Stop the prompt before it leaves.
Every prompt and response is scored, redacted or blocked inline — with a verdict you can explain to an auditor.

From prompt to verdict in four stages.
- 01
CLASSIFY
The prompt is scored across eight risk dimensions.
- 02
VALIDATE
Scores are checked for consistency and false-positive pressure.
- 03
POLICY
Your natural-language and preset policies are evaluated against the scores.
- 04
VERDICT
Allow, redact, or block. The decision and its reasoning are written to the audit chain.
What it does.
Eight-dimension risk scoring
PII, injection, jailbreak, toxicity, exfiltration, IP, policy intent and excessive agency — scored per prompt, per response.
Inline DLP & redaction
Detect and redact sensitive entities inline so work continues without the data ever leaving the perimeter.
Natural-language policy authoring
Write policy in plain English. XAIGuard compiles it to enforceable scoring thresholds — no rules DSL to learn.
Preset policy packs
Opinionated starting packs for PII, source code, regulated data and prompt injection. Turn on, tune, done.
Bulk scanning
Scan historical prompt logs, datasets and prompt libraries to find what already leaked — before your auditor does.
REST scanning API
An OpenAI-compatible endpoint and standalone scoring API. Govern any SDK call by changing one base URL.
One policy, one explainable verdict.
policy > "Never allow customer account numbers or unredacted contracts to reach an external model"
verdict: "BLOCK"
reason: "Customer account number detected in prompt"
matched_detectors: ["pii.account_number", "dlp.contract_text", "policy.nl-014"]
risk_scores: { pii: 0.98, exfiltration: 0.41, injection: 0.03 }
action: "block_and_alert"
latency_ms: 0.8
audit_hash: "ed25519:9f2c…a41e" — appended to tamper-evident chain
Every verdict maps to the controls your frameworks already name — evidence, not assertion.
Works together.
Deployment
PAC file, Browser Shield or API proxy — enforce from wherever your users already are.
ExploreAgent & MCP Governance
The same inline verdicts applied to autonomous agents and every MCP server they call.
ExploreCompliance & Evidence
Every allow, redact and block lands in a signed audit chain your auditor can verify.
Explore