Capability Thicket Cloud prompt scanners
Runtime blockingYes — at the execution boundaryNo
SSRF protectionYesNo
Deserialization hardeningYesNo
Works offline / air-gappedYesNo
No AI making blocking decisionsYesNo
Data leaves your processNeverAlways
OS kernel backstopYes (Linux ≥ 5.10)No

For organisations with data-sovereignty requirements, a cloud scanner that receives your prompts is not a viable option regardless of detection quality.

Watch it block real attacks →
hello@hedgerow.dev