# AiDren > AiDren is security infrastructure for production AI: a drop-in security proxy that sits between your > application and OpenAI, Anthropic, or Mistral. It screens every prompt and every > response, scans model files pulled from Hugging Face Hub or GitHub for malicious > code, enforces the policy you set per key, monitors an agent's outbound network > connections, and gives a whole team one shared view — before anything reaches > production. One line of code (change the API base URL). In plain terms: an LLM firewall and > AI security proxy, self-serve with public pricing, built and operated by Paul Freek (UK sole trader). Last updated: 2026-10-01 ## What it does - **Prompt-injection blocking**: a judge model screens every request before it reaches OpenAI, Anthropic, or Mistral. Injected or hidden instructions are blocked; clean traffic passes through unmodified. Multi-turn attacks are covered. Fails closed. - **Output and data-leak scanning**: every response is checked too (and, opt-in, prompts) for system-prompt leaks and data-leak patterns — emails, card numbers, IBANs, phone numbers, API keys, private keys. Per proxy key you choose off / monitor / enforce, and redact-the-match vs block-the-response. Works on non-streaming and streaming responses. - **Malicious model-file scanning**: route a download from Hugging Face Hub or GitHub (release assets and raw files) through AiDren and it is scanned for malicious code before it reaches disk. Formats: pickle (including one wrapped in a torch.save ZIP), safetensors, GGUF, ONNX, joblib, and Keras. It also checks for an extension/content mismatch. Non-model files pass straight through and do not count against the request allowance. - **Custom policy per key**: reusable named policies — term, regex, topic, threshold, and system-prompt-leak rules — attached to any proxy key, evaluated on prompt and response. Customer regex runs in a linear-time engine. The built-in judge still runs underneath; a policy adds to it. A Policy Impact Simulator can shadow-test a draft policy against a key's real live traffic without enforcing it. - **Agent egress monitoring**: the `@aidren/worker-agent` npm package watches an AI agent's own outbound connections and flags unexpected destinations without ever blocking a real one. - **Team accounts**: unlimited seats on every plan, email invites, one shared account, Owner and Member roles, and an audit log (with CSV export) of who created or revoked a key, changed a policy, or updated a setting. - **Pre-deploy attack test**: from inside the dashboard, paste a system prompt and AiDren runs about 20 real OWASP-tagged prompt-injection and jailbreak attempts (including multi-turn) against a cheap model using the customer's own upstream key, then shows what got through with protection off versus on, with remediation and an inline re-run. Included on every plan, including the trial. ## Facts - Supported LLM providers: OpenAI, Anthropic, and Mistral (more planned). - Model-file scanning sources: Hugging Face Hub and GitHub. Formats: pickle, safetensors, GGUF, ONNX, joblib, Keras. - Added latency: about 5ms of proxy overhead; requests that need screening also get one classification-model call (typically 200-500ms, run before the request is forwarded so it overlaps nothing). Short clearly-benign messages skip the classification call. - Failure mode: fails closed. If the classification pass cannot complete, the request is blocked, never forwarded unscreened. The classifier has a primary provider plus an automatic fallback. - Pricing: three tiers, all the full product — Starter £49/month (100,000 checked requests/month), Growth £149/month (500,000), Scale £399/month (2,000,000). Annual billing is two months free. 14-day free trial, no card required to start. The request number is a fair-use guide, not a hard cap. - Integration: change your API base URL to `https://api.aidren.co.uk` and keep the request format identical (OpenAI-, Anthropic-, or Mistral-compatible). Full API reference — base URLs, auth, error codes, model-file scanning, output scanning, policies, egress — at https://aidren.co.uk/docs.html - Data handling: request bodies pass through to make a block/allow decision and are not stored beyond the decision log shown in the customer dashboard. API keys are encrypted at rest and never logged in plain text. AiDren runs in the UK/EU and account data and decision logs stay there. - If a trial or subscription lapses, AiDren pauses proxied traffic rather than letting it through unprotected. - AiDren is operated by a UK sole trader trading as AiDren, registered with the UK Information Commissioner's Office (ICO), registration number ZCZ36167. ## Common questions **What is prompt injection?** Hidden instructions embedded in content an AI model reads (a webpage, an email, a file) that attempt to override the model's actual instructions. AiDren screens requests before they reach the model to catch this before it can hijack an agent. **Does AiDren scan the model's responses too, not just the prompt?** Yes. Output scanning checks every response for system-prompt leaks and data-leak patterns before it reaches the app; per key you choose whether a hit is redacted or the whole response blocked. **Does AiDren slow requests down?** It adds one classification pass before the request reaches OpenAI, Anthropic, or Mistral, typically well under the round-trip time to the model itself. Clean traffic is not modified. **Is this a proxy I self-host or a hosted service?