PromptGuard is a security layer between an application and its LLM provider that checks requests before they reach the model. It describes 15 detectors across six layers for threats such as prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware and tool injection. The product says it detects and redacts 43 PII types with reversible tokenization. Its SDK can automatically instrument supported LLM calls with one initialization call while leaving existing provider code unchanged. Listed providers include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM. Deployment choices include managed cloud, hybrid self-hosting and air-gapped deployment. Zero-retention mode does not store prompt or response content; default security events retain a shortened preview and content hash. PromptGuard says customer content is not used to train, fine-tune or evaluate models. The permanent Free tier includes 20,000 scans a month, one API key, one project and 24-hour log retention. Paid plans include a 14-day money-back guarantee, not a trial.
Who it is for
It suits teams adding request inspection and PII controls to applications that use LLM providers. Its deployment options include managed cloud, hybrid self-hosting and air-gapped use.
What is good
- Describes 15 detectors across six layers.
- Detects and redacts 43 PII types.
- Supports multiple named LLM providers.
- Offers managed cloud, hybrid self-hosting and air-gapped deployment.
- Free tier includes 20,000 monthly scans.
What to know first
- No time-limited free trial is offered.
- Hosted service does not currently offer an EU region.
- Five OWASP LLM Top 10 risks are only partially covered.
The Geeks Club review
PromptGuard: the full review
PromptGuard offers request inspection, data controls and several deployment modes for LLM applications. Review its stated coverage gaps and hosted-region limits against your requirements.
Overview
PromptGuard screens application requests before they reach an LLM provider, for teams that need security controls around model traffic. It combines broad threat detection with privacy controls and multiple deployment modes, but its hosted service is US-based and its stated OWASP coverage has gaps.
Key features
Threat detection and testing
PromptGuard describes 15 detectors across six layers for risks including prompt injection, jailbreaks, PII, data exfiltration, toxicity, fraud, secrets, malware and tool injection. It also supports tests for prompt injection, jailbreaks, data leakage, unsafe outputs and custom cases. That mix suits teams looking to screen live requests and assess application behavior; it is not a complete answer to LLM application security. PromptGuard says it covers five OWASP LLM Top 10 risks in full and five partially, with provenance verification and vector-store isolation among the gaps.
Privacy, integrations and deployment
The product says it detects and redacts 43 PII types, with reversible tokenization. This can mask sensitive values while preserving the option to restore them. Its SDK can instrument supported LLM calls with one initialization call and leave existing provider code unchanged, reducing the integration work for teams already using supported providers. Those include OpenAI, Anthropic, Gemini, Azure, Bedrock, Mistral, Cohere, DeepSeek, Groq, HuggingFace, Ollama and vLLM.
Managed cloud, hybrid self-hosting and air-gapped deployment give organizations options for different infrastructure and control requirements. Air-gapped licences validate offline with a signed key. In zero-retention mode, prompt and response content is not stored; default security events instead retain a truncated 500-character preview and content hash. PromptGuard says customer prompts, completions and documents are never used to train, fine-tune or evaluate models.
The hosted service runs on Google Cloud Run in us-central1, and the company says it does not offer a hosted EU region. Organizations that require EU-hosted service should weigh that limitation or consider self-hosting. GDPR and CCPA are supported; SOC 2 Type II certification has not yet been achieved, and ISO 27001 is planned.
Pricing
PromptGuard has a permanent free tier rather than a time-limited trial. Paid plans include a 14-day money-back guarantee, and no free trial is offered.
| Plan | Price | What it includes |
|---|---|---|
| Free | 0.00 USD per free | 20,000 scans a month, 1 API key, 1 project and 24-hour log retention; community support. |
| Team | 19.00 USD per month | 15,000 scans per seat, pooled; browser extension, macOS and Windows agent, fleet enrollment, MDM and org-wide policy; email support with a 48-hour response time. |
| Pro | 99.00 USD per month | 100,000 scans a month, 5 API keys, 5 projects and 7-day log retention. |
| Scale | Custom pricing | 500,000 requests a month, unlimited API keys and projects, 30-day log retention, and overage metered at $0.40 per 1,000 requests up to a spend cap; priority support with a 24-hour response time. |
| Enterprise | Custom pricing | Custom volume, fully air-gapped deployment, SCIM, IP allowlist, custom retention and dedicated support with a four-hour response SLA. |
Free is a useful starting point for a small project, but the single key and project, low retention and community support constrain team use. Team adds desktop and browser tooling, fleet management and pooled per-seat scans; its 15,000-scan allowance is a meaningful limit to check against expected traffic. Pro raises the monthly quota and key, project and retention caps, but costs more and does not state the Team plan's fleet features. Scale is aimed at higher-volume use, with an explicit overage rate and spend cap; Enterprise is the fit for custom volumes and air-gapped deployments. Both use custom pricing.
