Lakera
Also known as: Lakera Guard
AI security platform, now owned by Check Point, that screens prompts, responses and agent conversations at runtime against configurable guardrails and red teams the customer's models and agents with scored attacks that can gate releases in CI/CD.
Lakera, now owned by Check Point, sells two AI security products: AI Guardrails (formerly Lakera Guard), which screens AI traffic at runtime, and AI Red Teaming, which attacks a customer's models and agents before and after launch. Check Point announced the acquisition in September 2025. The lakera.ai site and its free sign-up still carry the Lakera name, while the documentation now presents the products as Check Point's.
AI Guardrails sits beside an application's models and agents: the application sends prompts, responses, retrieved content and agent conversations to the Guard API, which checks them against the guardrails in a project's policy, such as prompt defense, content moderation, data leakage prevention, malicious links, agent behavior defense, audio defense, custom guardrails and allow and deny lists.
The dashboard logs each screening request with its content and results, admins control logging, retention and SIEM export, and processing can be pinned to US, EU or Singapore endpoints or self-hosted on Kubernetes, Docker or air-gapped infrastructure. AI Red Teaming runs attack objectives against a target model or agent, scores each result, and can gate releases in CI/CD through its SDK.
Lakera fits security teams protecting customer-facing AI applications and agents, and teams that want to test those systems before shipping. It is a security layer, not an agent builder: it does not run workflows, ground agents in knowledge, give them memory or connect them to business systems.
Vendor details
Canonical URL
https://www.lakera.ai
Category
Agent infrastructure
Subcategory
AI security and red teaming
Funding status
Acquired by Check Point Software Technologies (NASDAQ: CHKP), in a deal announced in September 2025.
Company status
acquired
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Applications call the Guard API alongside their own models to screen prompts, responses, retrieved content and agent conversations, choosing a processing region by endpoint; AI Red Teaming reaches a customer's model or agent through built-in model connectors or a custom API wrapper and runs in CI/CD through its SDK. Agent platforms connect for discovery and risk assessment, and Enterprise logs export to SIEMs.
In practice
Your customer-facing chatbot can be tricked into leaking system prompts or PII. You send its traffic to the Guard API with a policy that blocks prompt injection and data leakage, and every screening lands in the dashboard log.
Before launching an agent with tool access, you need to know how it can be exploited. AI Red Teaming runs scored attacks against it, and a CI/CD gate blocks the release if any attack succeeds.
Your data must stay in the EU. You send screening requests to the EU endpoint and keep logs in the EU region, or self-host AI Guardrails in your own cluster.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Partial |
|---|---|
|
Lakera connects to agent platforms to discover agents and assess their risk, and it screens traffic through the Guard API. For red teaming it reaches customer agents through custom API wrappers, and it exports logs to SIEMs. All of this brings traffic in for screening and testing; no connector lets an agent take authenticated action in an outside system through Lakera. SourceLakera (Check Point), docs.lakera.ai llms.txt (connecting agent platforms, integration guide, Red custom API formats)read 2026-09-25 |
|
| Workflow Orchestration | Not documented |
|
The customer's agents run in their own frameworks, which own the steps and handoffs; Lakera screens and tests those agents without running their work. Red team scans are attack runs against a target, not agent work in several steps that the customer builds, and no workflow model is documented. SourceLakera (Check Point), docs.lakera.ai llms.txtread 2026-09-25 |
|
| Knowledge Grounding & RAG | Not documented |
|
Retrieved documents are screened for threats, but none of the customer's documents are indexed for an agent to ground its answers on, so there is no retrieval structure over the customer's corpus. SourceLakera (Check Point), docs.lakera.ai llms.txtread 2026-09-25 |
|
| Human Oversight & Guardrails | Full |
|
