AI Guardrails You Control: Secrets, Personal Data & Safety Scans on the Request Path
Cloptima detects credentials in prompts and responses, applies the personal-data rules you define, and routes content to Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or your own webhook — with per-request cost caps, a fail-safe choice, and versioned, audited profiles.
Guardrails shouldn't be a one-size-fits-all switch
Most gateway guardrails are all-or-nothing and tuned by the vendor, so teams get surprise blocks on their own legitimate traffic, or lack the coverage their region requires. Heavy safety scans also add cost and latency to every call. Teams need guardrails they define, can roll out safely, and can afford at scale.
- Vendor-tuned defaults block legitimate traffic you never asked to block
- Personal-data formats differ by country, so one global detector rarely fits
- Heavy semantic scans add cost and latency on every call
- Guardrail changes need an owner, a version history, and an audit trail
Your profiles, merged by strictest rule
A guardrail profile defines what happens to prompts and responses independently: observe, redact, or block. Cloptima ships built-in detection for credentials — API keys and tokens from major vendors, private keys, and secret assignments. For personal data you add your own rules, as terms or regular expressions, starting from US or EU templates. Mark one profile as your organization baseline and it applies to every policy; a team's profile can add protection but never weaken it. Rules run on a linear-time matcher, so a pattern cannot slow your traffic. For deeper checks — prompt injection, jailbreak, harmful content, sensitive-information entities — add Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or your own webhook on the same request path.
- Built-in credential detection for major cloud, AI, and developer platforms
- Your own rules for personal data and business terms, with US and EU starter templates
- Separate actions for prompts and responses: observe, redact, or block
- An organization baseline that teams can tighten but never loosen
- Azure AI Content Safety, AWS Bedrock Guardrails, Google Model Armor, or a webhook — on your own account or Cloptima-funded
- Responses are inspected as they stream
- Profile changes publish at once, are versioned, and appear in the audit log
Observe first, then redact, then block
Start from the Monitor-only template as your organization baseline and review what it finds for a week in the audit log. Then switch secrets to redact, add your personal-data rules, and move to block for the cases that must never reach a model.
Cost and latency stay in your hands
Built-in and custom rules run inside the gateway with no extra network call. When you add a provider scan, you can cap its list-price cost per request, choose whether a request over the cap skips the scan or is blocked, and skip the scan when a request is already slow. If the provider cannot be reached, you choose the policy: fail closed (block, the default) or fail open (continue on your own rules). You decide what is checked, and nothing else is.
Drop-In Integration in Seconds
Standard OpenAI and Anthropic protocol compatible. Point your existing client to the gateway and attach attribution headers.
curl https://api.cloptima.ai/v1/ai/chat/completions \
-H "Authorization: Bearer $CLOPTIMA_PAT" \
-H "X-Cloptima-Team: security" \
-H "X-Cloptima-App: customer-support-agent" \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-5.6",
"messages": [{"role": "user", "content": "Debug this config: api_key = abc123def456ghi789"}]
}'
# The bound guardrail profile checks the prompt before it reaches the provider:
# HTTP/1.1 403 Forbidden
# {"error": "Your AI request was blocked because it matched a configured safety rule.", "reason": "gateway_guardrail_blocked", "violations": ["secret_assignment"]}Compare Cloptima AI Gateway
See how Cloptima combines hot-path gateway controls with enterprise FinOps and cost reconciliation.
Cloptima vs LiteLLM
OpenAI-compatible gateway routing vs. full FinOps control plane, attribution, and hot-path team budget limits.
Cloptima vs Portkey
Routing and guardrails vs. pre-flight budget enforcement, finance ledger, and p95 7–15ms end-to-end latency.
Cloptima vs Cloudflare AI Gateway
Edge proxying vs. enterprise attribution, team quota enforcement, and provider bill matching.
Cloptima vs Helicone
LLM observability logs vs. active request-path budget controls, response caching, and unit economics.
Launch path
Create a profile from a template, make it your organization baseline, optionally add a provider integration and a per-request cost cap, attach profiles to policies, and watch findings in the audit log.
FAQ
Operationalize LLM FinOps Across Your Apps
Start with telemetry, gateway governance, or provider bill matching workflows. Keep model spend connected to engineering ownership and finance reporting.