01 · Stop worrying
Stop worrying about AI privacy and security.
Shutapp redacts 300+ types of personal information worldwide, blocks all kinds of attacks, and restores the data when the AI responds.
Protect yourself, your users and ship AI with confidence. Keep sensitive data out of the model,
shut malicious attacks, and prove compliance without slowing down development.
Free. 2M Tokens / Month. No card.
Full privacy and security, without changing your existing LLM call.
# pip install shutapp
from shutapp import Shutapp
import os
s = Shutapp(api_key=os.environ["SHUTAPP_API_KEY"])
safe, session = s.scan(user_input) # before your LLM call
reply = call_your_llm(safe) # your existing call, unchanged
final = s.rescan(reply, session=session).text # what you return to the userPII strips · injection / jailbreak · rescans
Where Shutapp lands
AI security should not hide behind best effort. It should publish the numbers, put money behind the promise, and become a protection partner, not a disclaimer.
The top-right is the only quadrant worth owning: proven defense, real commitment, no hand-waving. Today, it's us. Alone.
Hover each circle to see the breakdown.

How it works. Secured end to end.
Every request is processed inside secure hardware enclaves. Your data remains completely private and is never stored or seen by anyone.
Private values are replaced before the model call, then restored after the reply.Coverage~99.86%
User
The raw user prompt enters an isolated secure enclave for sensitive information redaction.
Originals are restored for your user, then all data is destroyed on delivery. Nothing is stored.
6Masking
Sensitive information is redacted. Only safe private text moves to the protection enclave.
The cleared reply moves back to the redaction enclave to restore the original values.
5Protection
Attacks gets blocked, only safe prompts goes to the LLM.
The LLM's reply re-enters the protection enclave for a harm-and-leak scan.
4LLM
Compliance proof
Every Shutapp decision produces a signed, cryptographic proof receipt. Your compliance evidence. Nothing personal is stored, only the signed evidence.
01 · Stop worrying
Shutapp redacts 300+ types of personal information worldwide, blocks all kinds of attacks, and restores the data when the AI responds.
02 · Ship fast
Three lines of code. Less than a tenth of a second and works with any AI model, continuously improving performance by our red team.
03 · Show proof
Every check returns a small signed cryptographic receipt — a tamper-proof record of what happened. Your team and your auditors can verify it themselves, without ever needing to see the original data.
Start free. Upgrade when you need more capacity.
Legal coverage
What we stop, the risk if we don't, the article that names it, and the cost. Every citation resolves to a primary regulator source (EUR-Lex, ICO, eCFR, HHS, FTC, SEC, NIST, OWASP).
Track 1
Six controls. Six article-level exposures.
Without it · Personal data sent to the model lands in provider logs and downstream traces.
Cost · Up to 4% of global revenue (GDPR) · up to USD 1.9M / year per HIPAA violation type.
GDPR Art. 5(1)(c) · HIPAA 45 CFR 164.502(b)
Without it · Untrusted input can override your instructions and trigger unauthorised actions or data disclosure.
Cost · Up to EUR 15M or 3% of global turnover (AI Act, operator obligations).
EU AI Act Art. 15(5) · OWASP LLM01:2025
Without it · Hidden instructions, pricing logic and tool definitions become public the moment they leak.
OWASP LLM07:2025 · GDPR Art. 5(1)(f)
Without it · Unfiltered model output can carry executable markup that your frontend treats as trusted.
OWASP LLM05:2025
Without it · A single misuse or runaway loop can exhaust budgets and trigger denial of service.
OWASP LLM10:2025
Without it · Without tamper-evident records you cannot prove what was processed, when, or under which policy.
GDPR Art. 5(2) · HIPAA 45 CFR 164.312(b) · NIST SP 800-53 AU-10
Track 2
Three places where the law puts a name on the indictment, not just a company logo. Receipts shift the burden of proof off you.
Without it · Liability attaches to the individual; signed receipts evidence what was processed and how.
Cost · Up to 3 years prison (DE) · up to 3 years (IT) · unlimited fines on individuals (UK).
BDSG Sec. 42 (DE) · Codice Privacy Art. 167 (IT) · DPA 2018 ss. 170-173 (UK)
Without it · Knowing disclosure of health data exposes the individual to fine and imprisonment.
Cost · Up to USD 250,000 and 10 years prison.
42 USC 1320d-6
Without it · The household exception does not cover a public commercial service (CJEU C-101/01).
Cost · Up to EUR 20M or 4% of your revenue, whichever is higher.
GDPR Art. 4(7) · Art. 2(2)(c)
Track 3
Where the line stops.
We do not run your DPIA, sign your DPA, file your 72-hour breach notice, or stand in for a HIPAA Business Associate Agreement. A gateway alone does not make you GDPR, HIPAA, or AI Act compliant. We make the evidence airtight; the legal paperwork is yours.
Informational only, not legal advice. Every cited article, section, and dollar figure is sourced in our internal research brief against tier-1 regulator and standards-body URLs only. Confirm against your own counsel before publishing or relying on any specific claim.
Line in the sand
Smaller perimeter, sharper language. Easier for security teams and the runtime owners who inherit this code.
Emails become [EMAIL_1], not █████. The model retains enough context.
Ed25519 on every scan. Verify offline · auditors meet signed bytes.
Heuristic + ProtectAI scores land in your telemetry. Detection, not mythology.
Bring a dev
Stacks per invite. No cap. Credited the moment they generate a key.
You get
They get
A few cookies help us understand what's useful on the site, so we can make it better. You're in control. Details in our Privacy Notice.