Prompt Guard · For apps that use AI

Check sensitive text before your app sends it to AI.

Building a support assistant, internal chatbot or another AI-powered app? Prompt Guard checks outgoing text for supported private information, such as email addresses and API keys. It can replace detected values or block the request before it reaches OpenAI, Anthropic or Gemini.

You need a developer to connect it to your software. It does not automatically protect conversations on the ChatGPT website or other AI websites.

Free browser demo · 100 free hosted requests · Paid plan: $19 USD/month

A customer email goes in. A placeholder comes out.

Suppose your app asks AI to summarize a support message. With the replace option selected, a detected email address is removed before the text is forwarded.

Before the check

“Please contact alex@example.com about the delayed order.”

After the check

“Please contact [email removed] about the delayed order.”

Illustrative placeholder. The interactive example below shows the scanner's actual output. Detection is pattern-based: it will not catch every kind of private information.

Try it free

Browser scanner: no account needed. Paste sample text and see what would be replaced or blocked. This demo stays in your browser and does not contact an AI provider.

Connected app: 100 free hosted requests. Create an account, save a policy and connect your app to test the hosted service.

Use it in your app: $19/month

Includes 10,000 hosted text requests per UTC month, saved rules, employee keys with provider permissions, and 30 days of activity metadata.

Your AI provider bills separately. No overage charges: requests stop when the allowance is used up. Plus applicable tax. Cancel anytime. This subscription covers Prompt Guard only.

What setup involves

  1. Choose the rules. Sign in with Google or email, choose replacement or blocking, and add any exact private terms you want detected.
  2. Create a Prompt Guard key. This lets your app use your saved rules.
  3. Have your developer connect the app. They route supported text requests through Prompt Guard using your own AI provider key. Test sample inputs before using real data.

Only requests sent through this connection are checked. You still need an account with OpenAI, Anthropic or Gemini.

Try it: see what gets removed

The sample is made up. Click “Inspect text locally” to see the result. Your sample text and private terms are not sent to our server or an AI provider.


        

For your developer: coverage, connection details and self-hosting

Explicit coverage

Read the synthetic detector evaluation and known misses

Recognizes supported API-key formats, PEM private keys, database URLs, email addresses, formatted US SSNs and phone numbers, Luhn-valid card numbers, and your literal terms.

Coverage is pattern-based. Names, addresses, proprietary code, encoded values and medical information are not comprehensively detected.

A narrow, enforceable endpoint

Text messages only, up to 16 KiB combined. Unsupported tools, files, images, embeddings and streaming are rejected. Quota exhaustion blocks requests instead of forwarding unfiltered traffic.

Your model provider charges separately. The hosted proxy receives raw prompts transiently to inspect them; it stores policy counts, never prompts or responses.

Connect an existing API client

Base URL: https://workflow-inspector.com/api/tools/ai-proxy/v1
Authorization: Bearer YOUR_PROMPT_GUARD_KEY
X-Upstream-API-Key: YOUR_OPENAI_KEY
Idempotency-Key: a-unique-request-id

POST /chat/completions
{"model":"gpt-4.1-mini","messages":[{"role":"user","content":"Your text"}],"max_completion_tokens":512}

Upstream keys are supplied per request and are not stored. Use environment variables in your server; never put keys in a public browser bundle.

30-day metadata history. Rotate or revoke the proxy key from your account. This covers traffic routed through the endpoint, not employee use of unrelated browser chat tools.

Run the scanner in your own environment

Deploy the managed gateway: mutual TLS, central policy, signed audits and workload routing controls

Download the dependency-free Node server and scanner together. The local server binds to loopback and requires your own bearer token and upstream key in environment variables.

PROMPT_GUARD_TOKEN=your-long-random-token OPENAI_API_KEY=your-provider-key node local-proxy.mjs

No HIPAA or regulatory certification is implied. Evaluate the detectors against your own data before relying on them.

Provider and team controls

The hosted gateway supports OpenAI, Anthropic and Gemini text chat through one redaction policy. Create expiring employee keys with individual provider permissions in your account. Managed employee browser or network enforcement requires your own administrative deployment.

Is Prompt Guard right for you?

Does it protect my team when they use ChatGPT in a browser?

No. The hosted service checks supported requests from software connected to it. Browser-wide or company-wide enforcement requires your own administrative deployment. See the deployment guide.

Will it remove every secret or personal detail?

No. It recognizes supported patterns and exact terms you configure. Names, addresses, medical information and proprietary source code are not comprehensively detected. Read the coverage evaluation and known misses.

Can I send files, images or streaming responses through it?

No. The hosted service supports text chat requests only. Files, images, tools, embeddings and streaming are rejected.

What happens to the text?

The free scanner works in your browser. The hosted service temporarily receives raw text to check it, then forwards allowed text to your selected AI provider. It records activity metadata, not prompt or response contents. Provider keys are supplied with each request and are not stored.

Is this a compliance certification?

No. Prompt Guard is a text-checking tool, not a compliance certification or a guarantee that sensitive information has been removed. It does not include a HIPAA business associate agreement.

We record limited first-party landing-page and campaign information as described in our Privacy Policy. This does not include text, private terms or scanner results. No third-party advertising tags are added by this page.