Runtime security
for every prompt and reply.
Verexa checks what goes into your model and what comes out of it. Redact PII, block leaked secrets and flag prompt injection without changing how you call your provider.
- Promptfrom your user
- Input checkpii → redact
- Your modelany provider
- Output checksecret_leak → block
- Replyto your user
Start here
01New to Verexa? Read these in order. Each one takes a few minutes.
Guard the client you already have
02Wrap your OpenAI client once. Every call is checked twice, the prompt on the way out and the reply on the way back, and both checks share one trace.
from openai import OpenAIfrom verexa import wrap_openaiclient = wrap_openai(OpenAI())completion = client.chat.completions.create( model="gpt-4o", messages=[{"role": "user", "content": "my email is jane.doe@example.com"}],)- No new call sites
chat.completionsandresponseswork as before. - Zero runtime dependenciesEvery SDK is a thin client over one HTTP endpoint.
- Fails open by defaultIf the API is unreachable, checks return
allowand your app keeps working. Switch to fail closed in one setting.
Every check returns a verdict
03A verdict carries one action, the detectors that ran, their scores and the text to use next. This is the response for the prompt above.
| detector | score | action |
|---|---|---|
| prompt.instruction_override | 0.00 | allow |
| prompt.unicode_obfuscation | 0.00 | allow |
| text.pii | 1.00 | redact |
- allow
- Nothing fired. The text passes through unchanged.
- redact
- Sensitive spans are replaced and the turn continues with the clean text.
- flag
- The turn continues and the verdict is recorded for review.
- block
- The wrapped call raises. The prompt or reply never gets through.
Seven detectors, three profiles
04A profile decides which detectors run and how long they may take. Pick one per project and environment, then tune single detectors in the policy.
Six rule-based detectors. No model calls, so the verdict is fast and repeatable.
Adds the injection classifier on input for attacks that rules alone miss.
The same layers, plus a synchronous judge on every verdict that is not already certain.
| Detector | Phase | Catches |
|---|---|---|
prompt.instruction_override | Input | Attempts to override or ignore your instructions |
prompt.unicode_obfuscation | Both | Hidden and look-alike Unicode used to smuggle text |
text.pii | Both | Emails, phone numbers and card numbers |
output.secret_leak | Output | API keys, tokens and other credentials in a reply |
output.system_prompt_leak | Output | Your system prompt repeated back to the user |
output.markdown_exfil | Output | Data hidden in markdown links and images |
prompt.injection_classifier | Input | Model-scored prompt injection and jailbreaks (balanced and audit) |
Install an SDK
05Same API, same verdicts, in the language you ship.
pip install verexaSee your first trace in the dashboard
Create an API key, send one guarded request and watch the verdict arrive in Events.