# Arcjet

> Runtime security platform for AI agents and web applications that enforces security policies in-code, blocking prompt injection, PII leaks, bot abuse, and unauthorized tool calls.

Arcjet is a runtime security platform built by Arcjet Labs, Inc. that integrates directly into application code to enforce security policies at the moment an action is taken — not at the network edge. It covers both AI agent workflows (coding agents like Claude Code, Cursor, Copilot, and Codex, as well as custom agents) and classic web application surfaces like HTTP routes, signup forms, and APIs. The company raised a seed round led by Andreessen Horowitz in 2023 and a Series A in 2025, and is SOC 2 Type 2 certified covering Security, Availability, and Confidentiality.

## What It Is

Arcjet is an in-code security SDK and cloud policy platform. Rather than sitting in front of an application as a proxy or gateway, Arcjet runs inside the handler or agent loop that takes the action, giving it access to the full execution context — typed tool arguments, user session data, file paths, and the history of prior steps in a run. It returns a typed decision object (allow, block, redact, hold for review) that the application code branches on, so unsafe actions never execute rather than being caught after the fact.

## How the In-Code Model Works

The core architecture separates observation, enforcement, and audit into three steps that happen before and after every agent action:

- **Observe**: Every action is captured inside the application and grouped by run, with full context including user, session, route, actor, tool label, typed arguments, and prior steps.
- **Enforce**: Each action is checked against rules — prompt injection, sensitive info, bot signals, action policy, run history — and a decision is returned before execution. The SDK bundles a WebAssembly module for local-first analysis; the cloud API adds roughly 20–30ms when needed.
- **Audit**: Every decision is stored with the policy version, actor, inputs, and run context. Sensitive checks run in-process so raw data never leaves the environment.

Policies can live in code (version-controlled, unit-testable, reviewed in PRs) or in remote policies managed by security teams in the Console and applied in real time without a code deploy.

## Security Controls

Arcjet ships a set of composable building blocks:

- **Prompt injection detection**: Catches hostile instructions in user input, API responses, and tool output before they reach the model, adding approximately 100ms via a specialist detection model.
- **Agent tool controls**: Scopes what each agent may do by identity, role, route, and typed input, enforced at the moment the tool is called via `guardTool()`.
- **Sensitive information and DLP**: Strips names, addresses, national IDs, bank and card numbers before they reach model context, logs, or third-party tools. Local detection via a bundled WebAssembly module (rampart) keeps data in-process.
- **Token and spend budgets**: Caps tokens and calls per user, org, or agent run using a token bucket that is shared across all endpoints in a run, preventing runaway loops.
- **Bot protection and Shield WAF**: Detects 600+ bot types across 25 categories, SQL injection, XSS, traversal attacks, email validation, and signup form protection — all returning the same decision object as agent guards.
- **Content moderation** (new): Screens agent outputs and user inputs for policy-violating content.

## Framework and Agent Coverage

Arcjet publishes 20 native SDKs and framework integrations across JavaScript/TypeScript (Next.js, Express, Fastify, SvelteKit, Remix, NestJS, Nuxt, Bun, Deno, Hono, Astro, React Router), Python (FastAPI, Flask), and Go. AI agent framework integrations — called Arcjet Guards — cover Claude Agent SDK, Claude Managed Agents, Cloudflare Think, CrewAI, Genkit, Google ADK, LangChain, LangGraph, Mastra, Microsoft Agent Framework, OpenAI Agents, Strands Agents, TanStack AI, Vercel AI SDK, and Vercel Eve. An installable Agent Skill (`npx skills add arcjet/skills`) gives AI coding agents the knowledge to add Arcjet protection to any project.

## Deployment and Trust

Evidence can be stored in Arcjet cloud, a single-tenant or private VPC deployment, or customer-managed storage. On the Enterprise plan, decisions export to Datadog, Splunk, SentinelOne, Panther, or Amazon S3 for SIEM integration. The platform is deployed to over 300 edge locations for low-latency policy evaluation. Arcjet states it has completed a SOC 2 Type 2 examination with an unqualified opinion covering Security, Availability, and Confidentiality; the report is available in their Trust Center.

## Update: Agent Runtime Security Launch

The homepage introduces Arcjet's positioning as "Agent Runtime Security," a category framing that extends the original web application security SDK to cover the full lifecycle of AI agent actions — tool calls, queue consumers, scheduled jobs, and workflow steps. New building blocks listed as recently added include prompt injection detection and content moderation. The Arcjet Skills repository (Apache 2.0, created April 2026, last updated September 2026) packages Arcjet's knowledge as an installable agent skill compatible with Claude Code, Cursor, GitHub Copilot, and any agentskills.io-compatible client.

## Features
- Prompt injection detection
- Agent tool controls (guardTool)
- Sensitive information and PII detection/redaction (DLP)
- Token and spend budget enforcement
- Bot protection (600+ bot types, 25 categories)
- Shield WAF (SQL injection, XSS, traversal)
- Rate limiting (token bucket, fixed window, sliding window)
- Email validation
- Signup form protection
- Content moderation
- Sequence drift detection across agent runs
- Remote policies (real-time, no code deploy)
- In-code rules (version-controlled, unit-testable)
- Dry run mode
- Audit log with full decision context
- SIEM export (Datadog, Splunk, SentinelOne, Panther, Amazon S3)
- SOC 2 Type 2 certified
- Local-first analysis via WebAssembly module
- MCP Server integration
- CLI
- Agent Skills installable via npx
- 20 native SDKs and framework integrations
- AI agent framework Guards (LangChain, CrewAI, OpenAI Agents, etc.)
- OPA Rego policy support for coding agents
- OpenTelemetry integration
- Single-tenant and private VPC deployment options

## Integrations
Next.js, Express, Fastify, SvelteKit, Remix, NestJS, Nuxt, Bun, Deno, Hono, Astro, React Router, FastAPI, Flask, Go net/http, LangChain, LangGraph, CrewAI, OpenAI Agents SDK, Claude Agent SDK, Claude Managed Agents, Cloudflare Think, Genkit, Google ADK, Mastra, Microsoft Agent Framework, Strands Agents, TanStack AI, Vercel AI SDK, Vercel Eve, Datadog, Splunk, SentinelOne, Panther, Amazon S3, OpenTelemetry, Claude Code, GitHub Copilot, Cursor, OpenAI Codex

## Platforms
WEB, API, VSC_EXTENSION, DEVELOPER_SDK, CLI

## Pricing
Freemium — Free tier available with paid upgrades

## Links
- Website: https://arcjet.com
- Documentation: https://docs.arcjet.com/
- Repository: https://github.com/arcjet/skills
- EveryDev.ai: https://www.everydev.ai/tools/arcjet
