All guides

Redact Personal Data with Custom Guardrail Rules

Write guardrail rules for personal data and business terms, starting from the US or European template.

9 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02Why the rules are yours
  3. 03Start from a regional template
  4. 04Terms or a pattern
  5. 05Add a rule
  6. 06Examples you can adapt
  7. 07Limits that keep traffic fast
  8. 08Test and tune
  9. 09As code

01

What you'll set up

You will add rules to a guardrail profile that catch the personal data and business terms that matter to you, test them against sample text, and tune them until they catch what you intend.

  • Rules created from a regional template
  • A custom rule of your own, by terms and by pattern
  • A redact-or-block choice for each rule
  • A tuning loop that keeps false matches low

You need a guardrail profile first. If you do not have one, start with the guide on creating your first guardrail profile.

02

Why the rules are yours

Credential formats are the same everywhere, so Cloptima detects them for you. Personal data is different. Formats vary by country, and what counts as sensitive depends on your business.

Built in

  • API keys, tokens, private keys, password assignments
  • The same everywhere

Your rules

  • National IDs, phone numbers, customer identifiers, internal codenames
  • Defined by you, tuned to your data

03

Start from a regional template

Create a profile from the US or European personal data template. Each includes editable rules and the credential rules for both prompts and responses.

TemplateRules included
US personal data redactionEmail addresses, Social Security numbers, US phone numbers, card-like numbers
European personal data redactionEmail addresses, IBANs, +3x and +4x phone numbers, card-like numbers

04

Terms or a pattern

A rule matches either a list of terms or one regular expression. Choose by what you are looking for.

UseWhenBehaves like
Term listFixed words and names, such as codenamesCase-insensitive by default. Whole words can be required.
Regular expression (RE2)Formats, such as IDs and host namesCase-sensitive by default. No look-ahead or back-references.

05

Add a rule

In the profile editor, add a custom rule under Prompts, Responses, or both.

  1. 1

    Give the rule an ID

    Use lowercase letters, digits, and underscores, such as project_codenames. Each ID is unique within a side.

  2. 2

    Choose how it matches

    Pick Term list or Regular expression (RE2).

  3. 3

    Choose On match

    Use Stage action to follow the side's action, or set Observe, Redact, or Block for this rule alone.

  4. 4

    Enter the terms or the pattern

    Terms go one per line. A pattern goes in the Pattern field.

  5. 5

    Set the toggles

    Case sensitive and Whole words change how matches work. Whole words needs each term to start and end with a letter, digit, or underscore.

  6. 6

    Save

    The rule is live as soon as the profile is saved.

Guardrail profile → Prompts → Add custom rule
1Rule ID
project_codenames
2Match
Term list
3On match
Stage action
4Terms (one per line)
project falcon internal-only
5Case sensitive
Off matches any letter case.Off
5Whole words
Skips matches inside longer words. Each term must start and end with an ASCII letter, digit, or underscore.On
Terms for names, patterns for formats.

06

Examples you can adapt

These cover the patterns teams ask for most.

GoalMatchRuleOn match
Keep a project codename out of promptsTerm list, whole wordsProject FalconBlock
Mask internal host namesRegular expression\b[a-z0-9-]+\.corp\.example\.com\bRedact
Mask employee IDs like EMP-123456Regular expression\bEMP-\d{6}\bRedact
Catch customer account numbersRegular expression\bACCT-\d{8}\bRedact
Flag a sensitive phrase for reviewTerm listinternal onlyObserve
What a redaction looks like
Before: Email [email protected] about account ACCT-20481977.
After:  Email [REDACTED_CUSTOM:email_address] about account [REDACTED_CUSTOM:account_number].

07

Limits that keep traffic fast

Rules run on a linear-time matcher, so no pattern can slow your traffic or stall other requests. To keep that guarantee, rules have bounds.

ItemLimitWhy
Terms per ruleUp to 10Keeps each rule focused
Length of a term or patternUp to 64 charactersKeeps matching predictable
Pattern featuresNo look-ahead and no back-referencesThese are what make matching unpredictable
Rules per profileDepends on your planSee pricing

08

Test and tune

Send a few sample prompts through a test key, then review the audit log after a few days in Observe.

  • Too many matches: tighten the pattern, or require whole words for a term
  • Missed matches: add a second rule for the other format, rather than one complex rule
  • A format that varies by country: add one rule per format, with clear IDs
  • Names and addresses in free text: add a provider safety scan, because pattern rules cannot understand meaning

09

As code

Teams that manage infrastructure in Terraform can keep guardrail profiles there.

main.tf
resource "cloptima_llm_guardrail_profile" "customer_data" {
  name = "Customer data protection"
  definition = jsonencode({
    input = {
      action    = "redact"
      detectors = { secret = {} }
      custom_rules = [
        { id = "employee_id", match = { regex = "\\bEMP-\\d{6}\\b" } },
        { id = "codename", match = { terms = ["Project Falcon"], whole_word = true }, action = "block" },
      ]
    }
    output = {
      action    = "redact"
      detectors = { secret = {} }
    }
  })
}

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial