Public beta/Seats limited to first 2,000 teams
Prompt privacy, solved

Encryptevery
prompt.
Shipwithout
leaking IP.

CIPHERBLOCK is the zero-knowledge privacy layer between your prompts and every LLM. Your instructions stay encrypted — end to end, in flight, and at rest.

AES-256 · Zero-knowledge

Plaintext (local)

Summarize our Q4 revenue strategy

encrypt

Ciphertext (wire)

▓▒░█▓▒░█▓▒░█

SOC 2 Type II Zero-knowledge Sub-10ms overhead

Trusted by 2,400+ AI-native teams

from seed to Series D

NORTHWINDLAYEREDHELIOFOUNDRYKOSMOSPROTOCOLOBLIQUERADIXMERIDIANCIPHERONQUORUMAETHERNORTHWINDLAYEREDHELIOFOUNDRYKOSMOSPROTOCOLOBLIQUERADIXMERIDIANCIPHERONQUORUMAETHER

01 / The problem

Your prompts are already your product.

Every system prompt, retrieval chain, and tool schema is a trade secret in plaintext. And every LLM provider logs, caches, or trains on something. The question isn't if your prompts leak — it's when.

73%

of enterprise AI features

leak prompts through third-party logs, fine-tuning datasets, or cached completions.

1 in 4

engineers admit

to pasting customer PII or proprietary code into an LLM without redaction.

$4.6M

avg. breach cost

for AI-adjacent incidents in 2025 — up 31% YoY per IBM Cost of a Breach.

At risk

System prompts

Logged by providers

At risk

User PII

Echoed in completions

At risk

Tool schemas

Scraped via jailbreaks

At risk

Retrieval context

Cached in CDNs

02 / How it works

Three lines of code.
Zero lines of plaintext.

Try it live

STEP / 01

Drop-in SDK

Wrap.

Install cipherblock in 30 seconds. We wrap your existing fetch to OpenAI, Anthropic, Mistral, or any OpenAI-compatible endpoint.

import { wrap } from "cipherblock"
const openai = wrap(new OpenAI())

STEP / 02

Zero-knowledge

Encrypt.

Sensitive tokens are encrypted with AES-256-GCM on your device using keys we never see. Public tokens pass through for model reasoning.

// auto-detected & encrypted:
// {customer_email}, {revenue}, {secret_sauce}

STEP / 03

One wire format

Route.

Ciphertext routes to any LLM. Responses are decrypted locally so only your app sees plaintext. Works with streaming, tools, and RAG.

const res = await openai.chat.complete(
  // response decrypted client-side
)

Promise • no change to model output

Same quality. Private by default.

Install SDK

03 / Toolkit

Everything you need.
Nothing you don't.

Built for the way modern teams ship AI — from prototype to production, with a security posture your CISO will actually sign.

Zero-knowledge keys

Keys that even we can't see.

Envelope encryption with per-workspace master keys in AWS KMS, GCP KMS, or your own HSM. We operate the ciphertext; you operate the trust.

key: workspace.master

alg: AES-256-GCM

kms: aws/kms:us-east-1

$ cipherblock rotate --workspace=prod

Auto-redact

PII detection in 19 languages.

Emails, card numbers, SSNs, IP, and free-form secrets get flagged and tokenized before they ever touch a model.

Any model

OpenAI, Claude, Gemini, Llama, or your own.

One SDK. 40+ providers. Switch with an env var.

Policy engine

Rules in YAML. Enforcement in ms.

allow / deny / redact by role, region, model, or cost.

Real-time audit

Every call, every token, every time.

Signed, append-only audit logs streamed to your SIEM. Stripe-quality observability for your prompt layer.

99.99%

uptime SLA

8.2ms

p50 overhead

7 yr

log retention

Deploy anywhere

Cloud, edge, or air-gapped. Your call.

Hosted SaaS with SOC 2 Type II, single-tenant VPC, or fully on-prem Helm chart for regulated workloads.

HostedVPCOn-premEdge (Vercel, Cloudflare)
Incl.

Streaming-safe

Token-level encryption for SSE

Incl.

Tool-call aware

Preserves JSON schemas

Incl.

Semantic cache

Private hit/miss matching

Incl.

Cost guardrails

Per-prompt spend limits

04 / Playground

Try it.
Right here.

Paste any prompt. Watch auto-redaction mark PII, then see the wire-format ciphertext your LLM actually receives. Nothing leaves your browser in this demo.

Plaintext / local

Auto-redact · detected 3

emailcardphone
Refund customer ⟨EMAIL⟩ on card ⟨CARD⟩for order #A-2219. Notify her at ⟨PHONE⟩.

