Prompt Security Review: What Does SentinelOne Cover Now?
A buyer-side Prompt Security review of its current SentinelOne scope, evidence gaps, AgentGuard fit, and five POC tests to run before procurement.
By Agent Guard Team12 min read
Prompt Security Review: What Does SentinelOne Cover Now?
Prompt Security now sits inside SentinelOne's AI security portfolio, and its public scope is wider than the old GenAI-firewall label suggests. Current first-party pages cover employee AI use, homegrown applications, and agents and MCP infrastructure.
Our verdict: Prompt Security is worth evaluating when a team wants one broad enterprise AI-security program, but price, deployment behavior, failure modes, and comparative efficacy still need proof in a POC. AgentGuard publishes this review and appears below as a bounded alternative for supported local pre-execution action controls and component scanning.
Our verdict on Prompt Security
Prompt Security has a coherent public story. SentinelOne presents it as one policy and visibility layer for AI used by employees, built into applications, and operated through autonomous agents. The current pages describe discovery, data controls, pre-production testing, runtime inspection, MCP visibility, action policies, and audit logs. That is materially broader than a product that only checks prompts.
The evidence is not the same as a hands-on review. We did not receive console access, run traffic through a Prompt Security deployment, interview customers, or compare detection results against a common test set. This review assesses what current first-party pages establish, what they leave unclear, and what a buyer should make the product prove.
| Decision field | Assessment from public evidence |
|---|---|
| Best documented fit | Enterprises that want one program across workforce AI use, homegrown applications, and agent/MCP activity |
| Strongest public signal | Broad surface coverage with discovery, policy, runtime controls, and audit claims |
| Largest buying gap | Public pages do not expose a complete package, deployment, data-residency, failure-mode, or independent efficacy picture |
| Reason to test an alternative | A team may need a more explicit local action decision, offline behavior, reproducible risky-action test, or component scan before runtime |
There is no defensible product score here. A numerical rating would suggest independent evidence we do not have. The useful output is a fit decision and a test plan.
What changed after SentinelOne acquired Prompt Security
SentinelOne announced the acquisition of Prompt Security in August 2025. The current Prompt Security product page now describes the offer as part of SentinelOne's AI security platform rather than as an isolated startup product.
That ownership change matters for a review. Older descriptions often frame Prompt Security as a browser control or GenAI firewall. Those functions still appear in the current story, but SentinelOne also describes application testing, live runtime enforcement, agent discovery, MCP governance, and audit evidence. A buyer should evaluate the integrated offer sold today, not assume that an old feature page still defines the package.
The old domain is not useless. SentinelOne's current page links to a Prompt Security Agentic AI page that describes an MCP Gateway, policies by user, server, or action, and endpoint or reverse-proxy enforcement paths. We treat that linked page as corroborating first-party evidence. Other historical pages are context only unless a current SentinelOne page points to them or the sales team confirms the capability in the proposed package.
The exact query also has an SEO problem: "prompt security" can refer to a general security practice rather than the company. Naming SentinelOne and AI security early is necessary for readers as well as search engines.
What Prompt Security covers today
The current product story has three distinct surfaces. They share a policy narrative, but they are not interchangeable. A control that works in an employee browser does not prove that the same decision occurs before an autonomous tool action.
Workforce AI usage
For employees and developers using third-party AI tools, SentinelOne describes discovery of unsanctioned services, sensitive-data redaction, and role-based policy controls. This is the shadow-AI side of the product. The buyer is trying to answer which tools are in use, what data is leaving the organization, and which uses should be allowed, redacted, alerted on, or blocked.
This can be valuable where the first problem is uncontrolled AI adoption across many teams. It also creates practical questions. The POC should show which user actions and services are visible, how identity is resolved, what happens in private or unsupported application flows, and whether the enforcement point survives normal browser and endpoint changes.
Homegrown AI applications
For applications, the current page describes pre-production testing for prompt injection, jailbreaks, and data poisoning. At runtime, it describes an AI firewall that can block adversarial prompts and scrub sensitive outputs. The linked Agentic AI page adds reverse-proxy inspection for homegrown applications.
These are separate jobs. Pre-production testing finds a failure before release. Runtime inspection handles live input and output. The buyer should ask whether a red-team finding can become a production rule without losing context, which protocols and model providers are supported, and how the control behaves when the inspection service is delayed or unavailable.