AI Guardrails screens prompts, responses and agent conversations inline against guardrails the customer sets in policies for each project: prompt defense, content moderation, data leakage prevention, malicious link detection, agent behavior defense and audio defense. Custom guardrails and allow and deny lists sit alongside them, and the policies come with a linter and a health check. These guardrails stop an input or output outright; no human approval step is documented. SourceLakera (Check Point), docs.lakera.ai llms.txt (defenses, policies, projects, Guard API, policies linter)read 2026-09-25 |
|
| Security, Identity & Governance | Full |
|
The access surface is deep. Enterprise plans get organization SSO, role based access control and organization settings that only admins can change. AI Red Teaming adds two layers of roles, organization roles (admin, member) and folder roles (viewer, member, admin), with a table of what each can do, plus API keys scoped to a folder that members create and admins revoke. Admins can switch prompt logging and data retention on or off, and PII is masked before logging. No attestation appears. The docs' security link, lakera.ai/security, now redirects to Check Point's AI security page, which names no certification, and the Lakera pages show no trust center link. SourceLakera (Check Point), docs.lakera.ai/docs/platform.md and /docs/red/folder-roles.md, and lakera.ai/security; docs.lakera.ai/docs/platformread 2026-09-25 |
|
| Observability & Auditability | Full |
|
Every screening request is logged on the AI Guardrails dashboard with the exact content screened: prompts, responses and agent conversations with their roles. Each entry also shows the checks run, the project mode and the detection results, a Threats view and analytics by project and time range sit on top, and the Platform API returns logs and analytics. Admins control prompt logging and data retention, Enterprise customers export logs to a SIEM, and AI Red Teaming keeps a separate audit trail through its management API. So the record holds the agent's own traffic, not only security events. SourceLakera (Check Point), docs.lakera.ai/docs/platform.md and llms.txt (logs, analytics, Red audit trail, screening agent conversations); docs.lakera.ai/docs/platformread 2026-09-25 |
|
| Memory & State Persistence | Not documented |
|
Screening logs and red team target profiles describe the customer's agents; they are not memory for them, and the agent never reads them as context to decide. No memory layer is documented. SourceLakera (Check Point), docs.lakera.ai llms.txtread 2026-09-25 |
|
| Deployment & Data Residency | Full |
|
Customers pick where screening runs by choosing an endpoint, a US endpoint across several regions, US East, US West, EU Ireland or Asia Singapore. They also set where logs are stored when the organization is created, with the EU as the default. AI Guardrails can be self hosted on premises or in a private cloud, through a Helm chart for any Kubernetes cluster, plain Docker or a fully air gapped install. SourceLakera (Check Point), docs.lakera.ai/docs/data-regions.md and /docs/selfhosting.md; docs.lakera.ai/docs/data-regionsread 2026-09-25 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Prebuilt detectors for prompt defense, content moderation, data leakage prevention, malicious links, agent behavior and audio are ready for the customer to assemble into policies, and evaluation datasets support proof of value testing. They are libraries the customer puts together, not packaged agents or workflows a buyer adopts as working units. SourceLakera (Check Point), docs.lakera.ai llms.txt (defenses, datasets)read 2026-09-25 |
|
| Triggers & Channel Coverage | Not documented |
|
Lakera does not start agents. Screening runs when the customer's code calls the Guard API, and red team scans start on demand or from the customer's own CI/CD pipeline, a gate the customer already owns. No schedule, webhook or event of Lakera's own wakes work. SourceLakera (Check Point), docs.lakera.ai/docs/red/sdk-how-tos/run-scans-in-ci-cd.md and llms.txt; docs.lakera.ai/docs/red/sdk-how-tos/run-scans-in-ci-cdread 2026-09-25 |
|
| Model Flexibility & Routing | Not documented |
|
Screening runs through Lakera's own detection models, and the customer's model calls are not proxied or routed: the application calls the Guard API alongside whatever model it already uses. Red Teaming targets are the customer's models under test, not a choice of models inside Lakera, and no model or provider for Lakera's own AI can be selected. SourceLakera (Check Point), docs.lakera.ai llms.txt (integration guide, Guard API, Red targets)read 2026-09-25 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A published API covers the platform, with an OpenAPI 3.1 specification. The Guard API screens content and returns detailed results, and it also lints policies and checks their health. The Platform API manages policies and projects end to end and returns logs and analytics. AI Red Teaming adds a versioned SDK and a management API for folders, members and API keys, along with the audit trail. The MCP server on docs.lakera.ai serves the documentation, not the product. SourceLakera (Check Point), docs.lakera.ai llms.txt (API docs, OpenAPI spec, Red SDK and management API)read 2026-09-25 |
