Archestra has introduced OpenAPPA, an open‑source security engine that blocks data exfiltration caused by prompt injection or model hallucination, and it recorded zero successful attacks on the Bench‑Corp and AgentThreatBench benchmarks. Engineers who deploy large language models need to understand how this result could affect the security posture of their AI pipelines.
Benchmark Results and Context
In the Bench‑Corp suite, which exercises 20 multi‑step enterprise workflows, OpenAPPA prevented every attempted breach. The same outcome was observed on AgentThreatBench, a separate test set. By comparison, Claude Code’s auto mode allowed a 10 % success rate and Microsoft’s FIDES benchmark showed a 31 % success rate. The zero‑success metric demonstrates that, under the tested conditions, OpenAPPA’s defenses were more effective than the two referenced alternatives.
Architectural Considerations for Prompt Injection Protection
OpenAPPA is positioned as a security engine that can be inserted into the inference path of an LLM service. Because it is open source, teams can review the implementation, customize policies, and align the component with existing CI/CD pipelines. The engine should sit between the user‑facing API and the model runtime, inspecting prompts and model outputs for patterns that could trigger exfiltration. Deploying it as a sidecar container or a dedicated microservice keeps the protection layer isolated from the core model serving stack.
Operational Impact and Evaluation Path
Adopting OpenAPPA requires adding its runtime to the deployment manifest and configuring any required policy files. Teams should replicate the Bench‑Corp and AgentThreatBench workloads in their own staging environment to verify that the zero‑success rate holds for their specific prompts and data flows. Ongoing monitoring should capture any false positives that could affect latency or user experience, and alerting should be set up for any deviation from expected block rates.
Related CloudNinjas coverage: AI engineering.
What This Means For Practitioners
Practitioners should treat OpenAPPA as a candidate control for prompt injection protection, run the supplied benchmarks against their own workloads, and assess integration overhead before committing to production use.



