> ## Documentation Index
> Fetch the complete documentation index at: https://docs.promptguard.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Plans & Limits

> PromptGuard plan limits, quotas, rate limiting, and usage calculation

<Note>
  For current pricing and to subscribe, see the canonical [pricing page](https://promptguard.co/pricing). This page documents the technical limits, quotas, and usage rules for each plan.
</Note>

## Plans

PromptGuard has three self-service tiers and an Enterprise tier. All tiers include the full detection pipeline (regex, ML, and LLM-based detection).

<CardGroup cols={3}>
  <Card title="Free" icon="gift">
    **\$0/month**

    * 10,000 requests/month
    * 1 project, 1 API key
    * All detectors (ML + LLM)
    * PII detection and redaction
    * 24-hour log retention
    * Community support
  </Card>

  <Card title="Pro" icon="bolt">
    **\$99/month**

    * 100,000 requests/month
    * 5 projects, 5 API keys
    * Custom security policies
    * 7-day log retention
    * Email alerts and support
  </Card>

  <Card title="Scale" icon="rocket">
    **\$199/month**

    * 1,000,000 requests/month (soft limit)
    * Unlimited projects and API keys
    * Advanced analytics
    * 30-day log retention
    * Priority support (24hr)
    * 99.9% uptime SLA
  </Card>
</CardGroup>

## Shadow AI

The plans above protect the AI features **you build**.
**[Shadow AI](/shadow-ai/overview)** — the browser extension and macOS/Windows
desktop agent that stop your **employees** leaking data into public AI tools —
is a distinct product you can use **on its own or alongside** the gateway.

* **Included with every plan:** *personal* Shadow AI protects **one** of your own
  devices, metered against your existing request quota — no separate bill.
* **Scale and above:** the *fleet* layer — MDM enforcement, an org-wide "required"
  policy, multi-device enrollment, and a per-employee usage rollup.
* **Standalone, per seat:** for rolling out to a whole team (or using Shadow AI
  exclusively), priced per seat and sized to your fleet — cloud, hybrid
  self-hosted, or air-gapped.

<Note>Rolling out to a team? Shadow AI starts with a 14-day pilot. [Book a pilot](https://calendly.com/promptguard/15min) or see [how it works](/shadow-ai/overview) and [deployment modes](/shadow-ai/deployment-modes).</Note>

## Enterprise

Enterprise adds team management, SSO, compliance controls, and custom infrastructure options.

<CardGroup cols={2}>
  <Card title="Organizations and RBAC" icon="users">
    Team workspaces with role-based access control (Owner, Admin, Member, Viewer).
  </Card>

  <Card title="SSO & Directory Sync" icon="lock">
    Single sign-on via [SAML or OIDC](/platform/sso) (Okta, Microsoft Entra ID, Google Workspace, and more), plus [SCIM Directory Sync](/platform/scim) for automatic provisioning and deprovisioning.
  </Card>

  <Card title="Audit Logs and Compliance" icon="shield-halved">
    Persistent audit trail with integrity hash chaining. GDPR data export and deletion endpoints.
  </Card>

  <Card title="Security Controls" icon="shield">
    IP allowlisting, webhook signing (HMAC-SHA256), and custom log retention.
  </Card>

  <Card title="Custom Limits" icon="sliders">
    Custom monthly request quotas, rate limits, and retention periods per organization.
  </Card>

  <Card title="Dedicated Support" icon="headset">
    Custom SLAs and dedicated account manager.
  </Card>
</CardGroup>

<Note>
  Contact [sales@promptguard.co](mailto:sales@promptguard.co) for Enterprise pricing.
</Note>

## Compliance & Governance

Evaluating PromptGuard for your organization? Here's where it stands:

<CardGroup cols={2}>
  <Card title="Certifications" icon="certificate">
    **SOC 2 Type II** on the roadmap (today: source access under NDA + verifiable self-host) · **GDPR / CCPA** supported (DPA available) · **ISO 27001** on roadmap
  </Card>

  <Card title="Standards alignment" icon="scale-balanced">
    **EU AI Act** (Articles 9–15) and **ISO/IEC 42001** — technical controls mapped.
  </Card>

  <Card title="Audit & data handling" icon="shield-halved">
    Tamper-evident [audit logs](/platform/audit-logs), pass-through architecture, configurable data residency and retention.
  </Card>

  <Card title="Full details" icon="book" href="/security/compliance">
    Read the complete Compliance & Security page.
  </Card>
</CardGroup>

