Try Bifrost Enterprise free for 14 days.
Request access
[ BIFROST GUARDRAILS ]

AI Guardrails for Every Model
Request and MCP Tool Call

Validate inputs, scan outputs, redact PII - all at the AI gateway layer, including MCP tool calls. Built for SOC 2 Type II, GDPR, and HIPAA compliance.

[ HOW GUARDRAILS WORK ]

How AI Guardrails Work in Bifrost

Bifrost splits guardrails into profiles, which define how content is checked, and rules, which define when a check runs and on which phase. A rule can link several profiles, and a profile can serve many rules.

Step 01

Create a profile

A profile configures one guardrail provider: local settings for Secrets Detection or Custom Regex, a judge model for Prompt Guardrails, or credentials and thresholds for an external service. Profiles are managed in the dashboard, the API, or config.json.

Step 02

Write a rule in CEL

A rule holds a Common Expression Language expression, an apply_to phase (input, output, or both), a sampling rate, a timeout, and the linked profiles. Expressions read request metadata such as model, provider, headers, team, and the virtual key in use.

Step 03

Attach guardrails to requests

Requests can also name guardrails with the x-bf-guardrail-id header, or x-bf-guardrail-ids for several in sequence. A bifrost_config.guardrails body block sets separate input and output guardrails and selects synchronous or asynchronous validation.

Step 04

Read the validation outcome

A passing request returns HTTP 200 with guardrail metadata, including processing_time_ms per stage. A blocked request returns HTTP 446 with the violation type, severity, and stage, and a modified request, such as a redacted response, returns HTTP 246.

[ GUARDRAIL PROVIDERS ]

See how guardrails map to AI security risks.

[ DETECTION CAPABILITIES ]

Comprehensive Protection Across Attack Vectors

From PII leakage to prompt injection attacks, Bifrost detects and prevents a wide range of security and compliance risks in real-time.

PII leakage prevention

Detect and redact 50+ types of sensitive information including SSNs, credit cards, addresses, medical records, and device identifiers before they reach or leave the model.

50+ PII types

Content safety filtering

Block or redact hate speech, sexual content, violence, self-harm, and profanity across inputs and outputs. Severity-based thresholds enable fine-grained control.

Multi-category

Prompt injection defense

Protect against direct and indirect prompt attacks, jailbreaks, and mutation attempts. Multiple providers offer layered defense against evolving attack vectors.

Multi-layered

Hallucination detection

Identify when models generate factually incorrect or unsupported information. Patronus AI provides context-aware evaluation for high-stakes applications.

Context-aware

Protected material screening

Azure Content Safety detects copyrighted content and protected intellectual property in model outputs, helping organizations avoid legal exposure.

Copyright detection

Custom organizational policies

Define business-specific rules in natural language (GraySwan) or through configuration. Enforce brand safety, regulatory requirements, and internal compliance policies.

No-code rules

[ MCP GUARDRAILS ]

MCP Guardrails for Agent Tool Calls

MCP guardrails check the tool-execution boundary itself, so a block stops the tool from running, not only the call the model proposed. Rules set target to mcp and match on mcp_client, mcp_tool, and mcp_arguments.

Inspect arguments before execution

An input rule inspects or redacts tool arguments before the tool runs. A block stops the call before any side effect occurs.

Inspect results before they return

An output rule allows, redacts, or withholds a successful tool result, so secrets and personal data never enter the agent's context.

Reuse the same profiles

Link any guardrail provider to MCP rules without extra setup. Agent and LLM rules share profiles, sampling, and timeouts on the same MCP gateway.

[ IMPLEMENTATION ]

Three Steps to Production Guardrails

Configure providers, define rules, and attach to requests. Full validation in minutes.

STEP 01

Configure guardrail providers

Set up guardrail provider profiles through the dashboard or API. Configure credentials, detection thresholds, and category filters for each provider.

# Via dashboard: Guardrails > Providers
# Or via config.json
{
  "guardrail_providers": [{
    "id": "bedrock-prod",
    "type": "aws_bedrock",
    "region": "us-east-1",
    "guardrail_id": "your-guardrail-id",
    "version": "DRAFT"
  }]
}
STEP 02

Create validation rules

Define when and how to validate requests using CEL expressions. Rules can apply to specific routes, models, virtual keys, or user attributes.

# Via dashboard: Guardrails > Configuration
# Or via config.json
{
  "guardrail_rules": [{
    "id": "customer-safety",
    "condition": "request.path.startsWith('/v1/chat')",
    "input_profiles": ["bedrock-prod"],
    "output_profiles": ["patronus-ai"],
    "action": "BLOCK"
  }]
}
STEP 03

Attach to requests

Apply guardrails via request headers or inline configuration. Bifrost validates inputs before sending to the model and outputs before returning to the client.

curl https://your-gateway/v1/chat/completions \
  -H "x-bf-guardrail-id: customer-safety" \
  -H "Authorization: Bearer vk-..." \
  -d '{
    "model": "gpt-4",
    "messages": [{"role": "user", "content": "..."}]
  }'

[ RESPONSE HANDLING ]

Validation Outcomes

Bifrost returns distinct HTTP status codes for pass, block, or warning responses with detailed violation metadata.

Pass

HTTP 200

Validation succeeded. Request processed normally with detailed guardrail metadata including processing times and rule results.

Block

HTTP 446

Violations detected and request blocked. Response includes violation details, severity levels, and affected content excerpts for audit trails.

Warning

HTTP 246

Violations detected but content modified (PII redacted) rather than blocked. Includes redaction counts and modification details.

[ ENTERPRISE FEATURES ]

Production-Grade Guardrail Controls

Advanced features for performance optimization, compliance, and operational flexibility.

