CADi · LLM applications
Causal prompt-injection detection for LLM applications, governed at the prompt boundary.
A per-prompt decision you can defend after the fact, not a black-box block.
Seeking build partnersCADi Prompt is an open invitation: we are looking for partners to build it with us. If you ship LLM applications and want the trust boundary governed, we would like to hear from you.
Get in touchPrompt injection is an input crafted to make a language model act against its instructions. As LLM applications take on real decisions, the moment of trusting an input becomes a decision in its own right - and one that is almost never governed or recorded.
A black-box filter can block a prompt, but it cannot tell you why it blocked, under what policy, or whether the block was warranted. When an injection attempt succeeds, or a legitimate input is wrongly refused, there is no defensible record of the call.
CADi Prompt applies the same causal engine to prompt-injection detection, so the decision to trust an input is governed like any other decision the firm is accountable for.
It produces a per-prompt allow, block or escalate, each carrying a causal rationale and an audit trace - so an injection attempt and the response to it can be evidenced later. A black-box filter cannot tell you why it blocked; this can.
Allow, block or escalate at the prompt boundary - a governed call, with the policy and the reasoning attached, rather than an opaque yes/no.
Every decision carries a causal rationale and an immutable trace, so an injection attempt and the response to it can be evidenced when it matters.
A black-box filter cannot tell you why it refused an input. CADi Prompt records the ground for the call, so the block itself is accountable.
The moment of trusting an input is treated as a first-class decision, held to the same standard as the decisions downstream of it.
Builders putting language models on a real decision path, who need the trust boundary governed rather than left to an opaque filter.
The functions accountable for how an AI system behaves under adversarial input, who must evidence that the trust decision was warranted.
CADi Prompt is one product in the CADi range: the same deterministic causal engine - nine layers, a do-calculus core and a hash-chained audit trail - pointed at the prompt boundary.
Treating prompt injection causally, rather than as pattern-matching, is what lets the engine give a reason for the call and a trace to defend it. It is the same governance every CADi product applies, aimed at the moment an AI decides whether to trust its input.
CADi is at v0.9 - built and running end-to-end - on nine pending UK patents. CADi Prompt governs and records the trust decision; it is not a guarantee that every injection will be caught, and it does not replace the rest of an application's security posture.
The causal mathematics is rigorous and correctly implemented. Today it runs on an assumed causal graph with heuristic inputs; it is analytical approximation on assumed inputs, not yet statistically validated against live outcomes. We lead with the rigour, and we name the caveat.