Guardrails

AI Guardrails You Control: Secrets, Personal Data & Safety Scans on the Request Path

Cloptima detects credentials in prompts and responses, applies the personal-data rules you define, and routes content to Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or your own webhook — with per-request cost caps, a fail-safe choice, and versioned, audited profiles.

app.cloptima.ai/llm/policies
Guardrail cost governance
Last 7 days · production policies
Illustrative
Requests scanned
1.8M
Blocked before egress
212
Recent guardrail events
Secret detected in prompt
app=support-ai · blocked
Blocked
Email address redacted
profile v3 · custom rule email_address
Redacted
Provider scan skipped
cost cap exceeded, request continued
Skipped

Guardrails shouldn't be a one-size-fits-all switch

Most gateway guardrails are all-or-nothing and tuned by the vendor, so teams get surprise blocks on their own legitimate traffic, or lack the coverage their region requires. Heavy safety scans also add cost and latency to every call. Teams need guardrails they define, can roll out safely, and can afford at scale.

  • Vendor-tuned defaults block legitimate traffic you never asked to block
  • Personal-data formats differ by country, so one global detector rarely fits
  • Heavy semantic scans add cost and latency on every call
  • Guardrail changes need an owner, a version history, and an audit trail

Your profiles, merged by strictest rule

A guardrail profile defines what happens to prompts and responses independently: observe, redact, or block. Cloptima ships built-in detection for credentials — API keys and tokens from major vendors, private keys, and secret assignments. For personal data you add your own rules, as terms or regular expressions, starting from US or EU templates. Mark one profile as your organization baseline and it applies to every policy; a team's profile can add protection but never weaken it. Rules run on a linear-time matcher, so a pattern cannot slow your traffic. For deeper checks — prompt injection, jailbreak, harmful content, sensitive-information entities — add Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or your own webhook on the same request path.

  • Built-in credential detection for major cloud, AI, and developer platforms
  • Your own rules for personal data and business terms, with US and EU starter templates
  • Separate actions for prompts and responses: observe, redact, or block
  • An organization baseline that teams can tighten but never loosen
  • Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or a webhook — on your own account or Cloptima-funded
  • Responses are inspected as they stream
  • Profile changes publish at once, are versioned, and appear in the audit log

Observe first, then redact, then block

Start from the Monitor-only template as your organization baseline and review what it finds for a week in the audit log. Then switch secrets to redact, add your personal-data rules, and move to block for the cases that must never reach a model.

Cost and latency stay in your hands

Built-in and custom rules run inside the gateway with no extra network call. When you add a provider scan, you can cap its list-price cost per request, choose whether a request over the cap skips the scan or is blocked, and skip the scan when a request is already slow. If the provider cannot be reached, you choose the policy: fail closed (block, the default) or fail open (continue on your own rules). You decide what is checked, and nothing else is.

Developer Quickstart

Drop-In Integration in Seconds

Standard OpenAI and Anthropic protocol compatible. Point your existing client to the gateway and attach attribution headers.

bash
curl https://api.cloptima.ai/v1/ai/chat/completions \
  -H "Authorization: Bearer $CLOPTIMA_PAT" \
  -H "X-Cloptima-Team: security" \
  -H "X-Cloptima-App: customer-support-agent" \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-5.6",
    "messages": [{"role": "user", "content": "Debug this config: api_key = abc123def456ghi789"}]
  }'

# The bound guardrail profile checks the prompt before it reaches the provider:
# HTTP/1.1 403 Forbidden
# {"error": "Your AI request was blocked because it matched a configured safety rule.", "reason": "gateway_guardrail_blocked", "violations": ["secret_assignment"]}

Launch path

Create a profile from a template, make it your organization baseline, optionally add a provider integration and a per-request cost cap, attach profiles to policies, and watch findings in the audit log.

FAQ

Operationalize LLM FinOps Across Your Apps

Start with telemetry, gateway governance, or provider bill matching workflows. Keep model spend connected to engineering ownership and finance reporting.

No credit card required
5-minute setup
Free trial