Prompt injection protection for documents

unmaskdoc

trust yourself

Indirect prompt injection is the number one risk for LLM applications according to OWASP. A single CV, invoice or contract with an invisible instruction is enough to make an AI assistant change a rating, leak data or take an unauthorised action. unmaskdoc verifies every document before it reaches the model.

The file is not stored and is never sent to any LLM or third-party cloud. The scan takes seconds on our EU server, then the file is deleted. Limit: 10 scans per day.

Why unmaskdoc

Two layers of verification in one scan.

LAYER 1 · WHERE

Document structure

We read PDF and Word as files, not as text. We see white text, microscopic fonts, text outside the page, metadata, comments, footers, JavaScript and attachments.

+
LAYER 2 · WHAT

Instruction content

We recognise instructions aimed at AI in 10 languages, including encoded (base64, hex), split into fragments and disguised with look-alike letters.

Document scanners detect hidden text but do not assess what it says. Prompt injection filters analyse the content but cannot see that it was hidden from people. unmaskdoc combines both analyses in a single pass: it matches how text is hidden with what it intends, and points to every hidden instruction together with its exact position in the document.

Private by design

The document never reaches any LLM. A deterministic engine on an EU server scans it and deletes it immediately. Only its SHA-256 hash remains.

Also on your premises, offline

The same engine as a Docker container on your server. For law firms, HR and companies whose documents must not leave their network.

No false alarms

White letters on a navy CV sidebar, OCR scans and ZUGFeRD e-invoices pass cleanly. An alarm only where something was hidden.

Explains every decision

Not “87% risk”, but specifics: what, where and why. The same file always gives the same result.

Built for LLM pipelines

An API in front of the model in RAG, agents and n8n automations. Works as the first layer before other security filters.

Fail-closed

If something cannot be checked, you get “unknown”, not “clean”. Nothing passes by accident.

Pricing

Start free. Pay when you scan more.

START Launch offer: -50% for the first 3 months for the first 50 companies. Annual billing: -20%.

Free

0 €

For checking single files

  • 10 scans per day
  • Browser scanner
  • Both profiles: documents and recruiting
Scan now

Team

79 € / month

For agencies and teams

  • 25,000 scans per month
  • Multiple API keys
  • Audit logs
  • Priority support
Join early access

On-premise

from 3 000 € / year

For law firms, HR and sensitive data

  • Docker container on your side
  • Works offline
  • Rule updates
  • Deployment support
Let's talk

Net prices. VAT invoice for EU businesses.