PromptGuard

B
B tier on AI Security Testing ToolsScore 7.2 · #3 of 29
Android app
Not listed
Free plan
Yes
Paid plans from
$19/mo
Runs on
api, Browser extension, Linux, Mac, self-hosted, Web, Windows
promptguard.co
The PromptGuard homepage

Summary

PromptGuard is a security layer between an application and its LLM provider that inspects requests before they reach the model. It describes 15 detectors across six layers for risks including prompt injection, jailbreaks, personal information exposure, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. The product says it can detect and redact 43 PII types using reversible tokenization. Its SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. Listed providers include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM. Deployment options include managed cloud, hybrid self-hosting, and air-gapped installations. In zero-retention mode, prompt and response content is not stored; default security events record a shortened preview and content hash. PromptGuard says customer content is not used to train, fine-tune, or evaluate models. The permanent Free tier includes 20,000 scans monthly, one API key, one project, and 24-hour log retention. Paid plans include a 14-day money-back guarantee, not a trial.

Who it is for

PromptGuard suits teams that want to inspect LLM requests before they reach a provider, with deployment options ranging from managed cloud to air-gapped installation. It may suit teams seeking PII controls or integrations with the listed providers.

What is good

  • Detects and redacts 43 PII types.
  • Offers managed, hybrid, and air-gapped deployment.
  • SDK can instrument supported calls with one initialization.
  • Zero-retention mode does not store prompt or response content.
  • Free tier includes 20,000 scans monthly.

What to know first

  • Hosted service does not currently offer an EU region.
  • SOC 2 Type II certification is not yet complete.
  • Free tier retains logs for 24 hours.
  • Paid plans have a money-back guarantee, not a trial.

Everything Xiaomi review

PromptGuard: the full review

PromptGuard offers request inspection, PII controls, and several deployment modes, with a free tier for smaller scan volumes. Consider its hosted-region limitation and log-retention settings when assessing fit.

Overview

PromptGuard is an inspection layer for applications that send requests to large language models, aimed at teams that need to screen traffic and control sensitive data. Its broad detection coverage and flexible deployment make it a strong fit for security-conscious LLM projects, though hosted customers must account for US-only service residency.

Key features

Threat detection and privacy controls

PromptGuard describes 15 detectors across six layers, covering prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection. It also supports tests for prompt injection, jailbreaks, data leakage, unsafe outputs, and custom cases, giving teams ways to check both incoming risks and output behavior. The stated OWASP LLM Top 10 coverage is not complete: five risks are covered in full and five partially, with provenance verification and vector-store isolation among the gaps.

The product says it detects and redacts 43 PII types, with reversible tokenization. That offers a way to mask sensitive values while retaining the option to restore them. Its SDK can automatically instrument supported LLM calls with one initialization call and leave existing provider code unchanged, which should suit teams that want to add inspection without rewriting provider integrations.

Deployment and data handling

Managed cloud, hybrid self-hosting, and air-gapped deployment give organizations different ways to place the security layer. Air-gapped licences validate offline with a signed key, a meaningful option for environments that cannot depend on a hosted service. The hosted service runs on Google Cloud Run in us-central1, and PromptGuard does not offer a hosted EU region; organizations requiring EU-hosted processing should look elsewhere or consider self-hosting.

Zero-retention mode stores no prompt or response content. In the default mode, security events keep a truncated 500-character preview and a content hash, so teams should weigh the operational value of event context against their own retention requirements. PromptGuard says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models. GDPR and CCPA are supported, but SOC 2 Type II certification has not yet been achieved and ISO 27001 is planned.

Integrations include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM, spanning hosted providers and local model stacks.

Pricing

PromptGuard has a permanent free tier rather than a time-limited trial. Paid plans include a 14-day money-back guarantee; no free trial is offered.

  • Free: 0.00 USD per free, with 20,000 scans a month, one API key, one project, 24-hour log retention, and community support. It is a useful starting point for small deployments, but the single key and short retention limit team use and incident review.
  • Team: 19.00 USD per month, with 15,000 scans per seat pooled, a browser extension and macOS/Windows agent, fleet enrollment, MDM, and organization-wide policy. This is the entry paid option for teams that need endpoint and fleet controls; scan volume scales by seat.
  • Pro: 99.00 USD per month, with 100,000 scans a month, five API keys, five projects, seven-day log retention, and email support with a 48-hour response time. It suits teams running several projects that need more capacity and longer review history than Free provides.
  • Scale: custom pricing for 500,000 requests/month, unlimited API keys and projects, and 30-day log retention. Overage is metered at $0.40 per 1,000 requests up to a spend cap. Priority support has a 24-hour response time, making this tier a fit for higher-volume operations that need faster help.
  • Enterprise: custom pricing for custom volume, fully air-gapped deployment, SCIM, IP allowlist, custom retention, and dedicated support with a four-hour response SLA. It is the strongest fit for organizations with isolation or access-control requirements, but requires a custom quote.

Free is the only clearly capped low-cost option; Team adds fleet management but uses a pooled per-seat quota, while Pro raises the monthly allowance and project count. Scale and Enterprise move to custom pricing, so buyers needing their capacity or controls should assess the quote alongside the relevant retention and support terms.

Platforms

PromptGuard supports API, browser extension, Linux, macOS, self-hosted, web, and Windows. This range works for teams integrating at the application layer as well as those deploying agents or keeping infrastructure in-house.

Who it's for

PromptGuard is best suited to teams putting LLM applications into production that want request screening, PII controls, and a choice of managed, hybrid, or air-gapped deployment. Its provider breadth and instrumentation approach favor teams already using supported model services or local stacks. It is less suitable for organizations that require an EU-hosted region, complete OWASP LLM Top 10 coverage, or an existing SOC 2 Type II certification.

