
Immunis inspects every LLM request, response, and agent tool call in real time and stops your secrets from ever leaving. Prompt injections, jailbreaks, unauthorized actions, and secret exfiltration get caught the moment they appear.
Vendor Agnocstic approach
The Problem
The Perimeter Has Moved Into Your Model
Traditional security was built for the network edge. Today your real attack surface is the prompt: injected instructions, jailbreaks, and agent tool calls with real-world side effects. OWASP's Top 10 for Large Language Model Applications treats prompt injection as a key LLM security risk. Static filters and allow-lists can't keep up with language. You need inline judgment on every request and every tool call.
The Solution
Introducing Immunis
The security engine at the core of Immunis. Sentinel sits as a transparent, enforcing proxy in front of any AI provider you route through it - the built-in providers (OpenAI, Anthropic, Gemini) or your own endpoint. It evaluates every request and every response against your tenant policies in real time - scoring risk in context, re-checking ambiguous cases, and keeping your secrets from ever reaching the model or leaving in a response. Legitimate traffic flows are untouched, malicious prompts, unauthorized tool calls, and secret leaks are stopped the moment they appear. Fully self-hosted: your data never leaves your infrastructure.
Key Capabilities
Built for the threats of AI Systems
Prompt Injection Defense
Novel prompt injections and jailbreaks are caught inline, with no signatures required. Validated against WildChat, OASST, AdvBench, and Tensor-Trust datasets.
Behavioral risk Scoring
Every request and tool call is risk-scored with uncertainty-aware verdicts. Ambiguous cases are re-checked, never blindly passed to your model.
Agent Tool Authorization
Every agent tool call is authorized synchronously, allow or deny, before it runs. Your agents can only ever act within the policy you define.
Multi Tenant Isolation
Every request is scoped to its own tenant's policy set and never crosses boundaries. One deployment, many tenants, each fully isolated from the rest.
Secret Exfiltration Defense
Your registered secrets never reach the model and never leave in a response. A leak is stopped at the boundary, no matter how the request is phrased.
Endocing Independent Inspection
Hidden and disguised attacks are caught just like plain ones. Obfuscation buys an attacker nothing - the verdict is the same either way.
How it works
From deployment to self hosted defense
1
Route your traffic thorugh Immunis
Point your existing OpenAI or Anthropic SDK at Sentinel with one base_url change. No rearchitecting, just two containers and you are live.
2
Evaluates from the first request
The engine risk-scores and policy-checks every request and tool call from day one. No training window, fully deterministic behavior.
3
Threats blocked automatically
Malicious prompts and unauthorized tool calls are blocked inline before your provider. Every security decision lands in your local audit trail.
Benefits
Everything you need to secure AI at the edge

Inline threat inspection
Every request, response, and tool call is inspected inline before it moves. Your secrets never reach the model and never leave in a response - a leak is stopped at the boundary, not found later in a log.

Full data sovereignity
Self-hosted by design, so decisions, audit logs, tenants, and policies stay within your infrastructure. Nothing ever leaves except plain license verification

Unified operator console
Every decision, latency trace, tenant, and policy verdict lives in one local frontend pane. It is served directly by Sentinel from your own deployment
95.2%
Threat detection rate
< 12ms
Decsision latency p95
< 1%
False positive rate
0%
Failed requests
Pricing
Protection scaled to your organization
Instance
One production Immunis instance, up to 3 tenants. Add more at the same flat rate.
month per instance
Full request & tool-call inspection
Prompt-injection & jailbreak detection
Agent tool-call authorization
Fail-safe enforcement
Secret-leak prevention
Encoding-independent inspection
Approved-destination control
Up to 3 tenants per instance
Each additional instance: €399 / month
Growth Bundle
POPULAR
One Growth Bundle, up to 10 production instances. Add more at the same flat rate.
month up to 10 instances
Full request & tool-call inspection
Prompt-injection & jailbreak detection
Agent tool-call authorization
Fail-safe enforcement
Secret-leak prevention
Encoding-independent inspection
Approved-destination control
Up to 10 production instances (3 tenants each)
Centralized billing & flat bundle pricing
ANNUAL
Enterprise & Partner
One package for enterprises, agencies, and resellers running Immunis at scale.
Price on request
Full request & tool-call inspection
Prompt-injection & jailbreak detection
Agent tool-call authorization
Fail-safe enforcement
Secret-leak prevention
Encoding-independent inspection
Approved-destination control
Custom-scale deployment & volume pricing (10+ instances)
Independent security review
ANNUAL
FAQs
Frequently Asked Questions
How does Immunis detect prompt injections and jailbreaks?
Sentinel inspects every request inline and risk-scores it against a multi-signal pipeline validated on established benchmark datasets (WildChat, OASST, AdvBench, Tensor-Trust, and prompt-injection sets). It does not rely on static signatures, so it catches novel attack phrasing the moment it appears, with a p95 decision under ~12ms.
Can Immunis stop my model from leaking secrets?
Yes. Your registered secrets are removed before the model ever sees them, and every response and outbound action is checked for secret material before it can leave. A leak is stopped at the boundary - and outbound actions carrying secrets only reach destinations you approve.
What about attacks hidden in Base64 or other endocings?
Encoding is not a bypass. Requests and responses are normalized across a wide range of encodings and obfuscation tricks before they are ever scored, so a disguised attack is treated exactly like its plaintext form.
What if a secret is split up or reversed to sneak it out?
It's still caught. Egress protection recognizes your secret by its actual value, not by a fixed pattern - so splitting, reversing, or encoding it makes no difference, including across streamed responses. The secret was redacted before anything left.
How long does deployment take?
Immunis runs as two containers (Sentinel + Ledger). You route your existing OpenAI/Anthropic SDK through Sentinel with a single base_url change. No rearchitecting, typically up and running fast.
How does Sentinel handle enforcement?
When a request or tool call is scored as malicious or out-of-policy, Sentinel blocks it inline before it reaches your provider, with configurable fail-closed behavior on timeout. Every decision is written to your local Ledger audit trail.
Where does my data go?
Immunis Cloud only handles license verification; no prompts, responses, secrets, or audit data ever leave your deployment.
How does pricing work?
One Immunis instance is a flat €150/month and covers up to 3 tenants. The Growth Bundle is €600/month for up to 10 instances, or €400/month billed annually. Distributors, agencies, and enterprises running many deployments get bundle pricing on request.

