LLM security guides,
in plain English.
These guides explain how LLM applications get attacked and how to defend them: what prompt injection is, how to prevent it, what the OWASP LLM Top 10 means for you, and what an LLM firewall can and cannot do. Each cites its sources and is honest about limits, including where a tool like AiDren does not help.
What you will learn
Read in order if you are new, or jump to the one you need.
What is prompt injection?
Direct vs indirect injection, how it differs from jailbreaking, why it is hard to fix, and the OWASP LLM01 mapping.
Read the guideHow to prevent prompt injection
A defence-in-depth checklist with code: least privilege, untrusted output, screening, egress limits, approvals and testing.
Read the guidePrompt injection examples
Twelve attack patterns with sanitised payloads, what each targets, why it works and how to mitigate it.
Read the guideOWASP Top 10 for LLM applications (2025)
All ten risks explained, with an honest table of what a proxy can, partly can and cannot cover.
Read the guideLLM firewall explained
What an LLM firewall is, how it differs from a WAF, gateway and guardrails library, and what to look for.
Read the guideFrom reading to doing
The guides are tool-neutral where they can be. When you want to act on them, these pages cover what AiDren does.
- Prompt injection protection screens every request with a judge model before it reaches your provider.
- Output scanning checks responses for secrets, personal data and system-prompt leaks.
- Model-file scanning checks downloads for malicious code before they reach disk.
- Egress monitoring reports unexpected outbound connections from an agent.
- The free attack test shows which attacks get through your own system prompt.
- Pricing is public: £49, £149 or £399 a month with a 14-day free trial.
Questions,
answered plainly.
Where should I start if I am new to LLM security?
Start with what is prompt injection, since it is the top risk on the OWASP list, then follow with the prevention checklist and the OWASP Top 10 guide for the wider picture.
Can I test my own app without signing up?
Yes. The free attack test demo runs six sample attacks against a system prompt you paste in, with no signup. The full test of about 20 attacks is part of the 14-day free trial.
Who writes these guides?
I do. I am Paul Freek, a UK sole trader and the operator of AiDren. Each guide cites its primary sources, such as OWASP and the UK NCSC, and says plainly where a proxy like AiDren does not help. More about me is on the about page.
See which attacks get through
your own prompt.
Six sample attacks, about 20 seconds, no signup.
Run the free demo