Skip to main content
For current pricing and to subscribe, see the canonical pricing page. This page documents the technical limits, quotas, and usage rules for each plan.

Plans

PromptGuard has three self-service tiers and an Enterprise tier. Every tier runs the same detection engine (regex, ML, and LLM-based detection); the tiers differ in which threat types it checks. Free checks prompt injection and PII. Pro and above add data exfiltration, toxicity, fraud, secret keys, malware and URL filtering. See Feature Comparison.

Free

$0/month
  • 20,000 requests/month
  • 1 project, 1 API key
  • Prompt injection detection (ML + LLM)
  • PII detection and redaction
  • 24-hour log retention
  • Community support

Pro

$99/month
  • 100,000 requests/month
  • 5 projects, 5 API keys
  • Full detector set: exfiltration, toxicity, fraud, secrets, malware, URLs
  • Custom security policies
  • 7-day log retention
  • Email alerts and support

Scale

$199/month
  • 500,000 requests/month, then metered overage to your spend cap
  • Unlimited projects and API keys
  • Advanced analytics
  • 30-day log retention
  • Priority support (24hr)
  • 99.9% uptime target (internal target; no signed SLA)

Shadow AI

The plans above protect the AI features you build. Shadow AI — the browser extension and macOS/Windows desktop agent that stop your employees leaking data into public AI tools — is a distinct product you can use on its own or alongside the gateway.
  • Included with every plan: personal Shadow AI protects two of your own devices, metered against your existing request quota — no separate bill. Need a third? Enrol it. Coverage is not what you are charged for, so growing it never needs a plan change; the scans meter exactly as the first device’s do.
  • On a Team plan: the fleet layer — MDM enforcement, an org-wide “required” policy, multi-device enrollment, and a per-employee usage rollup. Fleet is sold by the per-seat plans and by nothing else, so a gateway plan alone does not grant it however large.
  • Standalone, per seat: for rolling out to a whole team (or using Shadow AI exclusively), priced per seat and sized to your fleet — cloud, hybrid self-hosted, or air-gapped.
  • A seat starts when a device enrols, not when you invite someone. Invite the whole company for nothing; you pay for the machines that are actually being protected. Two devices are included per seat, so one person’s laptop and desktop are one seat. A device enrolled without anyone signing in — an MDM rollout, say — counts on its own, because nothing yet says whose it is. To fold it into its owner’s seat, have them connect it from the desktop app and then revoke the original enrolment: connecting enrols the machine afresh under their account rather than re-labelling the existing entry.
Rolling out to a team? Shadow AI starts with a 30-day trial — long enough to produce a full monthly report of what your staff nearly sent. Book a pilot or see how it works and deployment modes.

Enterprise

Enterprise adds team management, SSO, compliance controls, and custom infrastructure options.

Organizations and RBAC

Team workspaces with role-based access control (Owner, Admin, Member, Viewer).

SSO & Directory Sync

Single sign-on via SAML or OIDC (Okta, Microsoft Entra ID, Google Workspace, and more), plus SCIM Directory Sync for automatic provisioning and deprovisioning.

Audit Logs and Compliance

Persistent audit trail with integrity hash chaining. GDPR data export and deletion endpoints.

Security Controls

IP allowlisting, webhook signing (HMAC-SHA256), and custom log retention.

Custom Limits

Custom monthly request quotas, rate limits, and retention periods per organization.

Dedicated Support

Custom SLAs and dedicated account manager.
Contact sales@promptguard.co for Enterprise pricing.

Compliance & Governance

Evaluating PromptGuard for your organization? Here’s where it stands:

Certifications

SOC 2 Type II on the roadmap (today: source access under NDA + verifiable self-host) · GDPR / CCPA supported (DPA available) · ISO 27001 on roadmap

Standards alignment

EU AI Act (Articles 9–15) and ISO/IEC 42001 — technical controls mapped.

Audit & data handling

Tamper-evident audit logs, pass-through architecture, configurable retention. Self-host to keep data in your infrastructure.

Full details

Read the complete Compliance & Security page.
Need a specific certification, a DPA, or a security questionnaire completed? Contact sales@promptguard.co.

Feature Comparison

Integration Methods

All plans include every integration method:

Rate Limits

Monthly Request Quotas

Monthly quotas are tracked per account: See Reaching your limit for how to avoid an outage when you hit a quota.