Platforms
PromptGuard supports API, browser extension, Linux, macOS, self-hosted, web and Windows. Its deployment options span managed cloud, hybrid self-hosting and air-gapped installations, making it more flexible than a hosted-only gateway for organizations with strict infrastructure constraints.
Who it's for
PromptGuard is best suited to teams adding inspection and data controls to applications that use multiple LLM providers, especially where self-hosting or offline deployment matters. Smaller projects can start on Free, while teams that need organizational policy and endpoint tooling have a more relevant fit in Team. It is a weaker choice for organizations that require a hosted EU region or complete OWASP LLM Top 10 coverage.
Pros and cons
Pros
- Flexible deployment: Managed cloud, hybrid self-hosting and fully air-gapped deployment cover varied infrastructure requirements.
- Broad provider support: The named integrations range from major cloud providers to Ollama and vLLM, useful for teams working across hosted and local models.
- Practical privacy controls: Reversible PII tokenization and zero-retention mode address sensitive data handling, while default event previews are limited to 500 characters.
- Low-cost entry point: The permanent free tier includes 20,000 monthly scans, although its single project and API key limit its scope.
Cons
- Hosted region constraint: The hosted service runs in us-central1, with no hosted EU region.
- Incomplete stated OWASP coverage: Five risks are only partially covered, and provenance verification and vector-store isolation are named gaps.
- Certification status: SOC 2 Type II is not yet certified, while ISO 27001 remains planned.
- Plan limits need scrutiny: Free has only 24-hour log retention, and Team's scans are capped per seat even though pooled.
Alternatives
For an LLM security shortlist, compare LLM Security Tools, AI Guardrail Software and AI Security Testing Tools.
- Amazon Bedrock Guardrails is a paid, web-based option with separately priced text content filters and denied topics, and image content filters listed at 0.00 USD per month. Choose it when those Bedrock guardrail controls and their listed pricing fit better than PromptGuard's broader deployment choices.
- GuardionAI is a paid alternative with a free trial and an Enterprise plan billed by custom contract, offering unlimited requests and seats with up to 365-day log retention. Consider it if a trial and longer retention matter more than PromptGuard's published entry-level plans.
- Openlayer Guardrails has a free Basic plan with one member, five projects, 20,000 inference logs per month, 20 tests per project and three months of data retention. It is worth considering when those testing and retention limits suit your needs and PromptGuard's threat-inspection deployment options are not essential.
- GLACIS offers a free account with no card required and setup described as taking about a minute, for readers who prioritize a simple free entry point.
- WitnessAI is a paid API, web and Windows option with custom Enterprise pricing.
- Lasso AI Security Platform is a paid option for API, extension and web platforms.
- Prisma AIRS AI Gateway is a paid API, self-hosted and web option with consumption-based licensing through Software NGFW credits metered by token usage. Consider it when token-based gateway licensing better fits your procurement model.
- HiddenLayer AI Guardrails is a paid, self-hosted and web option priced at 5000000.00 USD per year on a 12-month contract; additional AWS infrastructure costs may apply. It is a different price and contract commitment from PromptGuard's free and per-month entry plans.
Verdict
Choose PromptGuard if your team needs request inspection, reversible PII controls and deployment flexibility across cloud, self-hosted or air-gapped environments. Its strongest case is combining provider breadth with those data controls; look elsewhere if hosted EU residency or more complete OWASP LLM Top 10 coverage is a requirement.
PromptGuard plans and pricing
All plansCompared on AI security testing tools
- Free plan
- Yes


