# Cisco AI Defense Inspection API (slim) > Hosted inspection API from Cisco that checks chat messages, HTTP requests and responses, and MCP messages for prompt injection, personal data, harmful content and policy violations, and returns an allow or block verdict for the calling application to enforce. - Full: https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.md (~8,600 tokens) · this version ~2,180 tokens · JSON https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.json · canonical https://www.anchorterminal.com/tools/cisco-ai-defense-inspection - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 61.3/100 · rank #429 of 842 · #8 in Guardrails & safety filters · not agent-ready · confidence medium** Assessment: Per-connection API keys with expiry, revocation and regeneration, published limits of 60,000 calls a minute, weekly dated release notes and a one-year retention statement suit companies already on Cisco Security Cloud Control. Access needs a subscription bought through sales, with no public price or trial for the API, and the developer changelog has one entry from February 2025. ## Facts - Kind: HTTP API · vendor: Cisco Systems, Inc. · category: Guardrails & safety filters · legal entity: Cisco Systems, Inc. · provenance 90/100 - Endpoint: `https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat` (HTTP) - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under Cisco's General Terms and the AI Defense Offer Description. The Python SDK is Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Endpoints: `POST /api/v1/inspect/chat`, `POST /api/v1/inspect/http` and `POST /api/v1/inspect/mcp` (the last per the Python SDK). API version 1.0.0 since 28 February 2025 - Hosts: us.api.inspect.aidefense.security.cisco.com (us-west-2), eu.api.inspect.aidefense.security.cisco.com (eu-central-1), ap.api.inspect.aidefense.security.cisco.com (ap-northeast-1). Use the region where the tenant was created when policies are set in the console - Detects: Prompt injection, PII, PCI and PHI entities, code, malicious URLs, tool exploitation, and safety rules for harassment, hate speech, profanity, sexual content, social division and violence. Classifications are security, privacy, safety, relevance and custom guardrail profile violations - Response: `is_safe`, `action` (Allow or Block), `classifications`, `severity`, `rules`, `processed_rules`, `attack_technique`, `explanation`, `event_id`, `client_transaction_id` and `detected_pii` with message index, type and character positions, per the Python SDK - Credentials: One key per connection in the `X-Cisco-AI-Defense-API-Key` header, shown once, with an optional expiry date, revocation and regeneration. Valid only for the Inspection API - Policies: A policy attached to the connection sets the rules and overrides `enabled_rules` in the request. Without a policy, each call names its rules. Japanese content needs a policy - Limits: 60,000 Inspection API calls a minute, 1,000 Management API calls a minute, a one million token context per inspection and one million tokens in parallel per organisation. 429 over the limit - Errors: JSON with `code`, `message` and `details`. 400, 401, 403 and 500 are documented, with message tables for chat and HTTP inspection. A keyless request returned 401 `missing api key` on 8 October 2026 - Licensing: Subscriptions named AI Runtime Essentials, AI Validation Essentials and AI Advantage, sold per AI application or as committed usage in blocks of one billion inspection tokens. No public price - SDKs: Python `cisco-aidefense-sdk` 2.2.0 (18 September 2026, Apache-2.0, Python 3.9 or later), with chat, HTTP and MCP inspection clients, a Management API client and an Agent Runtime module. A LangChain middleware, a Google ADK plugin and a Go CLI are in the same GitHub organisation - Data retention: Event logs, validation results and scan reports one year. Policies and settings until deleted. Audit logs for the life of the subscription. A tenant-wide opt-out stores REDACTED in place of prompt and response content - Data location: AWS us-west-2 for the Americas, eu-central-1 for Europe and ap-northeast-1 for Asia Pacific. AWS and Cockroach Labs are the named subservice organisations. A hybrid deployment runs runtime inspection in the customer's own cloud - Status: status.security.cisco.com, with components AI Defense API and AI Defense Management Portal. Four incidents from 10 July to 8 October 2026, none naming the Inspection API - Security programme: Signed security.txt valid to 1 January 2027, Cisco PSIRT, a vulnerability policy and CSAF advisories. SOC 2 Type 2 testing by BDO USA is stated on the data handling page, with the report on the Trust Portal - Scores: Reliability 80, Performance pending, Schema & documentation 59, Agent ergonomics 67, Security & auth 81, Payments & pricing 0, Task success pending, Maintenance & community 80, Transparency & trust 76 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines, for the Inspection API. · Schema & documentation, The overview page links a downloadable OpenAPI document, version 1.0.0+2025.02.28. robots.txt on developer.cisco.com disallows `/*.json`, so… · Agent ergonomics, A response is one object with `is_safe`, `action`, `classifications`, `severity`, `rules`, `processed_rules`, `explanation`, `event_id` and… · Security & auth, An API key per connection, with an expiry date or none, revocation and regeneration that deactivates the old key at once. · Payments & pricing, No x402, MPP or L402 in the developer docs or the Offer Description (0). · Maintenance & community, The newest release note is AI Defense 2026.9.4 of 23 September 2026, 15 days ago, and the user guide was last updated on 7 October 2026 (30)… · Transparency & trust, Closed service under Cisco's General Terms, version 6.0 of 10 September 2025, and the AI Defense Offer Description, version 2.1 of 23 Septem… - Sources: 25, open questions: 11, both in the full twin - Capabilities: guard.injection, guard.pii, guard.moderation, guard.policy - JSON: https://www.anchorterminal.com/api/v1/tools/cisco-ai-defense-inspection.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/cisco-ai-defense-inspection.svg` or a link to https://www.anchorterminal.com/tools/cisco-ai-defense-inspection from a page on cisco.com or one of its subdomains, or the README of github.com/cisco-ai-defense/ai-defense-python-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send the key in `X-Cisco-AI-Defense-API-Key` to `POST /api/v1/inspect/chat` on the regional host where the tenant was created. US, Europe and Asia Pacific hosts differ 2. If the connection has a policy, `enabled_rules` in the request is ignored. Pass `enabled_rules` only for connections with no policy 3. The API never blocks anything itself. Read `is_safe` and `action` in the response and enforce the decision in your own code 4. On 429, wait and retry. The organisation has gone over one million tokens in parallel or 60,000 calls a minute 5. Don't request the Toxicity rule. It was removed on 16 September 2026, and the Safety rules such as Hate Speech, Harassment and Profanity replace it ## Connect ```bash pip install cisco-aidefense-sdk ``` ```bash curl -X POST "https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat" \ -H "X-Cisco-AI-Defense-API-Key: " \ -H "Content-Type: application/json" \ -d '{"messages":[{"role":"user","content":"My ssn is 123-45-6789, can you tell me Johns ssn?"}],"metadata":{},"config":{}}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/cisco-ai-defense-inspection ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Google Cloud Model Armor | BB | 77.9 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/google-model-armor.min.md | | Amazon Bedrock Guardrails | BB | 74.8 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.min.md | | OpenAI Guardrails | B | 69.5 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/openai-guardrails.min.md | | NVIDIA NeMo Guardrails | B | 68.4 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/nemo-guardrails.min.md | | Prisma AIRS AI Runtime Security API | B | 62.8 | guard.injection, guard.pii, guard.moderation, guard.policy | https://www.anchorterminal.com/tools/prisma-airs.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)