Lakera
by Lakera (a Check Point Software Technologies company)
Runtime security, red teaming and shadow-AI control for enterprise GenAI
Lakera is an AI-native security platform that screens prompts, tool calls and model output in real time for prompt injection, jailbreaks, data leakage and toxic content. It is aimed at security and platform teams shipping customer-facing LLM applications and AI agents, and at CISOs who need evidence that employee GenAI use is discovered and controlled. Check Point acquired it in 2025.
Lakera is an AI-native security platform founded in Zurich in 2021 by David Haber, Mateo Rojas-Carulla and Matthias Kraft, and acquired by Check Point Software Technologies in a deal reported at roughly $300 million, announced 16 September 2025. The platform is sold as three product lines. AI Agent Security (the product formerly marketed as Lakera Guard) is the runtime layer: a single authenticated POST to https://api.lakera.ai/v2/guard screens prompts, retrieved content, tool calls and model output for direct and indirect prompt injection, jailbreaks, system-prompt extraction, PII and data leakage, toxic or violent content and suspicious links, across what the vendor states is 100+ languages and scripts at sub-50ms added latency. AI Red Teaming (Lakera Red) runs risk-based, pre-deployment adversarial testing that simulates the same attack classes before an application ships. Workforce AI Security covers the other direction — discovering shadow AI use inside the company and applying context-aware data protection to what employees paste into third-party assistants. Detection models are refreshed from Gandalf, the public prompt-injection game Lakera launched in May 2023, which has become one of the largest open corpora of real adversarial prompts and is the company's main technical differentiator. Deployment is SaaS by default, with EU hosting on the free Community tier and self-hosting plus US or Australia residency available on Enterprise. The trust centre lists ISO 27001:2022 across all three product lines, SOC 2 Type II for AI Agent Security and Workforce AI Security, and HIPAA for AI Agent Security. Named users include Dropbox, Pearson, Hinge Health, Cohere and Respell. Lakera raised $30 million in total, including a $20 million Series A led by Atomico in July 2024, and now anchors Check Point's Global Center of Excellence for AI Security.
The application-security or platform team putting a customer-facing LLM app or agent into production, who needs an inline guardrail with audit-ready certifications rather than a research project.
One API call in front of your model blocks prompt injection, jailbreaks and PII leakage at claimed sub-50ms latency, without building and maintaining your own detection models.
At a Glance
- Category
- Governance & Security
- Pricing
- Freemium, Usage-based, Contact for pricing
- Target Market
- CISOs, CTOs, Application Security Engineers, Enterprise Developers, AI Platform Teams
- Deployment
- Cloud-first, API-based, Self-hosted
- Founded
- 2021
- Headquarters
- Zurich, Switzerland
Key Features
- ✓Prompt injection and jailbreak detection
Classifies direct and indirect injection, jailbreaks and system-prompt extraction attempts on every request before the model sees them.
- ✓Single-endpoint Guard API
One authenticated POST to the v2/guard endpoint screens input and output, using an OpenAI chat-completions-shaped payload so integration is a small code change.
- ✓PII and data-leakage screening
Detects and redacts personal data in prompts and responses, which is what keeps regulated workloads inside their own data boundary.
- ✓Gandalf-derived detection corpus
Detection models are retrained on adversarial prompts harvested from the public Gandalf game, so coverage tracks attacks seen in the wild rather than a static benchmark.
- ✓AI Red Teaming (Lakera Red)
Runs risk-based adversarial simulations before deployment, so vulnerabilities surface in a test cycle instead of in production traffic.
- ✓Workforce shadow-AI discovery
Finds which third-party AI tools employees are actually using and applies context-aware data protection to what they paste in.
- ✓Per-project policies and allow-lists
Policies are tuned per project with allow-lists, which is how teams keep false positives from degrading the end-user experience.
Capabilities
Use Cases
- •Guarding a customer-facing support assistant
Screen every inbound prompt and outbound answer so an attacker cannot extract the system prompt or another customer's data from the assistant.
- •Securing an agent that calls internal tools
Inspect retrieved documents and tool arguments so a poisoned web page or ticket cannot steer the agent into an unintended action.
- •Pre-launch adversarial testing
Run Lakera Red against a release candidate to find jailbreak and injection paths before the application is exposed to real users.
- •Controlling employee GenAI use
Discover which assistants staff are using and block sensitive data from leaving the organisation through an unsanctioned chat window.
- •Meeting audit requirements for AI controls
Produce ISO 27001 and SOC 2 Type II evidence for the guardrail layer when auditors ask how GenAI risk is technically controlled.
Ideal For
Best For
- ✓Blocking direct and indirect prompt injection in customer-facing LLM applications and RAG pipelines
- ✓Screening AI agent tool calls and retrieved content before they reach a model or an action
- ✓Discovering shadow AI use and stopping sensitive data being pasted into third-party assistants
- ✓Pre-deployment red teaming of a GenAI application against jailbreaks and system-prompt extraction
- ✓Regulated buyers who need ISO 27001 and SOC 2 Type II evidence for the guardrail layer itself
Not Ideal For
- ✗Teams that require a fully air-gapped, self-managed deployment on day one — self-hosting is an Enterprise-only option gated behind a sales conversation, and the free tier is EU SaaS only
- ✗Engineering teams that want an open-source guardrail they can read, fork and run for free; open alternatives such as LLM Guard exist, and Lakera archived its own public GitHub organisation in August 2026
- ✗Buyers who need to size cost from a public price list — only the 10,000-request Community tier is published, so any production deployment starts with a quote
- ✗Teams looking for a full agent evaluation, tracing or conversation-flow platform; Lakera screens individual requests and does not replace observability or behavioural anomaly detection
Deployment
Market Analysis
Pros
- ✓Integration is genuinely small — a single POST endpoint in an OpenAI-compatible shape, so a guardrail can be in front of an app in hours
- ✓Certification coverage is unusually complete for this category: ISO 27001:2022, SOC 2 Type II and HIPAA, plus annual third-party penetration testing and a published sub-processor list
- ✓A real free tier (10,000 requests a month) lets a team evaluate detection quality on its own traffic before any sales contact
- ✓Multilingual coverage and low stated latency make it viable in front of real-time consumer-facing assistants
Cons
- ✗Enterprise pricing is entirely opaque; independent write-ups single out the contact-sales-only model as adding weeks to procurement and making fair tool comparison difficult
- ✗It is one layer, not a security programme — reviewers note it does not replace output monitoring, behavioural anomaly detection or conversation-flow control, and policy tuning on real traffic is required to keep false positives down
- ✗Self-hosting and non-EU data residency are Enterprise-gated, so teams with hard on-premise or sovereignty constraints cannot evaluate the real deployment shape for free
- ✗Lakera's public GitHub organisation, including the pint-benchmark prompt-injection benchmark, was archived on 6 August 2026 and is no longer maintained — the open research surface that built its credibility has gone quiet post-acquisition
- ✗Detection-rate and false-positive figures in circulation are vendor-reported; there is no current independent benchmark of the platform
Pricing
Community
$0
- ✓10,000 API requests per month
- ✓8,000-token maximum prompt size
- ✓SaaS hosting in the EU
- ✓Community support
Enterprise
Contact for pricing
- ✓Flexible request volume
- ✓Configurable prompt size
- ✓SaaS or self-hosted deployment
- ✓EU, US or Australia data residency
- ✓SSO, RBAC and SIEM integration
- ✓Dedicated support
Only the free Community tier is published: 10,000 API requests a month with an 8,000-token prompt ceiling, EU SaaS hosting and community-forum support. Everything a production deployment needs — higher request volume, self-hosting, US or Australia residency, SSO, RBAC and SIEM integration — sits behind an Enterprise quote with no list price, so cost cannot be estimated without contacting sales. Metering is by API request rather than seats or tokens.
Security & Compliance
Connect
Sources
This page was written from 8 sources, 7 on domains other than lakera.ai.
- 1.lakera.ai — lakera.aivendor
- 2.trust.lakera.ai — trust.lakera.ai
- 3.docs.lakera.ai — docs.lakera.ai
- 4.techcrunch.com — lakera which protects enterprises from llm vulnerabilities r
- 5.securityweek.com — check point to acquire ai security firm lakera
- 6.appsecsanta.com — lakera
- 7.eesel.ai — lakera pricing
- 8.github.com — lakeraai
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Reco
AI agent security and SaaS security platform that discovers, governs and secures every agent, app and identity
Ascerta
Enterprise AI management: measure the ROI, cost and adoption of every AI initiative, agent and coding tool
Arcjet
Runtime security for AI agents: observe, enforce and audit agent tool calls, with prompt-injection, PII and abuse controls in code
Exaforce
Agentic SOC and MDR platform whose Exabot AI agents detect, triage, investigate and respond, now with an AI-agent kill switch