Lakera logo

Lakera Review (2026)

The best-known prompt injection defence API, acquired by Check Point in September 2025 for a reported $300M. Still developed by the original Zurich team, but sales now run through Check Point enterprise procurement.

Researched

Rating

4.0

Starting Price

Not published

Free Plan

Yes

SDKs & Frameworks

4

Deployment

3

Best For

Teams that want managed, low-latency prompt injection defence with enterprise support and are comfortable with a proprietary API and an enterprise sales process.

Last Updated:

10 Things You Should Know About Lakera

  1. 1 Check Point announced its acquisition of Lakera in September 2025, in a deal reported at around $300 million
  2. 2 The acquisition brought Lakera Guard, Lakera Red and the Gandalf community dataset into Check Point's AI security platform
  3. 3 Check Point based its Global Center of Excellence for AI Security on the Lakera team
  4. 4 The Zurich research team still maintains Guard's detection models under Check Point
  5. 5 New sales are routed through Check Point enterprise procurement
  6. 6 Founded in 2021 in Zurich by David Haber, Mateo Rojas-Carulla and Matthias Kraft
  7. 7 Vendor reports 98%+ detection rates, sub-50ms latency and false positive rates below 0.5% across 100+ languages
  8. 8 Detection models are reported to learn from 100,000+ new adversarial samples daily, drawn partly from Gandalf's 80M+ prompts

Pros & Cons

Pros

  • The most battle-tested prompt injection detection available, trained partly on Gandalf's very large adversarial prompt corpus
  • Vendor reports 98%+ detection with sub-50ms latency and false positive rates below 0.5%, which if accurate is strong on all three axes at once
  • 100+ language coverage, which matters because injection attacks frequently arrive in a language your English-only filter never considered
  • The original Zurich research team still maintains the detection models under Check Point
  • Check Point ownership brings enterprise support and procurement credibility that a startup could not offer

Cons

  • No published pricing on any tier, so it cannot be cost-compared without contacting sales
  • Proprietary and not open source, so you cannot inspect or self-host the thing making security decisions
  • Sales now route through Check Point enterprise procurement, which typically means a slower and heavier buying process
  • Detection performance figures are vendor-reported and we could not independently verify them
  • Aggregator sites carry demonstrably wrong information about this product, so third-party research is unusually unreliable here

Features

Real-time detection of prompt injection, jailbreaks and data leakage
Lakera Red for adversarial and red-team testing
Detection models trained partly on the Gandalf community dataset
Screening across 100+ languages
Continuously updated from new adversarial samples

Acquired by Check Point, and it went well

Check Point acquired Lakera in September 2025, in a deal reported at around $300 million.

The acquisition brought Lakera Guard, Lakera Red and the Gandalf community dataset into Check Point’s AI security platform, and Check Point based its Global Center of Excellence for AI Security on the Lakera team.

Most importantly for anyone evaluating it: the Zurich research team still maintains Guard’s detection models.

That is the good version of this outcome, and it is worth naming because this site has documented the bad versions repeatedly. Helicone went into maintenance mode after Mintlify acquired it. Humanloop was acqui-hired and shut down. Traceloop’s platform became a feature of a governance product. Lakera is still being developed by the people who built it, inside a company whose core business is security.

The change buyers will feel is commercial rather than technical: new sales route through Check Point enterprise procurement. Expect a heavier process than signing up for an API.

The data is the moat

The technical case for Lakera rests on something competitors cannot easily replicate.

Its detection models are reported to learn from over 100,000 new adversarial samples daily, drawn partly from Gandalf - a public prompt injection game that has collected more than 80 million prompts from people genuinely trying to break an LLM.

That matters because of where the difficulty actually lies. Building a prompt injection classifier is not especially hard. Getting a large, continuously refreshed corpus of real attack attempts to train and evaluate it against is very hard. Lakera solved that by making a game people play voluntarily, and it has been compounding ever since.

The performance claims, and how to treat them

Lakera reports 98%+ detection, sub-50ms latency, and false positive rates below 0.5%, screening 100+ languages.

What makes those figures notable is that they claim strength on all three axes at once, which is the genuinely hard part. Any detector can hit high recall by flagging everything; the false positive rate determines whether your users can actually use the product. A guardrail that blocks 5% of legitimate requests is unusable no matter how good its detection looks.

These are vendor-reported and we have not verified them. If this is a serious evaluation, insist on testing against your own traffic. Detection performance is workload-specific, and the number that matters is your false positive rate on your users’ real inputs, not a benchmark figure.

The 100+ language coverage deserves more attention than it usually gets. A standard and effective bypass is writing the malicious instruction in a language your filtering was never tested against. English-only detection has a large, trivially exploitable blind spot, and broad language coverage is the kind of feature that shows up as an absence of failures you never see rather than as a headline capability.

Third-party information here is unusually unreliable

A specific warning, because it affected our own research.

We found aggregator listings describing Lakera as generic website security software with no API - which flatly contradicts what the vendor sells. That is not a stale figure or a nuance, it is a completely wrong product category.

Add that much comparison content has not registered the Check Point acquisition at all, and the practical conclusion is that almost all third-party information about Lakera should be treated as unreliable. Go to Check Point or the vendor’s own documentation.

The commercial friction

No published pricing on any tier. Community, Pro and Enterprise exist, a free plan is available, and you contact them for a quote. Since the acquisition, enterprise sales run through Check Point.

We are recording this as not published rather than estimating.