Ciphertext / wire

What your LLM provider sees

∷▓▫⟩⟩∎ ◆⟨◉◈▫⟪⟩⟫ ░▓░▓◈⟪⟪∷◉░⟨∷∎◯█◆∎ ▪⟪ ◉█∎░ ◆▫◯◆ ▓▪⟫█ ◎◈⟪░ ◉◇⟩▒ ⟫⟩◆ ◯▪▓▫∷ ◎▓◇◎◈⟩∎◇ ◯▒⟪∎⟪█ ▓◆◈ █⟨ ◯▒⟩⟨▫◯◆█⟪█⟩░█
108 chars in · 108 out · key #7

AES-256

cipher

GCM

mode

256b

key len

Demo uses a visual substitution cipher. Production uses AES-256-GCM with envelope keys in your KMS.

05 / Pricing

Priced like infra.
Not like SaaS.

Start free forever. Scale when you ship. No seat taxes, no surprise overages, no sales call to upgrade.

MonthlyYearly−17%

Hobby

For building & testing

$0/ mo
  • 10,000 tokens / mo encrypted
  • 2 models, 1 workspace
  • Community Discord
  • PII auto-redact (EN)
Start free

Pro

For shipping teams

$24/ mo

billed annually · $288/yr

  • 10M tokens / mo encrypted
  • Unlimited models & workspaces
  • All 19 PII languages
  • Policy engine (YAML)
  • Audit logs → your SIEM
  • 99.9% SLA · email support
Start 14-day trial

No card · cancel anytime

Enterprise

For regulated workloads

Custom
  • Unlimited encryption volume
  • Single-tenant VPC or on-prem
  • BYO KMS / HSM
  • SOC 2 Type II · HIPAA · DPA
  • 99.99% SLA · 24/7 support
  • Dedicated solutions engineer
Talk to sales

30-day money-back guarantee. If CIPHERBLOCK doesn't reduce your prompt-leak surface by 10×, we'll refund you.

SOC 2 Type IIGDPRHIPAA-readyPCI DSS

06 / Receipts

Loved by the teams
shipping the hardest AI.

4.9

G2 rating

127

reviews

We had three months of security review before our GPT feature could ship. CIPHERBLOCK took that to three days. Legal signed on a Friday.

Maya Okafor

Head of AI, Northwind

Zero-knowledge was table stakes for our hospital customers. CIPHERBLOCK is the only layer we found that doesn’t ask us to trust a vendor with plaintext.

Jordan Reyes

Staff Eng · HeliosHealth

Drop-in SDK, sub-10ms overhead, and the audit log is prettier than our Stripe dashboard. This is how infra should feel.

Samir Patel

CTO · Layered AI

We switched from a homegrown proxy to CIPHERBLOCK in an afternoon. Reduced our prompt-leak surface to zero without changing a single app-layer call.

Elena Vogt

Principal Architect · Kosmos

07 / Questions

The usual
suspects.

Yes. Master keys live in your KMS (AWS/GCP/Azure) or on-prem HSM. Our services only ever see ciphertext. We publish open-source attestation tooling so you can verify this claim on every release.

Median overhead is 8.2ms p50, 22ms p99. For streaming responses, encryption happens per token so users see no perceptible lag. We run global edge points in 19 regions.

OpenAI, Anthropic, Google (Gemini & Vertex), Mistral, Cohere, Groq, Together, Fireworks, AWS Bedrock, and anything with an OpenAI-compatible endpoint. SDKs for TypeScript, Python, Go, and Rust. Plugins for LangChain, LlamaIndex, and the Vercel AI SDK.

Yes. The Enterprise tier ships as a Helm chart with no external network dependency. Many of our regulated customers (health, finance, public sector) run fully air-gapped.

Nothing. Only sensitive entities are tokenized — the model reasons over placeholder tokens that preserve grammatical role. In our benchmarks, task quality is statistically identical to unencrypted baselines.

Per encrypted token, billed monthly. Hobby is free forever up to 10K tokens. Pro gives you 10M tokens + all features. No seats, no per-user fees, no overage traps — you get a hard spend cap.

Yes, on Enterprise. You own the keys, the logs, and the policy engine. We provide the same SDKs and a terraform module for air-gapped clouds.

Still curious? Chat with an engineer → book a 15-minute call.

08 / Ship it

Your prompts,
in lockdown.

Get early-access pricing, 10K tokens free every month, and a pair-programming session with our founding engineer. No card, no call required.

Free forever tier · 30-day money-back · cancel anytime

01

install SDK

02

wrap fetch

03

ship safe

Enterprise

Book a private demo

VPC · on-prem · HIPAA · 24/7 SE