Enforce PII redaction, secrets detection, and prompt injection guardrails on every model request and agent tool call from one AI gateway: Bifrost (by Maxim AI).
[ PERFORMANCE AT A GLANCE ]
[ THE PROBLEM ]
Per-app security code works for one or two services; consolidate it at the gateway as agents and tool integrations multiply.
PII filtering, credential scanning, and prompt screening live in each service's code, so coverage diverges as implementations are maintained independently.
Agents pass model-generated arguments to tools and feed results back to the model, so output from any connected MCP server can carry indirect prompt injection into the next call.
Prompts can contain customer records or API keys, and without detection in the request path that text reaches the provider and application logs.
Each application holds its own provider keys, so access cannot be scoped or revoked centrally.
[ THE QUESTIONS ]
Map each question a security review raises about LLM apps and agents to the Bifrost control that answers it.
| Question your team is asking | How Bifrost answers it | Capability |
|---|---|---|
| Can we stop PII from reaching model providers? | Detects emails, phone numbers, SSNs, and similar entities, then blocks or redacts before forwarding | PII redaction |
| Can we stop API keys and credentials leaking into prompts or responses? | Scans request and response text with 222 Gitleaks default rules and blocks or redacts matches | Secrets Detection |
| How do we block prompt injection and jailbreaks? | Evaluates inputs with guardrail providers such as AWS Bedrock Guardrails, Google Model Armor, and CrowdStrike AIDR | Guardrails |
| Do the same checks apply to agent tool calls? | MCP rules inspect tool arguments before execution and tool results before they return | MCP guardrails |
| Which tools can an agent call? | Filters stack at client, request, and virtual key level; an empty client list exposes no tools | Tool filtering |
| Who can call which models, and how much? | Each virtual key carries allowed providers and models, budgets, and rate limits | Virtual keys |
| Who changed a guardrail or access policy, and when? | Records administrative activity as HMAC-signed events, exportable and archivable to S3 or GCS | Audit logs |
| Does prompt and response data leave our network? | Runs inside your VPC or air-gapped, with no traffic over the public internet | In-VPC deployments |
| Does Bifrost secure model training data or weights? | The gateway governs traffic to and from models; training pipelines are secured in the ML platform | Outside gateway scope |
[ THREAT MODEL ]
Check each OWASP Top 10 for LLM Applications risk against the control Bifrost enforces, and see what sits outside gateway scope.
| Risk (OWASP 2025) | Gateway control | Coverage |
|---|---|---|
| Prompt injection, including indirect injection in tool results | Input guardrail rules on model requests; output rules on MCP tool results | Enforced at gateway (detection depends on provider) |
| Sensitive information disclosure | PII and secrets detection with runtime, logs-only, or reversible redaction | Enforced at gateway |
| Excessive agency | Tool filtering, virtual MCPs, and MCP guardrails before execution | Enforced at gateway |
| Unbounded consumption | Budgets and rate limits per virtual key, team, and customer | Enforced at gateway |
| Improper output handling | Output guardrail rules can block or redact responses | Shared: the application still validates output it executes |
| Misinformation | Hallucination detection through the Patronus AI profile | Shared: grounding and evaluation sit in the application |
| Supply chain, data and model poisoning | None | Outside gateway scope: model provider and ML pipeline |
| Vector and embedding weaknesses | None | Outside gateway scope: retrieval store access controls |
[ HOW IT WORKS ]
Route model requests and MCP tool calls through Bifrost to apply virtual keys, guardrail rules, and tool filters before traffic reaches providers.
Change one base URL as a drop-in replacement; keep the existing SDK.
Define policy once and apply it to every caller of the gateway.
[ CORE CAPABILITIES ]
Configure each control once in the Bifrost dashboard or config file, and apply it to every request.
PII redaction uses the Custom Regex PII Detection template, Presidio, or Azure AI Language PII. The logs_only mode leaves the live call unchanged and redacts Bifrost logs and trace-export content.
Runtime, logs, or bothSecrets Detection runs inside Bifrost with no external service, finds API keys, access tokens, and private keys in request and response text, and detects, blocks, or redacts them.
222 Gitleaks rulesGuardrail rules link to profiles from AWS Bedrock Guardrails, Azure Content Safety, Google Model Armor, Check Point's AI Agent Security, and other providers. Prompt Guardrails enforce your written policies with an LLM judge.
3 managed + 11 externalMCP guardrail rules run at the tool-execution boundary and can target a client, tool, or argument. An input block stops the tool before it runs; an output block keeps the result from the model.
Arguments and resultsTool filtering limits each agent to approved tools, and a tool must pass every filter level. Virtual MCPs bundle curated tools behind one endpoint attached to virtual keys.
Client, request, VKVirtual keys scope models, providers, budgets, and rate limits per caller. Audit logs record administrative changes as signed events, exportable as JSON, JSON Lines, or Syslog.
