Prompt Security is an AI security platform that protects organizations against prompt injection, data leakage, and shadow AI. It covers employee GenAI usage, AI agents, and homegrown LLM applications.
Itamar Golan (CEO) and Lior Drihem (CTO) founded the company in August 2023, according to its January 2024 launch announcement .
The company appears on SINET’s list of 2025 SINET16 Innovators .
SentinelOne announced its agreement to acquire Prompt Security on August 5, 2025. The deal closed on September 5, 2025, for about $180 million in cash and stock, according to SentinelOne’s Form 8-K .

What is Prompt Security?
Prompt Security takes a full-stack approach to GenAI security. Its value, as I read it, is covering employee GenAI usage, agents, and homegrown LLM applications in one policy layer.
SentinelOne now sells it as three Singularity Platform modules: AI Usage Control, Agentic AI Security, and AI Application Security.
Policies and AI risk visibility sit in the same console as endpoint, cloud, and identity security.
For employee-facing AI usage, a browser extension monitors prompts, file uploads, and responses. SentinelOne says the product governs 15,000+ AI tools and services.
For homegrown applications, an API integration screens inputs and outputs for injection attempts, data exfiltration, and policy violations. The system can block, redact, or alert depending on the configured policy.
| Capability | Details |
|---|---|
| Prompt Injection Protection | Detects and blocks prompt injection and jailbreak attempts in real time across homegrown LLM applications. SentinelOne markets the runtime protection as adding no noticeable latency. |
| Shadow AI Discovery | Detects employee usage of GenAI tools, including unapproved services, through the browser extension and endpoint integrations. Shows which AI tools are in use and what data is being shared. |
| Data Leakage Prevention | Uses contextual LLM-based detection to find and redact PII, PHI, secrets, and proprietary information before it reaches external GenAI tools or leaves homegrown applications. |
Key Features
| Feature | Details |
|---|---|
| Prompt Injection Detection | Prompt injection, jailbreaks, malicious output manipulation |
| Model Support | Model-agnostic: first- and third-party LLMs |
| Shadow AI Detection | Browser extension and endpoint visibility across 15,000+ AI tools and services (vendor figure) |
| Data Protection | PII, PHI, secrets, and proprietary data detection and redaction |
| Agentic AI | Discovery of agents and shadow MCP servers, MCP gateway controls |
| Deployment Options | SaaS module of SentinelOne Singularity; on-premises was offered before the acquisition, so confirm current options with SentinelOne |
| Red Teaming | Built-in testing for prompt injection, jailbreaks, and data poisoning |
| Content Filtering | Customizable policies with role- and department-based controls |
| Audit | Audit trail across AI interactions |
| Integration | Browsers, desktop apps, APIs |
Browser extension
The Prompt Security browser extension is the main tool for monitoring employee GenAI usage. It deploys in minutes.
It detects GenAI interactions dynamically through DOM analysis and user actions such as typing, pasting, clicking, and file uploads.
Instead of only blocking, the extension can coach employees in the moment when a prompt breaks policy. It can also block risky prompts, redact sensitive data in real time, or alert administrators.
Data leakage prevention
The platform uses contextual, LLM-based detection to identify sensitive information inside natural-language prompts.
It detects PII, PHI, secrets, and proprietary information. Healthcare customers use it in HIPAA-regulated settings.
When sensitive data is detected, the system can redact it automatically, block the interaction, or alert the platform admin, with each event logged.
Agentic AI security
The Agentic AI Security module maps agents and MCP servers in an environment, including shadow MCP servers and unsanctioned agent deployments.
An MCP gateway sits between AI applications and MCP servers to govern what agents can do. SentinelOne also extends coverage to AI coding assistants such as GitHub Copilot, Cursor, and Claude Code.
Red team testing
Prompt Security includes built-in red teaming that simulates attacks on LLM applications, including prompt injection, jailbreaks, and data poisoning. Findings feed into the runtime guardrails.
SentinelOne announced the Prompt Security acquisition on August 5, 2025 and completed it on September 5, 2025, for about $180 million in cash and stock.
Prompt Security is now built into the Singularity Platform. The prompt.security site hosts research and open-source tools, while the product is sold through SentinelOne.
Getting Started
- Request access through SentinelOne โ Prompt Security is sold as Singularity Platform modules, so start with a SentinelOne demo or account team.
- Roll out the browser extension to map employee AI usage, then set data protection and enforcement policies.
- Connect homegrown apps and agents through the API integration and MCP gateway to screen inputs, outputs, and agent actions.
When to use Prompt Security
Prompt Security fits organizations that need to secure GenAI usage on two fronts: how employees use third-party AI tools, and how homegrown LLM applications and agents resist attacks.
The browser extension approach gives security teams visibility into shadow AI without relying on network-level inspection.
The platform is especially relevant for regulated industries such as healthcare, financial services, and government. There, data leakage to AI tools is a compliance risk, and prompt injection can expose sensitive data.
For a broader overview of AI security risks, see the AI security guide . For AI red teaming specifically, look at Garak or Mindgard .
Prompt Security alternatives
One direct alternative is Lakera , acquired by Check Point in 2025. It is an API-first runtime guardrail with a published sub-50ms latency figure.
Lakera fits teams focused on homegrown apps rather than browser-based shadow AI discovery.
WitnessAI competes on the enterprise gateway pattern with intent-based behavioral controls and single-tenant data sovereignty.
Noma Security covers AI security posture, including agent inventory, MCP security, and runtime defense.
CalypsoAI , now offered by F5 as F5 AI Guardrails, is another enterprise runtime guardrail platform.
For open-source teams, LLM Guard provides input and output scanners as a self-hosted Python library, and NeMo Guardrails supports programmable safety policies. The AI security tools hub maps the full set.
