Guardrails
Four pre-call checks and two post-call checks run on every request. Blocked requests return 403 — never enqueued, never billed.
Guardrails always run before routing
The guardrail pipeline runs before any routing decision. A request that fails a pre-call check returns 403 immediately — it never reaches the LLM and is never billed.
Four pre-call layers
Prompt Injection
ML-based prompt-injection classifier. Confidence threshold configurable per policy group. ~30ms CPU latency. Cannot be disabled system-wide; threshold is adjustable.
PII Masking
PII detection engine. Default entities: EMAIL, CREDIT_CARD, SG NRIC, ID NIK, MY MyKad, TH National ID. Opt-in: PHONE, IP_ADDRESS, URL. Four modes: redact, tokenize, synthetic, block.
Content Moderation
Keyword + ML classifier. English + Bahasa Indonesia. ~5ms latency. Configurable per policy group.
Conversational Guardrails
YAML + flow-rule config per policy group. Conversational flow enforcement — blocks topic steering, jailbreaks, system-prompt disclosure.
Four ways to handle detected PII
Set pii_mode per API key or policy group. The default is redact.
redact (default)
tokenize
synthetic
block
See PII protection for the full mode reference.
Override guardrail defaults per API key
An API key's guardrail_overrides JSONB can selectively bypass guardrails independent of its policy group. Only PII and content moderation can be overridden per key — injection detection is mandatory.
Conversational flow enforcement
Configure via the dashboard Guardrails tab. YAML config + flow rules are stored per policy group and cached by config hash for performance.
Full guardrails overview: Platform / Guardrails →
Secure every AI call with guardrails
Guardrails run on every request — real-time and batch — before the model is ever called.