Extraction defense

What makes your AI product yours stays yours.

Garlic watches how every account uses your AI product, flags extraction and plants canary facts that give you evidence when a clone ships. Built for AI startups, from pre-seed to Series A.

Garlic runs automatically. During founding pilots, a person also reviews every result. 5 founding pilots open now.

C

Garlic Score · sample product · last 7 days

18% of its topics were asked by accounts showing extraction patterns.

Tap a row to see why it was flagged.Sample on synthetic data

The evidence

~24,000

fraudulent accounts generated more than 16 million exchanges with one frontier model to copy its capabilities.

Anthropic, February 2026

+185%

growth in scraping in one year. It is now 70.9% of bad-bot traffic. DataDome, September 2026.

Today, security means keeping attackers out.

The people cloning your AI product are signed-in users.

Every answer your product gives reveals a little of its prompts, workflows and data. Enough answers, and a competitor can rebuild it. Nothing breaks, and nobody notices.

Layer 1

Surface

What your product says and how it says it. Easy to imitate, hard to own.

Layer 2 · what extraction targets

Behaviour

How it decides: edge cases, refusals, judgment calls. Your prompts and workflows.

Layer 3 · what extraction targets

Data

What it knows that others don’t. For many startups, the real moat.

Garlic turns your usage logs into evidence of who is extracting your product.

Step 1

Send 7 days of logs

One export you already have. No SDK, no proxy, nothing in your request path.

Step 2

Your Garlic Score in 48 hours

Automated checks across every session, reviewed by a person before it reaches you.

Step 3

Act on it

If it shows extraction, the founding pilot adds weekly scores, alerts and canary facts.

Mapmakers draw fake streets to catch copiers. Garlic does the same for your AI product.

Canary facts are unique, plausible details placed in your outputs. If a clone repeats one, you have evidence it came from you.

Share only wins

Show your customers you’re Garlicked.

Once your Garlic Score is strong, or has improved, you can display the Garlicked badge. It shows protection, never your findings. Your results stay private.

Coming to founding customers first.

GarlickedExtraction defense by GarlicGARLICKED · EXTRACTION DEFENSE · GARLIC ·

Pricing

Pay for protection, not seats.

Founding pilot · 5 places

$1,500

90 days of Protect. Refundable within 14 days, no reasons needed. Credited in full to your first year.

  • A Garlic Score every week from your log export
  • Extraction alerts when a pattern appears
  • Canary facts for your outputs, with careful, human-approved checks of products you name
  • Evidence reports for any confirmed pattern
  • Direct access to the people building Garlic

After the pilot · Monitor

$500 / month

Extraction alerts. Includes 10,000 monthly active users, then $40 per 1,000.

After the pilot · Protect

$1,200 / month

Monitor, plus canary facts, evidence reports and the Garlicked badge. Includes 10,000 monthly active users, then $60 per 1,000.

Founding prices, kept for your first 12 months.

Questions

Is Garlic software or a service right now?

Software, with a person in the loop. Garlic’s analysis runs automatically. During founding pilots, a person reviews every result before it reaches you, and Garlic takes on more on its own only as its measured accuracy earns it. Evidence reports and anything that names another company are always signed off by a person.

Do you need access to my model or code?

No. Garlic works from a log export: timestamp, account, session and question text. No SDK and nothing in your request path.

What is a canary fact?

A unique, plausible but invented detail placed in your outputs. If a competitor’s product repeats it, that’s evidence the data came from you. It’s evidence, not legal proof.

How is this different from bot management or prompt guardrails?

Both keep attackers out. Bot tools judge traffic patterns and miss signed-in accounts asking plausible questions. Prompt guardrails judge one message at a time. Garlic looks at what each account asks across every session, which is where extraction shows up.

What should I remove from my logs first?

Names, emails and anything else that identifies your users. Pseudonymise account IDs and hash IP addresses. Garlic works on patterns, not identities.