HMAC-signed events[ GUARDRAIL PROVIDERS ]
[ COMPARISON ]
| Capability | AI agents alone | AI agents + Bifrost |
|---|---|---|
| PII handling | Implemented per application where needed | Detect, block, or redact on every request |
| Credential leakage | Depends on each service's scanning | Gitleaks-backed detection on inputs and outputs |
| Prompt injection screening | Per-application integration with a screening service | Guardrail profiles shared across all traffic |
| Tool-call inspection | Handled inside each agent framework | Guardrails on tool arguments and results |
| Tool access | Defined in each agent's configuration | Filtered by client, request, and virtual key |
| Model access and spend | Provider keys held in each service | Virtual keys with budgets and rate limits |
| Provider key storage | Environment variables per service | Resolved at runtime from AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault |
| Policy change history | Spread across repositories and consoles | Signed audit logs in one place |
[ USE CASES ]
One PII and secrets policy applies to every application behind the gateway, so a security review checks one rule set.
Each team's agents receive a virtual MCP of approved tools, and MCP guardrails inspect arguments before write actions run.
Healthcare and financial services teams run Bifrost in-VPC or air-gapped and redact regulated fields from prompts, logs, and exported traces.
CLI coding agents route through virtual keys, so secrets detection and budgets apply to terminal traffic too.
[ GOVERNANCE & COMPLIANCE ]
Bifrost is built for enterprises running mission-critical AI workloads that require top-tier performance, scalability, and reliability.
Multiple Fortune 500 companies in financial services, healthcare, technology, pharmaceuticals, and defense run it in production. Bifrost Enterprise adds the controls below to the AI guardrails platform.




SOC 2 Type II · ISO 27001 · HIPAA · GDPR
RBAC defines what each role can change, and data access control limits which guardrail configurations, keys, and MCP clients each role sees.
User provisioning connects Okta, Microsoft Entra, Google Workspace, and other OIDC providers, so access follows the directory.
Secret management resolves provider keys, virtual key values, and MCP auth headers from AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault at runtime.
Bifrost runs in your VPC, on-premises, or fully disconnected, and no prompts, responses, files, or telemetry leave your environment.
[ GO DEEPER ]
Rules, profiles, and guardrail providers across every request and response.
SecurityConfiguring guardrail providers and rules for production LLM workloads.
Access ControlVirtual keys, budgets, and role-based access for teams using LLMs.
GuideHow gateway redaction keeps personal data away from model providers.
ChecklistEnterprise checklist for authenticating, filtering, and auditing MCP tool access.
[ WHAT'S NEXT ]
Continue with governance, guardrails, MCP, and the rest of the resource library.
[ BIFROST FEATURES ]
Everything you need to run AI in production, from free open source to enterprise-grade features.
01 Governance
SAML support for SSO and Role-based access control and policy enforcement for team collaboration.
02 Adaptive Load Balancing
Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.
03 Cluster Mode
High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.
04 Alerts
Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.
05 Log Exports
Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.
06 Audit Logs
Comprehensive logging and audit trails for compliance and debugging.
07 Vault Support
Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.
08 VPC Deployment
Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.
09 Guardrails
Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.
[ SHIP RELIABLE AI ]
Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.
[ FAQ ]
Bifrost secures AI agents by routing their model requests and MCP tool calls through one AI gateway that applies guardrail rules, tool filters, and access limits. A typical setup gives each agent a virtual MCP of approved tools, redacts PII and secrets in both directions, and screens inputs and tool results for prompt injection.
Bifrost secures agent access with virtual keys, which scope the providers, models, budgets, and rate limits each agent can use. Tool access is filtered at client, request, and virtual key level, and MCP authentication supports per-user OAuth so each person connects under their own account.
The OWASP Top 10 for LLM Applications lists prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. Bifrost enforces controls for prompt injection, sensitive information disclosure, excessive agency, and unbounded consumption at the gateway.
Bifrost inspects MCP tool results with output guardrail rules before they return to the model. Detection comes from the linked provider: Azure Content Safety, Google Model Armor, and Gray Swan support indirect prompt injection detection, and several others support it depending on policy. An output block keeps the result out of the model's context.
Bifrost adds about 11µs of overhead per request at 5,000 RPS in sustained benchmarks. Guardrail providers add their own evaluation time, which is lowest for in-process checks such as Secrets Detection and Custom Regex. Rules can be sampled to a percentage of requests, and detect-only rules do not delay streaming.
Bifrost starts with `npx -y @maximhq/bifrost` or `docker run -p 8080:8080 maximhq/bifrost`, and existing applications need one base URL change because the gateway is OpenAI-compatible. Most teams route traffic the same day and then add guardrail rules, tool filters, and virtual keys from the dashboard.
Bifrost's open-source core, licensed under Apache 2.0, includes virtual keys, budgets and rate limits, MCP tool filtering, and virtual MCPs. Bifrost Enterprise adds guardrails (PII redaction, secrets detection, prompt injection providers), signed audit logs, RBAC, data access control, SSO, secret management, and in-VPC deployment support, with a free 14-day trial.