Bifrost Guardrails | Enterprise AI Safety & Policy Enforcement
Real-time validation of LLM inputs and outputs with PII detection, content moderation, prompt injection defense, and multi-provider guardrail support for enterprise compliance.
Two-Tier Architecture: Rules + Profiles
Rules decide what to check and when to check it. Profiles decide how to check it and which provider runs the check. Configure both once and apply them anywhere.
- Rules: When to validate. Define validation logic using Common Expression Language (CEL). Rules specify whether to check inputs, outputs, or both, and can reference multiple profiles for defense-in-depth. Example: Apply PII detection + content moderation to customer-facing endpoints.
- Profiles: How to validate. Configure external guardrail providers with credentials, thresholds, and detection parameters. Reusable profiles eliminate redundant configuration across rules. Example: AWS Bedrock profile with high-sensitivity PII detection.
Guardrail Providers
| Name | Logo Domain | Description | Capabilities | Categories |
|---|---|---|---|---|
| AWS Bedrock Guardrails | aws.amazon.com | Comprehensive protection with content filtering, PII detection, and image analysis | 50+ PII entity types detected; Prompt injection detection; Image content analysis; 13 AWS regions supported | Content Filtering; PII Detection; Prompt Defense; Image Safety |
| Azure Content Safety | microsoft.com | Severity-based filtering with multi-category detection and custom blocklists | 4-level severity filtering; Prompt Shield for jailbreaks; Protected material detection; Custom blocklists | Hate Speech; Violence; Sexual Content; Self-Harm |
| GraySwan Cygnal | grayswan.ai | Natural language rule definition with continuous violation scoring | No-code rule definition; 0-1 violation scoring; Mutation detection; 3 reasoning modes | Custom Policies; Indirect Injection; Fast/Balanced/Thorough |
| Patronus AI | patronus.ai | LLM-specific risk detection with hallucination and toxicity screening | Hallucination detection; Context-aware evaluation; Multi-turn analysis; Toxicity screening | Hallucinations; PII; Toxicity; Prompt Injection |
Detection Capabilities
- 50+ PII typesPII leakage prevention. Detect and redact 50+ types of sensitive information including SSNs, credit cards, addresses, medical records, and device identifiers before they reach or leave the model.
- Multi-categoryContent safety filtering. Block or redact hate speech, sexual content, violence, self-harm, and profanity across inputs and outputs. Severity-based thresholds enable fine-grained control.
- Multi-layeredPrompt injection defense. Protect against direct and indirect prompt attacks, jailbreaks, and mutation attempts. Multiple providers offer layered defense against evolving attack vectors.
- Context-awareHallucination detection. Identify when models generate factually incorrect or unsupported information. Patronus AI provides context-aware evaluation for high-stakes applications.
- Copyright detectionProtected material screening. Azure Content Safety detects copyrighted content and protected intellectual property in model outputs, helping organizations avoid legal exposure.
- No-code rulesCustom organizational policies. Define business-specific rules in natural language (GraySwan) or through configuration. