PromptGuard is built with enterprise security requirements in mind. This page outlines our security practices, compliance status, and data handling policies.
At a glance
For security teams evaluating PromptGuard, the three things that usually matter most:- What we do with your data — pass-through architecture: we scan prompts and responses in real time and don’t store prompt content or train on it. Your LLM provider keys stay with you. (See Data Handling.)
- Proof for auditors — every security decision is recorded in a tamper-evident, hash-chained audit log with event ID, threat type, confidence, and timestamp.
- Where we stand on frameworks — summarized in the table below.
“Compliant” vs “Aligned”: Compliant means we meet the requirement (with a DPA or independent attestation where applicable). Aligned means PromptGuard provides the technical controls a framework requires, but formal third-party certification is still in progress or out of scope. We don’t claim certifications we don’t hold.
Security Certifications
“Aligned” means PromptGuard provides the technical controls that satisfy the framework’s requirements. Formal certification (where applicable) requires third-party audit. For enterprise customers requiring specific compliance certifications, contact sales@promptguard.co to discuss your requirements.
EU AI Act Alignment
The EU AI Act (Regulation 2024/1689) imposes requirements on high-risk AI systems, enforceable from August 2, 2026. PromptGuard provides technical controls that map to each requirement:ISO/IEC 42001 Alignment
ISO/IEC 42001:2023 is the international standard for AI Management Systems. PromptGuard’s controls map to its Annex A requirements:Data Handling
What Data We Process
Data Flow
Pass-Through Architecture
PromptGuard operates as a pass-through proxy:- Prompts and responses are scanned in memory
- Content is not stored after processing
- Only metadata (timestamps, threat types, confidence scores) is logged
- Your data never touches disk in unencrypted form
Infrastructure Security
Cloud Infrastructure
Encryption
Network Security
- All endpoints require HTTPS
- Cloud Armor per-IP anti-abuse rate limiting at the network edge
- No public SSH access to infrastructure
- VPC-based isolation between services
- Private database connections (no public IP)
Access Control
Authentication Methods
API Key Security
- Keys are hashed with Argon2id before storage
- Only the prefix (
pg_live_xxxxxxxx...) is stored in plain text - Full key shown only once at creation
- Keys can be rotated without downtime
- Project-scoped API keys (no per-key permission types; tier gating via subscription)
Role-Based Access (Enterprise)
Audit Logging
What’s Logged
Accessing Audit Logs
- Go to Dashboard → Settings → Audit Logs
- Filter by date range, event type, or user
- Export as CSV or JSON
Log Export (Enterprise)
Enterprise customers can configure:- SIEM Integration: Stream logs to Splunk, Datadog, etc.
- S3 Export: Daily log exports to your bucket
- Webhook: Real-time log forwarding
Incident Response
Security Incident Process
- Detection: Automated monitoring + manual review
- Containment: Isolate affected systems
- Investigation: Root cause analysis
- Notification: Affected customers notified within 72 hours
- Remediation: Fix deployed, post-mortem published
Reporting Security Issues
Found a vulnerability? Contact us:- Email: security@promptguard.co
- Response Time: 24 hours for initial acknowledgment
- Bug Bounty: Coming soon
Data Residency
Current Regions
Planned Regions
Enterprise customers requiring specific data residency can request dedicated deployment in their preferred region.
Vendor Security
Subprocessors
LLM Providers
PromptGuard forwards requests to your chosen LLM provider. We do not store data sent to:- OpenAI
- Anthropic
- Google AI
- Cohere
- AWS Bedrock
- Azure OpenAI
AI Agent Governance
PromptGuard provides four governance capabilities for AI agents operating in production:Agent Identity
Register agents with verified cryptographic credentials. Each agent receives a uniquepgag_ secret that authenticates tool-call and guard requests. Self-asserted agent IDs still work (backward compatible), but verified agents get explicit identity confirmation in audit logs and governance reports.
POST /api/v1/agent/register— Register and receive a one-time credentialPOST /api/v1/agent/{agent_id}/rotate-credential— Revoke old credential, issue new oneX-Agent-Credentialheader for verified requests
Behavioral Drift Detection
After an agent accumulates sufficient observations, PromptGuard freezes a behavioral baseline capturing the agent’s normal tool-usage distribution. Every subsequent request is compared against this baseline using Jensen-Shannon divergence. If the distribution shifts beyond the configured threshold, aBEHAVIORAL_DRIFT alert fires.
Tamper-Evident Audit Trail
Every audit event’s SHA-256 hash incorporates the previous event’s hash, forming a cryptographic chain. If any event is modified or deleted, the chain breaks and verification fails. UsePOST /dashboard/audit-log/verify-chain to verify chain integrity over any time range.
Governance Reports
Generate auditor-facing narrative reports covering all four governance capabilities:Enterprise Security Features
Available on the Enterprise tier:Security Questionnaire
Need to complete a vendor security assessment? We provide:- CAIQ (Consensus Assessment Initiative Questionnaire)
- SIG Lite (Standardized Information Gathering)
- Custom Questionnaires (for Enterprise customers)
Responsible Disclosure
We appreciate security researchers who help keep PromptGuard secure:- Report the issue to security@promptguard.co
- Do not publicly disclose until we’ve addressed it
- Provide steps to reproduce
- Allow reasonable time for remediation (90 days)
Next Steps
Security Overview
Learn about threat detection
Audit Logs
Monitor user activity
Enterprise
See Enterprise features
Contact Sales
Discuss your requirements