The Runtime Firewall for AI Agents

The Runtime Firewall for AI Agents

Immunis inspects every LLM request, response, and agent tool call in real time and stops your secrets from ever leaving. Prompt injections, jailbreaks, unauthorized actions, and secret exfiltration get caught the moment they appear.

Vendor Agnocstic approach

The Problem

The Perimeter Has Moved Into Your Model

Traditional security was built for the network edge. Today your real attack surface is the prompt: injected instructions, jailbreaks, and agent tool calls with real-world side effects. OWASP's Top 10 for Large Language Model Applications treats prompt injection as a key LLM security risk. Static filters and allow-lists can't keep up with language. You need inline judgment on every request and every tool call.

The Solution

Introducing Immunis

The security engine at the core of Immunis. Sentinel sits as a transparent, enforcing proxy in front of any AI provider you route through it - the built-in providers (OpenAI, Anthropic, Gemini) or your own endpoint. It evaluates every request and every response against your tenant policies in real time - scoring risk in context, re-checking ambiguous cases, and keeping your secrets from ever reaching the model or leaving in a response. Legitimate traffic flows are untouched, malicious prompts, unauthorized tool calls, and secret leaks are stopped the moment they appear. Fully self-hosted: your data never leaves your infrastructure.

1 – Inspect

Sentinel inspects every LLM request, response, and agent tool call inline, in real time, before it reaches your model or your tools.

2 – Evaluate

Each action is risk-scored and evaluated against your tenant policies in real time, with a p95 decision under ~12ms.

3 – Enforce

Malicious prompts, unauthorized tool calls, and secret exfiltration are blocke instantly at the gateway legitimate traffic passes through untouched.

1 – Learn

Aegis Core observes and learns the unique heartbeat of your organization's digital ecosystem.

2 – Detect

Autonomously distinguishes between harmless anomalies and genuine attacks in real-time.

3 – Neutralize

Incinerates threats instantly while allowing legitimate business traffic to flow seamlessly.

Key Capabilities

Built for the threats of AI Systems

Prompt Injection Defense

Novel prompt injections and jailbreaks are caught inline, with no signatures required. Validated against WildChat, OASST, AdvBench, and Tensor-Trust datasets.

Behavioral risk Scoring

Every request and tool call is risk-scored with uncertainty-aware verdicts. Ambiguous cases are re-checked, never blindly passed to your model.

Agent Tool Authorization

Every agent tool call is authorized synchronously, allow or deny, before it runs. Your agents can only ever act within the policy you define.

Multi Tenant Isolation

Every request is scoped to its own tenant's policy set and never crosses boundaries. One deployment, many tenants, each fully isolated from the rest.

Secret Exfiltration Defense

Your registered secrets never reach the model and never leave in a response. A leak is stopped at the boundary, no matter how the request is phrased.

Endocing Independent Inspection

Hidden and disguised attacks are caught just like plain ones. Obfuscation buys an attacker nothing - the verdict is the same either way.

How it works

From deployment to self hosted defense

1

Route your traffic thorugh Immunis

Point your existing OpenAI or Anthropic SDK at Sentinel with one base_url change. No rearchitecting, just two containers and you are live.

2

Evaluates from the first request

The engine risk-scores and policy-checks every request and tool call from day one. No training window, fully deterministic behavior.

3

Threats blocked automatically

Malicious prompts and unauthorized tool calls are blocked inline before your provider. Every security decision lands in your local audit trail.

Benefits

Everything you need to secure AI at the edge

Inline threat inspection

Every request, response, and tool call is inspected inline before it moves. Your secrets never reach the model and never leave in a response - a leak is stopped at the boundary, not found later in a log.

Full data sovereignity

Self-hosted by design, so decisions, audit logs, tenants, and policies stay within your infrastructure. Nothing ever leaves except plain license verification

Unified operator console

Every decision, latency trace, tenant, and policy verdict lives in one local frontend pane. It is served directly by Sentinel from your own deployment

95.2%

Threat detection rate

< 12ms

Decsision latency p95

< 1%

False positive rate

0%

Failed requests

Pricing

Protection scaled to your organization

Instance

One production Immunis instance, up to 3 tenants. Add more at the same flat rate.

