SafePrompt · Prompt injection detection API
Get a free API key
SafePrompt
Prompt injection detection API for LLM apps and agents.

Terms of Service

Effective Date: September 24, 2025

Last Updated: September 12, 2026

TL;DR: SafePrompt is an integration-boundary security tool: it blocks the instructions that would hijack the AI where it is deployed. It is not a content moderation tool; pair it with your LLM provider's safety controls for harmful-content filtering (see Section 4a). Use our API responsibly, pay your bills on time, don't try to break our service. On the free plan, prompts we block join the shared network defence (24h anonymization). On a paid plan, contribution is switched on by default and covers every request; you can switch it off in the dashboard. Paid plans renew automatically every month until you cancel. No security is perfect; we're a startup doing our best.

1. Acceptance of Terms

By creating a SafePrompt account or using SafePrompt's API service ("Service"), you agree to these terms and to our Privacy Policy. The signup form says so above the button you press. If you're using the Service for an organization, you're agreeing on their behalf.

2. What We Provide

SafePrompt provides prompt injection detection via API. We offer:

  • Real-time prompt validation
  • Network intelligence protection (threat intelligence across all customers)
  • API access with your unique key
  • Dashboard for usage tracking
  • Documentation and basic support

2a. Threat Intelligence Collection (Phase 1A)

Free Plan Requirements:

By using the free plan, you agree that:

  • Automatic Collection: Blocked prompts are automatically collected for network intelligence
  • 24-Hour Retention: Full prompt text + client IP stored for 24 hours
  • Automatic Anonymization: After 24 hours, prompt text & IP are automatically deleted
  • Hashes: After the text and IP are deleted, cryptographic hashes remain with the record until it is deleted at 90 days
  • Part of the free plan: contributing blocked prompts is how the free plan works. It is what pays for the network defence every free account benefits from, and it is why the free plan costs nothing. If you do not want to contribute, a paid plan can switch it off, or you can stop using the service and ask us to delete your data. You can also object at any time under section 6 of the Privacy Policy
  • Network Benefit: You benefit from attacks detected across all customers

Paid Plans (Starter and Business):

On a paid plan you control contribution yourself, in Settings, Privacy and Data Controls, with the Intelligence Sharing switch:

  • Switched on, which is how a new account starts: we collect every request you send, safe and blocked. Prompt text and client IP are held for 24 hours, then cryptographic hashes remain with the record until it is deleted at 90 days
  • Switched off: we collect nothing from your account, safe or blocked
  • Same Accuracy: validation accuracy is identical either way
  • Network Protection: you still benefit from network intelligence when it is switched off

Legal Basis: Legitimate interest (network security) on every plan. Contribution on a paid plan starts switched on, so we do not describe it as your consent. You can object at any time, and on a paid plan you can switch it off yourself. See our Privacy Policy for complete details.

3. Your Responsibilities

You agree to:

  • Keep your API keys secure
  • Use the Service legally and ethically
  • Not attempt to reverse-engineer or resell our Service
  • Not overload our systems or exceed rate limits
  • Pay your subscription fees on time

4. Service Limitations

Important: Please understand:

  • No security solution is 100% perfect
  • We significantly reduce, not eliminate, injection risks
  • You remain responsible for your application's overall security
  • We may have occasional downtime for maintenance
  • As a startup, we're continuously improving the service

4a. Service Scope: What SafePrompt Is Not

SafePrompt is an integration-boundary security tool. It detects prompts that would attack the system where SafePrompt is deployed (your AI agent, server, console, downstream tools, or data store). It is not a content moderation, ethics, or data-loss-prevention layer.

In Scope (SafePrompt blocks these):

  • Instruction override and jailbreaks ("ignore previous instructions", DAN-style impersonation and role-play framing)
  • System-prompt extraction (queries targeting the AI's own configuration or persona)
  • Data extraction imperatives, including instructions to read sensitive host files such as /etc/passwd, cloud credentials or SSH keys on the integrated server
  • Exfiltration imperatives (instructions to send data to attacker-controlled URLs)
  • Indirect injection and RAG poisoning (instructions embedded in documents or tool results the AI is asked to follow)

Out of Scope (SafePrompt does NOT block these):

  • Knowledge questions about harmful topics ("How does phishing work?", "Explain SQL injection")
  • Generation requests for harmful artifacts that don't include an exfiltration target ("Write a phishing email template")
  • General PII or credential format questions ("What format does a credit card number have?")
  • Ethics, safety policy enforcement, or moral judgment of user intent
  • Content the underlying LLM provider's safety policy is designed to handle

Customer Responsibility: If your application needs to filter harmful-content requests in addition to integration-boundary attacks, you must pair SafePrompt with your LLM provider's content policy (e.g., OpenAI Moderation, Anthropic's built-in safety, Google's safety filters) or a dedicated content-moderation service. SafePrompt is not designed to substitute for those layers and we make no warranty that SafePrompt will block harmful-content requests outside the integration-boundary scope described above.

