features
What you can block, and how it is controlled
Stop PII, PHI, and PCI before it leaves
Catch sensitive data in a prompt, a response, or a tool call, and block it in real time. Set the rules once and apply them across every agent, so customer records, health data, and card data do not slip out.
Refuse the injected instruction
Detect prompt injection in untrusted input and stop the agent from acting on it. It does not follow a hidden instruction to exfiltrate data or call a tool it should not, because the action is checked before it runs.
Keep agents on the approved path
Block tool misuse and off-path actions. Allow intended actions to proceed while denying risky ones, such as account changes without consent or payment actions over the policy limit.
One control plane for every agent
Get a centralized, framework-agnostic control plane with deny-wins semantics, so the most restrictive decision blocks. It is open source, works with any agent framework, and runs on Luna. Every decision is logged for audit.