Secra sits between your agents and the LLM. Catches prompt injection, persona hijacking, and data exfiltration in real time - before damage occurs.
No credit card required · Free forever plan
Security + Era — Secra was founded when prompt injection and AI-native attacks made a new layer of defence inevitable.
——Purpose-built for AI teams who need security without the overhead.
O(n) multi-pattern matching in a single pass. Catches 30+ injection signatures in under 1ms. The best part? Zero LLM calls. Zero tokens charged. Blocks fire completely free.
Pre-processor → Rule engine → Groq LLM. Each layer only fires when the previous one is uncertain. Costs stay near zero for obvious attacks.
Generate sk_secra_ scoped keys shown once, bcrypt-hashed at rest. Drop them into any HTTP client and you're protected.
Don't just block — rewrite. Secra strips injection payloads and returns a clean prompt your LLM can safely process. Get protection without breaking your flow.
Validate LLM-generated tool calls before execution. Stops function-injection attacks that target your agent's action layer.
Real-time logs of every scanned prompt, verdict, threat category, and token spend. Understand your attack surface.
Each layer only activates when the previous one is uncertain — keeping token costs near zero for obvious attacks.
Install the SDK, grab your free key, and start blocking attacks before your first LLM call.
One endpoint to protect your agent. Full SDK wrappers for Python and JavaScript.
/v1/scan1× wordsScan a prompt through 3 layers — Aho-Corasick, rules, and LLM. Returns a BLOCK / REVIEW / ALLOW decision with threat type and score.
/v1/sanitize2× wordsStrip injection patterns from a dirty prompt. Returns a clean version safe to pass to your LLM, with a diff of what was removed.
/v1/scan-content1× wordsScan web pages or documents for indirect injection before injecting them into your agent's context window.
/v1/validate-tool50 flatValidate an agent tool call before execution. Catches destructive shell commands, path traversal, and network exfiltration.
/v1/usage/balanceFreeCheck your token balance, plan name, and days until next reset. Zero tokens consumed.
/v1/usage/historyFreeFull scan history with metadata. Raw prompts are never stored — only SHA-256 hashes for audit trails.
Pay for what you scan. Tokens reset monthly. No seat fees, no setup costs.