Direct injection
Jailbreak prompts, instruction override, persona hijack, detected and blocked at prompt time.
Indirect injection
Payloads hidden in PDFs, emails, webpages, and tool outputs, caught before the model reads them.
Multimodal injection
Attacks embedded in images, audio, and video, inspected before the model processes them.
Semantic detection
Purpose-trained classifiers + deterministic rules. No LLM-as-judge fragility.