Screen what your inbox
feeds your agent.

One poisoned ticket can turn a helpful support agent into the attacker's hands. Parse screens every message for injection, exfiltration and fraud before your agent acts — deterministic verdicts in milliseconds, a receipt for every decision. Start in monitor for $0; production keys from $12/mo (Solo) or $49/mo (Pro).

Screen one. Forward the report. No key, no meeting.
Running a fleet, not one inbox? Team is the 11th agent and named environments that persist. Undeclared Chrome tools return HTTP 403 on the gateway. Running an assistant that drafts replies, triages tickets or reads customer messages? Screen a batch of your own tickets and see what it would refuse. On 19 lines of financial-crime investigative prose the deterministic layer refused none — the corpus size and measured surface are published. Two modes are a trade, not a speed setting; a false positive is why that trade is documented.
scroll
/

Integrate this afternoon

One POST at the boundary. Score, categories, action — and a receipt.

# screen a retrieved document before your agent acts on it
curl -s https://www.parsethis.ai/v1/parse \
  -H "Authorization: Bearer $PARSE_API_KEY" \
  -d '{"prompt": "<untrusted content>"}'

# → {
    "risk_score": 8.7,
    "verdict": "critical",
    "categories": ["instruction_override", "data_exfiltration"],
    "recommended_action": "block",
    "trace_id": "prs_7fd2"  // your receipt
  }
4 detection layers9 risk categoriesreceipt on every verdict
npm install @parsethis/sdk
then: wrap your agent — screening runs at every trust boundary.
10x faster, zero data egress: Add "mode":"pattern-only" for deterministic screening with no prompt text sent to any third party. Learn more →
What it gives up: the deterministic layer misses paraphrased and indirect attacks the semantic layer catches — an injection hidden in a package README or a fetched document can pass it. Use it on chat-speed paths; run the full pipeline on anything your agent fetched. Precision numbers →

Test Lab

Blind fixtures probe whether your agent resists injection — before your customers do.

Open the test lab →

Monitor first, block later

Ship in monitor mode, then dial to block per environment. Every change is versioned.

Read about the dial →

Four surfaces. One decision.

Screen before authority — at all four places an agent can be steered.

User & RAG input

Injection and hidden instructions in what it reads.

POST /v1/parse

Tool & browser output

Data that parses like instruction.

POST /v1/parse

Generated output

Screened before users, tools, or memory.

POST /v1/screen-output

Agent handoff

Delegation verified before work is accepted.

POST /v1/agent/trust/verify
§

Screening is the floor.
Governance is the product.

Seven controls around the pipeline. Evidence your auditor can read.

TOOL POLICY

Ban a capability, not a name

One rule on browser covers browser_use, playwright, computer_use and every MCP name it hides behind. A team lead cannot write themselves an exception.

REGISTRY

Every agent on record

Status, risk, owner, last seen. Freeze or retire from one place.

POLICY

Enforcement you dial

Monitor, warn, or block — per environment, versioned with diffs.

DATA

Boundaries on data

Grants, egress control, and volume budgets per agent.

EVIDENCE

Receipts & SIEM

Category, score, action, trace ID — sealed and forwarded.

ATTESTATION

Coverage, proven

Screened vs. unscreened traffic over any window.

CROSSWALK

Framework mapping

OWASP LLM, NIST AI RMF, EU AI Act, ISO 42001, and SOC 2 TSC — certifications on the roadmap, controls aligned today.

Hand this to the agent. It wires itself.

A copy-paste integration prompt for any agent runtime — Bearer-key first. x402 is not configured on this deployment.

Copy into an agentIntegration prompt
$

Start free. Scale on evidence.

Freeunlimited instant screening · 50 deep/day · org governance after a verified account$0foreverInstall →
Solomy agent · 3,000 deep/mo · no idle expiry$12/moStart →
Promy product’s agents · 10 agents, 3 environments$49/moDeploy →
Teamunlimited agents · 11th agent · named envs persist · undeclared Chrome 403$199/moScale →
Team: the 11th agent is 201 and named environments persist. Undeclared Chrome tools return HTTP 403 on the gateway. $47 one-time Security Audit · x402 pay-per-call is not configured on this deployment (see /v1/pricing).

Field notes.

Agent governance,
receipted.