On this page
01
What you'll set up
You will add rules to a guardrail profile that catch the personal data and business terms that matter to you, test them against sample text, and tune them until they catch what you intend.
- Rules created from a regional template
- A custom rule of your own, by terms and by pattern
- A redact-or-block choice for each rule
- A tuning loop that keeps false matches low
You need a guardrail profile first. If you do not have one, start with the guide on creating your first guardrail profile.
02
Why the rules are yours
Credential formats are the same everywhere, so Cloptima detects them for you. Personal data is different. Formats vary by country, and what counts as sensitive depends on your business.
Built in
- API keys, tokens, private keys, password assignments
- The same everywhere
Your rules
- National IDs, phone numbers, customer identifiers, internal codenames
- Defined by you, tuned to your data
03
Start from a regional template
Create a profile from the US or European personal data template. Each includes editable rules and the credential rules for both prompts and responses.
| Template | Rules included |
|---|---|
| US personal data redaction | Email addresses, Social Security numbers, US phone numbers, card-like numbers |
| European personal data redaction | Email addresses, IBANs, +3x and +4x phone numbers, card-like numbers |
04
Terms or a pattern
A rule matches either a list of terms or one regular expression. Choose by what you are looking for.
| Use | When | Behaves like |
|---|---|---|
| Term list | Fixed words and names, such as codenames | Case-insensitive by default. Whole words can be required. |
| Regular expression (RE2) | Formats, such as IDs and host names | Case-sensitive by default. No look-ahead or back-references. |
05
Add a rule
In the profile editor, add a custom rule under Prompts, Responses, or both.
- 1
Give the rule an ID
Use lowercase letters, digits, and underscores, such as project_codenames. Each ID is unique within a side.
- 2
Choose how it matches
Pick Term list or Regular expression (RE2).
- 3
Choose On match
Use Stage action to follow the side's action, or set Observe, Redact, or Block for this rule alone.
- 4
Enter the terms or the pattern
Terms go one per line. A pattern goes in the Pattern field.
- 5
Set the toggles
Case sensitive and Whole words change how matches work. Whole words needs each term to start and end with a letter, digit, or underscore.
- 6
Save
The rule is live as soon as the profile is saved.
- 1Rule ID
- project_codenames
- 2Match
- Term list
- 3On match
- Stage action
- 4Terms (one per line)
- project falcon internal-only
- 5Case sensitive
- Off matches any letter case.Off
- 5Whole words
- Skips matches inside longer words. Each term must start and end with an ASCII letter, digit, or underscore.On
06
Examples you can adapt
These cover the patterns teams ask for most.
| Goal | Match | Rule | On match |
|---|---|---|---|
| Keep a project codename out of prompts | Term list, whole words | Project Falcon | Block |
| Mask internal host names | Regular expression | \b[a-z0-9-]+\.corp\.example\.com\b | Redact |
| Mask employee IDs like EMP-123456 | Regular expression | \bEMP-\d{6}\b | Redact |
| Catch customer account numbers | Regular expression | \bACCT-\d{8}\b | Redact |
| Flag a sensitive phrase for review | Term list | internal only | Observe |
Before: Email [email protected] about account ACCT-20481977.
After: Email [REDACTED_CUSTOM:email_address] about account [REDACTED_CUSTOM:account_number].07
Limits that keep traffic fast
Rules run on a linear-time matcher, so no pattern can slow your traffic or stall other requests. To keep that guarantee, rules have bounds.
| Item | Limit | Why |
|---|---|---|
| Terms per rule | Up to 10 | Keeps each rule focused |
| Length of a term or pattern | Up to 64 characters | Keeps matching predictable |
| Pattern features | No look-ahead and no back-references | These are what make matching unpredictable |
| Rules per profile | Depends on your plan | See pricing |
08
Test and tune
Send a few sample prompts through a test key, then review the audit log after a few days in Observe.
- Too many matches: tighten the pattern, or require whole words for a term
- Missed matches: add a second rule for the other format, rather than one complex rule
- A format that varies by country: add one rule per format, with clear IDs
- Names and addresses in free text: add a provider safety scan, because pattern rules cannot understand meaning
09
As code
Teams that manage infrastructure in Terraform can keep guardrail profiles there.
resource "cloptima_llm_guardrail_profile" "customer_data" {
name = "Customer data protection"
definition = jsonencode({
input = {
action = "redact"
detectors = { secret = {} }
custom_rules = [
{ id = "employee_id", match = { regex = "\\bEMP-\\d{6}\\b" } },
{ id = "codename", match = { terms = ["Project Falcon"], whole_word = true }, action = "block" },
]
}
output = {
action = "redact"
detectors = { secret = {} }
}
})
}