Skip to content
Prompt Security

Prompt Security

NEW ACQUIRED
Category: AI Security
License: Commercial
Suphi Cankurt
Suphi Cankurt
+8 Years in AppSec
Updated October 7, 2026
4 min read
Key Takeaways
  • SentinelOne announced the deal on August 5, 2025 and closed it on September 5, 2025, for about $180 million in cash and stock; the product is now built into the Singularity Platform.
  • Sold as three SentinelOne modules: AI Usage Control (workforce AI), Agentic AI Security (agents and MCP servers), and AI Application Security (homegrown LLM apps).
  • The browser extension detects GenAI usage through DOM analysis and user actions, and SentinelOne says it governs 15,000+ AI tools and services.
  • Contextual LLM-based detection redacts PII, PHI, secrets, and proprietary data before it reaches external GenAI tools.

Prompt Security is an AI security platform that protects organizations against prompt injection, data leakage, and shadow AI. It covers employee GenAI usage, AI agents, and homegrown LLM applications.

Itamar Golan (CEO) and Lior Drihem (CTO) founded the company in August 2023, according to its January 2024 launch announcement .

The company appears on SINET’s list of 2025 SINET16 Innovators .

SentinelOne announced its agreement to acquire Prompt Security on August 5, 2025. The deal closed on September 5, 2025, for about $180 million in cash and stock, according to SentinelOne’s Form 8-K .

Prompt Security dashboard (pre-acquisition UI) showing GenAI apps in use, sensitive data detections by type, risky users, and alerts by detection engine over time

What is Prompt Security?

Prompt Security takes a full-stack approach to GenAI security. Its value, as I read it, is covering employee GenAI usage, agents, and homegrown LLM applications in one policy layer.

SentinelOne now sells it as three Singularity Platform modules: AI Usage Control, Agentic AI Security, and AI Application Security.

Policies and AI risk visibility sit in the same console as endpoint, cloud, and identity security.

For employee-facing AI usage, a browser extension monitors prompts, file uploads, and responses. SentinelOne says the product governs 15,000+ AI tools and services.

For homegrown applications, an API integration screens inputs and outputs for injection attempts, data exfiltration, and policy violations. The system can block, redact, or alert depending on the configured policy.

CapabilityDetails
Prompt Injection ProtectionDetects and blocks prompt injection and jailbreak attempts in real time across homegrown LLM applications. SentinelOne markets the runtime protection as adding no noticeable latency.
Shadow AI DiscoveryDetects employee usage of GenAI tools, including unapproved services, through the browser extension and endpoint integrations. Shows which AI tools are in use and what data is being shared.
Data Leakage PreventionUses contextual LLM-based detection to find and redact PII, PHI, secrets, and proprietary information before it reaches external GenAI tools or leaves homegrown applications.

Key Features

FeatureDetails
Prompt Injection DetectionPrompt injection, jailbreaks, malicious output manipulation
Model SupportModel-agnostic: first- and third-party LLMs
Shadow AI DetectionBrowser extension and endpoint visibility across 15,000+ AI tools and services (vendor figure)
Data ProtectionPII, PHI, secrets, and proprietary data detection and redaction
Agentic AIDiscovery of agents and shadow MCP servers, MCP gateway controls
Deployment OptionsSaaS module of SentinelOne Singularity; on-premises was offered before the acquisition, so confirm current options with SentinelOne
Red TeamingBuilt-in testing for prompt injection, jailbreaks, and data poisoning
Content FilteringCustomizable policies with role- and department-based controls
AuditAudit trail across AI interactions
IntegrationBrowsers, desktop apps, APIs

Browser extension

The Prompt Security browser extension is the main tool for monitoring employee GenAI usage. It deploys in minutes.

It detects GenAI interactions dynamically through DOM analysis and user actions such as typing, pasting, clicking, and file uploads.

Instead of only blocking, the extension can coach employees in the moment when a prompt breaks policy. It can also block risky prompts, redact sensitive data in real time, or alert administrators.

Data leakage prevention

The platform uses contextual, LLM-based detection to identify sensitive information inside natural-language prompts.

It detects PII, PHI, secrets, and proprietary information. Healthcare customers use it in HIPAA-regulated settings.

When sensitive data is detected, the system can redact it automatically, block the interaction, or alert the platform admin, with each event logged.