The trade-off worth being explicit about: NeMo Guardrails and Guardrails AI are free and open source. What you are buying from Lakera is detection quality backed by an adversarial dataset nobody else has, plus managed operation and enterprise support. What you are giving up is transparency, self-hosting, and the ability to know what it costs before you talk to someone.

Should you use it?

Use Lakera if prompt injection is a real threat to your product, you want managed low-latency detection with enterprise support, and an enterprise sales process is normal for you.

Don’t use it if you need to inspect or self-host what makes your security decisions, you need published pricing, or an open-source guardrail would suffice.

Bottom line: the strongest managed prompt injection defence available, with a training-data advantage that is genuinely hard to compete with, now inside a security company that appears to be looking after it. Test the false positive rate on your own traffic before committing, and expect procurement rather than a signup form.


Acquisition, team status and product claims verified against contemporaneous reporting and vendor sources on 3 August 2026. Detection performance figures are vendor-reported and have not been independently tested. Pricing is not published and has not been estimated. Several third-party aggregator descriptions of this product were found to be factually wrong and were disregarded. This is a researched directory entry - we have not yet instrumented this platform with our reference application.

Pricing Plans

Community

$0

  • Free tier available
  • Limits not publicly documented
Most Popular

Pro

Not published

  • Contact for a quote
  • No public rate card

Enterprise

Not published

  • Now routed through Check Point enterprise procurement
  • Contact sales

SDKs & Frameworks

REST API Python SDK Model and provider agnostic Screens 100+ languages

Deployment

Managed API (cloud) Part of Check Point's AI security platform Not open source

Eval Methods

Real-time prompt injection detection Jailbreak detection Data leakage detection Lakera Red for offensive testing

Corporate Status

Acquired by Check Point, September 2025

Our Verdict

Lakera is the strongest managed prompt injection defence available and the acquisition has not obviously damaged it. Check Point acquired the company in September 2025 in a deal reported around $300 million, taking Lakera Guard, Lakera Red and the Gandalf dataset into its AI security platform, and basing its Global Center of Excellence for AI Security on the Zurich team. That team still maintains the detection models, which is the outcome you want from an acquisition and is notably better than what happened to Helicone. The technical case rests on data. Lakera's models learn from a very large stream of adversarial prompts, drawn partly from the Gandalf community game, and that corpus is genuinely hard for a competitor to replicate. Vendor figures of 98%+ detection at sub-50ms latency with under 0.5% false positives are strong if accurate, though we could not verify them. The friction is commercial - nothing is published on pricing, and buying now means Check Point enterprise procurement rather than a credit card.

Similar Tools

Frequently Asked Questions

What changed after the Check Point acquisition?

Ownership and how you buy it, more than the product. Check Point acquired Lakera in September 2025 in a deal reported around $300 million, taking Guard, Red and the Gandalf dataset into its AI security platform and basing its Global Center of Excellence for AI Security on the Lakera team. Crucially the Zurich research team still maintains the detection models, which is the good version of this outcome - compare Helicone, which went into maintenance mode after acquisition. The practical change for buyers is that sales now route through Check Point enterprise procurement, so expect a heavier process than signing up to an API.

What makes the detection actually good?

The training data, which is the part competitors cannot easily copy. Lakera's models are reported to learn from over 100,000 new adversarial samples daily, drawn partly from Gandalf - a public prompt injection game that has collected more than 80 million prompts from people actively trying to break an LLM. That is an unusually rich and continuously refreshed corpus of real attack attempts rather than synthetic examples. Building a detector is not hard; getting the adversarial data to train and evaluate it is, and Lakera solved that with a game people play voluntarily.

Are the performance claims trustworthy?

They are vendor-reported and we have not verified them. The figures cited are 98%+ detection, sub-50ms latency and false positives below 0.5%, across 100+ languages. What makes them notable is that they claim strength on all three axes simultaneously, which is the hard part - a detector can trivially hit high recall by flagging everything, and the false positive rate is what determines whether your users can actually use the product. Treat the specific numbers as unconfirmed and, if this is a serious evaluation, insist on testing against your own traffic. A guardrail with a 5% false positive rate on your particular workload is unusable regardless of what it scores on a vendor benchmark.

Why does 100+ language coverage matter?

Because injection attacks do not arrive in the language you designed for. A common and effective bypass is simply writing the malicious instruction in a language your filtering was never tested against, and English-only detection has a large blind spot that is trivial to exploit. Broad language coverage is one of the more practically important features in a guardrail and one of the easiest to overlook when comparing feature lists, because it does not appear as a headline capability - it appears as an absence of failures you never see.

What does it cost?

Not published. Lakera offers Community, Pro and Enterprise tiers with a free plan available, but no pricing is listed on any tier and you must contact them for a quote. Since the acquisition, enterprise sales run through Check Point. We are recording this as not published rather than estimating. If cost transparency matters to your process, note that the open-source alternatives - NeMo Guardrails and Guardrails AI - are free, and the trade-off you are weighing is detection quality and managed operation against a sales cycle and an unknown bill.

Why do you warn about third-party sources here?

Because they are unusually bad for this product specifically. In researching this page we found aggregator listings describing Lakera as generic website security software with no API, which flatly contradicts what the vendor actually sells. That is not a nuance or a stale figure, it is a completely wrong description of the product category. Combined with the acquisition, which much of the comparison content has not registered at all, we would treat almost all third-party information about Lakera as unreliable and go to Check Point or the vendor's own documentation.