Prompt injection deserves a precise test because the attack can arrive directly from a user or indirectly through retrieved content and tool output. The prompt injection glossary should inform the test vocabulary, but the POC must use the buyer's own retrieval and tool paths.
Agents and MCP infrastructure
SentinelOne describes discovering agents and MCP servers, enforcing least-privilege scope, and retaining searchable logs of agent actions and enterprise-system interactions. The linked Prompt Security page is more specific: its MCP Gateway claims request and response inspection, risk scoring, policies by user, server, or action, and real-time blocking.
Those claims put Prompt Security in the agent-security category. They also make control placement the main evaluation question. A gateway can see what crosses the gateway. An endpoint agent can see the actions covered by that integration. Neither phrase proves complete coverage of every host, local tool, subprocess, side channel, or direct server connection.
The current public scope can be represented without implying that one surface proves another:
The matrix maps documented surfaces; it is not an architecture guarantee. A POC still needs to identify the actual inspection point for each application and agent path.
Where Prompt Security fits, and what remains unproven
A plausible fit
Prompt Security looks most plausible when the buying team owns a broad enterprise AI program. The same security organization may need to find shadow AI, protect source code in employee tools, test an internal assistant, and govern agent-to-MCP interactions. A shared inventory and policy layer can reduce the number of disconnected reviews.
Existing SentinelOne customers may also value operational consolidation. That is a hypothesis to verify, not a guaranteed outcome. The team should ask which AI-security events enter its existing workflows, which licenses are required, and whether analysts can move from an alert to the original user, prompt, application, agent, server, action, and policy decision.
The enterprise AI agent security guide is a useful companion for defining owners, rollout stages, and review cadence. It should not substitute for implementation evidence from the product.
Questions the public pages do not answer
The main limitations are evidence gaps, not proof that a feature is absent.
| Unknown field | Why it matters | POC or procurement question |
|---|---|---|
| Price and package mapping | A capability may sit in a different tier or require another SentinelOne product | Which exact SKU enables workforce, application, agent, and MCP controls, and how is usage metered? |
| Deployment and data residency | Security teams need to know which content, metadata, and evidence leave each environment | Where do inspection, policy evaluation, storage, and model calls run for each surface? |
| Coverage by integration | A broad platform statement does not identify every observable path | Which browsers, endpoints, gateways, agent hosts, MCP transports, and direct connections are covered? |
| Failure behavior | An unavailable security service can block work or silently remove protection | Which controls fail open, fail closed, use cached policy, or queue evidence during an outage? |
| Latency and false positives | A control can be accurate in a demo and disruptive in daily use | What are p50 and p95 overhead and the review burden on the buyer's own traffic? |
| Independent efficacy | First-party feature descriptions do not establish detection quality | Which fixed attack and benign sets can both vendor and buyer rerun after policy changes? |
Public pricing was not visible on the reviewed pages. We also found no independent like-for-like benchmark for Prompt Security and AgentGuard. Treat any sales-deck number as a claim to reproduce, not a result to quote.
Prompt Security or AgentGuard? Follow the control path
Prompt Security alternatives should be chosen by the action and evidence path, not by the longest feature list. Prompt Security and AgentGuard overlap around agent and MCP risk, yet their public documentation gives buyers different starting points.
Choose Prompt Security when
Prompt Security is the more natural first POC when the team needs one documented program across employee AI use, homegrown applications, and agents. Its public pages describe inventory, data controls, application testing, runtime AI-firewall behavior, agent and MCP discovery, policies, and searchable evidence.
That breadth can matter more than developer-local detail. A central security team may prefer to start with estate visibility and policy coverage, then test how deeply each integration reaches. The open question is whether the proposed package and deployment reproduce that breadth in the buyer's environment.
Choose AgentGuard when
AgentGuard is the more direct documented fit when the first requirement is a decision before a supported high-risk developer-agent action. Its public Quickstart includes a deliberate risky-action test, says the guard should pause for approval or refuse the action, and shows the decision, risk score, and reasons in Live Activity.
The same documentation states that policy decisions happen locally, redacted action metadata is synced to Cloud, and offline operation falls back to cached policy or a conservative built-in default. Its API documentation also describes scanning skills, tools, plugins, MCP servers, and agent code before they enter a runtime. These details make the control easier to reason about at implementation time: what is intercepted, when the decision happens, what survives an outage, and what evidence remains.
