Intelligent Threat Prevention for LLMs, Agents, and APIs
Inline AI firewall that inspects every prompt, response, and tool call. Blocks prompt injection, jailbreaks, data exfiltration, hallucinations, toxicity, and unauthorized tool use — with sub-millisecond latency impact.
See AI Firewall and Guardrails in Action
See AI Gateway: Shadow AI, Embedded AI, and Policy Enforcement in Action
Built for agentic AI, not just chatbots
AI Firewall sits between your users and every model — whether that's ChatGPT, Claude, Gemini, a self-hosted LLM, or an internal agent framework. Policies inspect every prompt, response, and tool call in real time.
Prompt & response inspection
Every prompt and every model response passes through a policy DSL. Detect prompt injection, jailbreaks, and unauthorized instructions before they reach the model or your user.
Inline data loss prevention
PII, PHI, secrets, classified markings, and custom-sensitivity tokens are redacted or blocked before a prompt ever leaves your perimeter.
Tool-use & function-call governance
Allow-list the tools an agent can invoke. Inspect arguments, enforce argument types, and revoke tool access the moment a policy violation fires.
Sub-millisecond latency
Inline or out-of-band deployment patterns. Inline adds under a millisecond to most inference paths; out-of-band captures telemetry with zero user impact.
DDoS & API protection
Rate-limit, throttle, and isolate abusive callers at the AI API layer. Adaptive rules tune themselves against live traffic patterns.
Adversarial ML defense
Detect model-inversion, membership-inference, and poisoning attempts across both provider APIs and self-hosted models.
Key Capabilities
AI Firewall training videos
Free training videos are recorded in the live AI Firewall platform. AI-edited, with an AI voiceover. See the AI Firewall training series
Dashboard
AI Firewall Dashboard: see your AI usage before you secure it
The AI Security Dashboard tracks audit records, registered members, AI HealthChecks, and configured LLMs, and shows which models handle general queries, reliability and hallucination checks, and RAG. Token Usage splits the last seven days into input and output tokens.
Secure Chat
AI Firewall Secure Chat: catch sensitive data before a prompt goes anywhere
Secure Chat detects PII like a name, address, and Social Security number, stops with a compliance warning, and swaps each value for a realistic stand-in so no model sees the real data. The anonymized prompt goes to more than one model, and Reliability Check scores every answer side by side.
Activity History
AI Firewall Activity History: prove every prompt was handled safely
Activity History logs every prompt, the model's response, and its compliance, privacy, and reliability assessments. Each entry shows the detected issues and the guardrail resolutions applied, the evidence trail security and compliance teams ask for.
File Sanitization
AI Firewall File Sanitization: clean documents before they reach AI tools
File Sanitization cleans uploaded files by removing malicious content, with a job history showing each run's status, owner, and type. Name a job, attach a document, and Start Sanitizing adds it to the list as Pending until processing finishes.
Keyword Policy
AI Firewall Keyword Policy: block, disguise, or preserve the words in every prompt
Safeguard Keywords blocks jailbreaks, misuse, and restricted content, and Anonymize Keywords hides private terms like a company name. Don't Anonymize Keywords keeps business terms and product names intact so prompts keep their meaning.
Workspace Settings
AI Firewall Workspace Settings: match privacy rules to the regulations you answer to
Choose a privacy level, Fictionalize or Mask as the security preference, and reliability features aimed at preventing hallucinations. Compliance settings select regulations like CCPA, HIPAA, and PCI DSS, plus sensitive keyword attributes grouped by category.
LLM Configuration
AI Firewall LLM Configuration: bring your own models without giving up control
Administrators set up the models the workspace can use, with automatic AI health checks and privacy monitoring on a lightweight ZeroTrusted.ai privacy model. Each configured model gets a card with its role, active status, and its own key.
AI Gateway Rules
AI Firewall AI Gateway Rules: take control of shadow AI
AI Gateway Rules decide which public AI tools are off limits, at the domain level, with block lists and white lists. Every rule moves through Approved, Requested, and Declined, and records its type, status, who created it, and when.
Proxy Settings
AI Firewall Proxy Settings: control what flows through the Shadow AI proxy
Proxy Settings configures trusted IP addresses, safeguard keywords, PII detection thresholds, and enforcement behavior. With Enforcement Mode set to Block, requests containing PII or keywords are blocked rather than just flagged with a warning.
Audits & Logs
AI Firewall Audits & Logs: who used AI, how, and what the firewall did
Audits & Logs brings the organization's records together: an organization-wide audit log with the guardrail resolutions for every prompt, API logs for every call, and notifications tracking every system alert that goes out.
Identity Policy Center
AI Firewall Identity Policy Center: know exactly who is using AI
Administrators invite users with specific roles, one at a time or by file upload, and can update a role, send a reset email, remove access, or suspend a user. Authorized Users lists each person's role, status, and login method.
Access and Roles
AI Firewall Access and Roles: safe AI settings every user gets automatically
Organization-wide policies cover audit logging, keyword safeguards, sanitization, compliance checks, and hallucination detection, and apply to all connected users. Roles Management starts from the default Admin, Power User, and User roles, each with its own permissions.
AI Assistant
AI Firewall AI Assistant: ground AI in your own documents, under control
The AI Assistant combines file upload with search so teams can manage and retrieve their own data through AI. Each persona shows its RAG status and approval, and a Detected PII column marks which personas have PII findings.
AI HealthCheck
AI Firewall AI HealthCheck: catch models that quietly drift
AI HealthCheck assesses the performance, reliability, and security of your AI models. Data Drift scans pair a patient model with a state-of-the-art reference model and open into a full report, and the Hallucination tab keeps its own scan history.
Developer API
AI Firewall Developer API: give your own applications the same protection
API Documentation covers Secure AI Prompt, RAG Assistant, AI HealthCheck, Audit Log, Shadow AI, and API Keys, with every parameter documented. Each API key can be scoped to specific modules and users and shows when it expires and when it was last used.
AI FinOps & Cost-Risk Assessment
Every AI call has a cost and a risk. AI SOAR FinOps and the AI Firewall allocate, optimize, compare, and control AI spend: cost by user, agent, and model, verified savings, API run rate versus private GPU TCO, and Shadow AI signals checked against evidence.
Recorded in the live ZeroTrusted.ai platform. AI-edited, with an AI voiceover.
Deploy where it fits
Three operational modes — pick one per application or combine them across your AI portfolio.
Inline proxy
Terminates AI API traffic for prompt/response inspection. Ideal for production-path enforcement with hard-block policies.
Out-of-band
Mirrors traffic for detection-only workflows and A/B policy tuning. Zero latency impact on the production path.
Browser / edge
Combines with Shadow AI Protection to enforce at the user's edge — for unmanaged AI endpoints and shadow AI usage.
AI Agent Attack Readiness
The assessment tests two layers. The ZeroTrusted.ai AI Firewall enforces policy on prompts, tools, and data. AI SOAR correlates, investigates, and responds.
Ready to deploy AI Firewall?
See how AI Firewall integrates with your existing security stack. Schedule a personalized demo today.