Prompt Security
Prompt Security, a SentinelOne product, governs enterprise AI use across employees, autonomous agents, MCP servers and homegrown apps. It discovers shadow AI, redacts sensitive data and blocks prompt injection across 15,000+ AI services. Quote-based purchase only.
What is Prompt Security?
Prompt Security is an enterprise AI security platform, today a SentinelOne product integrated into the Singularity platform. The company behind it was founded in Israel in August 2023 by Itamar Golan (CEO) and Lior Drihem (CTO); its acquisition by SentinelOne was announced on 5 August 2025, and the site now carries the title Prompt Security | From SentinelOne.
The platform is organized around three pillars. AI Usage Control covers how employees and developers use AI: it discovers shadow AI, producing an inventory of unsanctioned tools along with who uses them and with what data, and it governs more than 15,000 AI tools and services, with a claim of 100% visibility over employee usage, code assistants, applications and agents. Agentic AI Security addresses autonomous agents and the Model Context Protocol: an MCP Gateway, presented as the first comprehensive solution for agentic AI security, detects rogue MCP servers, dynamically scores the risk of more than 13,000 MCP servers listed on GitHub, and records agent actions in a searchable audit log. AI Application Security protects homegrown GenAI apps through an AI Gateway that sits between the application and the LLM or MCP server and inspects requests and responses in real time.
Code assistants are named explicitly, GitHub Copilot, Cursor and Claude Code, and are protected against leakage of intellectual property and secrets. Pre-production red teaming is converted automatically into production guardrails on a shared policy fabric. Deployment is claimed to take minutes, with no complex integration and no infrastructure change, using a lightweight agent or a reverse proxy; hosting can be cloud, self-hosted VPC or on-premise, and the platform is LLM-agnostic. A REST API is exposed at app.prompt.security/api/protect with an APP-ID header.
Alongside the commercial product, three free open source tools are published: Prompt Fuzzer (ps-fuzz, 16 providers and 16 attack types), ClawSec for OpenClaw, NanoClaw and Hermes agents, and OneClaw for visibility over OpenClaw deployments. The prompt.security site has itself become a resource portal, with a blog, a glossary, the AI Security Academy, the PromptCast podcast, an AI Security Startup Map and AI usage statistics, while the product page now lives on sentinelone.com. Stated risks addressed include shadow AI, sensitive data leaking to models, prompt injection, jailbreaks, unsafe outputs, data poisoning, unauthorized agent actions, Denial of Wallet and remote code execution.
What it does
- Inventory every AI tool, code assistant and shadow AI service in use across the organization
- Redact sensitive data and enforce policies across 15,000+ AI services in real time
- Block adversarial prompts and sanitize sensitive outputs through a real-time AI firewall
- Map every autonomous agent and MCP server running in the environment
- Apply least privilege to agents so they operate only within their defined scope
- Test for prompt injection, jailbreaks and data poisoning before going to production
- Log every agent action in a searchable audit trail
When to use Prompt Security / When not to
A quick filter to help you decide if Prompt Security is the right fit.
When to use Prompt Security
- Enterprise security teams (CISO, SOC, AppSec, GRC) looking for a single control point over company-wide AI use
- Regulated organizations that need a vendor certified FedRAMP High, SOC 2 Type 2, ISO 27001:2022, and aligned with HIPAA, PCI DSS and GDPR
- Existing SentinelOne customers, since Prompt Security is administered from the same Singularity console
- Engineering teams rolling out code assistants such as GitHub Copilot, Cursor and Claude Code who must keep secrets and proprietary code out of prompts
- Platform and AI teams exposed to autonomous agents and MCP servers, who need inventory, least-privilege enforcement and an audit trail
When not to use Prompt Security
- Individuals and freelancers: there is no free plan, no public price and no self-service sign-up
- Small organizations with no dedicated security function, as buying runs through a quote and an authorized third-party partner
- Anyone looking for a generative AI assistant: the platform secures AI tools, it does not produce content
- Mobile-first users: there is no iOS or Android application, only a web console and an API
- Buyers who require 24/7 support, since the product addendum commits to business hours only, Sunday to Friday, 8am to 8pm Israel time
How to use Prompt Security
A typical end-to-end flow, from setup to results.