<Note>
  Need a specific certification, a DPA, or a security questionnaire completed? Contact [sales@promptguard.co](mailto:sales@promptguard.co).
</Note>

## Feature Comparison

| Feature                           | Free                    | Pro                     | Scale      | Enterprise |
| --------------------------------- | ----------------------- | ----------------------- | ---------- | ---------- |
| **Monthly requests**              | 10,000                  | 100,000                 | 1,000,000  | Custom     |
| **Projects**                      | 1                       | 5                       | Unlimited  | Unlimited  |
| **API keys**                      | 1                       | 5                       | Unlimited  | Unlimited  |
| **Over-limit behavior**           | Block, or pay-as-you-go | Block, or pay-as-you-go | Soft limit | Soft limit |
| **Pay-as-you-go overage**         | Opt-in                  | Opt-in                  | Opt-in     | Opt-in     |
|                                   |                         |                         |            |            |
| **Regex-based detection**         | Yes                     | Yes                     | Yes        | Yes        |
| **ML-enhanced detection**         | Yes                     | Yes                     | Yes        | Yes        |
| **LLM-based detection**           | Yes                     | Yes                     | Yes        | Yes        |
| **Secret key detection**          | Yes                     | Yes                     | Yes        | Yes        |
| **URL filtering**                 | Yes                     | Yes                     | Yes        | Yes        |
| **Jailbreak LLM detection**       | Yes                     | Yes                     | Yes        | Yes        |
| **Tool injection detection**      | Yes                     | Yes                     | Yes        | Yes        |
| **Content safety classification** | Yes                     | Yes                     | Yes        | Yes        |
| **Multi-turn drift detection**    | Yes                     | Yes                     | Yes        | Yes        |
| **Custom policies**               | --                      | Yes                     | Yes        | Yes        |
| **PII redaction**                 | Yes                     | Yes                     | Yes        | Yes        |
|                                   |                         |                         |            |            |
| **Auto-instrumentation**          | Yes                     | Yes                     | Yes        | Yes        |
| **Guard API**                     | Yes                     | Yes                     | Yes        | Yes        |
| **Agent Security API**            | Yes                     | Yes                     | Yes        | Yes        |
| **Framework integrations**        | Yes                     | Yes                     | Yes        | Yes        |
|                                   |                         |                         |            |            |
| **Log retention**                 | 24 hours                | 7 days                  | 30 days    | Custom     |
| **Advanced analytics**            | --                      | --                      | Yes        | Yes        |
| **Email alerts**                  | --                      | Yes                     | Yes        | Yes        |
| **Audit logs**                    | --                      | --                      | --         | Yes        |
| **GDPR export/deletion**          | --                      | --                      | --         | Yes        |
|                                   |                         |                         |            |            |
| **Organizations & RBAC**          | --                      | --                      | --         | Yes        |
| **Per-project roles**             | --                      | --                      | --         | Yes        |
| **SSO (SAML & OIDC)**             | --                      | --                      | --         | Yes        |
| **Directory Sync (SCIM)**         | --                      | --                      | --         | Yes        |
| **IP allowlist**                  | --                      | --                      | --         | Yes        |
| **Webhook signing**               | --                      | --                      | --         | Yes        |
| **Custom retention**              | --                      | --                      | --         | Yes        |
| **Idempotency keys**              | Yes                     | Yes                     | Yes        | Yes        |
| **Rate limit headers**            | Yes                     | Yes                     | Yes        | Yes        |
|                                   |                         |                         |            |            |
| **Support**                       | Community               | Email                   | Priority   | Dedicated  |
| **Uptime SLA**                    | --                      | --                      | 99.9%      | 99.95%     |

## Integration Methods

All plans include every integration method:

| Method                     | Description                                            | Best For            |
| -------------------------- | ------------------------------------------------------ | ------------------- |
| **Auto-instrumentation**   | `promptguard.init()` -- one line secures all LLM calls | Most applications   |
| **Guard API**              | `POST /api/v1/guard` -- scan content directly          | Custom workflows    |
| **HTTP Proxy**             | Change base URL to `api.promptguard.co`                | Drop-in replacement |
| **Framework integrations** | Native callbacks for LangChain, Vercel AI SDK          | Framework users     |

## Rate Limits

### Monthly Request Quotas

Monthly quotas are tracked **per account**:

| Plan           | Limit     | Behavior When Exceeded                                      |
| -------------- | --------- | ----------------------------------------------------------- |
| **Free**       | 10,000    | Blocks with `429` until you upgrade or enable pay-as-you-go |
| **Pro**        | 100,000   | Blocks with `429` until you upgrade or enable pay-as-you-go |
| **Scale**      | 1,000,000 | Continues processing (soft limit) + email alerts            |
| **Enterprise** | Custom    | Continues processing + alerts                               |

See [Reaching your limit](#reaching-your-limit) for how to avoid an outage when you hit a quota.

### Per-Minute Rate Limits

Per-account requests-per-minute limits:

| Plan           | Rate Limit                    |
| -------------- | ----------------------------- |
| **Free**       | 60 rpm                        |
| **Pro**        | 300 rpm                       |
| **Scale**      | 600 rpm                       |
| **Enterprise** | 1,000 rpm (custom on request) |

### Infrastructure Anti-Abuse Limiting

Separately from your plan limits, a Cloud Armor layer enforces a per-IP request limit at the network edge:

* Applies to all plans, independent of the per-account limits above
* Health-check and CORS preflight paths are exempt
* Exists to block abusive traffic, not to cap normal usage

## Reaching your limit

PromptGuard is designed so you **never lose protection at a critical moment**. As you approach your monthly quota, the dashboard shows a banner at 90% used, and again when you hit 100%. When you reach your limit, you have two ways to keep serving traffic:

<CardGroup cols={2}>
  <Card title="Upgrade your plan" icon="arrow-up">
    Move to a higher tier for a larger monthly quota. Upgrades take effect **immediately** — traffic resumes the moment you upgrade.
  </Card>

  <Card title="Enable pay-as-you-go" icon="gauge-high">
    Keep your current plan and pay only for requests **above** your quota, billed per request at the end of the cycle. Turn it on from the at-limit banner or **Settings → Billing**.
  </Card>
</CardGroup>

On **Free** and **Pro**, requests over the quota return `429 Too Many Requests` **until** you upgrade or enable pay-as-you-go — at which point traffic resumes. On **Scale** and **Enterprise**, the quota is a soft limit: traffic keeps flowing and you're alerted, with overage billed if pay-as-you-go is enabled.

<Note>
  Pay-as-you-go is **opt-in** — you're never charged for overage unless you turn it on. The `429` response includes a link to enable it, so an over-quota integration can recover without code changes.
</Note>

<Warning>
  Set a budget you're comfortable with. Pay-as-you-go trades a hard stop for usage-based cost, so monitor **Settings → Billing → Usage** to avoid surprises during a traffic spike.
</Warning>

## How Usage Is Calculated

One request = one API call to any of these endpoints:

| Endpoint                           | Counts as |
| ---------------------------------- | --------- |
| `POST /api/v1/chat/completions`    | 1 request |
| `POST /api/v1/completions`         | 1 request |
| `POST /api/v1/guard`               | 1 request |
| `POST /api/v1/agent/validate-tool` | 1 request |

Usage is independent of token count, model used, or response length.

<Note>
  PromptGuard uses a **pass-through model**: you provide your own LLM API keys (OpenAI, Anthropic, etc.), and PromptGuard only charges for security services. LLM costs go directly to your provider.
</Note>

## FAQ

<AccordionGroup>
  <Accordion title="Can I change plans at any time?">
    Yes. Upgrade or downgrade at any time. Upgrades take effect immediately; downgrades at the next billing cycle.
  </Accordion>

  <Accordion title="What happens if I exceed my request limit?">
    You won't be locked out without a choice. On Free and Pro, over-quota requests return `429 Too Many Requests` until you either upgrade or enable pay-as-you-go — then traffic resumes. Scale and Enterprise use soft limits, so your app keeps running and you receive alerts. See [Reaching your limit](#reaching-your-limit).
  </Accordion>

  <Accordion title="What is pay-as-you-go?">
    An opt-in valve so you don't lose protection when you hit your quota. With it enabled, requests above your monthly limit keep being processed and are billed per request at the end of the cycle. It's off by default — you're never charged for overage unless you turn it on.
  </Accordion>

  <Accordion title="Do you offer a free trial?">
    The Free tier (10,000 requests/month) includes the full detection pipeline. Use it to evaluate before upgrading.
  </Accordion>

  <Accordion title="Can I self-host PromptGuard?">
    Self-hosted deployment is available for Enterprise customers. Contact [sales@promptguard.co](mailto:sales@promptguard.co) for details.
  </Accordion>

  <Accordion title="Do failed or blocked requests count against my quota?">
    Yes. Every API call counts, including retries and blocked requests.
  </Accordion>
</AccordionGroup>