** Hosted. Sign up, add an upstream OpenAI, Anthropic, or Mistral key, get a proxy key, and point your app at AiDren's endpoint. **Can AiDren scan model files from GitHub?** Yes — route the download through AiDren (release assets and raw files) and any pickle, safetensors, GGUF, ONNX, joblib, or Keras file is scanned for malicious code before it reaches disk, the same as Hugging Face Hub files. **Can I see what AiDren would catch before committing?** Yes — the built-in attack test runs about 20 real prompt-injection and jailbreak attempts against your system prompt and shows what gets through with protection off versus on. Free on every plan. A free 6-attack sample (one per category) runs on https://aidren.co.uk/attack-test.html with no signup. ## Getting started 1. Sign up at https://app.aidren.co.uk/signup (14-day free trial, no card required). 2. Add your OpenAI, Anthropic, or Mistral API key — encrypted at rest, used only to forward requests to the real provider. 3. Create a proxy key and point your app's base URL at https://api.aidren.co.uk. Example request: ```bash curl https://api.aidren.co.uk/v1/chat/completions \ -H "Authorization: Bearer YOUR_AIDREN_PROXY_KEY" \ -H "Content-Type: application/json" \ -d '{"model": "gpt-4o", "messages": [{"role": "user", "content": "Hello"}]}' ``` ## Product pages - [Prompt injection protection](https://aidren.co.uk/prompt-injection.html): judge-model screening of every request, fail-closed, multi-turn aware. - [LLM output scanning](https://aidren.co.uk/output-scanning.html): scan responses for system-prompt leaks, PII and secrets; redact or block per key. - [Malicious model file scanner](https://aidren.co.uk/model-scanning.html): scan pickle, safetensors, GGUF, ONNX, joblib and Keras files from Hugging Face and GitHub before they reach disk. - [Custom policy per key](https://aidren.co.uk/policy.html): term, regex, topic, limit and system-prompt-leak rules, with shadow testing. - [Agent egress monitoring](https://aidren.co.uk/egress.html): the worker-agent npm package flags unexpected outbound connections (reports, never blocks). - [Team accounts](https://aidren.co.uk/team.html): unlimited seats, Owner and Member roles, audit log with CSV export. - [Free prompt injection attack test](https://aidren.co.uk/attack-test.html): 6 attacks free with no signup; the full ~20-attack test is in the trial. - [MCP server and third-party agent security](https://aidren.co.uk/oss-agents.html): wrap agents you did not write. ## Learn - [Learn hub](https://aidren.co.uk/learn.html): LLM security guides and explainers by Paul Freek. - [What is prompt injection?](https://aidren.co.uk/learn/what-is-prompt-injection.html): definition, direct vs indirect, jailbreaks vs injection, why it is hard to fix (NCSC), OWASP LLM01. - [How to prevent prompt injection](https://aidren.co.uk/learn/how-to-prevent-prompt-injection.html): defence-in-depth checklist with code; where a proxy helps and where it does not. - [Prompt injection examples](https://aidren.co.uk/learn/prompt-injection-examples.html): twelve attack patterns with sanitised payloads and mitigations. - [OWASP Top 10 for LLM applications (2025)](https://aidren.co.uk/learn/owasp-top-10-for-llm-applications.html): all ten risks, with what a proxy can, partly can and cannot cover. - [LLM firewall](https://aidren.co.uk/llm-firewall.html): what an LLM firewall is, how it differs from a WAF, gateway and guardrails library, and how AiDren implements one. ## Pricing, docs and company - [Pricing](https://aidren.co.uk/pricing.html): Starter £49, Growth £149, Scale £399 a month; 14-day free trial, no card. - [API reference](https://aidren.co.uk/docs.html): base URLs, auth, endpoints, model-file scanning, policies, errors and limits. - [About](https://aidren.co.uk/about.html): who runs AiDren (Paul Freek, UK sole trader, ICO ZCZ36167). - [Contact](https://aidren.co.uk/contact.html): sales, support and security disclosure. - [Service status](https://aidren.instatus.com): uptime and incidents. ## Comparisons - [How AiDren compares](https://aidren.co.uk/compare.html): self-serve proxy vs detection API vs enterprise platform vs open source. - [AiDren vs Lakera Guard](https://aidren.co.uk/aidren-vs-lakera.html): Lakera alternative, with sources and last-checked date. - [AiDren vs LLM Guard](https://aidren.co.uk/aidren-vs-llm-guard.html): hosted proxy vs open-source library. - [AiDren vs Protect AI Guardian](https://aidren.co.uk/aidren-vs-protect-ai.html): self-serve vs enterprise model-file scanning. ## Limitations - Egress monitoring reports unexpected connections; it never blocks them. - Supported LLM providers today: OpenAI, Anthropic and Mistral. Model-file scanning covers six formats. - Streaming responses are scanned after they finish unless the key buffers streams, so Enforce cannot retro-block a relayed stream by default. - No tool stops prompt injection completely; screening is one layer alongside least-privilege tool access and human approval. - AiDren does not hold SOC 2 or ISO 27001 certification. ## Optional - [Sign in](https://app.aidren.co.uk/login) and [sign up](https://app.aidren.co.uk/signup) - [Privacy policy](https://aidren.co.uk/privacy.html) - [Terms of service](https://aidren.co.uk/terms.html) - [Cookie policy](https://aidren.co.uk/cookies.html) - [Data Processing Agreement](https://aidren.co.uk/dpa.html) ## Contact hello@aidren.co.uk