Arcjet is the runtime security platform that ships in your AI code. Detect prompt injection, authorize agent tool calls, redact sensitive data, and block bots and abuse. Real-time security building blocks you call inside your app, before an action happens.
Cloudflare is great, but it requires you to force users through them, which is normally fine except in hindsight. Also, the rules engine is a bit better inside of ArcJet and can be managed from code within the project or with their MCP.
Their new agent runtime security platform is a must-have for engineering teams to enforce policy the moment an AI agent acts, and keep the evidence to prove what happened and why. Detect prompt injection, authorize agent tool calls, block bots and abuse. It's available now.
Start for free with this prompt or follow the quickstart to protect your first agent tool and LLM calls:
1. Run: npx skills add arcjet/skills
2. Add Arcjet protection to my app
Curious to know what the community thinks about security these days.
Report
Congrats on the launch! How out-of-the-box is the implementation and later use?
@denis_prodan Pretty out-of-the-box. You can add Arcjet to an existing app with a small SDK integration, and it starts observing whatβs happening without requiring you to deploy or rebuild your agents. From there, you can layer in policies as needed (prompt injection, sensitive data, rate limits, tool/API actions, etc.) and move from observe to enforce when youβre ready.
this π and you can find an exhaustive list of supported coding agents, AI agent frameworks and SDKs in this get started guide: https://docs.arcjet.com/get-started
@denis_prodanΒ You can implement Arcjet manually - we have language SDKs e.g. JS, Python, Go, as well as direct integrations to AI agent frameworks like Eve, Mastra, LangChain, Google ADK, Claude Managed Agents. But most of our users just install the skill with `npx skills add arcjet/skills` and have their agent implement it!
Congrats on the launch to the Arcjet team! Can teams use custom security policies or call an external decision service at a specific authorization step?
@mathsocietyΒ Arcjet security policies can be implemented in code or via remote OPA/Rego policies. In-code means your dev team can manage the policies alongside the code & actions being taken. Great if you want to integrate security into your dev lifecycle, but often this is where security teams prefer to manage policies separately. Arcjet enables that as well - Open Policy Agent / Rego policies that can be created and modified instantly through the Arcjet cloud platform (web, API, MCP, CLI). And you can use both together as well.
@yangliu44Β Yes, Arcjet is focused on AI agent observability, which is necessary for enforcement. We're not trying to replace general observability tools e.g. agent traces, so we work alongside any existing tools you already use.
@malandinΒ It's up to you which data (if any) you use as part of the inputs/analysis. PII detection is the policy most likely to interact with your data, where we use an ML model that runs in-process (p50 6ms latency) so the data never leaves your environment.
Report
Does it add much latency when you check for prompt injection before every action?
@manonbriffautΒ It depends on the policies you have configured. We run our own models for prompt injection detection so that can take around 100ms to complete the analysis, but for PII detection the p50 is 6ms, and for tool guards it's less than 1ms.
Report
How much latency is introduced by these checks on the request path, particularly for the agent flows which require multiple checks? Btw, Congratulations @davidmytton@cassie_arcjet & Team. πβοΈ
Thanks @aymi_malikΒ ! The latency varies based on your policy settings. Our prompt injection detection takes about 100ms, while PII detection has a median latency of 6ms, and tool guards take under 1ms
Thanks, Matt - glad it's working well for you!