Skip to main content
PromptGuard Enterprise provides multi-tenancy, SSO, role-based access control, persistent audit logs, IP allowlisting, and custom billing — all built-in. No separate deployment needed.For custom Enterprise plans, contact us at enterprise@promptguard.co.

Enterprise Features Overview

What’s Included

Getting Started

1. Create Your Organization

2. Invite Team Members

3. Set Organization Context

All dashboard API calls accept the X-Organization-Id header to scope operations to your organization:

RBAC (Role-Based Access Control)

Role Hierarchy

Enforcing Roles

Roles are enforced server-side. No client-side bypasses possible:

Self-Hosted Deployment

Run the entire PromptGuard engine — API, dashboard, database, cache — on your infrastructure. In the package’s default Air-gapped mode, prompts, verdicts and events stay on your network, with egress denied by your firewall; the Shadow AI agents on your fleet point at your engine instead of our cloud.
Self-hosting is part of the Enterprise agreement: you receive source access (Business Source License — you can audit exactly what the engine does with your data), a signed license file, and the deployment package described here. Contact sales@promptguard.co to get set up.

Deploy with Docker Compose

The deployment package ships a hardened Compose stack (API with read-only filesystem and dropped capabilities, Postgres, Redis, dashboard, and nginx as the single entry point to the API). The API and dashboard are signed, prebuilt images in PromptGuard’s private registry; your licence comes with a read-only pull credential and the release you are licensed for. From the package root:
Key environment choices (all documented inline in deploy/docker-compose.yml):

Deploy with Helm (Kubernetes)

Generate the three API secrets once (openssl rand -hex 32, or -hex 16 for the salt), keep them in your secret store, and pass the same values on every helm upgrade: changing the salt or the encryption key makes the provider credentials already stored unreadable. The chart includes HPA autoscaling, pod disruption budgets and ingress. It runs on a PostgreSQL and a Redis you operate, such as a managed cloud database or one run by a Kubernetes operator, and refuses to install until both Secrets and the three API secrets are named. On a fresh database the user in DATABASE_URL must be a superuser, or have CREATEROLE and BYPASSRLS, because the first migration creates database roles.

How licensing works (and why it is privacy-safe)

Your license is an Ed25519-signed file verified locally against PromptGuard’s public verification key (embedded in the deployment package). There is no license server in the request path, and licensing sends no content:
  • Signature verification is local and offline — the engine checks the signature and expiry itself, on startup.
  • Air-gapped mode makes no licence calls. With DEPLOYMENT_MODE=airgap (the deployment package default) the license heartbeat is disabled entirely — the license is enforced by signature and expiry alone.
  • Connected mode’s only licence call is a daily, metadata-only heartbeat (license id, node fingerprint, customer name — never prompts, verdicts, or any request content). If the heartbeat can’t get out, the engine keeps serving through a configurable grace window (PROMPTGUARD_LICENSE_GRACE_DAYS). If the window runs out, billable requests get a 503 until the next heartbeat that reaches us — the engine keeps trying hourly, and recovery needs no restart.
  • What you can verify yourself: the license and heartbeat code paths are in the source you receive (shared/licensing/, shared/billing/license.py) — auditable end-to-end, including exactly what the heartbeat payload contains.

Point your Shadow AI fleet at your engine

The agent is identical in cloud and self-host modes — only the engine URL changes. Detection, redaction, and event storage all happen inside your perimeter.

Load Balancer Configuration

Security Hardening

Network Security

Secret Management

RBAC Configuration

Compliance

Persistent Audit Logs (SOC 2)

All security-relevant events are persisted to the audit_events table with tamper-resistant integrity hash chaining. Querying interaction logs:
Available filters: Each event includes an integrity_hash (SHA-256) for tamper detection.

GDPR Compliance

Data Export (Right to Access):
Returns all user data: profile, organizations, projects, subscriptions, and security events. Data Deletion (Right to Erasure):
Cascading deletion of all user data. An audit record is created before deletion for compliance tracking.

Monitoring and Observability

Enterprise Monitoring Stack

Custom Alerting Rules

Grafana Dashboards

Disaster Recovery

Backup Strategy

Disaster Recovery Runbook

Performance Optimization

Enterprise Performance Tuning

Auto-scaling Configuration

Integration Examples

Enterprise SSO Integration (SAML & OIDC)

PromptGuard supports SAML 2.0 and OIDC single sign-on, configured per organization. Compatible with Okta, Microsoft Entra ID, Google Workspace, Auth0, OneLogin, and any compliant provider.
The recommended path is self-serve: an org admin connects their IdP through a hosted setup portal — see Single Sign-On (SSO) and Directory Sync (SCIM). The direct-OIDC configuration below is the manual alternative for self-hosted deployments.
Direct OIDC flow (self-hosted):
  1. User visits https://api.promptguard.co/dashboard/auth/sso/{org-slug}/authorize
  2. PromptGuard redirects to IdP with PKCE challenge
  3. User authenticates at IdP
  4. IdP redirects back with authorization code
  5. PromptGuard exchanges code for tokens, retrieves user info
  6. User is auto-provisioned (if enabled) and logged in
Configuration (stored in organizations.settings.sso_config):
Supported IdP Providers:

Enterprise API Gateway Integration

Cost Optimization

Resource Planning

Usage Analytics Dashboard

Best Practices Summary

  • Zero Trust Architecture: Verify every request and user
  • Defense in Depth: Multiple security layers and controls
  • Least Privilege: Minimal necessary access permissions
  • Regular Audits: Automated compliance and security scanning
  • Incident Response: Documented procedures and automation
  • Horizontal Scaling: Auto-scaling based on metrics
  • Connection Pooling: Efficient database and cache connections
  • Caching Strategy: Multi-layer caching for optimal performance
  • Resource Limits: CPU and memory constraints for stability
  • Load Testing: Regular performance validation under load
  • Infrastructure as Code: Version-controlled deployments
  • Blue-Green Deployments: Zero-downtime releases
  • Comprehensive Monitoring: Real-time metrics and alerting
  • Automated Backups: Regular, tested backup procedures
  • Documentation: Maintained runbooks and procedures
  • Data Classification: Understand and protect sensitive data
  • Audit Trails: Comprehensive logging and immutable records
  • Regular Assessments: Scheduled compliance reviews
  • Privacy by Design: Built-in privacy protections
  • Vendor Management: Ensure third-party compliance

Support and Migration

Enterprise Support Channels

  • 24/7 Support: Critical issue response within 1 hour
  • Dedicated CSM: Assigned Customer Success Manager
  • Architecture Review: Quarterly infrastructure assessments
  • Training Programs: Enterprise security and operations training
  • Migration Assistance: White-glove migration from existing solutions

Professional Services

  • Custom Integration: Tailored integration with existing systems
  • Security Assessment: Comprehensive security posture evaluation
  • Performance Tuning: Optimization for enterprise workloads
  • Compliance Consulting: Industry-specific compliance guidance
  • Disaster Recovery Planning: Business continuity strategy development

Enterprise Portal

Access enterprise dashboard and management tools

Professional Services

Get white-glove setup and migration assistance

Security Center

Configure advanced security policies and monitoring

Compliance Hub

Manage regulatory compliance and audit requirements
Need enterprise support? Contact our team at enterprise@promptguard.co for personalized deployment assistance.