Stop prompt injection before it reaches
your AI agent or LLM.
Unwhisper is a firewall for AI / LLM inputs. It inspects text, chats and files including PDFs, images, Office documents and archives, and returns a clear pass/fail verdict before the content ever touches your large language model.
Your model reads more than humans can see.
Teams are wiring language models into products that read content they can’t see and don’t control. Uploaded CVs, invoices, support email, web pages and even chat can carry prompt injections designed to subvert your agent. Because LLMs mix instructions and data in a single input, attackers can hide their instructions inside seemingly benign documents.
Direct prompt-injection attacks against LLM-based AI web agents with no dedicated defence layer, only the models’ built-in safeguards, succeeded 79–92% of the time across every configuration tested.*
* Wang et al., arXiv:2606.13385, June 2026
These injections are often hidden or encoded to evade human review and basic filters: white or tiny text in a PDF, words buried in image pixels, using steganography, Base64-encoded payloads, via attacks written in other languages, and more.
In tests, Unwhisper blocked 100% of direct prompt-injection attacks and 95% of indirect (latent) jailbreak injections, while passing 99% of legitimate web content.*
* NVIDIA garak v0.15.1 red team tests including dan.DanInTheWild (99 valid prompts), promptinject.HijackLongPrompt and latentinjection.LatentJailbreak; pass rate measured on a 5,298-document legitimate web corpus; using current production model.
How it works - one API call, one verdict
- 1
Send the content
Post the raw bytes, text or a file, to a single REST endpoint. No multipart, no Base64, no SDK required.
- 2
Unwhisper inspects it
Files are unpacked, decoded, OCR’d and normalised, then scored by our custom-trained classifiers analysing content and context.
- 3
You get a verdict
PASSorFAIL, with confidence scores and per-finding detail. Forward the clean text, or block the file.
What it catches
Scans files, not just text.
PDFs, images, Office documents and archives, including scanned pages, read via OCR.
Sees what humans can’t.
Invisible text, zero-width Unicode tricks, content hidden in image pixels and file metadata.
Decodes disguised payloads.
Base64, hex, URL-encoded and rotated text is automatically decoded and scanned.
Speaks the attacker’s language.
Attacks written in foreign languages or disguised with lookalike characters are normalised and detected.
One call, one verdict.
A simple REST API returns pass/fail with confidence scores and per-finding detail, easy to wire into any pipeline.
Forensic reports on demand.
When a file is blocked, get a visual work-up showing exactly what was found, and where it was hiding.
Who it’s for
Built for teams putting AI to work on content they don’t control: document upload and CV screening, retrieval pipelines, email and ticket triage, AI agents that browse the web. If untrusted content meets your model, Unwhisper sits in between and protects your business.
What’s under the hood
We built Unwhisper over the past two years as an internal tool to protect our own web data pipelines and LLM chat systems. Having solved the problems we kept hitting when putting LLMs and AI agents into real-world production, we decided to share it.
Under the hood, Unwhisper combines multiple custom-trained AI models, deliberately not LLMs, with deep data inspection pipelines. We test against multiple industry benchmarks, ensure no benchmark data leaks into our training sets, and run Unwhisper in production ourselves across other Cyberrock services.
Runs anywhere
Cloud
Call our hosted API. Nothing to run, nothing to maintain. It runs on AWS in London and we provide a zero-logging guarantee.
On-premises
Run it inside your own environment via Docker, so sensitive documents never leave your network. Enquire for details.
Edge
We have a minimal version small enough to run on hardware as modest as a Raspberry Pi. Enquire for details.
Put it in front of your model.
Register with a work email and start scanning in minutes on our free test tier and REST API, no card required.
Talk to us about Unwhisper
Tell us what you’re building and we’ll come back to you within one working day.
