Independent reference. We are independent of every vendor listed. No affiliate links. No sponsored placements.
FAQ

Frequently Asked Questions

Ten common questions about prompt-injection vendor pricing, quote-only reality, OWASP coverage and TCO.

10
Questions
JSON-LD
FAQPage schema
2026-06
Last verified
20
Vendors referenced

All questions

What is the cheapest published prompt-injection guardrail rate in 2026?

AWS Bedrock Guardrails publishes $0.08 per 1,000 text units for the prompt-attack filter, verified June 2026. Other Bedrock filter scopes (content, sensitive info, denied topics) cost more per 1K.

Why are so many AI security vendors quote-only?

Eleven of the twenty vendors we track publish no public list price. Vendors prefer this because it lets them price-discriminate and bundle inside platform deals. It is bad for buyers because you cannot build a board paper from a contact-sales page.

Do you publish any quote-only vendor rates?

No. We will not infer a number we cannot source. Quote-only vendors get a Quote Only badge on every page they appear on; the only number we link to is the vendor's request form.

Is OWASP LLM Top 10 a real standard?

Yes. The 2025 edition lives at genai.owasp.org/llm-top-10/ and is the canonical LLM-attack taxonomy. We map every vendor on the site to its OWASP coverage.

What is the OWASP LLM01 ranking?

LLM01 is the number-one ranked risk for LLM applications and is prompt injection. Both direct and indirect variants are in scope.

How much should a small org spend on prompt-injection defence?

Under 50 seats with one or two LLM features, a free tier path plus 0.1 FTE engineering is typically enough. Around $25-30K per year all-in, mostly the FTE.

What does an AI red team engagement cost?

Vendors do not publish red-team engagement rates, so we cannot state a market figure. For illustrative year-1 budgeting we model a $25-75K band (midpoint $40K) composed from publicly-discussed engagement sizes, not a survey average. Continuous red-team subscriptions are quote-only.

Is the EU AI Act in force?

Yes. Regulation (EU) 2024/1689 entered into force in August 2024. Different obligations apply at different staged dates; the general-purpose AI rules begin to apply in August 2026.

Does open source defend against prompt injection for free?

License-free, yes. NeMo Guardrails, Garak and Guardrails AI are all Apache 2.0; Promptfoo is MIT. All four are permissive open-source licences. The FTE, infra and on-call costs to operate them are real and usually wipe out the saving above 1,000 LLM calls per minute.

What is the Lakera Check Point relationship in 2026?

Check Point acquired Lakera in a deal announced in September 2025 and reported at around $300 million. Lakera's Zurich headquarters becomes Check Point's Global Center of Excellence for AI Security. Lakera Guard, Lakera Red and the free Lakera Community tier remain available on the Lakera platform.

Last verified June 2026Source: vendor pricing pages. See /methodology.