Arcjet vs Lakera: Lakera alternatives compared

Lakera screens prompts at a gateway. Arcjet alternatives add in-app guards on tools, budgets, and workflows.

14 min read
In short: Lakera, now part of Check Point, screens prompts, outputs, and agent steps through its Guard API, and your code acts on the flag. Arcjet enforces policy on the action itself, in your code and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code. Compare scope, data handling, and when to use each.

Arcjet vs Lakera: which Lakera alternative fits?

Lakera, part of Check Point since October 22, 2025, sells Lakera Guard, documented as AI Guardrails: an API that your application calls to screen prompts, model outputs, and agent steps for prompt attacks, data leakage, harmful content, and unknown links. Arcjet is an AI agent runtime security platform that enforces policy in the path of the action: in your code for agents and applications you build, and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code, with no proxy to route through.

The key difference is what each product decides on. Lakera returns a verdict on content that your code then acts on, and Arcjet returns a policy decision on the tool call, command, or destination itself. Choose Lakera when you want a content-screening API from a large security vendor with a self-hosted option. Choose Arcjet when you need a decision on the action, with application context, before it runs.

Arcjet publishes this comparison. Competitor details come from Lakera's and Check Point's public documentation, reviewed on September 25, 2026. This comparison covers documented scope and integration, not independently measured detection quality.

Arcjet vs Lakera at a glance

The following table compares Lakera and Arcjet across 11 areas, from where each product enforces to how each is priced.

AreaLakera (Check Point AI Security)Arcjet
Where it enforces

Your application calls the Guard API and

decides what to do with the flagged result

In the path of the action: an SDK call in your code before the tool or request runs, or the coding agent's own hook before the tool call runs

Coding agents

Workforce AI Security

discovers code assistants and MCP workflows through a browser extension or desktop agent; public docs don't describe policy on individual coding-agent tool calls

Policy on Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code tool calls, prompts, and model switches through their hooks, installed through managed settings

Custom agents

Guard API calls at each workflow step; agent discovery and native platform integrations are

early access and on the roadmap

JavaScript, TypeScript, Python, and Go SDKs with integrations for 15 agent frameworks

Prompt injection

Prompt Defense for direct and indirect attacks

Prompt injection detector in the Arcjet Cloud API
PII and sensitive data

Data Leakage Prevention

, including system prompt leakage

Sensitive information detection that can run inside your process, plus a server-side detector for coding-agent hooks

Tool and action policy

Agent Behavior Defense

: a Dangerous Deviation detector and a tool allow and deny list

Guard policies in Rego or a builder over tool name, command, path, destination, MCP server, model, and your own inputs

Links and destinationsMalicious Links detection for unknown links in model output

Destination threat analysis scores the hosts an agent is about to contact with Arcjet threat intelligence, plus egress and MCP allowlists

Discovery and posture

Agent discovery and per-agent risk ratings in AI Agent Security (early access)

Agent activity and sessions from hooks, OpenTelemetry, and the Claude Compliance API; no posture scanning of cloud assets

Web application securityNot documented in Lakera's docs

Bot detection, rate limiting, Shield WAF, email validation, and signup protection in the same SDK

Deployment

SaaS or a self-hosted container

SaaS; hook decisions evaluate at the edge in over 300 data centers

Pricing

Free start and enterprise plans through sales

Published: Individual $25 per month, Startup $299 per month, Enterprise custom, plus usage

What does Lakera do after the Check Point acquisition?

Lakera is Check Point's AI security product line, with Lakera Guard at its center. Check Point announced its acquisition of Lakera on September 16, 2025, and completed it on October 22, 2025. Lakera's Zurich and San Francisco teams form the base of Check Point's Global Center of Excellence for AI Security. The Lakera documentation at docs.lakera.ai is branded Check Point AI Security, and it describes three products: Workforce AI Security, AI Agent Security, and AI Red Teaming.

AI Guardrails, the Lakera Guard API, is a control layer around models, assistants, and agents. Lakera's guardrails cover five areas: Prompt Defense, Content Moderation, Data Leakage Prevention, Malicious Links, and Agent Behavior Defense. Agent Behavior Defense adds a Dangerous Deviation detector for actions outside an agent's mandate and an allow and deny list for tool calls. You pick from preset policy templates or build your own.

The Lakera integration guide describes the enforcement model. Your application sends content to the Guard API and receives a flagged result with an optional breakdown, then decides whether to block, ask for confirmation, mask, or log. Detect and Enforce modes switch behavior from the dashboard without a code change.

