SafePrompt · Prompt injection detection API
Get a free API key
SafePrompt
Prompt injection detection API for LLM apps and agents.

Security and data handling

SafePrompt deletes the prompt text of every blocked request after 24 hours, so an attack on your app never becomes a lasting copy of your users' words on our servers. This page is specific enough to check.

Security facts last reviewed: 12 September 2026

The rule: on the free plan we store only the prompts we block. On a paid plan, contribution starts switched on and we store every request you send, safe and blocked, until you switch it off in the dashboard. Stored prompt text and the raw client IP are deleted after 24 hours by an hourly job, and the hashes that remain go with the record at 90 days. Validating a prompt means sending it to a language model, so your prompt text reaches the providers listed below. We do not sell data.

What data does SafePrompt store?

  • Safe prompts: on the free plan, processed in memory and never written to storage, with only the result and request metadata logged. On a paid plan they are stored for 24 hours while Intelligence Sharing is switched on, which is how an account starts; switch it off in Settings, Privacy and Data Controls and we store nothing.
  • Blocked prompts: prompt text and the client IP are held briefly for network defence, then deleted.
  • Request metadata: timestamp, account id, verdict, threat categories, processing time.
  • Account data: email and a hashed password. Billing runs through Stripe and we never store card numbers.
  • Attack pattern hashes: cryptographic hashes, pseudonymous rather than anonymous, deleted with the record they belong to at 90 days.

How long does SafePrompt keep your data?

DataDeleted afterEnforced by
Blocked prompt text24 hoursHourly retention job
Client IP, raw24 hoursHourly retention job
Hash of a blocked prompt, hash of the IP90 daysScheduled record deletion
Multi-turn session data2 hours idle, 24 hours at mostHourly session cleanup
Request metadata30 daysScheduled deletion
Account dataLife of the account, then 90 days after you close itDeletion request

Windows enforced by scheduled jobs against the production database, September 2026.

Two categories sit outside this table because no scheduled job in the API enforces them: billing records, kept for seven years because tax law requires it, and usage metrics at 90 days. The privacy page carries the full table.

The job proves its own work. After each run it queries for personal data older than the window and raises a critical alert if it finds any, so a silent no-op is noticed instead of passing as success.

Who else processes your prompts?

SafePrompt pins provider routing in code and versions it in git, so a change is a reviewable code change rather than a silent configuration switch. Since 17 August 2026 your prompt reaches only the companies below. Before that date, routing fallbacks were enabled and a small fraction of requests may have reached other inference providers available through OpenRouter. The privacy page carries the same list plus the email and analytics processors, and records that history too.

  • OpenRouter: routing gateway.
  • Groq, Cloudflare, Together AI, DeepInfra: inference providers.
  • TypeSafe: an additional safety check, reached through OpenRouter.
  • Supabase: database, hosted on AWS.
  • Vercel: API hosting, AWS us-east-1.
  • Cloudflare Pages: frontend delivery.
  • Stripe: payments. Stripe never receives prompt content.

Inference providers operate globally and the region for a given request is not pinned. If you need a fixed inference region, tell us before you integrate.

How are your API keys protected?

  • Your API key is stored as a hash, so nobody can read it back, including us.
  • API traffic runs over TLS; always call the https:// endpoint.
  • The database is encrypted at rest with AES-256.
  • Every read is scoped to your API key, so one account's records are not reachable from another's. That scoping is enforced in the API and in database row-level security, and it is on the list for the first external test.
  • Provider tokens and database credentials are platform-managed secrets and never reach source control. A secret scanner in the deploy pipeline blocks live-format keys before anything ships.

Your data stays yours

  • Export: download your data from your dashboard at any time. You can also ask us at [email protected] and we send it within 30 days.
  • Deletion: erase the identifiable data from your last 24 hours yourself in dashboard settings. To close an account and delete the data we hold, email [email protected] and we do it within 30 days. The prompt and IP hashes are not removed on request; they are deleted with their record at 90 days.
  • Data Processing Agreement: on request from [email protected].
  • We never sell your personal information and we never share it for cross-context advertising. The free plan does trade blocked prompts for the service, and the privacy page sets out what that exchange is worth and how to leave it.
  • Network intelligence: paid plans can switch off pattern sharing.

How do you report a vulnerability?

Send a security issue to [email protected]. We aim to acknowledge within two business days and to give you an initial assessment within ten, and we will credit you in the fix announcement if you want it. If we are going to miss that, we will tell you.

Safe harbour. If you follow the rules below, we will not bring or support legal action against you for your research, and we will say so in writing if anyone asks. Stay within them: test only against your own account and your own data, never another customer's; do not run denial-of-service, spam or social-engineering tests; do not access, copy, keep or publish anyone else's personal data, and stop and tell us the moment you encounter it; do not test our suppliers' systems, because we cannot speak for them; and give us 90 days to fix an issue before publishing, or agree a different date with us.

We cannot waive claims that belong to our customers, and we cannot bind law enforcement. What we can promise is our own conduct, and this is it.

Privacy and DPA requests: [email protected]. General support: [email protected].

Where we are today

SafePrompt publishes its security posture as it stands, so you can size the risk before you integrate.

  • Penetration testing: the first external test is planned once paid usage covers the cost, and no third-party test has run yet. Next review 1 October 2026.
  • Compliance evidence: we publish the retention windows, the processors and the controls instead of a badge, and we will answer a security questionnaire directly. SOC 2 is not started, and we review that position quarterly. Next review 1 October 2026.
  • Availability: your integration decides what to do when a check cannot complete, block or log and continue, and the API itself fails closed on internal errors. We publish no status page and make no availability commitment, so design your integration with an explicit fallback.
  • Benchmark: our detection suite is public, and we publish every run including the failures, and the suite is our own, not an externally curated set. See what SafePrompt covers.
  • Key management: provider tokens and database credentials are platform-managed secrets that never reach source control. We run no dedicated hardware security module or external key-management service.
  • Access control: production access is limited to a small founding team, and every administrative change to the block and allow lists is logged. A formal periodic access review is not in place yet.

See what gets blocked

Your free key runs this check from your own app, with no card. You can watch a blocked verdict in the playground first, with no key and no signup.

Get a free API key