Agentic AI security

The Agentic AI Security module maps agents and MCP servers in an environment, including shadow MCP servers and unsanctioned agent deployments.

An MCP gateway sits between AI applications and MCP servers to govern what agents can do. SentinelOne also extends coverage to AI coding assistants such as GitHub Copilot, Cursor, and Claude Code.

Red team testing

Prompt Security includes built-in red teaming that simulates attacks on LLM applications, including prompt injection, jailbreaks, and data poisoning. Findings feed into the runtime guardrails.

Note
SentinelOne acquisition

SentinelOne announced the Prompt Security acquisition on August 5, 2025 and completed it on September 5, 2025, for about $180 million in cash and stock.

Prompt Security is now built into the Singularity Platform. The prompt.security site hosts research and open-source tools, while the product is sold through SentinelOne.

Getting Started

  1. Request access through SentinelOne โ€” Prompt Security is sold as Singularity Platform modules, so start with a SentinelOne demo or account team.
  2. Roll out the browser extension to map employee AI usage, then set data protection and enforcement policies.
  3. Connect homegrown apps and agents through the API integration and MCP gateway to screen inputs, outputs, and agent actions.

When to use Prompt Security

Prompt Security fits organizations that need to secure GenAI usage on two fronts: how employees use third-party AI tools, and how homegrown LLM applications and agents resist attacks.

The browser extension approach gives security teams visibility into shadow AI without relying on network-level inspection.

The platform is especially relevant for regulated industries such as healthcare, financial services, and government. There, data leakage to AI tools is a compliance risk, and prompt injection can expose sensitive data.

Tip
Best for
Enterprise security teams that need to simultaneously control employee GenAI usage (shadow AI, data leakage) and protect homegrown LLM applications against prompt injection and data exfiltration โ€” especially in regulated industries.

For a broader overview of AI security risks, see the AI security guide . For AI red teaming specifically, look at Garak or Mindgard .

Prompt Security alternatives

One direct alternative is Lakera , acquired by Check Point in 2025. It is an API-first runtime guardrail with a published sub-50ms latency figure.

Lakera fits teams focused on homegrown apps rather than browser-based shadow AI discovery.

WitnessAI competes on the enterprise gateway pattern with intent-based behavioral controls and single-tenant data sovereignty.

Noma Security covers AI security posture, including agent inventory, MCP security, and runtime defense.

CalypsoAI , now offered by F5 as F5 AI Guardrails, is another enterprise runtime guardrail platform.

For open-source teams, LLM Guard provides input and output scanners as a self-hosted Python library, and NeMo Guardrails supports programmable safety policies. The AI security tools hub maps the full set.

Note: SentinelOne announced the acquisition on August 5, 2025 and completed it on September 5, 2025, for about $180 million in cash and stock. Prompt Security is now built into the Singularity Platform as AI Usage Control, Agentic AI Security, and AI Application Security.

Frequently Asked Questions

What is Prompt Security?
Prompt Security is an enterprise platform for securing generative AI use across an organization. It covers employee GenAI tools, AI agents, and homegrown LLM applications, with protection against prompt injection, data leakage, and shadow AI. SentinelOne completed its acquisition of Prompt Security on September 5, 2025.
How much does Prompt Security cost?
Prompt Security is a commercial platform acquired by SentinelOne in 2025. Pricing is not publicly listed โ€” contact SentinelOne for current pricing and packaging details.
Does Prompt Security detect shadow AI?
Yes. SentinelOne says AI Usage Control discovers and governs 15,000+ AI tools and services, including unapproved ones. Admins see which AI tools employees use and what data they share, and can coach users, redact sensitive data, or block risky prompts.
How does the Prompt Security browser extension work?
The browser extension deploys in minutes and detects GenAI usage by analyzing the page DOM and user actions such as typing, pasting, clicking, and file uploads. It can coach employees in the moment, redact sensitive data, or block a prompt based on policy.
How does Prompt Security compare to Lakera Guard?
Both detect prompt injection. Prompt Security adds workforce controls such as shadow AI discovery and browser-based data redaction, plus agent and MCP governance. Lakera Guard is an API-first runtime guardrail for LLM apps and agents. Prompt Security is now part of SentinelOne; Lakera is part of Check Point.