- Request a demo from the SentinelOne landing page or take the interactive product tour: there is no self-service sign-up
- Go through sales to obtain a quote, the purchase itself being completed with an authorized third-party partner
- Choose a deployment model: cloud, self-hosted VPC or on-premise
- SETUP phase: connect the environment, using a lightweight agent or a reverse proxy for homegrown applications
- Sign in to the customer console at prompt.security/sign-in, or administer the product from the unified Singularity console
- BUILD phase: define policies by role, department, user, group or custom GPT
- For a homegrown AI app, redirect openai.api_base to https://app.prompt.security/api/protect, or call the API directly with the APP-ID and Content-Type headers
- Review the inventory of AI tools, agents and MCP servers, then the audit log of agent actions
- EVOLVE phase: scale as AI adoption spreads across departments
- Contact support at contact@prompt.security or through a shared Slack channel, Sunday to Friday, 8am to 8pm Israel time; Professional Services for installation, configuration, integration and training are available on request and billed separately
Pros & Cons
Pros
- Covers the three AI surfaces (employee usage, homegrown applications, agents and MCP servers) in a single product
- Backed by the group's compliance base: FedRAMP High, SOC 2 Type 2 audited by Schellman, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, BSI C5:2020 and IRAP Protected
- Flexible hosting (cloud, self-hosted VPC or on-premise) and LLM-agnostic, so it works with internal or third-party models
- Complete and dated legal documentation: DPA, subprocessor list (20 May 2026) and a dedicated product addendum (14 May 2026)
- Three free open source tools let teams evaluate the approach before buying
- Formalized support SLAs by severity, with a two business hour response target for L1 and L2
- One-line API integration for homegrown applications, and a unified console for existing Singularity customers
Cons
- No public price for Prompt Security: the platform-packages grid only covers Singularity packages billed per endpoint
- Purchase must go through an authorized third-party partner, so the final price is not set by the vendor
- No self-service sign-up or trial; every call to action on the site leads to a demo request
- Support is business hours only, Sunday to Friday, 8am to 8pm Israel time
- No public API documentation page, and the technical documentation sits behind the customer portal
- prompt.security no longer presents the product itself: evaluating it means moving over to sentinelone.com
- No documented opt-out from model training, no Article 27 EU representative, and no numeric retention period for personal data collected through the websites
Pricing & Plans
There is no free plan and no published price for Prompt Security. The SentinelOne platform packages page lists Singularity Complete at USD 179.99 per endpoint per year and Singularity Commercial at USD 229.99 per endpoint per year, with Singularity Enterprise on quotation; those prices are quoted excluding tax for 5 to 100 workstations, and none of the three packages lists Prompt Security among its features. The vendor states that all purchases are made through an authorized third-party partner and that the published prices do not reflect final pricing. The Master Subscription Agreement provides for a free evaluation license of up to 30 days, granted at SentinelOne's discretion. Billing runs on purchase order and quote, with a True-Up clause where usage exceeds the order in force.
- No pricing plan is published under the Prompt Security name
- USD 179.99 per endpoint per year - 14-day data retention
- endpoint and cloud protection
- AI Security Assistant
- USD 229.99 per endpoint per year - 90-day retention
- Identity Detection & Response
- Managed Threat Hunting
- on quotation - Agentic AI SOC Analyst
- Full Visibility & Forensics
- guided onboarding and training
- up to 30 days under the Master Subscription Agreement
- Prompt Fuzzer
- ClawSec and OneClaw
Data, GDPR & hosting
A consolidated view of how Prompt Security handles your data.
GDPR overview
GDPR implementation is documented rather than simply asserted. A public Data Protection Addendum and a dated subprocessor list are available. Transfers rely on the European Commission's standard contractual clauses and the UK International Data Transfer Addendum, and SentinelOne certifies to the EU-U.S. Data Privacy Framework, the Swiss-U.S. DPF and the UK Extension with the U.S. Department of Commerce, the FTC acting as enforcement authority. Adequacy references include Article 45 GDPR, Article 45 UK GDPR together with section 17A of the Data Protection Act 2018, and Annex 1 of the Swiss O-FADP. A data protection officer is reachable at privacy@sentinelone.com. The contact page states the product supports compliance with frameworks such as HIPAA, PCI DSS and GDPR through audit-ready logging, retention and reporting. The privacy notice in force is dated 14 May 2026. No Article 27 EU representative is designated in the pages collected.
Who owns the data?
The Master Subscription Agreement is entered into between SentinelOne, Inc. and the customer. Under section 7, SentinelOne owns the Solutions, the Documentation, the System Data and all associated intellectual property rights. The customer keeps its own Customer Data, which the Data Protection Addendum states is processed exclusively to provide the Solutions, including any retention period purchased for a specific Solution. Access to and storage of that data are available only during the Subscription Term. On termination, all copies of Customer Data are deleted within 60 days of the Cessation Date unless law requires storage, written certification of deletion is supplied within 10 days of a written request, and the security annex describes the deletion as irretrievable.
Reuse rights
Customer Data is processed exclusively to deliver the Solutions, and the CCPA clauses of the Data Protection Addendum prohibit SentinelOne from selling or sharing it. System Data is a separate category, split into Technical & Operational, Console, Feature Usage and Threat Data: it is used to improve performance and functionality, and Threat Data specifically feeds SentinelOne's proprietary machine learning engines. The privacy notice states that "any limited personal information contained within System Data is never incorporated into the Solutions, nor is it used to contact or market products or services". The documents collected govern what the vendor may do with the data rather than restricting the customer's reuse of its own Customer Data, but access and storage are contractually tied to the Subscription Term. A subprocessor list dated 20 May 2026 names AWS, Google LLC, Microsoft Azure, Anthropic PBC, OpenAI, Cloudflare, Salesforce, Zendesk, Atlassian, Slack, Twilio, Zoom, Five9, ShareFile, Torq, Zimperium, Dovetail and Monday.com; Anthropic, OpenAI, Azure and Google appear under an LLM hosting activity, with a processing country described as dependent upon customer configuration. Sixteen SentinelOne subsidiaries also act as affiliate subprocessors.
