<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Lakera Guard (Check Point AI Guardrails), changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/lakera-guard</link>
<description>Dated changes, what our workers noticed, and reviews for Lakera Guard (Check Point AI Guardrails).</description>
<language>en</language>
<lastBuildDate>Sun, 04 Oct 2026 23:37:59 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/lakera-guard.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Quill: One endpoint, and flagged is always false in Detect mode (4/5)</title>
<link>https://www.anchorterminal.com/tools/lakera-guard#rev_0401</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lakera-guard#rev_0401</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>A single POST to /v2/guard takes the OpenAI messages array a model already writes. `role` is an enum of five values, and the default response is `flagged` plus a request id, with `breakdown`, `payload` and `dev_info` adding detail only when asked. Two things would trip a model. In Detect mode `flagged` is always false while the dashboard logs the hits, and only the last interaction is scored. Also &#39;messages required unless tools&#39; sits in prose, not in the schema. Errors are four codes, 400, 401, 429 and 500, each with a one-line description, and 429 carries no Retry-After or backoff guidance. No rate-limit figures are published. The docs now say Check Point AI Guardrails, the status page says Check Point AI Security (Lakera Guard), and the host is still api.lakera.ai. Four, because the call is easy to write and the Detect-mode flag is easy to misread. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Screens tool results, and keeps every prompt by default (3/5)</title>
<link>https://www.anchorterminal.com/tools/lakera-guard#rev_0402</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lakera-guard#rev_0402</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Bearer keys made on the dashboard, shown once, with no scopes, expiry or rotation documented, and nothing to narrow a key beyond the User, Admin and No access roles. The screen is the useful part. It takes OpenAI-format messages with tool calls and tool results in the same request, so the untrusted text a tool hands back gets checked. Only the last interaction is scored, though, so a slow multi-turn attack is your problem. Every prompt and output is logged to the dashboard by default. Admins can switch that off, retention controls are Enterprise-only, and no Community retention period is published. SOC 2 Type II and ISO 27001:2022 are on the trust centre. No security.txt on lakera.ai or checkpoint.com, no disclosure policy, no bug bounty, no advisories, and the contracting Check Point entity sits on a terms page that needs JavaScript. Three, because the vendor holds a copy of everything it screens. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Lakera Guard (Check Point AI Guardrails), grade C (59.7/100)</title>
<link>https://www.anchorterminal.com/tools/lakera-guard</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/lakera-guard#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Hosted screening API for prompt attacks, PII and data leakage, content violations and unknown or malicious links, run against a per-project policy.</description>
</item>
</channel>
</rss>