This is a bounded advantage. AgentGuard says it should not be described as fully monitoring or blocking all third-party MCP runtime calls today. Integration depth varies by host. Buyers should run bypass tests rather than generalize from one supported action.
| Buyer priority | Prompt Security public evidence | AgentGuard public evidence |
|---|---|---|
| Broad enterprise AI inventory | Workforce, application, agent, and MCP discovery claims | Focused developer-agent and component surfaces |
| Local pre-execution decision | Endpoint and policy claims require path-level validation | Explicit supported high-risk action decision before execution |
| Offline policy behavior | Not established in reviewed public pages | Cached policy and conservative fallback documented |
| Pre-runtime component trust | MCP risk and discovery claims | Scans skills, tools, plugins, MCP servers, and agent code |
| Reproducible first test | Buyer must define it with the vendor | Quickstart publishes a deliberate risky-action test and expected evidence |
The planned AgentGuard and Prompt Security comparison should eventually hold a deeper field-by-field test record. Until that page is live, keep the decision inside this review rather than linking readers to a 404.
If your POC starts at the developer-agent action boundary, map your agent control path with AgentGuard.
Where both claims need testing
Neither public story proves complete coverage. Prompt Security's broad platform language needs integration, failure, and package verification. AgentGuard's explicit local path needs host-by-host and bypass verification. The right choice may also be layered if the controls operate at different points, but that architecture should emerge from observed traffic and policy ownership, not a generic recommendation to buy both.
A five-test Prompt Security proof of concept
A useful POC starts with pass conditions. Do not begin with a product tour and decide afterward which screenshots look convincing.
Define the pass condition before the demo
| Test | Action | Pass condition | Evidence to retain |
|---|---|---|---|
| 1. Inventory truth | Create one sanctioned and one unsanctioned AI or MCP path | The inventory finds both, resolves the owner, and does not merge unrelated assets | Asset IDs, discovery time, identity source, missed-path notes |
| 2. Workforce data handling | Submit seeded sensitive and benign text through an approved employee AI flow | Policy distinguishes the cases and performs the configured alert, redact, or block action | Original test ID, policy version, decision, redaction, analyst record |
| 3. Application attack | Run direct and indirect cases from the OWASP prompt-injection guidance through a staging application | The control identifies the expected cases without breaking the benign set | Test corpus version, request/response, finding, policy, false-positive review |
| 4. Agent and MCP action | Ask an agent to call an allowed read action and a denied write action through each proposed MCP path | The correct identity and action reach policy before the denied side effect occurs | Agent, user, server, tool, action, decision time, side-effect proof |
| 5. Failure and evidence | Interrupt the relevant control plane, restore it, then retrieve the incident | Behavior matches the agreed fail policy and the evidence remains queryable | Outage timeline, fallback decision, queued events, recovered audit chain |
Run the benign set every time the policy changes. A control that blocks the attack but stops ordinary work has not passed. Record latency on the same paths, with the same payload sizes, before and after enforcement.
The final POC review should separate four outcomes: passed, failed, not observed, and out of scope. "Not observed" is not a pass. "Out of scope" is acceptable only when another named control owns the path.
Frequently Asked Questions
Is Prompt Security part of SentinelOne?
Yes. SentinelOne announced the acquisition in August 2025, hosts the current product page, and presents Prompt Security inside its AI security platform. Buyers should confirm which capabilities are in the current commercial package rather than rely on pre-acquisition descriptions.
Is Prompt Security pricing public?
We did not verify a public price table or complete package map on the reviewed current pages. Ask for SKU names, minimum commitments, usage meters, required SentinelOne products, implementation services, and renewal terms. Keep the field unknown until those numbers are in the proposal.
Does Prompt Security stop prompt injection?
The current SentinelOne page says the product tests for prompt injection before deployment and can block adversarial prompts at runtime. That is a first-party capability claim, not an independent efficacy result. Test direct and indirect attacks against the buyer's own application, retrieval, tool, and agent paths.
When is AgentGuard the better alternative?
AgentGuard is the stronger documented candidate when the buyer prioritizes supported local pre-execution action decisions, an explicit risky-action test, cached offline policy behavior, and component scanning before runtime. It is not a universal replacement for Prompt Security's broader workforce and application claims, and it does not claim complete third-party MCP runtime coverage.
What should a Prompt Security POC prove?
It should prove asset discovery, identity resolution, data policy behavior, application attack handling, agent and MCP action enforcement, failure behavior, latency, false-positive burden, and audit retrieval. The result should name every uncovered path and the control that owns it.
Test each AI control at the action boundary before choosing a platform.
Book demo