$ llmgaurd --protect production

Your LLM reads everything.
So do attackers.

LLMGaurd builds security controls for AI systems: guardrails that inspect what models read and do, protection for AI use across browsers, desktop apps, and coding agents, and red-team tooling for testing in controlled environments.

focus
LLM apps · agents · endpoints
framework
OWASP LLM Top 10
stage
research preview
guardrail · inspect inbound/vendor-invoice-0921.eml sanitized

From: [email protected]

Subject: September invoice

 

Hi team, the September invoice is attached.

Payment terms are net 30 as agreed.

[stripped: hidden instruction]LLM01 · hidden instruction

Thanks, Ana · Accounts

illustrative demomodule: guardrails

[01] threat model

AI systems fail in new ways.
Most teams find out in production.

T1

Prompt injection

Any text a model reads can try to give it orders: web pages, emails, PDFs, tool output. Agents with real permissions turn that into real impact.

T2

Data leakage

Source code, secrets, and customer records flow into AI tools every day: pasted into chatbots, uploaded to desktop apps, or read into context by coding agents. Usually nobody can see it.

T3

Untested behaviour

Most LLM features ship without adversarial testing. The failure modes surface after launch, usually reported by someone else.

[02] modules

Three controls across the AI lifecycle.

all products →
mod_01 guardrails in design
appguardllm
in  redact   2 secrets
ctx strip    1 injected instruction
out deny     send_email() — out of scope
log decision 7f3a written

Guardrails

A policy layer between your application and any LLM. It inspects prompts, retrieved content, tool calls, and responses before they reach users or systems.

  • Prompt-injection & jailbreak detection
  • PII and secret redaction, both directions
  • Tool-call allowlists and output policy
  • Audit log for every decision
mod_02 workplace-shield researching
endpoint · fin-laptop-07           policy
───────────────────────────────────────────
chrome      chat.ai-tool       coach
coding-agent  llm api          redact ×2
desktop-ai  personal acct      block
python3     llm api (new)      block
ide-copilot company tenant     allow
browser + endpoint · one policy, every process

Workplace AI Shield

Visibility and control over every way AI is used at work: a browser extension for AI chat tools, plus a lightweight agent on managed endpoints that sees any process talking to an LLM, from desktop AI apps and coding agents to CLI harnesses and local scripts.

  • Endpoint agent: per-process LLM traffic inspection
  • Browser extension for paste, upload, and chat
  • Secrets, source, and PII redacted before they leave
  • Shadow AI discovery and central policy
mod_03 redteam-lab planned
$ redteam run --target staging --suite owasp
PASS llm01/direct-basic        24/24
FAIL llm01/indirect-email-html 21/24
PASS llm07/prompt-extraction  16/16
WARN llm06/tool-abuse         11/12
──────────────────────────────────
score 94.7%  Δ +3.1 vs v1.8

Red Team Lab

Adversarial testing for LLM apps and agents, for authorised use in controlled environments. Repeatable attack suites, mapped to OWASP, run on every release.

  • Injection & jailbreak suites
  • Agent and tool-abuse scenarios
  • Mapped to OWASP LLM Top 10
  • Regression tracking across releases

[03] coverage map

Mapped to the OWASP LLM Top 10.

LLM01 Prompt Injection GSR
LLM02 Sensitive Info Disclosure GSR
LLM03 Supply Chain GSR
LLM04 Data & Model Poisoning GSR
LLM05 Improper Output Handling GSR
LLM06 Excessive Agency GSR
LLM07 System Prompt Leakage GSR
LLM08 Vector & Embedding Weaknesses GSR
LLM09 Misinformation GSR
LLM10 Unbounded Consumption GSR

Planned coverage, based on the OWASP Top 10 for LLM Applications 2025.

> request_access()

Ship AI features without
shipping new attack surface.