5. Pricing, Billing and Renewal

Free plan. 10,000 validations a month, no card, no time limit. Nothing renews because there is nothing to charge.

Paid plans. Starter is $29 a month and Business is $99 a month, charged through Stripe. Your subscription renews automatically every month, at the same price, and we charge the card on file on each renewal date, until you cancel.

Cancelling. Cancel any time from Settings in your dashboard, in one step and with no fee. Cancellation takes effect at the end of the month you have already paid for, and you keep your quota until then. You can also ask us through our contact form.

Refunds. We do not generally refund part of a month. If something went wrong on our side, tell us and we will make it right.

Price changes. If we raise the price of your plan, we will email you at least 30 days before it takes effect and ask you to confirm. If you do not confirm, your subscription will not renew at the new price and will end instead. We will never charge you more than the price you agreed to.

Nothing beyond your plan. There is no overage billing. Requests past your monthly limit return HTTP 429 with the date your quota resets.

6. Privacy & Data

We process prompts to detect threats, and what we keep, for how long, is set out in our Privacy Policy. We never sell your data. We never use your prompts to train models. We do use the patterns we learn from blocked prompts to improve our detection rules, which is a different thing and is described in the Privacy Policy.

6a. Data Processing Agreement

Where you send us personal data belonging to your users, you are the controller and we are your processor. If you need a Data Processing Agreement, request one at [email protected] and we will put one in place with you.

7. Intellectual Property

We own the Service and its technology. You own your content. Any feedback you provide becomes ours to use freely. Don't use our name or logo without permission.

8. Warranty Disclaimer

The Service is provided "as is" without warranties of any kind. We don't guarantee it will be error-free, uninterrupted, or meet all your needs. Use at your own risk.

9. Limitation of Liability

Our liability is limited to the amount you paid us in the past 12 months or $100, whichever is greater. We're not liable for indirect, consequential, or punitive damages.

This means if a prompt injection gets through despite using our service, we're not liable for any resulting damages beyond the limit above.

10. Indemnification

You'll defend and indemnify us from claims arising from your use of the Service, violation of these terms, or violation of any laws or third-party rights.

11. Dispute Resolution

Let's talk first: Before any legal action, contact us through our contact form to try resolving issues informally.

If that doesn't work, disputes will be resolved through binding arbitration in Clark County, Nevada, before JAMS under its Streamlined Arbitration Rules. We pay the filing and arbitrator fees above what it would have cost you to file the same claim in court. Disputes must be brought individually, and not as a class action or class arbitration.

Two things you keep. Either of us may still bring a claim in small claims court if it qualifies, and either of us may ask a court for an injunction to protect intellectual property.

Opting out of arbitration. You can opt out of this section within 30 days of first accepting these terms by telling us through our contact form. Opting out costs you nothing and changes nothing else in these terms.

12. Legal Fee Protection

Frivolous Claims: If you bring a claim against us that a court or arbitrator determines to be frivolous, filed in bad faith, or brought for an improper purpose (such as to harass), you agree to reimburse us for our reasonable attorney's fees and costs.

Good Faith Required: Before filing any legal action, you must attempt resolution through our contact form and allow 30 days for response. This helps avoid unnecessary legal costs for both parties.

13. Account Termination

Either party can terminate at any time. We may suspend or terminate accounts that violate these terms or pose security risks. You're responsible for charges incurred before termination.

14. Changes to Terms

We may update these terms. For any change that materially affects your rights, we will email you at least 30 days before it takes effect, and continued use after that date means you accept it. If you would rather not accept, cancel before the date and we will refund the unused part of the month. Changes to price follow Section 5 instead, which needs your confirmation.

15. General Provisions

  • Governing law: Nevada, USA
  • Entire agreement: These terms, the Privacy Policy, the Data Processing Agreement where one is signed, and the plan and pricing details on our pricing page
  • Severability: Invalid provisions don't affect the rest
  • No waiver: Not enforcing a right doesn't waive it

16. Contact Information

For all inquiries, please use our contact form.

Company:
Reboot, Inc.
930 S 4th St Ste 209-5981
Las Vegas, NV 89101
United States

Final Note: We're a small team building something we believe developers need. These terms protect both of us while we grow. If you have specific concerns about any terms, reach out through our contact formand we'll do our best to address them.