SentinelProxy
Tom Phillips Labs

Catch what your AI agents get wrong — and ship the fix.

SentinelProxy is the self-healing security layer for AI agents. It watches your traffic, flags the hallucinations, prompt injections and PII leaks a firewall can't see, and hands back a hardened system prompt— proven against your real traffic, off your critical path.

HallucinationsPrompt injectionPII leaksCompetitor mentions
Works with n8n · LangChain · LiteLLM · Dify·UK-hosted · GDPR-minimised
Free · no sign-up

How breakable is your prompt?

Paste a system prompt for an instant vulnerability check, and copy a hardened rewrite. Want the real thing? Logged-in projects get the full Claude-powered attack battery run against your live agent.

PromptBreaker

Plants a secret canary in your prompt, then fires extraction attacks at it. An attack cracks the prompt if the agent leaks the canary.

How it works

Detect, prove, heal — one loop

Point your agent at one webhook. SentinelProxy grades every call, proves a fix against the whole failure class, and hands it back — confirmed against your live traffic before you adopt it.

01 · Ingest

Logs in, instantly

Point your Dify / n8n / LangChain / LiteLLM agent at one webhook. We return 200 immediately and scrub PII at the edge — never on your critical path.

02 · Diagnose

A judge that reads every call

Claude grades each exchange against your guardrails — hallucination, prompt injection, PII leakage, competitor mentions.

03 · Heal

A patch, not just a block

Get a copy-paste system-prompt fix — proven against the failing case and the whole failure class, then confirmed against production traffic.

New · Prevention mode

Don't just catch it — stop it

The mirror tells you what broke. Switch on the inline gateway and SentinelProxy steps onto the critical path: your workflow calls it and waits for an allow · block · rewritedecision — a real-time WAF for your agent.

Mirror · always on

“We told you it broke”

Asynchronous, off your critical path. Every call graded and healed in the background — full visibility, zero added latency.

Gateway · opt-in

“We stopped it”

Synchronous. Block a prompt-injection before the model sees it, or redact PII out of a response before your user does. Per-rule, in real time.

Monitor first

Shadow mode shows what it would have blocked before you enforce anything.

Opt-in per guardrail

Enforce the rules you trust; the rest keep just watching.

Fails open

On a timeout or error, traffic passes through — never your point of failure.

Turn on the gatewayCall it from n8n, Dify or any HTTP step · monitor on Pro, blocking on Team.
Works with your stack

Installable plugins, not just a webhook

Native integrations for every major agent platform — install the package or node, point it at your project, and the self-healing loop starts. Each is a thin, open-source wrapper around one ingest call, so there's nothing to maintain.

n8nCommunity node

Install the SentinelProxy node from Community Nodes, add the credential, and drop it after any LLM or AI Agent step.

n8n-nodes-sentinelproxy

Settings → Community Nodes → Install

LangChainPython & JS

One callback handler logs every chain call. Pass it in the callbacks array — nothing else changes.

pip install sentinelproxy

or npm i sentinelproxy-langchain

LiteLLMPython

Register one success callback and every completion — across any provider LiteLLM proxies — is mirrored.

pip install sentinelproxy

litellm.success_callback = [...]

DifyMarketplace plugin

Add the native SentinelProxy node from the Dify Marketplace — no code, drop it into any Chatflow or Workflow.

Marketplace → SentinelProxy

Log Agent Turn node

On something else? Any stack that can POST JSON works via the universal webhook — copy-paste snippets are in every project's Connect tab.

Bring your own key · save 25%

Use your own Claude key, manage your own cost

Plug in your own Anthropic API key and every evaluation, fix and red-team bills to your account — not ours. You get 25% off your plan, uncapped evaluations, your data flowing through your own Anthropic contract, and your choice of judge model (Haiku, Sonnet or Opus). Toggle it on or off any time — your key is stored encrypted and never leaves the server.

Pricing

Start free, scale when you ship

Every plan includes the full detection → self-heal → prove-the-fix loop and configurable guardrails. Paid plans unlock batch pattern-healing, the PromptBreaker red-team and bring-your-own-key. Tiers differ on projects, log retention and monthly evaluations — bring your own Claude key on any paid plan for 25% off and uncapped evaluations.

Free
Free

Kick the tyres on one agent.

  • 1 project
  • 500 evaluations / month
  • 3-day log retention
  • Detection, self-healed prompts & prove-the-fix
  • Configurable guardrails
Start free
ProPopular
£39/mo

For indie & mid-market builders.

  • 5 projects
  • 20,000 evaluations / month
  • 30-day log retention
  • Batch pattern-healing
  • PromptBreaker red-team
  • Inline gateway — monitor mode
  • Bring your own key (−25%, uncapped)
  • Email support
Choose Pro
Team
£149/mo

For agencies & platform teams.

  • 20 projects
  • 100,000 evaluations / month
  • 90-day log retention
  • Everything in Pro
  • Inline gateway — block & rewrite
  • Priority support
Choose Team
Enterprise
Custom

Volume, governance & SLAs.

  • Unlimited projects
  • Unlimited evaluations
  • Inline gateway — full prevention
  • Custom retention
  • SSO, DPA & data-processing terms
  • Self-host option · SLA
Contact sales

Prices exclude VAT. Self-serve checkout is rolling out — paid plans are activated on request today; email tom@tomphillips.uk.

Stop patching prompts by hand.

Create a project, drop one webhook into your agent, and let the self-healing loop do the tedious part.

Get started free