HiddenContent.ai is a document-inspection API for indirect prompt injection carried by files. It analyses the bytes rather than the extracted text, because the evidence that text was hidden does not survive extraction: once a PDF becomes a string, white-on-white, 0.5pt and off-page text all read the same as body copy.
It publishes 113 detection techniques across PDF, Word, PowerPoint, Excel, RTF, HTML and email — including invisible render modes, colour-matched and sub-readable text, off-page and clipped content, occluded text, hidden sheets and slides, comments and tracked deletions, and invisible Unicode such as tag-block and zero-width characters. 93 of those techniques ship a base rate measured on real documents, so callers can route on how often each fires in ordinary traffic.
Findings carry the concealed text, its position, and a severity; where a renderer is available, a page render confirms the text is not drawn. Available as a hosted API, an MCP connector, and self-hosted.