Zero-trust for AI agentsInvisible tripwires · real-time tamper detection

Catch agents
going rogue.

The runtime security layer for every AI workflow you run. Trappr stops prompt injection, keeps your sensitive data out of third-party LLMs, and catches tampering the second it happens — across n8n, Make, Dify, LangChain, and beyond.

Set up in < 5 minno SDK, no agents to install
9 platformsn8n · Make · Dify · LangChain…
Free to startno credit card required
trappr · live · workspace · dify-prod
12 workflows protected
Triggerwebhook · POST
LLM Callclaude · sonnet
Tool · DBpostgres · read
CODE · rogueadded 14:02
Sendemail · out
TAMPER DETECTEDnode added — CODE / exfil. baseline hash mismatch · session quarantined
Works with
n8n·Make·Dify·LangChain·Flowise·Zapier·OpenAI·Anthropic·Gemini
The problem

AI agents are a new attack
surface nobody's watching.

Your IDS doesn't speak prompt. Your WAF doesn't read workflow graphs. The moment you ship an agent, you ship an unmonitored execution layer.
01 · INVISIBLE

Prompt injection is invisible

Attackers manipulate your agent's system prompt mid-run. You find out from customers, not your stack.

02 · UNDETECTED

Workflow tampering goes undetected

Someone adds a rogue node, changes a connection, or swaps your LLM provider. Your automation just… runs it.

03 · LEAKING

Sensitive data leaks to LLMs

PII, internal terms, and API keys get sent verbatim to third-party models. No log. No mask. No trail.

How it works

Deploy in minutes.
Protect forever.

No SDK. No agents to install. Connect your platform and Trappr fingerprints your workflows in seconds — then watches every run.
STEP 01

Connect your platform

Link your n8n, Make, Dify, or custom workflow. Trappr fingerprints every node, every connection, every prompt.

STEP 02

Trappr sets the tripwires

Invisible canary tokens are embedded in your agent's system prompt. If anyone extracts and replays it, the trap fires.

STEP 03

Monitor in real time

Every workflow scan compares live state against your baseline. Hash mismatch = instant alert. Changed node, added tool, modified prompt — caught.

STEP 04

DLP masks secrets automatically

Before any message reaches the LLM, Trappr strips and replaces sensitive terms, PII, and custom keywords. The model gets masked tokens. Your data stays yours.

Features

Everything you need.
Nothing you don't.

Eight capabilities. One dashboard. Designed for the team that already has too many tabs open.

Canary tokens

Invisible tripwires in system prompts. Fire the moment someone extracts and replays your prompt.

Tamper detection

Baseline + live hash comparison on every node, edge, and parameter. Red node = something changed.

DLP masking

Dictionary + regex rules mask sensitive data before it hits the LLM. Unmasks the response before returning.

Real-time alerts

Slack, email, or webhook alerts the moment something goes wrong. No polling. No delay.

AI gateway

Route LLM traffic through Trappr. Log every request, cost, latency, and DLP event in one place.

Multi-platform

n8n, Make, Dify, LangChain, Flowise, Zapier, custom agents. One dashboard for all of them.

Agent vault

Every agent gets a fingerprint, a canary token, and a scoped API key — managed and rotatable.

Execution tracking

Full lifecycle tracking of every workflow run — who, what, when, how long, and what it cost.

Demo

See it catch a tamper
in real time.

A Dify workflow. Someone added a rogue CODE node after baseline. Trappr caught it in the next scan — red node, critical alert, full diff.
trappr / workspaces / dify-prod / workflows / customer-support-v3
CRITICAL · INCIDENT-04F2
workflow · live scan
WebhookPOST /support
LLM · classifyclaude-sonnet
OK
Knowledge basevector search
OK
LLM · respondclaude-sonnet
OK
CODE · ⚠ rogueadded 14:02 · unknown
TAMPERED
Replysend · user
OK
Incident · 14:02:31 UTC

Workflow tampering detected

A new CODE node was inserted between the response LLM and reply. Baseline hash a7f1… does not match live hash 9c2b…. Session quarantined pending review.

nodes.count = 5 · hash a7f1c…
+nodes.count = 6 · hash 9c2b4…
+node[5] = CODE · author: unknown
+edge: respond → CODE → reply
Severity
CRITICAL · 9.4
Action taken
Quarantined
Notified
#sec-alerts · oncall
Replay
trappr.io/r/4f2b
Live demo

See Trappr in action.
We'll walk you through it.

Leave your details and we'll reach out within 24 hours to schedule a personalised demo — tailored to your stack and use case.

30-minute live walkthrough
Your workflows, your threat model
No sales pressure — just the product

Book a demo

Pricing

Built for teams running
AI at scale.

Free to start. Transparent at every tier. No per-event nickel-and-diming.
Starter
Free
Perfect for trying it out.
  • 1 workspace connection
  • 3 monitored workflows
  • 100 gateway requests / mo
  • Canary tokens
  • Community support
Enterprise
Talk to us
For regulated industries and large-scale deployments.
  • Everything in Business
  • Unlimited gateway requests
  • Unlimited seats
  • SSO / SAML
  • On-prem or private cloud
  • Custom retention & compliance
  • Dedicated security review
  • White-glove onboarding · named contact

Your AI agents need
a bodyguard.

Set up in under 5 minutes. No agents to install. No SDK required.