Skip to content
AgentGuard
All articles
Review

Prompt Security Review: What Does SentinelOne Cover Now?

A buyer-side Prompt Security review of its current SentinelOne scope, evidence gaps, AgentGuard fit, and five POC tests to run before procurement.

By Agent Guard Team12 min read

Prompt Security Review: What Does SentinelOne Cover Now?

Prompt Security now sits inside SentinelOne's AI security portfolio, and its public scope is wider than the old GenAI-firewall label suggests. Current first-party pages cover employee AI use, homegrown applications, and agents and MCP infrastructure.

Our verdict: Prompt Security is worth evaluating when a team wants one broad enterprise AI-security program, but price, deployment behavior, failure modes, and comparative efficacy still need proof in a POC. AgentGuard publishes this review and appears below as a bounded alternative for supported local pre-execution action controls and component scanning.

Our verdict on Prompt Security

Prompt Security has a coherent public story. SentinelOne presents it as one policy and visibility layer for AI used by employees, built into applications, and operated through autonomous agents. The current pages describe discovery, data controls, pre-production testing, runtime inspection, MCP visibility, action policies, and audit logs. That is materially broader than a product that only checks prompts.

The evidence is not the same as a hands-on review. We did not receive console access, run traffic through a Prompt Security deployment, interview customers, or compare detection results against a common test set. This review assesses what current first-party pages establish, what they leave unclear, and what a buyer should make the product prove.

Decision fieldAssessment from public evidence
Best documented fitEnterprises that want one program across workforce AI use, homegrown applications, and agent/MCP activity
Strongest public signalBroad surface coverage with discovery, policy, runtime controls, and audit claims
Largest buying gapPublic pages do not expose a complete package, deployment, data-residency, failure-mode, or independent efficacy picture
Reason to test an alternativeA team may need a more explicit local action decision, offline behavior, reproducible risky-action test, or component scan before runtime

There is no defensible product score here. A numerical rating would suggest independent evidence we do not have. The useful output is a fit decision and a test plan.

What changed after SentinelOne acquired Prompt Security

SentinelOne announced the acquisition of Prompt Security in August 2025. The current Prompt Security product page now describes the offer as part of SentinelOne's AI security platform rather than as an isolated startup product.

That ownership change matters for a review. Older descriptions often frame Prompt Security as a browser control or GenAI firewall. Those functions still appear in the current story, but SentinelOne also describes application testing, live runtime enforcement, agent discovery, MCP governance, and audit evidence. A buyer should evaluate the integrated offer sold today, not assume that an old feature page still defines the package.

The old domain is not useless. SentinelOne's current page links to a Prompt Security Agentic AI page that describes an MCP Gateway, policies by user, server, or action, and endpoint or reverse-proxy enforcement paths. We treat that linked page as corroborating first-party evidence. Other historical pages are context only unless a current SentinelOne page points to them or the sales team confirms the capability in the proposed package.

The exact query also has an SEO problem: "prompt security" can refer to a general security practice rather than the company. Naming SentinelOne and AI security early is necessary for readers as well as search engines.

What Prompt Security covers today

The current product story has three distinct surfaces. They share a policy narrative, but they are not interchangeable. A control that works in an employee browser does not prove that the same decision occurs before an autonomous tool action.

Workforce AI usage

For employees and developers using third-party AI tools, SentinelOne describes discovery of unsanctioned services, sensitive-data redaction, and role-based policy controls. This is the shadow-AI side of the product. The buyer is trying to answer which tools are in use, what data is leaving the organization, and which uses should be allowed, redacted, alerted on, or blocked.

This can be valuable where the first problem is uncontrolled AI adoption across many teams. It also creates practical questions. The POC should show which user actions and services are visible, how identity is resolved, what happens in private or unsupported application flows, and whether the enforcement point survives normal browser and endpoint changes.

Homegrown AI applications

For applications, the current page describes pre-production testing for prompt injection, jailbreaks, and data poisoning. At runtime, it describes an AI firewall that can block adversarial prompts and scrub sensitive outputs. The linked Agentic AI page adds reverse-proxy inspection for homegrown applications.

These are separate jobs. Pre-production testing finds a failure before release. Runtime inspection handles live input and output. The buyer should ask whether a red-team finding can become a production rule without losing context, which protocols and model providers are supported, and how the control behaves when the inspection service is delayed or unavailable.