The Lakera guide recommends screening the input and the model's output together after the model responds and before the user sees it. The guide also suggests screening each agent step, tool use, and tool definition.

Lakera AI Agent Security adds agent discovery, per-agent risk ratings, and runtime protection through the same Guard API. Check Point documents AI Agent Security as early access, with native platform integrations on the roadmap. Workforce AI Security is the employee-facing product: a browser extension or desktop agent that discovers AI tools, including code assistants and MCP workflows, and applies data loss prevention to prompts and uploads.

What is Arcjet?

Arcjet is an AI agent runtime security platform that discovers the agents running in your organization, enforces policy across every action, prompt, and tool call, and keeps the evidence to prove what happened. Arcjet enforces where the action happens instead of on the network.

For coding agents, the hooks that Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code already fire call Arcjet, with no SDK and no code change. You install the hook through managed settings or mobile device management (MDM) so developers can't remove it without admin access. One Arcjet policy applies across all five agents and decides before the tool call runs. Arcjet has 12 starter policies for coding agents, covering destructive commands, history rewrites, protected paths, credential access, piped installers, MCP allowlists, egress allowlists, destination threats, model allowlists, sensitive information, prompt injection, and npm publish.

For agents and applications you build, the Arcjet JavaScript, TypeScript, Python, and Go SDKs provide guard() for tool calls, queue workers, and MCP handlers, and protect() for HTTP routes. Arcjet integrates with 15 agent frameworks, including the Claude Agent SDK, LangChain, LangGraph, Mastra, OpenAI Agents, the Vercel AI SDK, CrewAI, and Google ADK. You write Guard policies in Rego or a visual builder, run them in dry run before going live, and publish them from the Arcjet Console or MCP server, and changes take effect in real time.

Arcjet destination threat analysis scores the hosts an agent is about to contact with Arcjet threat intelligence, so a policy can deny a fetch, an install, or an MCP server that it rates high risk. The same SDK covers bots, rate limiting, Shield WAF, and email validation on HTTP routes. The Arcjet Console records every decision and session, and on the Enterprise plan decisions export to Datadog, Splunk, SentinelOne, Panther, and Amazon S3.

How do Arcjet and Lakera differ?

Arcjet differs from Lakera in four ways: what each product decides on, how each covers coding agents, where each handles data, and how much of the application each covers. The following sections cover each difference, then a test that settles an evaluation.

A verdict your code acts on versus a decision at the action

Lakera's Guard API returns a flag, and your application turns that flag into a block. That model works well for chat interfaces, where the natural checkpoint is the model's reply.

An agent's risk is often the action: a shell command, a file write, a refund, or a request to a new host. A content classifier answers whether text looks malicious. A content classifier doesn't answer whether this user may refund this invoice, or whether this command deletes a protected path.

Arcjet decides on the action with its arguments and context. An Arcjet Guard policy can read the tool name, the parsed command, the target path, the destination host, and inputs your code supplies, such as tenant or plan. The decision returns before the tool runs. For more information about where that check sits, see AI agent security architecture.

Coding agents

Coding agents run on developer laptops and in CI with shell access, repository write access, and credentials. Check Point's Workforce AI Security discovers code assistants and applies data loss prevention to what employees send. Check Point's public documentation doesn't describe a policy on each coding-agent tool call.

Arcjet enforces on the tool call through the agent's own hook, so a git push --force to main, a read of ~/.aws/credentials, or a curl | sh installer is denied before it runs. Hook behavior differs by vendor: Claude Code and Copilot HTTP hooks fail open by vendor design, while Cursor and Codex use a command wrapper that fails closed. For the full model and its limits, see how to secure AI coding agents.

Data handling

Lakera evaluates content by receiving it, in its SaaS or in a self-hosted container you run. The self-hosted option is a real advantage when prompts can't leave your network.

Arcjet's sensitive information detector can run inside your process, so the raw body isn't sent for that check. Arcjet prompt injection detection runs in the Arcjet Cloud API, and coding-agent hooks use a server-side sensitive information detector. Evaluate data handling per detector; for more information, see keeping security inspection local.

Scope beyond AI content

Lakera focuses on AI inputs, outputs, and agent behavior, with red teaming as a separate product. Arcjet also covers the web application around the agent: bot detection, rate limiting, token budgets, Shield WAF, and signup protection through the same SDK. If your AI feature is an HTTP endpoint, one Arcjet integration can rate limit the caller, block bots, and screen the prompt.

