NewRuntime governance for MCP servers and agentic workflows

Your AI security tools are solving yesterday's problem.

Traditional tools evaluate risk one prompt at a time. But your AI isn't a chatbot - it's a stateful agent operating across sessions, tools, and time.

Start Free - 1M Requests →Compare Platforms
No model changesNo provider lock-inOne endpoint change
<300ms
Runtime overhead
6 layers
Of runtime protection
1M free
Requests to start
ZKP
Verifiable compliance proof
GDPR ReadyHIPAA ReadyEU AI Act
Works with your existing AI stack
The Problem

Four threats your current stack can't stop.

Firewalls and DLP were built for stateless requests. Agentic AI is stateful - it reasons across a session, calls tools, and acts on your systems. The risk isn't a bad packet; it's an AI doing something it was never supposed to do.

Threat 01

Prompt injection & jailbreaks

A single crafted input hijacks the model's instructions - exfiltrating data or triggering actions you never authorised. Static filters can't see intent.

Threat 02

Sensitive data leakage

PII, secrets and proprietary context flow into prompts and out through responses - into models and logs you don't control.

Threat 03

Ungoverned tool & MCP actions

Agents call tools, hit APIs and execute MCP actions autonomously. Without a policy gate, one bad decision becomes a real-world action.

Threat 04

Compliance blindness

When the auditor asks what your AI did and why, "we don't log that" isn't an answer. Most stacks have no verifiable record of AI decisions.

The Solution

A Runtime Governance Layer Built for the AI Era.

VANGUARD is an AI governance platform for managing agentic AI risk and policy enforcement. It sits inline between your applications, models, tools, and workflows to inspect risk, mediate actions, enforce policy, and retain governance evidence. No model changes. No provider lock-in.

Why guardrails aren't governance →

See exactly what happens to every request.

Walk through the seven runtime operations VANGUARD runs on every prompt and response - threat detection, DLP, policy evaluation, provider forwarding, response filtering, and ZKP audit evidence.

See how it works →
Core Capabilities

Six layers of runtime control. One enforcement point.

VANGUARD policy panel - prompt injection regex detector with block threshold, ML Prompt Guard detection threshold, and PII/secret DLP redaction toggles.
01 - Threat Detection

Prompt Injection Detection

Two-tier detection: fast regex patterns combined with ML classification (Meta Prompt Guard 2). Catches known attack patterns, encoded payloads, and novel injection attempts with configurable confidence thresholds.

Regex engineML classifierConfigurable thresholds
02 - Data Protection

Deep Data Loss Prevention

Named Entity Recognition plus pattern matching detects and redacts PII (emails, SSNs, phone numbers, credit cards), unstructured entities (names, orgs, locations), and secrets (API keys, tokens, credentials).

NER engineSecret scanningBi-directional
Data Protection dashboard - secrets prevented, traffic containing PII, redactions in vs out, PII types over time, and PII by route.
Attack types (regex rules) and content-safety categories (S1-S14 hazards) breakdown.
03 - Content Safety

Content Safety Classification

Identifies harmful content across five categories: hate speech, insults, sexual content, violence, and misconduct. Per-category actions - block, mask, or log - are configurable to your product's risk tolerance.

5 harm categoriesPer-category policyBlock/mask/log
04 - Response Filtering

Output Sanitisation

Post-processing layer catches what the model itself failed to prevent: credential leakage in generated code, hallucinated PII in responses, and policy violations in model outputs before they reach your users.

Code inspectionHallucination PIIResponse rewrite
Security Overview dashboard - requests scanned, threats blocked, harmful content blocked, data masked, decisions over time, and top threats.
policy.rego
default decision := {"action": "allow", "reason": null}

decision := {
    "action": "block",
    "reason": "prompt_injection_above_threshold",
} if {
    "prompt_injection" in enabled_detectors
    input.detection.prompt_injection.risk_score >= 65
} else := mask_decision if {
    "pii" in enabled_detectors
    count(matching_types) > 0
    redact_phase_enabled
} else := {"action": "allow", "reason": null}
05 - Policy Governance

Policy-as-Code Enforcement

Define granular, tenant-specific rules in Rego using Open Policy Agent (OPA). Control detection thresholds, feature flags, redaction rules, and rate limits. Version-controlled and instantly deployable like any infrastructure policy.

OPA / RegoMulti-tenantVersion controlled
06 - Compliance

ZKP Audit Trail

Every interaction is logged with immutable records, risk scores, and Zero-Knowledge Proof-based evidence bundles. Prove compliance to auditors without exposing interaction content. Designed for GDPR, HIPAA, and EU AI Act.

Zero-Knowledge ProofsSHA-256 hashingTamper-proof
Audit Log Explorer - every decision VANGUARD made, searchable and explainable, with action, risk, and threats/PII/harm.
Integration

One endpoint change.
Complete protection.

VANGUARD requires no changes to your AI models, no renegotiation of provider contracts, and no infrastructure overhaul. Change one environment variable. Start protecting immediately.

1

Point your AI calls to VANGUARD

Replace your LLM provider base URL with your VANGUARD proxy endpoint. One environment variable.

2

Configure your policy

Start with secure-by-default templates or define custom Rego policies for your tenant's risk profile.

3

Monitor and prove compliance

Every interaction is logged, scored, and cryptographically attested. Your dashboard surfaces threats in real time.

Full architecture deep-dive →
client.js
import OpenAI from "openai";

// Point your existing client at VANGUARD - one-line change
const client = new OpenAI({
  baseURL: "https://your-tenant.raguard.ai/v1",
  apiKey: process.env.OPENAI_API_KEY,
});

// All requests now inspected + protected
Compare with peers

See how VANGUARD stacks up against the alternatives.

Why VANGUARD wins

Where VANGUARD fits.

Platform
Primary Layer
Strongest Fit
VANGUARD Difference
Lakera
Prompt defence
Prompt injection, jailbreaks, unsafe interactions
Governs agent actions, tool calls, and runtime policy
Portkey
AI gateway
Routing, observability, reliability, cost control
Adds governance and trust enforcement above infrastructure
Protect AI
MLSecOps
Lifecycle AI and ML security
Focuses on production agent behaviour and runtime controls
Microsoft Prompt Shields
Cloud-native prompt protection
Azure AI prompt and document attack detection
Vendor-neutral and action-oriented across clouds and tools
Gray Swan AI
Red teaming
Adversarial testing and attack discovery
Enforces policy continuously in production
Akto
API and agent exposure
API discovery, testing, MCP and agent posture
Governs permissions and runtime execution

Your AI is in production. Is your security?

Govern every prompt, tool call and response - in under 300ms, with proof. Start free, or talk to us about enterprise.

Start Free - 1M Requests →