NewThe Go SDK is here

Runtime security
for every prompt and reply.

Verexa checks what goes into your model and what comes out of it. Redact PII, block leaked secrets and flag prompt injection without changing how you call your provider.

one turn · two checks · one trace
  1. Prompt
    from your user
  2. Input check
    pii → redact
  3. Your model
    any provider
  4. Output check
    secret_leak → block
  5. Reply
    to your user

Start here

01

New to Verexa? Read these in order. Each one takes a few minutes.

Guard the client you already have

02

Wrap your OpenAI client once. Every call is checked twice, the prompt on the way out and the reply on the way back, and both checks share one trace.

Wrap the OpenAI client
from openai import OpenAIfrom verexa import wrap_openaiclient = wrap_openai(OpenAI())completion = client.chat.completions.create(    model="gpt-4o",    messages=[{"role": "user", "content": "my email is jane.doe@example.com"}],)
  • No new call siteschat.completions and responses work as before.
  • Zero runtime dependenciesEvery SDK is a thin client over one HTTP endpoint.
  • Fails open by defaultIf the API is unreachable, checks return allow and your app keeps working. Switch to fail closed in one setting.

Every check returns a verdict

03

A verdict carries one action, the detectors that ran, their scores and the text to use next. This is the response for the prompt above.

POST /v1/check · phase input0.05 ms
inmy email is jane.doe@example.com
outmy email is [redacted email]
detectoraction
prompt.instruction_overrideallow
prompt.unicode_obfuscationallow
text.piiredact
action redactdegraded false
allow
Nothing fired. The text passes through unchanged.
redact
Sensitive spans are replaced and the turn continues with the clean text.
flag
The turn continues and the verdict is recorded for review.
block
The wrapped call raises. The prompt or reply never gets through.

Seven detectors, three profiles

04

A profile decides which detectors run and how long they may take. Pick one per project and environment, then tune single detectors in the policy.

deterministic
30msbudget

Six rule-based detectors. No model calls, so the verdict is fast and repeatable.

balanced
1.5sbudget

Adds the injection classifier on input for attacks that rules alone miss.

audit
8sbudget

The same layers, plus a synchronous judge on every verdict that is not already certain.

DetectorPhaseCatches
prompt.instruction_overrideInputAttempts to override or ignore your instructions
prompt.unicode_obfuscationBothHidden and look-alike Unicode used to smuggle text
text.piiBothEmails, phone numbers and card numbers
output.secret_leakOutputAPI keys, tokens and other credentials in a reply
output.system_prompt_leakOutputYour system prompt repeated back to the user
output.markdown_exfilOutputData hidden in markdown links and images
prompt.injection_classifierInputModel-scored prompt injection and jailbreaks (balanced and audit)

Read about each detector or configure them in a policy.

Install an SDK

05

Same API, same verdicts, in the language you ship.

Install
pip install verexa

See your first trace in the dashboard

Create an API key, send one guarded request and watch the verdict arrive in Events.

Create an API key