Prompt-injection protection companies, products & suppliers

Controls whose job is blocking or detecting prompt injection, including via tools. Jobs: injection detection; untrusted-context marking; tool-call gating.

What is Prompt-injection protection?

Controls whose job is blocking or detecting prompt injection, including via tools. Jobs: injection detection; untrusted-context marking; tool-call gating.

What problems does it solve?

Tool-using apps will follow instructions hidden in retrieved documents.

Typical business use cases

  • Injection detection
  • Untrusted-context marking
  • Tool-call gating

Important capabilities

  • Detectors
  • Context marking
  • Blocks

What buyers should evaluate

  • False-negative on indirect injection
  • Latency
  • Bypass tests

Risks and governance considerations

A detector that fails open on tool output.

Procurement checklist

  • Fail closed vs open
  • Indirect injection tests
  • Logs

Relevant AI Trustmark assurance

AI Trustmark independent findings appear only when an assessment or certificate exists. Category membership does not imply verification.

Methodology · How verification works

Companies and providers

Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.

  • Akamai is the cybersecurity and cloud computing company that powers and protects business online. Akamai publishes Akamai Firewall for AI as named AI products. Akamai is used for P

  • Cloudflare publishes Cloudflare DLP, Cloudflare Agents SDK MCP Support, and Cloudflare Workers AI as named AI products. Cloudflare is used for Agent integration / MCP and AI agents

  • CrowdStrike is a global cybersecurity leader with an advanced cloud-native platform for protecting endpoints, cloud workloads, identities and data. CrowdStrike publishes Falcon Clo

  • Unified delivery & security for applications, APIs, & AI workloads across any infrastructure, trusted by 85% of the Fortune 500. F5 publishes F5 AI Guardrails and F5 AI Red Team as

  • We help agent builders create reliable, robust and secure products. Invariant Labs publishes Invariant Explorer and Invariant Gateway as named AI products. Invariant Labs is used f

  • The AI-native security platform to accelerate GenAI initiatives—trusted by Fortune 500s, backed by the world’s largest AI red team. Lakera publishes Lakera Guard as named AI produc

  • Meta Platforms sells family-of-apps advertising products and open Llama models. Public AI pages cover research models, Llama releases and developer tooling. Meta publishes LlamaFir

  • Implement Zero Trust, Secure your Network, Cloud workloads, Hybrid Workforce, Leverage Threat Intelligence & Security Consulting. Cybersecurity Services & Education for CISO’

  • Open-source tools, research, analysis, and guidance to understand and respond to AI threats. Prompt Security publishes Prompt Security Automated AI Red Teaming and Prompt Security

  • The AI Security Platform that catches vulnerabilities in development. Trusted by 156 of the Fortune 500 and 300,000+ developers worldwide. Promptfoo publishes ModelAudit as named A

  • Deploy Bravely with the world’s most comprehensive AI security platform securing your AI agents, apps, models and data at every step. Protect AI publishes ModelScan, LLM Guar

  • Radware publishes Radware LLM Firewall as named AI products. Radware is used for Prompt-injection protection work. Radware is recorded in Israel. Radware publishes product informat

Products

Claimed products appear first. Ranking packs and payment do not change this list.

Also used in this category

These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.

Related categories

Relevant procurement and assurance guides

Frequently asked questions

What is Prompt-injection protection?

Controls whose job is blocking or detecting prompt injection, including via tools. Jobs: injection detection; untrusted-context marking; tool-call gating.

What should not be listed as Prompt-injection protection?

Products whose buyer job is broad LLM security suites, content moderation, or guardrail policy engines. Those belong on their own category page so search queries are not split.

Has AI Trustmark independently assessed every Prompt-injection protection supplier?

No. A category listing is descriptive. Independent assessment is shown only on company or product pages that carry Trustmark evidence.

How should prompt injection and tool-output attacks be controlled?

Agents that read untrusted content or tool output can be instructed to exfiltrate data or take writes. Buyers should ask what is treated as untrusted, whether tool output can change the plan, and what tests were run. Scanner marketing is not the same as independent testing.

What security testing evidence should buyers request for an AI product?

Ask what was tested, against which version, whether prompt-injection, data-exfiltration and tenant isolation were in scope, and where failed prompts were stored. A generic ISO certificate or a vendor scanner screenshot is not by itself an AI TrustMark assessment.

What model or provider changes should a buyer insist on being told about?

Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.

How should buyers verify where AI customer data is processed?

Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.

Does a TrustMark on one product cover the rest of the company?

No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.