Test both on the same workflow

A fair test runs Lakera and Arcjet against the same labeled corpus and workflow. Include a benign task, a direct and an indirect prompt injection, a disallowed tool call, and a policy-service timeout. Record false positives, missed attacks, unauthorized effects that reached the downstream service, task completion, and added latency. The agent security test matrix gives a structure for this test.

Which fits: Lakera, Arcjet, or both?

Choose Lakera for content screening in chat and RAG applications, Arcjet for decisions on agent actions and coding-agent tool calls, and both when you have both workloads. The following sections describe the fit for each product.

When to choose Lakera

Lakera fits when any of the following apply:

  • You want a content-screening API for chat and retrieval-augmented generation (RAG) applications, and your code already has a natural checkpoint after the model responds.
  • Prompts can't leave your network and you need a self-hosted container.
  • You're standardizing on Check Point and want AI security in the same vendor relationship, with red teaming and employee AI monitoring alongside.

When to choose Arcjet

Arcjet fits when any of the following apply:

  • You run Claude Code, GitHub Copilot, Cursor, OpenAI Codex, or Muse Code and need one policy that decides on their tool calls before they run.
  • Your agents take actions where the arguments matter: commands, file paths, destinations, refunds, or messages to recipients.
  • You want policy in Rego with dry run, real-time publishing, and a record of every decision.
  • You want bot detection, rate limiting, and WAF rules on the same routes as your AI checks, with published pricing.

Using both

Lakera and Arcjet can run together. Lakera screens chat content where you already call it, and Arcjet enforces on the tool calls and coding-agent actions that follow. Assign one owner for the final execution decision so two controls don't disagree without anyone noticing.

What are the alternatives to Lakera?

The alternatives to Lakera fall into three groups: enforcement at the action, application-side evaluators and platform suites from other security vendors, and AI gateways with guardrails. If you're replacing Lakera or comparing it with other options, the following products cover overlapping ground:

  • Arcjet: enforcement on the action in code and in coding-agent hooks, with prompt injection, sensitive information, and destination threat detectors, plus web application security.
  • Datadog AI Guard: an evaluator that you call from your application, with policy in Datadog, for teams that already run Datadog tracing.
  • Prompt Security (SentinelOne): employee AI use, homegrown AI applications, and agent controls in the SentinelOne platform.
  • Prisma AIRS (Palo Alto Networks): runtime API and network inspection, AI red teaming, and model scanning for Palo Alto Networks customers.
  • AI gateways such as Portkey and LiteLLM: guardrails on the model traffic that you route through the gateway.

For the wider market, see AI agent security platforms. To separate discovery from enforcement requirements, see posture management versus runtime security.

Frequently asked questions

What is the difference between Arcjet and Lakera?

Lakera, now part of Check Point, is an API that screens prompts, model outputs, and agent steps for prompt attacks, data leakage, harmful content, and unknown links, and your application acts on the flagged result. Arcjet enforces policy on the action itself: in your code before a tool or request runs, and in the hooks of Claude Code, GitHub Copilot, Cursor, OpenAI Codex, and Muse Code before a tool call runs.

Is Arcjet an alternative to Lakera?

Yes, for prompt injection and sensitive information detection in AI applications. Arcjet also adds policy on agent tool calls, coding-agent hooks, destination threat analysis, and web application security. Lakera also offers a self-hosted container and AI red teaming, so compare those requirements separately.

Who owns Lakera?

Check Point Software Technologies announced its acquisition of Lakera on September 16, 2025, and completed it on October 22, 2025. Lakera's documentation is branded Check Point AI Security and covers Workforce AI Security, AI Agent Security, and AI Red Teaming.

Can you use Lakera and Arcjet together?

Yes. Lakera can screen chat content where your application already calls it, and Arcjet can enforce policy on the tool calls and coding-agent actions that follow, such as shell commands, file writes, and requests to new hosts. Assign one owner for the final execution decision so the two controls don't disagree without anyone noticing.

Does Arcjet inspect content locally?

Arcjet's sensitive information detector can run inside your process, so the raw body isn't sent for that check. Prompt injection detection runs in the Arcjet Cloud API, and coding-agent hooks use a server-side sensitive information detector. Evaluate data handling per detector.

AI runtime security in your code

Protect your AI agent workflows with Arcjet

Arcjet runs inside your application, where it can use runtime context to enforce agent actions and budgets, detect prompt injection, and protect sensitive information before a workflow acts.