🛡AIGuardian

Frequently asked questions

Everything you need to know about how AIGuardian works, integrates and is metered.

How do I integrate AIGuardian?

The fastest path is the Claude Code plugin: one marketplace install wires enforcing hooks, the MCP server and the guardrails skill together. You can also call the REST API from any language, or point ANTHROPIC_BASE_URL at AIGuardian to use the drop-in proxy.

What checks run on every prompt?

Prompt injection, jailbreak, toxicity, secret detection, restricted topics (your own rules), data exfiltration, web-content injection and PII redaction. Checks run in order, short-circuit on the first confirmed block, and every result carries OWASP LLM Top 10 and MITRE ATLAS tags.

What happens to a shell command my agent wants to run?

It is risk-scored from 0 to 1 across factor groups (baseline, command, sensitive reads, credential egress, destructive patterns). Hard floors such as rm -rf / are denied outright; borderline commands are handed to you for approval; safe commands run without a prompt.

Do you store my prompts?

No. Prompts are evaluated in memory and discarded. We keep the decision, the names of the checks that fired, latency and token counts. You can opt in to keep the flagged text for review from the console.

What counts as a request?

Each evaluation of any kind: an input check, an action authorization, an output validation, a code scan, a policy evaluation, or one gateway completion. All plans share the same meter.

Is the free plan really free?

Yes. It is a one-time credit of 1,000 requests with one API key, valid for 30 days after sign-up. It does not refill monthly; when it runs out you pick a paid plan.

What happens when I hit my limit?

Requests return 429 QUOTA_EXCEEDED and the hook shows the message in your agent. On a paid plan the quota resets next cycle or when you upgrade; on the free plan you choose a paid plan.

Can I bring my own model key?

Yes. Save your OpenAI or Anthropic key in Settings; it is encrypted at rest and only used for gateway and proxy calls. Model spend stays on your account.

Does the hook cost LLM tokens?

No. Hooks run as a separate process outside the model context, so screening never consumes Claude tokens. Only the optional MCP tools use a small amount of context, like any tool call.

Do you offer self-hosting?

Enterprise deployments can run AIGuardian inside your own VPC with SSO and an SLA. See the Enterprise page.