Data retention & training
Hosting summary
SentinelOne describes itself as a U.S.-based company operating globally, and the privacy notice states that personal information is provided to the company in the United States. The declared hosting subprocessors are Amazon Web Services (410 Terry Avenue North, Seattle), Google LLC, Microsoft Azure and Cloudflare, whose processing country is listed as dependent upon customer configuration, so the actual jurisdiction follows the deployment chosen by the customer. The product can be run in the cloud, in a self-hosted VPC or fully on-premise. Eight European subsidiaries are listed as affiliate subprocessors, in Dublin, Munich, Amsterdam, Paris, Milan, Warsaw, Prague and Hellerup, but none is designated as an EU contracting entity. Hosting-related certifications include ISO 27017:2015 for cloud security, ISO 27018:2019 for personal data in public clouds, BSI C5:2020 and FedRAMP High (marketplace reference FR1919071020A). Transfers out of Europe are framed by standard contractual clauses, the UK International Data Transfer Addendum and the Data Privacy Framework.
Things to keep in mind
Risks and trade-offs to weigh before adopting Prompt Security.
- Automated guardrails can breed a false sense of safety: real-time filtering and employee coaching lower the risk but do not remove the need for human judgement about what is typed into an AI tool
- The prices displayed on the platform-packages page do not apply to Prompt Security, and the final price is set by an authorized third-party partner
- The True-Up clause means any usage above the purchase order in force is billed retroactively
- No training opt-out is documented: System Data, including Threat Data, feeds SentinelOne's proprietary machine learning engines
- EU to United States transfers rely on the Data Privacy Framework and standard contractual clauses, but no Article 27 EU representative is designated and no numeric retention period is stated for data collected through the websites
- The LLM subprocessors (Anthropic, OpenAI, Azure, Google) have a processing country dependent upon customer configuration, which should be pinned down contractually
- Support is limited to business hours, Sunday to Friday, 8am to 8pm Israel time, so an incident raised outside that window waits; product information itself has moved to sentinelone.com, which complicates evaluation from prompt.security
Setup & Integrations
Technical difficulty
Technically light, commercially demanding. The vendor promises deployment in minutes with no complex integration and no infrastructure change, through a three-step path: connect the environment, define the policies, then scale. Homegrown applications are covered by a lightweight agent, a reverse proxy or a one-line API redirect. The real friction lies elsewhere: a quote is mandatory before anything starts, there is no self-service, and no public technical documentation exists to prepare the rollout. Guided onboarding and training are available as Professional Services, billed separately.
Deployment
Integrations
Behind Prompt Security
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Who publishes Prompt Security?
How much does Prompt Security cost?
Is there a free trial?
Which security certifications does the vendor hold?
Where is the data hosted?
Is customer data used to train models?
Is a DPA available?
How long is data kept?
Is there an API?
What free tools and integrations are available?
Should you pick Prompt Security?
Prompt Security is a mature enterprise product rather than a tool an individual can pick up. Its distinguishing feature is coverage: employee and developer AI usage, homegrown GenAI applications, and autonomous agents with their MCP servers are handled by a single platform, where most competitors address one surface at a time. Since the acquisition by SentinelOne it inherits a substantial compliance base, with FedRAMP High, SOC 2 Type 2, ISO 27001:2022, ISO 27017:2015, ISO 27018:2019, BSI C5:2020 and IRAP Protected, along with complete and dated legal documentation: a Data Protection Addendum, a subprocessor list and a product-specific addendum. Hosting flexibility (cloud, self-hosted VPC or on-premise) and an LLM-agnostic design make it workable in constrained environments.
The reservations are commercial more than technical. There is no public price for this product, no self-service sign-up, and every purchase goes through an authorized third-party partner, which lengthens the buying cycle and puts the final amount outside the vendor's control. Support is business hours only. Evaluation is also made harder by the fact that prompt.security no longer hosts the product page, which now sits on sentinelone.com, while the original domain has become a resource portal. On the governance side, no training opt-out is documented, no Article 27 EU representative is named, and the processing country of the LLM subprocessors depends on customer configuration, all of which deserve contractual clarification.
Teams wanting to assess the approach before engaging with sales have a free route in: the three open source tools, Prompt Fuzzer, ClawSec and OneClaw, are published on GitHub and require no subscription. For an organization with a security team, an enterprise budget and real exposure to AI, the product is a serious candidate; outside that profile, it is out of reach.
- Choosing a selection results in a full page refresh.
- Opens in a new window.