Prompt Security logo

Prompt Security Review (2026)

Runtime GenAI security acquired by SentinelOne in August 2025. Press reported around $250M; the SEC filing says roughly $180M. Its MCP Gateway, sitting in front of 13,000+ known MCP servers, is the most forward-looking asset in this segment.

Researched

Rating

3.0

Starting Price

Not published

Free Plan

No

SDKs & Frameworks

3

Deployment

3

Best For

Existing SentinelOne customers who want GenAI runtime protection inside their endpoint security platform, and any team where agents calling MCP servers is a live security concern.

Last Updated:

10 Things You Should Know About Prompt Security

  1. 1 SentinelOne signed a definitive agreement to acquire Prompt Security on 5 August 2025
  2. 2 Press reports estimated roughly $250 million, with some placing it between $250M and $300M
  3. 3 The SEC filing records approximately $180 million in cash and Class A common stock, including 1,555,099 shares issued
  4. 4 Prompt Security was two years old and had raised roughly $23 million
  5. 5 Investors included Hetz Ventures, Jump Capital, Ridge Ventures, Okta and F5
  6. 6 Its MCP Gateway sits between AI applications and more than 13,000 known MCP servers
  7. 7 The gateway assigns dynamic risk scores and enforces allow, block, filter or redact actions
  8. 8 The acquisition expands SentinelOne's Singularity platform into security for AI

Pros & Cons

Pros

  • The MCP Gateway is genuinely ahead of the field - almost nothing else in this category treats the Model Context Protocol as an attack surface
  • Dynamic risk scoring across 13,000+ known MCP servers is a real dataset advantage, not a feature checkbox
  • Runtime enforcement with allow, block, filter and redact gives graduated responses rather than a binary verdict
  • SentinelOne ownership brings enterprise distribution and endpoint security integration
  • Strong return for a two-year-old company on $23M raised, which suggests the technology was genuinely wanted

Cons

  • No standalone product - it is now a capability inside SentinelOne's Singularity platform, so you are buying SentinelOne
  • No published pricing, and buying means enterprise security procurement
  • Proprietary, not open source, and not independently self-hostable
  • Independent technical evaluation is now very difficult, since it is no longer documented as a standalone product
  • Roadmap follows SentinelOne's platform strategy rather than AI application teams

Features

Real-time runtime protection for generative AI applications
Data leakage prevention from generative AI tools
MCP Gateway intercepting every call, prompt template and response
Dynamic risk scoring for MCP servers with allow, block, filter or redact enforcement
Prompt injection detection at runtime

The MCP Gateway is the reason to care

Most of this page is about an acquisition, but the technology underneath is genuinely ahead of the field, and it is worth leading with.

Prompt Security’s MCP Gateway sits between AI applications and more than 13,000 known MCP servers, intercepting every call, prompt template and response, assigning each server a dynamic risk score, and enforcing allow, block, filter or redact.

Here is why that matters more than another prompt injection filter.

The Model Context Protocol is turning the set of tools an agent can reach into a supply chain. And supply chains are where security problems concentrate, because trust is transitive and verification is nobody’s job.

An agent able to call thousands of potential servers has an attack surface that looks nothing like a chatbot’s. Critically, a prompt injection delivered through a compromised or malicious MCP server bypasses input filtering entirely - it never arrives through the user’s prompt, so a guardrail watching the user input sees nothing wrong.

Almost nothing else in this category treats MCP as an attack surface at all. Of everything we have reviewed in guardrails, this is the most forward-looking capability.

The deal figures do not match, again

Announced 5 August 2025. Press reports estimated roughly $250 million, with some placing it between $250M and $300M. Financial terms were not formally disclosed.

SentinelOne’s SEC filing records approximately $180 million in a mix of cash and Class A common stock, including 1,555,099 shares issued.

A gap of around 28%.

This is now the second case in this segment where the filing contradicts the coverage. F5 announced CalypsoAI at $180 million; its FY2026 10-Q recorded a $145.2 million close - a 19% gap.

Two data points is enough to name the pattern: reported AI security deal values appear to systematically overstate what is actually paid. Press figures plausibly fold in retention packages, earnouts, or equity valued optimistically at announcement.

If you are trying to assess how much this market is really worth - which matters when you are guessing whether your vendor gets bought next - read the filings, not the headlines.

What it returned, and what that says

Prompt Security was roughly two years old and had raised about $23 million, from Hetz Ventures, Jump Capital, Ridge Ventures, and notably Okta and F5.

Roughly $180 million on $23 million in two years is a strong outcome, and it indicates the technology was genuinely wanted rather than a talent acquisition with a product attached. Contrast Baserun, which raised $500K and disappeared into LlamaIndex without an announcement.

One detail worth noting on its own: F5 was an investor in Prompt Security and separately acquired CalypsoAI. The same strategic buyers appear on both sides of this consolidation, which tells you how small and interconnected this market actually is.

You are buying SentinelOne

No standalone product, no published pricing, no independent documentation of the kind you would need to evaluate it separately. The capability is being absorbed into Singularity, SentinelOne’s platform.

So the question becomes whether you want GenAI runtime protection from your endpoint security vendor. Reasonable if you already run SentinelOne. A substantial adoption if you do not.

The strategic framing is worth noting: SentinelOne’s long focus was AI for security - using AI to make security products better. This is security for AI, which is a different business, and the whole industry is making that turn at once.

The consolidation is not finished

AcquirerTarget
SentinelOnePrompt Security
Check PointLakera
F5CalypsoAI
CrowdStrikePangea
CiscoRobust Intelligence
Palo Alto NetworksProtect AI

Reporting indicates the M&A spotlight subsequently moved to Lasso, Aim and Pillar.

For buyers, the implication is structural: the independent guardrails vendor is becoming a transitional category rather than a permanent one. If you are choosing a specialist today, price in the possibility that it belongs to a security platform within eighteen months.

Should you use it?

Use it if you are a SentinelOne customer, or agents calling MCP servers is a live concern for you and you can justify the platform.

Don’t use it if you want a standalone guardrail you can trial and price, or an open-source option would serve.

Bottom line: the best thinking in this category on where the attack surface is actually going, wrapped in a platform purchase. If MCP risk is your problem, note that the alternatives - NeMo Guardrails, Guardrails AI, Lakera, Fiddler - are all weaker on exactly that dimension.


Acquisition date, reported figures and filed consideration verified against SentinelOne’s press release, contemporaneous reporting and SEC filing summaries on 3 August 2026. Reported and filed values differ and both are given. No standalone pricing is published. This is a researched directory entry - we have not instrumented this platform with our reference application.

Pricing Plans

Enterprise

Not published

  • Now sold within SentinelOne's Singularity platform
  • No standalone public pricing
  • Contact SentinelOne sales

SDKs & Frameworks

REST API Model and provider agnostic MCP protocol

Deployment

SentinelOne Singularity platform MCP Gateway fronting 13,000+ known MCP servers Not open source

Eval Methods

Real-time runtime protection Prompt injection detection Data leakage prevention Dynamic MCP server risk scoring

Corporate Status

Acquired by SentinelOne, announced 5 August 2025

Our Verdict

Prompt Security is now part of SentinelOne, and the interesting thing it brought is the MCP Gateway. That component sits between AI applications and more than 13,000 known MCP servers, intercepting every call, prompt template and response, assigning each server a dynamic risk score and enforcing allow, block, filter or redact. As agents increasingly call external tools through the Model Context Protocol, the set of servers your agent can reach becomes a genuine supply chain, and almost nothing else in this category treats it as one. That is the most forward-looking asset we have found in guardrails. The commercial reality is the same as CalypsoAI's - there is no standalone product, no published pricing, and evaluating it means evaluating SentinelOne. Worth noting on the deal itself, press coverage reported roughly $250 million and in places $250M to $300M, while the SEC filing records approximately $180 million in cash and Class A stock. That is the second time in this segment we have found filed consideration materially below the reported figure.

Similar Tools

Frequently Asked Questions

Which deal figure is correct?

The SEC filing, and the gap is worth understanding. Press reports estimated roughly $250 million, with some placing it between $250M and $300M, while financial terms were not formally disclosed. SentinelOne's filing records approximately $180 million in a mix of cash and Class A common stock, including 1,555,099 shares issued. That is a gap of around 28%. This is now the second case we have documented in this segment - F5 announced CalypsoAI at $180 million and its 10-Q recorded a $145.2 million close. The pattern is consistent enough to be useful. Reported AI security deal values appear to systematically overstate what is actually paid, likely because press figures fold in retention packages, earnouts or equity valued optimistically. If you are assessing this market, read the filings.

What is the MCP Gateway and why does it matter?

It sits between your AI applications and the Model Context Protocol servers they call, intercepting every call, prompt template and response, assigning each server a dynamic risk score, and enforcing allow, block, filter or redact. This matters because MCP is turning the set of tools an agent can reach into a supply chain, and supply chains are where security problems concentrate. An agent that can call 13,000 potential servers has an attack surface that looks nothing like a chatbot's, and a prompt injection delivered through a compromised or malicious MCP server bypasses input filtering entirely because it does not arrive through the user's prompt. Almost nothing else in this category treats MCP as an attack surface at all, which makes this the most forward-looking capability we have found in guardrails.

Can I buy it standalone?

No. It is being absorbed into SentinelOne's Singularity platform, with no standalone public pricing and no independent product documentation of the kind you would need for a separate evaluation. Practically, acquiring this capability means becoming a SentinelOne customer, which is a much larger commitment than an API subscription. The relevant question is whether you want GenAI runtime protection from your endpoint security vendor - a reasonable proposition if you already run SentinelOne, and a substantial adoption otherwise.

Was $180M a good outcome for a company that raised $23M?

Very good, and it tells you something about demand. Prompt Security was roughly two years old and had raised about $23 million from Hetz Ventures, Jump Capital, Ridge Ventures, and notably Okta and F5. Returning something in the region of $180 million on that in two years indicates the technology was genuinely wanted rather than a talent acquisition dressed up. It is a useful contrast with Baserun, which raised $500K and was absorbed into LlamaIndex without an announcement. One detail worth noting for its own sake - F5 was an investor here and separately acquired CalypsoAI, so the same strategic buyers appear on both sides of this consolidation.

What does the acquisition signal about the market?

A shift from AI for security to security for AI. SentinelOne's long-standing focus was using AI to improve security products; this acquisition is about protecting AI systems themselves, which is a different business. It fits the wider pattern - Check Point bought Lakera, F5 bought CalypsoAI, CrowdStrike bought Pangea, Cisco bought Robust Intelligence, Palo Alto bought Protect AI. Reporting indicates the M&A spotlight subsequently moved to Lasso, Aim and Pillar, so the consolidation is not finished. For buyers the implication is that the independent guardrails vendor is becoming a transitional category rather than a permanent one.

What are the alternatives if I do not want SentinelOne?

For open-source guardrails, NVIDIA NeMo Guardrails is Apache 2.0 and actively maintained, and Guardrails AI is the other serious option. For managed detection, Lakera is the strongest, though it now sells through Check Point. For guardrails running inside your own environment, Fiddler is the most direct commercial option. None of them currently address MCP server risk the way Prompt Security's gateway does, so if that is your specific concern, the alternatives are weaker on exactly the thing that makes this product interesting.