Sampling control

Apply guardrails to a percentage of requests for performance optimization while maintaining statistical confidence.

Async processing

Choose synchronous or asynchronous validation modes. Async reduces latency for non-critical checks.

Defense-in-depth

Link multiple provider profiles to single rules for sequential validation and comprehensive protection.

Comprehensive logging

Detailed audit trails capture every validation with timestamps, results, and violation details for compliance.

Timeout configuration

Set maximum execution duration per rule to prevent guardrail latency from impacting user experience.

Multi-region support

Deploy guardrails across 13 AWS regions. Azure Content Safety profiles can target region-specific endpoints for data residency compliance.

[ USE CASES ]

AI Guardrails for Enterprise AI Workloads

Healthcare HIPAA compliance

Prevent PHI leakage in patient-facing chatbots. AWS Bedrock detects medical record numbers, health plan IDs, and clinical notes before they leave the model.

Financial PII protection

Block credit card numbers, SSNs, and account details in banking applications. Multi-provider validation ensures no sensitive data escapes detection.

Prompt injection defense

Protect against adversarial inputs attempting to override system instructions. GraySwan and Azure Prompt Shield detect mutation attempts and indirect attacks.

Content moderation for UGC

Filter user-generated content in social platforms. Severity-based thresholds allow nuanced handling of hate speech, violence, and sexual content.

Hallucination prevention

Validate factual accuracy in high-stakes applications like legal research or medical advice. Patronus AI detects unsupported claims and inconsistencies.

Brand safety enforcement

Define custom organizational policies in natural language. Ensure model outputs align with brand voice, values, and regulatory requirements.

[ COMPLIANCE FRAMEWORKS ]

Built for Regulatory Compliance

Bifrost Guardrails help organizations meet regulatory requirements with automated detection, redaction, and comprehensive audit trails.

AICPA SOC

SOC 2 Type II

Comprehensive audit trails and access controls for guardrail enforcement

GDPR

GDPR

Personal data protection and right-to-erasure compliance

ISO 27001

ISO 27001

Information security management and certification alignment

HIPAA

HIPAA

PHI detection and redaction for healthcare applications

Ready to Deploy Production Guardrails?

Protect your LLM applications with multi-provider guardrails, real-time validation, and comprehensive compliance controls.

[ BIFROST FEATURES ]

Open Source & Enterprise

Everything you need to run AI in production, from free open source to enterprise-grade features.

01 Governance

SAML support for SSO and Role-based access control and policy enforcement for team collaboration.

02 Adaptive Load Balancing

Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.

03 Cluster Mode

High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.

04 Alerts

Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook and more.

05 Log Exports

Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export capabilities for compliance, monitoring, and analytics.

06 Audit Logs

Comprehensive logging and audit trails for compliance and debugging.

07 Vault Support

Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.

08 VPC Deployment

Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls.

09 Guardrails

Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents.

[ SHIP RELIABLE AI ]

Try Bifrost Enterprise with a 14-day Free Trial

[quick setup]

Drop-in replacement for any AI SDK

Change just one line of code. Works with OpenAI, Anthropic, Vercel AI SDK, LangChain, and more.

1import os
2from anthropic import Anthropic
3
4anthropic = Anthropic(
5 api_key=os.environ.get("ANTHROPIC_API_KEY"),
6 base_url="https://<bifrost_url>/anthropic",
7)
8
9message = anthropic.messages.create(
10 model="claude-3-5-sonnet-20241022",
11 max_tokens=1024,
12 messages=[
13 {"role": "user", "content": "Hello, Claude"}
14 ]
15)
Drop in once, run everywhere.

[ FREQUENTLY ASKED QUESTIONS ]

Common Questions

What are AI guardrails?

AI guardrails are checks that run on the prompts sent to a language model and on the responses it returns, and that allow, block, or modify content according to a policy. Bifrost runs them at the AI gateway, so one set of rules covers every application and provider routed through it, including MCP tool calls made by agents.

What are examples of AI guardrails?

Common AI guardrails include PII redaction, prompt injection and jailbreak detection, secrets detection, toxicity filtering, hallucination detection, and organization-specific policies such as blocking definitive medical diagnoses. Bifrost supports each through its managed providers and external services such as AWS Bedrock Guardrails, Azure Content Safety, Google Model Armor, and Patronus AI.

What are the best guardrails for LLM apps?

The right combination depends on the risk being controlled: Secrets Detection and Custom Regex suit known formats, PII services such as Presidio suit personal data, and model-based services suit prompt injection and semantic policies. Bifrost links several profiles to one rule for layered checks, and this comparison of guardrail platforms for prompt injection covers the options further.

Do guardrails add latency to LLM requests?

Guardrails add the processing time of each linked profile, which Bifrost reports as processing_time_ms in the response metadata. Secrets Detection and Custom Regex run in-process with no external call, while external providers add a network round-trip. Sampling rates, per-rule timeouts, and asynchronous validation limit the effect on high-traffic endpoints.

Can Bifrost redact PII instead of blocking the request?

Bifrost redacts PII for providers that support Bifrost-managed redaction: Custom Regex, Secrets Detection, Microsoft Presidio, Azure AI Language PII, Check Point's AI Agent Security, and Singulr AI. The runtime_reversible mode replaces values with reversible placeholders, and a walkthrough of PII and injection guardrails shows the modes in practice.

How are guardrail rules scoped to teams, models, or tools?

Each rule carries a CEL expression evaluated against request metadata: model, provider, headers, virtual key, team, customer, and user for LLM traffic, or MCP client, tool, and arguments for tool calls. A rule such as team == "team-platform" applies only to that team's requests, so guardrail policy follows the same identities used for budgets.