OpenSecureAI Prompt Firewall checks text before it reaches an LLM and applies a policy to allow, flag, or block it. Its separate prompt-injection and PII/secrets engines identify risks, then the policy blocks injection or secrets while redacting and flagging PII. The live demonstration runs entirely in the browser and says nothing is uploaded. Developers can also use the open-source, dependency-free core as an npm package or CLI in applications and CI. The CLI reads files or standard input and can return a nonzero exit code when findings reach a chosen threshold. The middleware can check both model inputs and outputs. An API key unlocks hosted detections for obfuscation, indirect injection, tool abuse, multilingual overrides, and de-obfuscation. The LLM Gateway supports OpenAI, Anthropic, xAI, and Groq using users’ own provider keys; OpenSecureAI says those keys are not stored or logged. Free includes 2,000 API requests per month; Pro costs $49/month and includes 50,000 requests per month.
Who it is for
It is aimed at AI application teams deploying LLM features and developers building agents. The npm package and CLI also suit teams that want checks in applications or CI.
What is good
- Checks both model inputs and outputs
- Open-source, dependency-free npm package and CLI
- Free plan includes 2,000 API requests monthly
- Gateway supports four listed providers
- Browser demonstration says nothing is uploaded
What to know first
- Hosted enhanced detections require an API key
- Team seats and SSO are planned, not listed as available
Verdict
Prompt Firewall combines policy-based blocking and redaction with browser, package, and CLI options. Teams should distinguish the core checks from hosted detections unlocked by an API key.
OpenSecureAI Prompt Firewall plans and pricing
All plansCompared on AI guardrail software
- Free plan
- Yes
- Paid from
- $49/mo
- Deployment
- hybrid
- Prompt injection defense
- Yes
- PII detection
- Yes
- Jailbreak detection
- Yes
- Custom policies
- Yes
- SDK languages
- TypeScript