|
| Testing, Debugging & Optimization | Full |
|
AI Red Teaming tests the customer's own models and agents. Targets connect to a model or a custom agent API, scans run attack objectives against them, and each result carries an attack success score from 0 to 5, an indicator and an explanation, with a pass or fail verdict. A documented CI/CD gate script runs a scan on each release and fails closed, blocking on failed, errored or unscored results, with custom pass and fail criteria. Tool tracing covers agent tool calls during scans. Testing AI systems is what Lakera sells, and the artifact under test is the customer's. SourceLakera (Check Point), docs.lakera.ai/docs/red/sdk-how-tos/run-scans-in-ci-cd.md and llms.txt (red quickstart, interpreting results, trace agent tools); docs.lakera.ai/docs/red/sdk-how-tos/run-scans-in-ci-cdread 2026-09-25 |
|
| Browser & Computer Use | Not documented |
|
Lakera screens and tests AI traffic and does not operate a browser or a computer; no capability of that kind is documented. SourceLakera (Check Point), docs.lakera.ai llms.txt and lakera.airead 2026-09-25 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free to start · plan prices not readable (client-rendered page) · enterprise via sales
not readable; the pricing page renders client side
Included quota
Not public. Lakera Guard (runtime protection) and Lakera Red (red teaming) are licensed through enterprise agreements, increasingly via Check Point Infinity, where AI security can be added to existing deployments.
What is public
A free sign-up path and the product structure (AI Guardrails and AI Red Teaming) are public; prices were not readable.
Billing mechanics
A free self-serve sign-up exists; paid plan structure is on a client-rendered pricing page, and enterprise licensing runs through sales, including through Check Point.
Cost watchouts
Runtime screening scales with AI traffic, and self-hosting AI Guardrails runs on the customer's own Kubernetes or Docker infrastructure, with GPU acceleration supported.
Variable cost rationale
As a runtime API screening every prompt and response, cost typically scales with AI traffic volume, but exact metering and rates are set in enterprise agreements and not public.
Additional watchouts
Documentation, support and the security page now carry Check Point branding, so enterprise contracts may run through Check Point.
Overage / add-ons
Not publicly disclosed; commercial terms are set through enterprise sales.
Sales call required
Yes, required for paid access
Free / trial
lakera.ai offers "Start for free" sign-up at platform.lakera.ai; the free plan's limits were not readable
Lowest paid plan
Not public; sold through enterprise sales and the Check Point Infinity platform
Commercial notes
Now part of Check Point Software. Sold to Fortune 500 enterprises through the Check Point go to market, with the runtime API offering near immediate time to protect. Gandalf serves as a free, public on ramp and intelligence source.
Key ambiguities
platform.lakera.ai/pricing renders client side and returned only a shell, so whether paid plans carry published prices is unknown; the badge stays contact_only until someone reads it.
Cancellation / refund
Not publicly disclosed; set in enterprise agreements.
Support SLA / resale
Enterprise support through Check Point, including the Infinity Portal already used for its other security products.
Missing data
Plan names, prices and limits on platform.lakera.ai/pricing, which did not render to a fetch.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Lakera
The closest documented capability profiles to Lakera among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- OpenBox AI6.0 / 14A lighter documented profile than Lakera
- F5 AI Guardrails9.0 / 14Adds documented Triggers & Channel Coverage and Model Flexibility & RoutingLakera vs F5 AI Guardrails →
- Galileo9.0 / 14Adds documented Triggers & Channel Coverage and Model Flexibility & Routing
- Guardrails AI7.0 / 14Adds documented Model Flexibility & RoutingLakera vs Guardrails AI →
- Monte Carlo8.0 / 14Adds documented Triggers & Channel Coverage
- Opik9.0 / 14Adds documented Triggers & Channel Coverage and Model Flexibility & Routing
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded