Validate inputs, scan outputs, redact PII - all at the AI gateway layer, including MCP tool calls. Built for SOC 2 Type II, GDPR, and HIPAA compliance.
[ HOW GUARDRAILS WORK ]
Bifrost splits guardrails into profiles, which define how content is checked, and rules, which define when a check runs and on which phase. A rule can link several profiles, and a profile can serve many rules.
A profile configures one guardrail provider: local settings for Secrets Detection or Custom Regex, a judge model for Prompt Guardrails, or credentials and thresholds for an external service. Profiles are managed in the dashboard, the API, or config.json.
A rule holds a Common Expression Language expression, an apply_to phase (input, output, or both), a sampling rate, a timeout, and the linked profiles. Expressions read request metadata such as model, provider, headers, team, and the virtual key in use.
Requests can also name guardrails with the x-bf-guardrail-id header, or x-bf-guardrail-ids for several in sequence. A bifrost_config.guardrails body block sets separate input and output guardrails and selects synchronous or asynchronous validation.
A passing request returns HTTP 200 with guardrail metadata, including processing_time_ms per stage. A blocked request returns HTTP 446 with the violation type, severity, and stage, and a modified request, such as a redacted response, returns HTTP 246.
[ GUARDRAIL PROVIDERS ]
See how guardrails map to AI security risks.
[ DETECTION CAPABILITIES ]
From PII leakage to prompt injection attacks, Bifrost detects and prevents a wide range of security and compliance risks in real-time.
Detect and redact 50+ types of sensitive information including SSNs, credit cards, addresses, medical records, and device identifiers before they reach or leave the model.
50+ PII typesBlock or redact hate speech, sexual content, violence, self-harm, and profanity across inputs and outputs. Severity-based thresholds enable fine-grained control.
Multi-categoryProtect against direct and indirect prompt attacks, jailbreaks, and mutation attempts. Multiple providers offer layered defense against evolving attack vectors.
Multi-layeredIdentify when models generate factually incorrect or unsupported information. Patronus AI provides context-aware evaluation for high-stakes applications.
Context-awareAzure Content Safety detects copyrighted content and protected intellectual property in model outputs, helping organizations avoid legal exposure.
Copyright detectionDefine business-specific rules in natural language (GraySwan) or through configuration. Enforce brand safety, regulatory requirements, and internal compliance policies.
No-code rules[ MCP GUARDRAILS ]
MCP guardrails check the tool-execution boundary itself, so a block stops the tool from running, not only the call the model proposed. Rules set target to mcp and match on mcp_client, mcp_tool, and mcp_arguments.
An input rule inspects or redacts tool arguments before the tool runs. A block stops the call before any side effect occurs.
An output rule allows, redacts, or withholds a successful tool result, so secrets and personal data never enter the agent's context.
Link any guardrail provider to MCP rules without extra setup. Agent and LLM rules share profiles, sampling, and timeouts on the same MCP gateway.
[ IMPLEMENTATION ]
Configure providers, define rules, and attach to requests. Full validation in minutes.
Set up guardrail provider profiles through the dashboard or API. Configure credentials, detection thresholds, and category filters for each provider.
# Via dashboard: Guardrails > Providers
# Or via config.json
{
"guardrail_providers": [{
"id": "bedrock-prod",
"type": "aws_bedrock",
"region": "us-east-1",
"guardrail_id": "your-guardrail-id",
"version": "DRAFT"
}]
}Define when and how to validate requests using CEL expressions. Rules can apply to specific routes, models, virtual keys, or user attributes.
# Via dashboard: Guardrails > Configuration
# Or via config.json
{
"guardrail_rules": [{
"id": "customer-safety",
"condition": "request.path.startsWith('/v1/chat')",
"input_profiles": ["bedrock-prod"],
"output_profiles": ["patronus-ai"],
"action": "BLOCK"
}]
}Apply guardrails via request headers or inline configuration. Bifrost validates inputs before sending to the model and outputs before returning to the client.
curl https://your-gateway/v1/chat/completions \
-H "x-bf-guardrail-id: customer-safety" \
-H "Authorization: Bearer vk-..." \
-d '{
"model": "gpt-4",
"messages": [{"role": "user", "content": "..."}]
}'[ RESPONSE HANDLING ]
Bifrost returns distinct HTTP status codes for pass, block, or warning responses with detailed violation metadata.
HTTP 200
Validation succeeded. Request processed normally with detailed guardrail metadata including processing times and rule results.
HTTP 446
Violations detected and request blocked. Response includes violation details, severity levels, and affected content excerpts for audit trails.
HTTP 246
Violations detected but content modified (PII redacted) rather than blocked. Includes redaction counts and modification details.
[ ENTERPRISE FEATURES ]
Advanced features for performance optimization, compliance, and operational flexibility.
Apply guardrails to a percentage of requests for performance optimization while maintaining statistical confidence.
Choose synchronous or asynchronous validation modes. Async reduces latency for non-critical checks.
Link multiple provider profiles to single rules for sequential validation and comprehensive protection.
Detailed audit trails capture every validation with timestamps, results, and violation details for compliance.
Set maximum execution duration per rule to prevent guardrail latency from impacting user experience.
Deploy guardrails across 13 AWS regions. Azure Content Safety profiles can target region-specific endpoints for data residency compliance.
[ USE CASES ]
Prevent PHI leakage in patient-facing chatbots. AWS Bedrock detects medical record numbers, health plan IDs, and clinical notes before they leave the model.
Block credit card numbers, SSNs, and account details in banking applications. Multi-provider validation ensures no sensitive data escapes detection.
Protect against adversarial inputs attempting to override system instructions. GraySwan and Azure Prompt Shield detect mutation attempts and indirect attacks.
Filter user-generated content in social platforms. Severity-based thresholds allow nuanced handling of hate speech, violence, and sexual content.
Validate factual accuracy in high-stakes applications like legal research or medical advice. Patronus AI detects unsupported claims and inconsistencies.
Define custom organizational policies in natural language. Ensure model outputs align with brand voice, values, and regulatory requirements.
[ COMPLIANCE FRAMEWORKS ]
Bifrost Guardrails help organizations meet regulatory requirements with automated detection, redaction, and comprehensive audit trails.

Comprehensive audit trails and access controls for guardrail enforcement

Personal data protection and right-to-erasure compliance

Information security management and certification alignment

PHI detection and redaction for healthcare applications
[ WHAT'S NEXT ]
Continue with governance, guardrails, MCP, and the rest of the resource library.
Enforce PII redaction, secrets detection, and prompt injection guardrails on every LLM request and agent tool call from one gateway.
Access ControlVirtual keys, budgets, rate limits, routing, and enterprise RBAC with SSO.
MCPHigh-performance tool execution for AI agents with approvals and audit trails.
[ BIFROST FEATURES ]
Everything you need to run AI in production, from free open source to enterprise-grade features.
01 Governance
SAML support for SSO and Role-based access control and policy enforcement for team collaboration.
02 Adaptive Load Balancing
Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.
03 Cluster Mode
High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.
04 Alerts
Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.
05 Log Exports
Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.
06 Audit Logs
Comprehensive logging and audit trails for compliance and debugging.
07 Vault Support
Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.
08 VPC Deployment
Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.
09 Guardrails
Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.
[ SHIP RELIABLE AI ]
Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.
[ FREQUENTLY ASKED QUESTIONS ]
AI guardrails are checks that run on the prompts sent to a language model and on the responses it returns, and that allow, block, or modify content according to a policy. Bifrost runs them at the AI gateway, so one set of rules covers every application and provider routed through it, including MCP tool calls made by agents.
Common AI guardrails include PII redaction, prompt injection and jailbreak detection, secrets detection, toxicity filtering, hallucination detection, and organization-specific policies such as blocking definitive medical diagnoses. Bifrost supports each through its managed providers and external services such as AWS Bedrock Guardrails, Azure Content Safety, Google Model Armor, and Patronus AI.
The right combination depends on the risk being controlled: Secrets Detection and Custom Regex suit known formats, PII services such as Presidio suit personal data, and model-based services suit prompt injection and semantic policies. Bifrost links several profiles to one rule for layered checks, and this comparison of guardrail platforms for prompt injection covers the options further.
Guardrails add the processing time of each linked profile, which Bifrost reports as processing_time_ms in the response metadata. Secrets Detection and Custom Regex run in-process with no external call, while external providers add a network round-trip. Sampling rates, per-rule timeouts, and asynchronous validation limit the effect on high-traffic endpoints.
Bifrost redacts PII for providers that support Bifrost-managed redaction: Custom Regex, Secrets Detection, Microsoft Presidio, Azure AI Language PII, Check Point's AI Agent Security, and Singulr AI. The runtime_reversible mode replaces values with reversible placeholders, and a walkthrough of PII and injection guardrails shows the modes in practice.
Each rule carries a CEL expression evaluated against request metadata: model, provider, headers, virtual key, team, customer, and user for LLM traffic, or MCP client, tool, and arguments for tool calls. A rule such as team == "team-platform" applies only to that team's requests, so guardrail policy follows the same identities used for budgets.