Per-Minute Rate Limits

Per-account requests-per-minute limits:

Infrastructure Anti-Abuse Limiting

Separately from your plan limits, a Cloud Armor layer enforces a per-IP request limit at the network edge:
  • Applies to all plans, independent of the per-account limits above
  • Health-check and CORS preflight paths are exempt
  • Exists to block abusive traffic, not to cap normal usage

Reaching your limit

PromptGuard is designed so you never lose protection at a critical moment. As you approach your monthly quota, the dashboard shows a banner at 90% used, and again when you hit 100%. When you reach your limit on a paid plan, you have two ways to keep serving traffic (on Free, upgrading is the way):

Upgrade your plan

Move to a higher tier for a larger monthly quota. Upgrades take effect immediately — traffic resumes the moment you upgrade.

Enable pay-as-you-go

Keep your current paid plan and pay only for requests above your quota, billed per request at the end of the cycle, up to a spend cap you set. Turn it on from the at-limit banner or Settings → Billing. Not available on Free, which has no payment method to bill.
On Free, requests over the quota return 429 Too Many Requests until you upgrade. On Pro, they return 429 until you upgrade or enable pay-as-you-go — at which point traffic resumes. On Scale, the quota is soft but the spend is not: traffic keeps flowing past 500,000 and is metered at 0.40per1,000requests,uptoaspendcapthatdefaultsto0.40 per 1,000 requests, up to a spend cap that defaults to 500. Past the cap, requests return 429 until you raise it; set the cap to $0 and Scale stops at its quota instead. Enterprise is contractually uncapped. These rules apply to every counted request (see How Usage Is Calculated), whichever endpoint it arrives on. The one exception is Shadow AI: scans from the desktop agent count against the same quota but are never refused for it, because a data-loss control that stops at a billing threshold would either block your staff’s work or let content leave unscanned.
On Pro, pay-as-you-go is opt-in — you’re never charged for overage unless you turn it on, and the 429 response includes a link to enable it, so an over-quota integration can recover without code changes. On Scale, overage metering is on by default with a 500spendcap,soatrafficspikenevertakesyouoffline;lowerthecap,orsetitto500 spend cap, so a traffic spike never takes you offline; lower the cap, or set it to 0, from Settings → Billing. On Free, the 429 links to the upgrade instead.
Set a budget you’re comfortable with. Pay-as-you-go trades a hard stop for usage-based cost, so monitor Settings → Billing → Usage to avoid surprises during a traffic spike.

How Usage Is Calculated

One request = one API call to any of these endpoints: POST /api/v1/agent/validate-tool checks a tool call against your agent policy without running the detection pipeline, and does not count. Usage is independent of token count, model used, or response length.
PromptGuard uses a pass-through model: you provide your own LLM API keys (OpenAI, Anthropic, etc.), and PromptGuard only charges for security services. LLM costs go directly to your provider.

FAQ

Yes. Upgrade or downgrade at any time. Upgrades take effect immediately; downgrades at the next billing cycle.
You won’t be locked out without a choice. On Free, over-quota requests return 429 Too Many Requests until you upgrade. On Pro, they return 429 until you either upgrade or enable pay-as-you-go — then traffic resumes. Scale keeps running past the quota with overage metered to your spend cap (default $500), and you receive alerts; past the cap requests return 429 until you raise it. Enterprise is contractually uncapped. See Reaching your limit.
A valve so you don’t lose protection when you hit your quota. With it enabled, requests above your monthly limit keep being processed and are billed per request at the end of the cycle, up to your spend cap. On Pro it’s off by default — you’re never charged for overage unless you turn it on. On Scale it’s on by default with a 500cap,whichyoucanlowerorsetto500 cap, which you can lower or set to 0. It isn’t available on Free.
There is no time-limited trial. The Free tier (20,000 requests/month) runs prompt injection and PII detection with the same ML and LLM engine as the paid tiers, so you can evaluate those before upgrading. Secret keys, data exfiltration, URL filtering, toxicity and the other text threat types are checked from Pro upwards; on Free they are not raised.
Self-hosted deployment is available for Enterprise customers. Contact sales@promptguard.co for details.
Yes. Every API call counts, including retries and blocked requests.