01234567890

month per instance

Full request & tool-call inspection

Prompt-injection & jailbreak detection

Agent tool-call authorization

Fail-safe enforcement

Secret-leak prevention

Encoding-independent inspection

Approved-destination control

Up to 3 tenants per instance

Each additional instance: €399 / month

Growth Bundle

POPULAR

One Growth Bundle, up to 10 production instances. Add more at the same flat rate.

01234567890
,
01234567890
01234567890
01234567890

month up to 10 instances

Full request & tool-call inspection

Prompt-injection & jailbreak detection

Agent tool-call authorization

Fail-safe enforcement

Secret-leak prevention

Encoding-independent inspection

Approved-destination control

Up to 10 production instances (3 tenants each)

Centralized billing & flat bundle pricing

ANNUAL

Enterprise & Partner

One package for enterprises, agencies, and resellers running Immunis at scale.

Price on request

Full request & tool-call inspection

Prompt-injection & jailbreak detection

Agent tool-call authorization

Fail-safe enforcement

Secret-leak prevention

Encoding-independent inspection

Approved-destination control

Custom-scale deployment & volume pricing (10+ instances)

Independent security review

ANNUAL

FAQs

Frequently Asked Questions

How does Immunis detect prompt injections and jailbreaks?

Sentinel inspects every request inline and risk-scores it against a multi-signal pipeline validated on established benchmark datasets (WildChat, OASST, AdvBench, Tensor-Trust, and prompt-injection sets). It does not rely on static signatures, so it catches novel attack phrasing the moment it appears, with a p95 decision under ~12ms.

Can Immunis stop my model from leaking secrets?

Yes. Your registered secrets are removed before the model ever sees them, and every response and outbound action is checked for secret material before it can leave. A leak is stopped at the boundary - and outbound actions carrying secrets only reach destinations you approve.

What about attacks hidden in Base64 or other endocings?

Encoding is not a bypass. Requests and responses are normalized across a wide range of encodings and obfuscation tricks before they are ever scored, so a disguised attack is treated exactly like its plaintext form.

What if a secret is split up or reversed to sneak it out?

It's still caught. Egress protection recognizes your secret by its actual value, not by a fixed pattern - so splitting, reversing, or encoding it makes no difference, including across streamed responses. The secret was redacted before anything left.

How long does deployment take?

Immunis runs as two containers (Sentinel + Ledger). You route your existing OpenAI/Anthropic SDK through Sentinel with a single base_url change. No rearchitecting, typically up and running fast.

Will Sentinel replace my existing security tools?

Sentinel is the dedicated security control for the AI layer. It protects LLM requests and agent tool calls, covers prompt injections, jailbreaks, and unauthorized tool calls, and gives you the security layer your existing stack does not have.

How does Sentinel handle enforcement?

When a request or tool call is scored as malicious or out-of-policy, Sentinel blocks it inline before it reaches your provider, with configurable fail-closed behavior on timeout. Every decision is written to your local Ledger audit trail.

Where does my data go?

Immunis Cloud only handles license verification; no prompts, responses, secrets, or audit data ever leave your deployment.

How does pricing work?

One Immunis instance is a flat €150/month and covers up to 3 tenants. The Growth Bundle is €600/month for up to 10 instances, or €400/month billed annually. Distributors, agencies, and enterprises running many deployments get bundle pricing on request.

Stop the next incident before it reaches your model.

Deploy Immunis and give your AI systems the inline, self-hosted defense they deserve. Two containers, one base_url change, up and running fast.

Don't take our word for it: every headline metric on this page comes from a documented 24-hour SOAK test. 172,800 security decisions across benign, mixed, adversarial-burst, and recovery load, with zero HTTP failures.

Stop the next incident before it reaches your model.

Deploy Immunis and give your AI systems the inline, self-hosted defense they deserve. Two containers, one base_url change, up and running fast.

Don't take our word for it: every headline metric on this page comes from a documented 24-hour SOAK test. 172,800 security decisions across benign, mixed, adversarial-burst, and recovery load, with zero HTTP failures.

Stop the next incident before it reaches your model.

Deploy Immunis and give your AI systems the inline, self-hosted defense they deserve. Two containers, one base_url change, up and running fast.

Don't take our word for it: every headline metric on this page comes from a documented 24-hour SOAK test. 172,800 security decisions across benign, mixed, adversarial-burst, and recovery load, with zero HTTP failures.