AI safety middleware
for .NET.
Screens inputs for prompt injection, PII, toxicity, and 19 harm categories before they reach your LLM. Runs in process. One NuGet install, four lines of code.
Six scanners.
One middleware call.
Built for .NET teams shipping LLM features to production. Everything runs in your process and logs where the rest of your app logs.
Prompt injection and jailbreaks
Instruction overrides, role hijacking, delimiter injection, social engineering. An ML classifier catches novel attack phrasings that pattern lists miss.
Multilingual PII
Emails, phones, SSNs, Luhn validated cards, person names, addresses, passports, tax IDs, in 50+ languages. Redact PII in place or block it outright.
Toxicity and harm categories
Multilingual toxicity detection plus 19 harm categories: hate, violence, self harm, user distress, exploitation. Classified in the source language, no translation hop.
Evasion resistant
Normalization defeats leetspeak, zero width characters, homoglyphs, Base64, and markdown tricks before the models ever see the input.
No scanner egress
Models run in process. That's one fewer data processor in your privacy review. Works fully offline for local LLM and air gapped deployments.
ASP.NET Core native
Drop in middleware: AddInvarixGuard, UseInvarixGuard, done. Or call the scanning engine standalone from any .NET 8+ app.
using Invarix.Guard.Extensions;
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddInvarixGuard(options => options
.BlockInjection()
.BlockPII()
.BlockToxicContent());
var app = builder.Build();
app.UseInvarixGuard(); // ← adds the safety middleware to the pipeline
app.MapPost("/chat", (ChatRequest r) => Results.Ok(new { reply = "safe" });
app.Run();Licenses, not subscriptions.
Free on NuGet, one payment for Professional, a quote for anything custom.
Community
Free for evaluation, internal tools, and commercial products. The main restriction: you can't offer it to third parties as a hosted or managed service.
- Prompt injection and jailbreak detection, heuristics plus ML
- PII detection and redaction across 50+ languages
- Multilingual toxicity classification
- 19 semantic harm categories, plus custom categories you define
- ASP.NET Core middleware or standalone scanning engine
Professional
Lifetime licenseFor teams that need the custom blocklist scanner in production. All future updates included, no support of any kind.
- Custom blocklist scanner with rules your ops team edits in JSON
- Each rule matches on exact keywords, semantic embeddings, or both
- Hot reload: change rules without redeploying
- Per rule actions: block, warn, or log
- Offline license validation, no licensing server to run
Custom solution
For teams with regulated, multi environment, or air gapped deployments that need something the standard tiers don't cover.
- Direct technical scoping with the founder
- Custom contractual terms
- Air gapped or sovereign cloud deployment guidance
- Extra harm categories defined with you