Lakera
Prompt-injection and AI security for LLM apps
Overview
Lakera Guard protects LLM applications from prompt injection, data exfiltration and other AI-specific attacks. Founded by ex-Daedalean (aviation AI safety) team. Used by enterprises shipping consumer-facing LLM products. Free tier; enterprise plans for production deployments.
Use cases
What you can produce with Lakera
- Screen every user prompt through the Guard API and block direct and indirect prompt-injection and jailbreak attempts before they reach your LLM.
- Detect attempts to extract your system prompt or make the model leak confidential context, and stop the response before it is returned.
- Flag personally identifiable information and unsafe content in model inputs and outputs so your application can redact or refuse.
- Protect a multilingual user base with detection that works across more than 100 languages, not just English.
- Red-team your LLM application with Lakera Red before launch to surface exploitable weaknesses in a controlled exercise.
- Train your team on prompt-attack techniques by playing Gandalf, Lakera's free game where players try to trick an AI into revealing a password.
ASEAN Perspective
Lakera in Southeast Asia
ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).
Lakera is a specialist AI-security company focused on protecting LLM applications from prompt injection, jailbreaks, data leakage and other GenAI-specific threats, offering real-time guardrails (Lakera Guard) and automated red-teaming. As GenAI moves into production, this is an increasingly necessary layer, and Lakera is one of the most recognised names in the category, with credibility boosted by its popular Gandalf prompt-injection challenge.
It is a developer/enterprise security tool, so it assumes you have an LLM app to defend and the engineering maturity to integrate guardrails, and serious use is enterprise-priced. It offers an API/SDK and is globally sold; ASEAN organisations can adopt it, though data-residency for regulated sectors should be confirmed directly. Strong and well-targeted for teams that take AI security seriously.
What people say
The headline on Lakera is ownership: Check Point acquired the Zurich company in September 2025 in a deal widely reported at around $300 million, folding Lakera Guard, the Lakera Red red-teaming product and the Gandalf dataset into Check Point's AI security platform. The original research team continues to maintain the detection models from Zurich, but new sales now route through Check Point enterprise procurement, which changes the buying experience for the startups that made up much of Lakera's early community.
What users consistently praise is detection quality with low friction. Guard screens prompts and outputs for direct and indirect prompt injection, jailbreaks and system-prompt extraction across more than 100 languages, with the company claiming 98-percent-plus detection at sub-50ms latency, and 2026 reviews largely focus on how well it holds up in production. Dropbox is publicly cited as using it to protect user data in generative AI features. Lakera's secret weapon is Gandalf, its prompt-injection game: over a million players have generated 80 million-plus adversarial prompts that continuously feed the threat-intelligence models, a data moat competitors struggle to match.
The grumbles are practical rather than fundamental. Production reviews dwell on tuning false positives, since an over-eager guardrail that blocks legitimate user requests is its own outage, and every added inference hop is latency someone must budget for. Post-acquisition, some observers also question how the developer-friendly free tier and roadmap will fare inside a large network-security vendor whose centre of gravity is firewalls, not APIs.
Lakera fits teams shipping consumer-facing or high-risk LLM applications that need a dedicated, battle-tested guardrail layer rather than hand-rolled regex filters, and it is an especially natural choice for organisations already standardised on Check Point. Hobby projects can start with the self-serve tier; serious deployments should expect an enterprise sales motion.
Summary of public user & expert reviews, compiled by RECATOOLS.
About this listing
This entry was compiled from publicly available data including Lakera's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Lakera unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Lakera directly →
Spotted something out of date? Suggest an update →
Lakera in the news
Developer Tools
DuneSlide: Two Cursor Flaws Turn a Zero-Click Prompt Injection Into Code Execution
Cybersecurity
AWS Confirms First Production Prompt-Injection Compromise in Bedrock Agents — Enterprise C...
Cybersecurity
EchoLeak: Zero-Click Prompt Injection in Microsoft 365 Copilot Quietly Exfiltrates Enterpr...
More in Security & Safety