 is planned.

Pricing

PromptGuard uses a freemium model. The permanent Free plan costs 0.00 USD per free and includes 20,000 scans a month, one API key, one project and 24-hour log retention. With community support and a single project, it is a sensible evaluation tier, but its short retention and narrow project limit constrain ongoing multi-project use. There is no free trial; paid plans include a 14-day money-back guarantee.

Team costs 19.00 USD per month and provides 15,000 scans per seat, pooled, plus a browser extension, macOS and Windows agent, fleet enrollment, MDM and organization-wide policy. It is the entry paid choice for teams that need endpoint management and shared policy, though the quota is tied to seats rather than a single monthly allowance.

Pro costs 99.00 USD per month for 100,000 scans a month, five API keys, five projects and seven-day log retention. It fits teams running several integrations or projects that need more capacity than Free; the published plan facts do not describe Team's extension and fleet features as part of Pro.

Scale has custom pricing and includes 500,000 requests a month, unlimited API keys and projects, and 30-day log retention. Overage is metered at $0.40 per 1,000 requests up to a spend cap, so buyers should account for consumption beyond quota. Enterprise also has custom pricing, with custom volume, fully air-gapped deployment, SCIM, IP allowlist, custom retention and dedicated support with a four-hour response SLA. Support steps up from community on Free to email with a 48-hour response time on Pro, priority with 24 hours on Scale, and dedicated four-hour response on Enterprise.

Platforms

PromptGuard is offered across API, browser extension, Linux, macOS, self-hosted, web and Windows. That range supports both service integration and managed endpoint use, while hybrid and air-gapped deployment give security teams options beyond the hosted service.

Who it's for

PromptGuard is best suited to organizations building LLM applications that want request inspection, PII controls and deployment flexibility across multiple providers. Free can serve a small proof of concept; Team adds endpoint and fleet controls, while Pro raises scan and project capacity. Scale and Enterprise address higher volume, longer retention or tightly controlled deployment needs.

It is a weaker fit for buyers requiring complete coverage of the OWASP LLM Top 10, hosted EU residency, or an already-achieved SOC 2 Type II certification. Its own stated coverage gaps and trust posture make those requirements worth resolving before choosing a plan.

Pros and cons

  • Pros: Reversible tokenization across 43 PII types gives teams a specific privacy control rather than detection alone.
  • Pros: Managed, hybrid and air-gapped deployment, with offline licence validation, serve environments with different connectivity constraints.
  • Pros: Auto-instrumentation can add checks without changing supported provider code, reducing integration disruption.
  • Cons: Five OWASP LLM Top 10 risks are only partially covered, including gaps such as provenance verification and vector-store isolation.
  • Cons: Hosted service is in us-central1 with no hosted EU region, limiting it for residency-bound deployments.
  • Cons: SOC 2 Type II certification has not been achieved, which may disqualify it for some assurance requirements.

Alternatives

Consider LLM Security Tools, AI Guardrail Software or AI Security Testing Tools to compare options in those categories.

GuardionAI is a paid alternative with a free trial and an Enterprise plan offering unlimited requests and seats under custom contract pricing; consider it if those terms suit your procurement better.

Amazon Bedrock Guardrails is a paid, web-platform option with separately priced text content filters and denied topics, plus free image content filters; it may suit buyers comparing those specific controls and charges.

Openlayer Guardrails offers a free tier with 20,000 inference logs a month, 20 tests per project and three months of data retention, making it worth considering for test- and log-focused evaluation.

WitnessAI is a paid alternative with custom-priced Enterprise service and API, web and Windows platforms.

GLACIS offers a free account and API, self-hosted and web platforms, and may suit buyers comparing free-entry options.

Lasso AI Security Platform is a paid option with API, extension and web platforms.

HiddenLayer AI Guardrails is a paid, self-hosted and web option with a listed platform price of 5000000.00 USD per year on a 12-month contract; additional AWS infrastructure costs may apply.

Prisma AIRS AI Gateway uses consumption-based licensing through Software NGFW credits tied to token usage, with the required credits determined through sales.

Verdict

Choose PromptGuard if you need broad provider coverage, practical PII handling and a path from managed cloud to self-hosted or air-gapped deployment. Its strongest case is the combination of request inspection and deployment choice; look elsewhere if hosted EU residency, complete OWASP LLM Top 10 coverage or current SOC 2 Type II certification is non-negotiable.

PromptGuard plans and pricing

All plans
Free Free 20,000 scans a month · 1 API key · 1 project · 24-hour log retention promptguard.co · 30 Sept 2026
Team $19/mo 15,000 scans per seat, pooled · browser extension and macOS/Windows agent · fleet enrollment, MDM, org-wide policy promptguard.co · 30 Sept 2026
Pro $99/mo 100,000 scans a month · 5 API keys · 5 projects · 7-day log retention promptguard.co · 30 Sept 2026
Scale Not published 500,000 requests/month · unlimited API keys and projects · 30-day log retention · overage metered at $0.40 per 1,000 requests up to spend cap promptguard.co · 30 Sept 2026
Enterprise Not published Custom volume · fully air-gapped deployment · SCIM · IP allowlist · custom retention · dedicated support with 4-hour response SLA promptguard.co · 30 Sept 2026

Compared on AI security testing tools

Free plan
Yespromptguard.co

Facts

Product
PromptGuard is a security layer between an application and its LLM provider that inspects requests before they reach the model.promptguard.co · 30 Sept 2026
Threat detection
The product describes 15 detectors across six layers for threats including prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection.promptguard.co · 30 Sept 2026
PII controls
PromptGuard says it detects and redacts 43 PII types, with reversible tokenization.promptguard.co · 30 Sept 2026
Deployment
The product offers managed cloud, hybrid self-hosting, and air-gapped deployment; air-gapped licences validate offline with a signed key.promptguard.co · 30 Sept 2026
Integrations
The site lists integrations/providers including OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM.promptguard.co · 30 Sept 2026
SDK behavior
Its SDK can auto-instrument supported LLM calls with one initialization call while leaving existing provider code unchanged.promptguard.co · 30 Sept 2026
Security data handling
Zero-retention mode does not store prompt or response content, while default security events record a truncated 500-character preview and content hash.promptguard.co · 30 Sept 2026
Training
PromptGuard says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models.promptguard.co · 30 Sept 2026
Certifications
The trust page says SOC 2 Type II is not yet certified, ISO 27001 is planned, and GDPR and CCPA are supported.promptguard.co · 30 Sept 2026
Residency
The hosted service runs on Google Cloud Run in us-central1, and the company says it does not currently offer a hosted EU region.promptguard.co · 30 Sept 2026
Support
Pricing lists community support for Free, email support with a 48-hour response time for Pro, priority support with 24 hours for Scale, and dedicated support with four hours for Enterprise.promptguard.co · 30 Sept 2026
Trial
The pricing FAQ says Free is a permanent tier rather than a time-limited trial; paid plans include a 14-day money-back guarantee.promptguard.co · 30 Sept 2026
Notable limits
The product says five OWASP LLM Top 10 risks are covered in full and five are partial, with stated gaps including provenance verification and vector-store isolation.promptguard.co · 30 Sept 2026
Company
PromptGuard is the trading name of PG Tech Ltd, registered in England and Wales, with a registered office in London.promptguard.co · 30 Sept 2026

Best PromptGuard alternatives

See all 20

Where it ranks on Specifiction

Is PromptGuard yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources