REPORTLeader in public prompt-injection benchmarks#1 in public benchmarks

Drop‑in defense for your AI agent.

Gate sits between your agent and the model, screening every request for attacks and leaks. Cuts your token spend automatically, and configures in minutes.

Setup in minutes One endpoint, every model
Coding Agents
Claude Code
Cursor
OpenClaw
Codex
OpenCode
GATE
Redacted · PIIada@company.com
Blocked · Injection"Ignore previous instructions…"
Flagged · SecretAWS_SECRET_KEY=AKIA…
Compressed · 1,247 tokens4 transforms · −38% prompt
Model APIs
Anthropic
OpenAI
Google
xAI
OpenRouter
→ outboundinspected inline← inbound

Keep your Claude Code or ChatGPT subscription.

Or run hundreds of models directly through Gate.

Threats → defense

Three real risks.
One inline gateway.

Relying on the model to defend itself will never be enough. Gate blocks attacks before they reach the model.

OWASP LLM #1 · 2025

Prompt injection

One line of attacker text can override your system prompt — exfiltrating data, calling tools, or hijacking the conversation.

Blocked before the model sees it.

Secrets · PII

Credential & PII leakage

A customer's SSN, an API key, an internal note — one wrong response is all it takes to send a secret somewhere it shouldn't be.

Redacted before the response returns.

Indirect injection

Hijacked tool calls

Your agent trusts whatever its tools return. An attacker-controlled webpage, ticket, or doc becomes its next set of orders.

Stopped before your agent acts.

How Gate responds

Defense on every request, in both directions.

01 — Connect

A drop-in proxy for the model API.

Gate accepts the same calls your agent already makes and forwards them to the model.

02 — Inspect

Gate scans every call and every response.

Checked in either direction for injection attempts, credential leaks, and PII.

03 — Decide

You write the policy.

Gate enforces it inline: blocking attacks, redacting secrets, flagging the rest, and sealing every decision to a tamper-evident audit log.


Benchmarks

97.4%

F1 across 16 public prompt-injection benchmarks
ranked #1 on 8 of them · 1% FPR

Leading public benchmarks. Enterprise grade without the enterprise.

Across 16 cited prompt-injection benchmarks, Gate leads the pack on overall performance. Head-to-head against the leading enterprise vendor, Gate averages 96.6% F1 versus 83.7%. Read the methodology, the data, and every per-benchmark score in the report.

Average F1, matched FPR higher is better

across 4 public benchmarks with published head-to-head F1

Gate
96.6%
Lakera Guard
83.7%
Gate ahead by +12.9 pts

Mean F1 across deepset, gentel-jailbreaking, gentel-goal-hijacking, and gentel-prompt-leaking, with Gate re-tuned to the competitor's published FPR per dataset. Source: Gate AI Prompt Injection Benchmark report, May 26, 2026.


Cost

Save tokens with every request.
Save 20%+.

Gate applies compression and caching to your requests, saving you tokens without changing model outputs. Most users can expect 20% savings or more, without changing workflows.

Request compression

Gate's lossless, cache-aware compression shrinks every outbound prompt without changing what the model sees. Same response back, fewer tokens billed.

−20%+ tokens per request

Prompt-cache injection

Gate marks reusable prefixes such as system, tools, and history so upstream providers bill them at the discounted cached rate. Works across any provider with a prompt cache.

2–10× cheaper on the cached prefix

Private beta

Be early.

Leave your email and we'll send you an invite when space opens up.


Audit trail

Every action, on an immutable audit trail.

Every prompt, reply, and rule decision Gate handles is written to a blockchain-backed audit trail and anchored to Constellation Digital Evidence. Independently verifiable by anyone, without going through Gate.

Immutable on write. Each entry is cryptographically chained to the one before it and anchored on-chain. Nothing can be quietly altered after the fact — not by your team, not by us.

Independently verifiable. Hand a single record to an auditor, regulator, or counterparty. They confirm it against the Digital Evidence record themselves. Zero trust required.

Built to outlast us. The proofs live on Constellation's Digital Evidence layer, not on our servers. If we disappear tomorrow, your audit trail stays verifiable.

Learn about Digital Evidence →
Audit trail · agent_42 Verified
15:42:08 Prompt scanned · cleanmodel: claude-sonnet-4-6 · 1,204 tokens 9a3f…c014
15:42:11 Injection blocked · indirect (tool output)rule: r/exfiltration · severity: high e1c2…b8d7
15:42:14 Reply scanned · 2 secrets redactedapi_key, access_token 7f12…0a5e
15:42:14 Anchored to Digital Evidencebatch #12,402 · block 4,891,205 root b04c…

Get going

From signup to first scanned request, in under a minute.

Connect the AI tools you already use, then keep your provider or pay as you go. One endpoint, every model. Same scanning and audit trail either way.

01 How you connect

FOR DEVELOPERS

Change one line.

Point your existing SDK at Gate. Same code, same provider key, same response shape. Every request is now scanned and audited.

# Point your existing SDK at the gateway.
# No other code changes.

from openai import OpenAI

client = OpenAI(
  base_url="https://gate.constellationgate.ai/v1",
  api_key=os.getenv("GATE_API_KEY"),
)

02 How you pay

Bring your own keys.

Already have an Anthropic, OpenAI, or another provider account? Keep paying them directly. Gate adds the security inspection, redaction, and audit trail on top. The model side stays exactly as it was.

Anthropic OpenAI Gemini Grok

Your provider, your bill. Gate adds security and audit on top.

Pay as you go.

No provider account, no contracts. Top up a balance with Gate and run any model from a single endpoint. Frontier closed-source and the best open-source models, side by side.

Claude Sonnet 4.6 Claude Opus 4.7 GPT-5 Gemini 2.5 Pro Grok 4 Llama 4 405B Mistral Large 3 Qwen3 Max DeepSeek V3.2

+ hundreds more · frontier and open-source · one endpoint

Made it this far? Grab a beta seat →