Pros and cons

  • Pro: Broad threat coverage and tests for injection, jailbreaks, leakage, unsafe outputs, and custom cases support both screening and application checks.
  • Pro: Reversible tokenization for 43 PII types and zero-retention mode give privacy-conscious teams concrete controls over content handling.
  • Pro: Hybrid and air-gapped deployments, including offline licence validation, accommodate restricted environments.
  • Con: Hosted service is limited to us-central1, so it does not meet a requirement for an EU-hosted region.
  • Con: OWASP coverage has stated partial areas, including provenance verification and vector-store isolation, leaving some risks to other controls.
  • Con: Default security events retain a 500-character preview, and Free retains logs for only 24 hours; organizations should select modes and plans with those periods in mind.

Alternatives

  • Enkrypt AI Guardrails is another freemium option with API, self-hosted, and web platforms; its Explore tier is free forever with 500 starting credits, 50 credits per month, seven-day data retention, and community support, so it may suit readers comparing credit-based entry plans.
  • OpenSecureAI Prompt Firewall offers self-hosted and web platforms with a free tier, making it an alternative for readers comparing deployment choices.
  • Fiddler Guardrails is a freemium API, self-hosted, and web option whose free tier covers harmful exposure, hallucinations, toxicity, PII/PHI, prompt injection, and jailbreak attempts; choose it when that stated free-tier focus is a closer match.
  • Openlayer Guardrails is a freemium API, self-hosted, and web alternative with a free Basic tier; consider it when comparing guardrail options with a free starting plan.
  • Pangea AI Guard is a freemium alternative available for API, extension, and self-hosted use.
  • Oracle Mobile Authenticator is a free alternative for Android, iOS, and Windows.
  • HiddenLayer AI Runtime Security is a paid option for API, Linux, self-hosted, and web platforms.
  • Radware Alteon is a paid API, Linux, self-hosted, and web option with custom-priced Alteon Perform.

Browse the AI Guardrail Software, LLM Security Tools, and AI Security Testing Tools lists for related options.

Verdict

PromptGuard is a strong choice for teams that want broad LLM request inspection, reversible PII masking, and deployment options that extend to air-gapped environments. Its main trade-offs are the lack of an EU hosted region, incomplete coverage of several OWASP risks, and plan-dependent log retention; choose another tool if those constraints conflict with your security or residency requirements.

PromptGuard plans and pricing

All plans
Free Free 20,000 scans a month · 1 API key · 1 project · 24-hour log retention promptguard.co · 30 Sept 2026
Team $19/mo 15,000 scans per seat, pooled · browser extension and macOS/Windows agent · fleet enrollment, MDM, org-wide policy promptguard.co · 30 Sept 2026
Pro $99/mo 100,000 scans a month · 5 API keys · 5 projects · 7-day log retention promptguard.co · 30 Sept 2026
Scale Not published 500,000 requests/month · unlimited API keys and projects · 30-day log retention · overage metered at $0.40 per 1,000 requests up to spend cap promptguard.co · 30 Sept 2026
Enterprise Not published Custom volume · fully air-gapped deployment · SCIM · IP allowlist · custom retention · dedicated support with 4-hour response SLA promptguard.co · 30 Sept 2026

Compared on AI security testing tools

Free plan
Yespromptguard.co

Facts

Product
PromptGuard is a security layer between an application and its LLM provider that inspects requests before they reach the model.promptguard.co · 30 Sept 2026
Threat detection
The product describes 15 detectors across six layers for threats including prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware, and tool injection.promptguard.co · 30 Sept 2026
PII controls
PromptGuard says it detects and redacts 43 PII types, with reversible tokenization.promptguard.co · 30 Sept 2026
Deployment
The product offers managed cloud, hybrid self-hosting, and air-gapped deployment; air-gapped licences validate offline with a signed key.promptguard.co · 30 Sept 2026
Integrations
The site lists integrations/providers including OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama, and vLLM.promptguard.co · 30 Sept 2026
SDK behavior
Its SDK can auto-instrument supported LLM calls with one initialization call while leaving existing provider code unchanged.promptguard.co · 30 Sept 2026
Security data handling
Zero-retention mode does not store prompt or response content, while default security events record a truncated 500-character preview and content hash.promptguard.co · 30 Sept 2026
Training
PromptGuard says customer prompts, completions, and documents are never used to train, fine-tune, or evaluate models.promptguard.co · 30 Sept 2026
Certifications
The trust page says SOC 2 Type II is not yet certified, ISO 27001 is planned, and GDPR and CCPA are supported.promptguard.co · 30 Sept 2026
Residency
The hosted service runs on Google Cloud Run in us-central1, and the company says it does not currently offer a hosted EU region.promptguard.co · 30 Sept 2026
Support
Pricing lists community support for Free, email support with a 48-hour response time for Pro, priority support with 24 hours for Scale, and dedicated support with four hours for Enterprise.promptguard.co · 30 Sept 2026
Trial
The pricing FAQ says Free is a permanent tier rather than a time-limited trial; paid plans include a 14-day money-back guarantee.promptguard.co · 30 Sept 2026
Notable limits
The product says five OWASP LLM Top 10 risks are covered in full and five are partial, with stated gaps including provenance verification and vector-store isolation.promptguard.co · 30 Sept 2026
Company
PromptGuard is the trading name of PG Tech Ltd, registered in England and Wales, with a registered office in London.promptguard.co · 30 Sept 2026

Best PromptGuard alternatives

See all 12

Where it ranks on Everything Xiaomi

Is PromptGuard yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources