Skip to main content

PromptShields

Secure AI Applications in 3 Lines of Code

PyPI Python License Downloads

An enterprise-grade, bidirectional LLM security framework. Defend against prompt injection, jailbreaks, data leakage, and PII exposure in production applications.


Installation

pip install promptshields

Optional extras

Core install covers pattern matching, session tracking, canary tokens, and the pre-trained ML ensemble. Some features need extra dependencies:

# Output DLP engine (Bloom filters, Aho-Corasick, semantic similarity)
pip install "promptshields[output]"

# Semantic/embedding-based matching (sentence-transformers)
pip install "promptshields[ml]"

# Framework integrations (LangChain, LiteLLM, LlamaIndex, CrewAI)
pip install "promptshields[integrations]"

# Everything
pip install "promptshields[all]"

Quick Start

from promptshield import Shield

shield = Shield.balanced()
result = shield.protect_input(user_input, system_prompt)

if result['blocked']:
    print(f"Blocked: {result['reason']} (score: {result['threat_level']:.2f})")
    print(f"Breakdown: {result['threat_breakdown']}")

Features & Capabilities

Feature PromptShields DIY Regex Paid APIs
Setup Time 3 minutes Weeks Days
Cost Free Free $$$$
Privacy 100% Local Local Cloud
F1 Score 0.97 (RF) / 0.96 (DeBERTa) ~0.60 ~0.95
ML Models 3 + DeBERTa None Black box
Async Native DIY Varies

Protection Scope

  • Prompt injection attacks (direct and indirect)
  • Jailbreak attempts (DAN, persona replacement)
  • System prompt extraction
  • PII leakage and sensitive data exposure
  • Session anomalies
  • Encoded/obfuscated attacks (Base64, URL, Unicode)

Security Modes

Choose the right tier for your application latency requirements:

Shield.fast()       # ~1ms  - High throughput (pattern matching only)
Shield.balanced()   # ~2ms  - Production default (patterns + session tracking)
Shield.strict()     # ~7ms  - Sensitive apps (+ 1 ML model + PII detection)
Shield.secure()     # ~12ms - Maximum security (3 ML models ensemble)

Upgrading to v3.0.0

Version 3.0.0 introduces a massive update with the new bidirectional Output Filter.

Output Engine (Data Leakage Prevention)

Prevent sensitive data, PII, and proprietary knowledge from leaking through LLM generations securely before they reach the user.

  • 4-Layer Scanning Pipeline: Defends against data leakage using Bloom Filters, Aho-Corasick exact matching, Honeypot traps, and Embedding-based Semantic Similarity checks.
  • Semantic Leakage Detection: Natively utilizes sentence-transformers to detect when the LLM's output is highly semantically similar to your proprietary system prompts or private databases.
  • Contextual PII Redaction: A heavily-optimized detection system to proactively redact sensitive information securely.
from promptshield import OutputFilter

filter = OutputFilter(
    system_prompt="You are a secret agent...",
    enforce_pii=True,
    enforce_embeddings=True
)

safe_text, was_redacted = filter.scan_output("My name is John Doe.")

Performance & Hardening

  • Complete thread-safety for multi-tenant high-concurrency environments.
  • Strict HMAC-SHA256 authenticated webhooks.
  • Lazy-loading implementation for heavy dependencies (numpy, sentence-transformers) for lightning-fast cold starts.

Developer Experience

YAML Configuration

Launch shields declaratively without changing application code.

shield = Shield.from_config("promptshield.yml")

Slack and Teams Webhooks

Instantly trigger webhooks whenever high-severity threats are blocked natively.

shield = Shield.balanced(webhook_url="https://hooks.slack.com/...")

Async and FastAPI Support

Native middleware integration for modern web frameworks.

from promptshield import Shield
from promptshield.integrations.fastapi import PromptShieldMiddleware

app.add_middleware(PromptShieldMiddleware, shield=Shield.balanced())

Benchmark Results

Trained on the highly curated neuralchemy/Prompt-injection-dataset:

Model F1 ROC-AUC FPR Latency
Random Forest 0.969 0.994 6.9% <1ms
Logistic Regression 0.964 0.995 6.4% <1ms
Gradient Boosting 0.961 0.994 7.9% <1ms
LinearSVC 0.959 0.995 10.3% <1ms
DeBERTa-v3-small 0.959 0.950 8.5% ~50ms

Pre-trained models available on Hugging Face:


Documentation

Full API reference, guides, and integration details are available in the GitHub repository.


License

MIT License — see LICENSE

Built by Sanskar Jajoo / NeurAlchemy — AI Security and LLM Safety Research

Metadata

Release files for promptshields 3.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for promptshields 3.2.0
File Size Uploaded
promptshields-3.2.0.tar.gz 4.0 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for promptshields 3.2.0
File Interpreter ABI Platform
promptshields-3.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 8.0 MB

Release files / promptshields-3.2.0.tar.gz

Download URL promptshields-3.2.0.tar.gz
Size 4.0 MB
Tags Source
SHA-256 checksum
How to use checksums
8c8352059c31a860ec59c14f7aae1f5211bb0f36acb410ef91d92ee1ccf75333
BLAKE2b-256 checksum
How to use checksums
c84603903001d2877709a3937b658493a29edd1b4a520fff59c1f34f6fa1af59
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.0

Release files / promptshields-3.2.0-py3-none-any.whl

Download URL promptshields-3.2.0-py3-none-any.whl
Size 4.1 MB
Tags Python 3
SHA-256 checksum
How to use checksums
12581872de7a4eccb5e220f410fcd0ab2c2c87620edd86b2e5f68de8df1e25a4
BLAKE2b-256 checksum
How to use checksums
2b33b8030ff07b2f728b4efcfe01bb27727eba3eff8c6a59cb0b91f223bdf62d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.10.0

Release history Release notifications | RSS feed

This release

3.2.0 This release

2 release files

3.0.1

2 release files

3.0.0

2 release files

2.7.0

2 release files

2.6.0

2 release files

2.5.1

2 release files

2.5.0

2 release files

2.1.4

2 release files

2.1.3

2 release files

2.1.2

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.9

2 release files

2.0.8

2 release files

2.0.7

2 release files

2.0.6

2 release files

2.0.5

2 release files

2.0.4

2 release files

2.0.3

2 release files

2.0.2

2 release files

2.0.1

2 release files

2.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page