Prompt injection deserves a precise test because the attack can arrive directly from a user or indirectly through retrieved content and tool output. The prompt injection glossary should inform the test vocabulary, but the POC must use the buyer's own retrieval and tool paths.

Agents and MCP infrastructure

SentinelOne describes discovering agents and MCP servers, enforcing least-privilege scope, and retaining searchable logs of agent actions and enterprise-system interactions. The linked Prompt Security page is more specific: its MCP Gateway claims request and response inspection, risk scoring, policies by user, server, or action, and real-time blocking.

Those claims put Prompt Security in the agent-security category. They also make control placement the main evaluation question. A gateway can see what crosses the gateway. An endpoint agent can see the actions covered by that integration. Neither phrase proves complete coverage of every host, local tool, subprocess, side channel, or direct server connection.

The current public scope can be represented without implying that one surface proves another:

Matrix comparing Prompt Security's documented workforce AI, homegrown application, and agent and MCP surfaces

The matrix maps documented surfaces; it is not an architecture guarantee. A POC still needs to identify the actual inspection point for each application and agent path.

Where Prompt Security fits, and what remains unproven

A plausible fit

Prompt Security looks most plausible when the buying team owns a broad enterprise AI program. The same security organization may need to find shadow AI, protect source code in employee tools, test an internal assistant, and govern agent-to-MCP interactions. A shared inventory and policy layer can reduce the number of disconnected reviews.

Existing SentinelOne customers may also value operational consolidation. That is a hypothesis to verify, not a guaranteed outcome. The team should ask which AI-security events enter its existing workflows, which licenses are required, and whether analysts can move from an alert to the original user, prompt, application, agent, server, action, and policy decision.

The enterprise AI agent security guide is a useful companion for defining owners, rollout stages, and review cadence. It should not substitute for implementation evidence from the product.

Questions the public pages do not answer

The main limitations are evidence gaps, not proof that a feature is absent.

Unknown fieldWhy it mattersPOC or procurement question
Price and package mappingA capability may sit in a different tier or require another SentinelOne productWhich exact SKU enables workforce, application, agent, and MCP controls, and how is usage metered?
Deployment and data residencySecurity teams need to know which content, metadata, and evidence leave each environmentWhere do inspection, policy evaluation, storage, and model calls run for each surface?
Coverage by integrationA broad platform statement does not identify every observable pathWhich browsers, endpoints, gateways, agent hosts, MCP transports, and direct connections are covered?
Failure behaviorAn unavailable security service can block work or silently remove protectionWhich controls fail open, fail closed, use cached policy, or queue evidence during an outage?
Latency and false positivesA control can be accurate in a demo and disruptive in daily useWhat are p50 and p95 overhead and the review burden on the buyer's own traffic?
Independent efficacyFirst-party feature descriptions do not establish detection qualityWhich fixed attack and benign sets can both vendor and buyer rerun after policy changes?

Public pricing was not visible on the reviewed pages. We also found no independent like-for-like benchmark for Prompt Security and AgentGuard. Treat any sales-deck number as a claim to reproduce, not a result to quote.

Prompt Security or AgentGuard? Follow the control path

Prompt Security alternatives should be chosen by the action and evidence path, not by the longest feature list. Prompt Security and AgentGuard overlap around agent and MCP risk, yet their public documentation gives buyers different starting points.

Choose Prompt Security when

Prompt Security is the more natural first POC when the team needs one documented program across employee AI use, homegrown applications, and agents. Its public pages describe inventory, data controls, application testing, runtime AI-firewall behavior, agent and MCP discovery, policies, and searchable evidence.

That breadth can matter more than developer-local detail. A central security team may prefer to start with estate visibility and policy coverage, then test how deeply each integration reaches. The open question is whether the proposed package and deployment reproduce that breadth in the buyer's environment.

Choose AgentGuard when

AgentGuard is the more direct documented fit when the first requirement is a decision before a supported high-risk developer-agent action. Its public Quickstart includes a deliberate risky-action test, says the guard should pause for approval or refuse the action, and shows the decision, risk score, and reasons in Live Activity.

The same documentation states that policy decisions happen locally, redacted action metadata is synced to Cloud, and offline operation falls back to cached policy or a conservative built-in default. Its API documentation also describes scanning skills, tools, plugins, MCP servers, and agent code before they enter a runtime. These details make the control easier to reason about at implementation time: what is intercepted, when the decision happens, what survives an outage, and what evidence remains.

This is a bounded advantage. AgentGuard says it should not be described as fully monitoring or blocking all third-party MCP runtime calls today. Integration depth varies by host. Buyers should run bypass tests rather than generalize from one supported action.

Buyer priorityPrompt Security public evidenceAgentGuard public evidence
Broad enterprise AI inventoryWorkforce, application, agent, and MCP discovery claimsFocused developer-agent and component surfaces
Local pre-execution decisionEndpoint and policy claims require path-level validationExplicit supported high-risk action decision before execution
Offline policy behaviorNot established in reviewed public pagesCached policy and conservative fallback documented
Pre-runtime component trustMCP risk and discovery claimsScans skills, tools, plugins, MCP servers, and agent code
Reproducible first testBuyer must define it with the vendorQuickstart publishes a deliberate risky-action test and expected evidence

The planned AgentGuard and Prompt Security comparison should eventually hold a deeper field-by-field test record. Until that page is live, keep the decision inside this review rather than linking readers to a 404.

If your POC starts at the developer-agent action boundary, map your agent control path with AgentGuard.

Where both claims need testing

Neither public story proves complete coverage. Prompt Security's broad platform language needs integration, failure, and package verification. AgentGuard's explicit local path needs host-by-host and bypass verification. The right choice may also be layered if the controls operate at different points, but that architecture should emerge from observed traffic and policy ownership, not a generic recommendation to buy both.

A five-test Prompt Security proof of concept

A useful POC starts with pass conditions. Do not begin with a product tour and decide afterward which screenshots look convincing.

Five-test Prompt Security proof-of-concept sequence with a policy-change retest path

Define the pass condition before the demo

TestActionPass conditionEvidence to retain
1. Inventory truthCreate one sanctioned and one unsanctioned AI or MCP pathThe inventory finds both, resolves the owner, and does not merge unrelated assetsAsset IDs, discovery time, identity source, missed-path notes
2. Workforce data handlingSubmit seeded sensitive and benign text through an approved employee AI flowPolicy distinguishes the cases and performs the configured alert, redact, or block actionOriginal test ID, policy version, decision, redaction, analyst record
3. Application attackRun direct and indirect cases from the OWASP prompt-injection guidance through a staging applicationThe control identifies the expected cases without breaking the benign setTest corpus version, request/response, finding, policy, false-positive review
4. Agent and MCP actionAsk an agent to call an allowed read action and a denied write action through each proposed MCP pathThe correct identity and action reach policy before the denied side effect occursAgent, user, server, tool, action, decision time, side-effect proof
5. Failure and evidenceInterrupt the relevant control plane, restore it, then retrieve the incidentBehavior matches the agreed fail policy and the evidence remains queryableOutage timeline, fallback decision, queued events, recovered audit chain

Run the benign set every time the policy changes. A control that blocks the attack but stops ordinary work has not passed. Record latency on the same paths, with the same payload sizes, before and after enforcement.

The final POC review should separate four outcomes: passed, failed, not observed, and out of scope. "Not observed" is not a pass. "Out of scope" is acceptable only when another named control owns the path.

Frequently Asked Questions

Is Prompt Security part of SentinelOne?

Yes. SentinelOne announced the acquisition in August 2025, hosts the current product page, and presents Prompt Security inside its AI security platform. Buyers should confirm which capabilities are in the current commercial package rather than rely on pre-acquisition descriptions.

Is Prompt Security pricing public?

We did not verify a public price table or complete package map on the reviewed current pages. Ask for SKU names, minimum commitments, usage meters, required SentinelOne products, implementation services, and renewal terms. Keep the field unknown until those numbers are in the proposal.

Does Prompt Security stop prompt injection?

The current SentinelOne page says the product tests for prompt injection before deployment and can block adversarial prompts at runtime. That is a first-party capability claim, not an independent efficacy result. Test direct and indirect attacks against the buyer's own application, retrieval, tool, and agent paths.

When is AgentGuard the better alternative?

AgentGuard is the stronger documented candidate when the buyer prioritizes supported local pre-execution action decisions, an explicit risky-action test, cached offline policy behavior, and component scanning before runtime. It is not a universal replacement for Prompt Security's broader workforce and application claims, and it does not claim complete third-party MCP runtime coverage.

What should a Prompt Security POC prove?

It should prove asset discovery, identity resolution, data policy behavior, application attack handling, agent and MCP action enforcement, failure behavior, latency, false-positive burden, and audit retrieval. The result should name every uncovered path and the control that owns it.

Test each AI control at the action boundary before choosing a platform.

Book demo

Related

Continue exploring