Prompt Firewall

Scan it. Contain it. Send it safely.

Prompt Firewall gives your AI two layers of protection in the same run. First, it scans every piece of incoming content for hidden attacks. Then it locks that content inside a secure boundary your AI is told to treat as data, not instructions. Scanning catches the attacks we recognise. Containment protects against everything else.

How it works

From untrusted content to a protected prompt, in one call

01

Pass content through the firewall

Before your AI reads any untrusted input, route it through Prompt Firewall. Emails, web pages, PDFs, Office docs, spreadsheets, images.

02

We scan for attacks

Multiple detection engines run at once. They strip away disguises, decode hidden messages, spot fake conversations, and catch every trick attackers use to sneak instructions past defences. All of this in 3 to 12 milliseconds, across hundreds of languages.

03

We lock it inside a secure boundary

Containment wraps untrusted content inside a secure boundary your AI treats as data, not instructions. Even if an attack slips past scanning, it stays trapped inside the boundary and cannot give orders to your AI.

04

You get a ready-to-use prompt

We send back a complete prompt you can hand straight to your AI: content wrapped, security rules in place, plus a verdict and a list of anything we found. If something is dangerous, we tell you. You decide what to do with it.

Two layers

Scan it.
Contain it.

Scanning catches attacks we recognise: hijack attempts, hidden commands, invisible characters, impersonation, and more, across hundreds of languages. Containment protects against everything else by locking content inside a boundary your AI treats as data, not instructions. Together, they give you defence in depth against prompt injection.

Speed

Invisible
Your users never notice it

Both layers run in 3 to 12 ms. Roughly 100 times faster than running another AI to screen the content, much cheaper, and no expensive hardware needed.

Capabilities

Built for security teams that ship fast

Easy to add

Simple API. Flexible by design.

Scanning and containment in the same run. Fits any architecture: RAG pipelines, tool-use chains, multi-agent systems, or a straightforward chatbot. PDFs, Word docs, spreadsheets, images, plain text. Works from any language.

EU company · EU servers only · GDPR-compliant · PII redacted before logging
RAG, agent, and chatbot architectures all routed through a single heySec check before reaching the AI model. Any stack, one integration.

Full visibility

A complete record of every request

Every scan, every containment, every verdict is logged. You always know what came in, what we found, and how we protected it. If your auditor asks, if a customer questions something, or if you need to investigate an incident, the answer is right there in plain language.

An activity log where every request is recorded, with one contained item expanded to show its type, severity, source, and matched span, plus a full audit trail.

Coverage

Every kind of attack, two layers of defence

Scanning catches known attack types. Containment makes sure that even unknown techniques stay trapped inside the boundary and cannot give orders to your AI. When new attacks appear, we add detection rules automatically, and containment has you covered in the meantime.

Hijack attempts
Content that tells your AI to ignore your rules or pretend to be a different assistant. Caught in any language, even if the wording is paraphrased.
Scrambled text
Instructions disguised in codes and scrambled formats that look like gibberish to you but give orders to your AI. We unscramble every layer.
Look-alike letters
Letters from other alphabets that look identical to normal ones but read as something completely different to your AI.
Invisible characters
Characters your eye cannot see at all, slipped into otherwise innocent-looking text to smuggle commands to your AI.
Hidden messages
Secret instructions tucked into the first letters of paragraphs, between spaces, or buried in patterns that only a machine would notice.
Instructions split into pieces
Attacks that break a command into small harmless-looking fragments and ask your AI to piece them together. We spot the whole pattern.
Impersonation
Fake conversations and false authority cues designed to trick your AI into thinking an attacker is you, your company, or a trusted user.
Mixed alphabets
Words that blend letters from different alphabets so the page looks normal to a human but reads as something else to your AI.
Attacks inside files
PDFs, Word docs, spreadsheets, slide decks, and images. We open every file, read everything inside, and check it before your AI does.

Speed

Both layers run in milliseconds

Scanning and containment happen together in one pass. A short message clears in a blink. Even a long document only adds a small pause. Your users never notice the protection. No special hardware, no GPUs, just standard servers doing their job quickly.

What you are protecting
How long it takes
A normal email or short message
Under 400 µs
A support ticket or web page
3–12 ms
A typical PDF or Word doc
20–30 ms
A large report or long document
Under a second
Busy traffic, many users at once
1,000+ per second

Make your AI safe to read the real world

Join the private beta. One API call gives you scanning and containment from day one.