Deflected Platform

Prompt Firewall

Every prompt, inspected. Every attack, deflected.

An inline AI gateway that inspects every prompt and response in real time. It blocks prompt injection, jailbreaks, PII leakage, and data exfiltration before they reach your model or your users.

The risk this closes

Every LLM feature you ship widens your attack surface. A single crafted prompt can override your system instructions, coax the model into leaking data, or turn your own assistant against its guardrails — and traditional web firewalls never see it, because the payload is natural language, not code.

The attacks are concrete. An instruction hidden in a support ticket, a PDF, or a web page your retrieval pipeline ingests can tell the model to ignore its rules and dump the context window — including records from other customers. A user can talk an assistant past its safety layer and pull system prompts, API keys, or connection strings that were never meant to surface. An agent with tool access can be steered into calling an internal API or sending data to an attacker-controlled endpoint. None of this trips a signature-based defense.

The business impact lands on you. A single successful exfiltration is a reportable breach, a regulatory exposure, and a loss of the customer trust that made the AI feature worth shipping. The model's own alignment is not a control you can audit, and it was never designed to be your last line of defense. That gap is what Prompt Firewall closes.

Built to run in production

1

Inspect

Every prompt and response passes through the gateway inline, in the request path, with sub-second latency.

2

Classify

Detects injection, jailbreak patterns, PII, secrets, and exfiltration attempts using layered detectors.

3

Enforce

Blocks, redacts, or allows each request against your policy — with safe fallbacks that never break the app.

4

Log

Writes an immutable, queryable record of every decision for audit, tuning, and incident review.

What you get

Stop prompt injection in real time

Malicious instructions are caught and neutralized in the request path, before they reach the model.

Prevent sensitive data leaving in model output

Outbound responses are scanned and redacted so PII, secrets, and regulated data never escape.

Full audit log of every decision

Every allow, block, and redaction is recorded with context — ready for compliance and forensics.

Built for teams putting models in production

If your application sends untrusted input to an LLM, Prompt Firewall sits in front of it. It is designed for the people accountable when that model misbehaves.

Teams shipping LLM features

Product and engineering groups embedding chat, copilots, or agents get a policy layer they control — so a launch is not gated on hand-rolled prompt filtering that breaks with every model change.

Regulated industries

Financial services, healthcare, and public sector teams get inline PII and secret redaction plus an immutable decision log — controls that map to SOC 2, the NIST AI RMF, and EU AI Act obligations.

Platform and security teams

CISOs and heads of AI get a single enforcement point across every model and vendor, with centralized policy, telemetry, and audit — instead of security logic scattered through application code.

In the real world

Customer-facing chatbot

Public users probe the assistant for system prompts, discounts, or another customer's data. Prompt Firewall inspects each turn, blocks jailbreak and injection attempts, and redacts sensitive output before it reaches the screen.

RAG over internal docs

Retrieved documents can carry hidden instructions that hijack the model. The firewall scans retrieved content and the generated answer, stripping embedded injection and preventing regulated data from leaking across tenants.

Autonomous agent with tools

An agent that can call APIs or run actions is a high-value target. Policy checks sit between the model and its tools, so a manipulated agent cannot invoke unauthorized calls or exfiltrate data through an action.

Why teams choose Prompt Firewall

Inline and production-grade

Not a research demo. Prompt Firewall runs in the request path with sub-second latency and safe fallbacks, so enforcement never becomes the reason your application goes down.

Quantum-secured by default

Every byte in transit is protected with NIST-standardized post-quantum cryptography — ML-KEM-1024 (FIPS 203) in a hybrid X25519 scheme with AES-256 — defending against harvest-now, decrypt-later attacks.

Full auditability

Every allow, block, and redaction is written to an immutable, queryable log with full context — the evidence trail your auditors, incident responders, and regulators expect.

Quantum-secured by default

Every byte handled by Prompt Firewall is protected with NIST-standardized post-quantum cryptography — ML-KEM-1024 key encapsulation (FIPS 203) in a hybrid scheme. Your data stays sealed against harvest-now, decrypt-later attacks, today and after quantum computers arrive.

Questions, answered

Does an inline firewall add latency to every request?
Prompt Firewall runs in the request path and inspection completes in sub-second time, so the overhead is small relative to model inference itself. It is engineered for production traffic, with safe fallbacks: if a check cannot complete, the gateway follows your configured policy rather than failing the request, so enforcement never becomes a single point of failure for your application.
How does it actually detect prompt injection and jailbreaks?
It uses layered detectors rather than a single rule set. Every prompt and response is classified for known injection and jailbreak patterns, instruction-override attempts, PII, secrets, and exfiltration signals — including instructions hidden inside retrieved documents and tool output. Detection is not a static blocklist; the layered approach is built to catch novel phrasings that signature-based filters miss, and each decision is enforced against the policy you define.
Does Prompt Firewall see our data, and how is it handled?
Inspection requires the gateway to process prompt and response content in transit, and it is engineered so that content is protected end to end. Every byte is secured with NIST-standardized post-quantum cryptography — ML-KEM-1024 (FIPS 203) key encapsulation in a hybrid X25519 scheme with AES-256 — defending against harvest-now, decrypt-later attacks. Data handling maps to SOC 2 controls, and every decision is written to an immutable, queryable audit log so you can see exactly what was inspected and why.
How is this different from our WAF or the model's own safety layer?
A WAF inspects code-level payloads — SQL injection, cross-site scripting, malformed requests — and is blind to attacks written in natural language. The model's own alignment is not a control you can configure, audit, or rely on as a last line of defense. Prompt Firewall is purpose-built for the LLM layer: it enforces your policy on prompts, responses, and tool calls, redacts sensitive output, and logs every decision, giving you an auditable enforcement point that neither a WAF nor the model provides.

See Prompt Firewall on your stack

Book a working session with our team. We will map Prompt Firewall to your environment, tune policy to your risk tolerance, and show exactly where it fits — before you write a line of integration code.