Note /
What prompt injection is
It is the risk that makes an agent a different proposition from a chatbot. It appears by name on our published exclusion list, so it is worth being exact about what it is and what we do and do not claim about it.
What it is
An agent does its job by reading things. A support ticket, an email in a shared inbox, a document somebody attached, a record in the CRM it was connected to. Prompt injection is when the text it reads contains instructions and the agent acts on them as instructions rather than handling them as content. The attempt does not have to be clever or technical. It can be a sentence written into a ticket, addressed to whatever is reading the ticket, asking it to do something other than its job.
Why it matters more once software can act
A system that only answers, if it is misled, has given a wrong answer to somebody who can weigh it. An agent that is misled has done something, inside a system you keep records in. That difference is the whole reason hardening is the product here rather than an upgrade offered later.
What the default posture does about it
Two of the shipped defaults carry the weight, and neither of them is specific to injection. Least privilege means an agent reaches the tools its job needs and nothing else, so an instruction to go and touch something outside that set finds nothing to act on. Human sign-off means actions with consequences wait for a person, so an injected instruction that does reach a consequential action still has to get past somebody who was not expecting it. Training and guidance come with every install, and the posture your deployment runs under is written into the handover document you sign, so what an agent may do unsupervised is a decision you made rather than one you find out about. Stated from the other end, a deployment somebody wants run with the guardrails off is refused outright, at any price.
What we do not claim
We do not claim to have solved this. Nowhere on this site will you find a promise that injection is prevented or reliably detected, and that absence is deliberate rather than an oversight. Agentic systems carry residual risk. What the posture does is limit how far an injected instruction can get, and put a person in front of the actions that carry consequences. That is a smaller claim than safety, and a true one.
Where the line sits, in writing
Consequences of prompt injection or social engineering after handover, where the security posture was signed off, rest with you. That sentence is on the exclusion list published on the pricing page, not in small print you meet after something has gone wrong. Our obligation is hardening to the posture you agreed plus the training and guidance around it. Yours is how the agents get used once they are running on your infrastructure. Publishing that before you buy is the only version of it we consider honest.
If you are already running a framework
If something is already running in your business, the useful question is what it can be talked into doing. A standalone security audit of an existing agent deployment is on the add-on menu at $700, and it does not require you to have bought anything else from us.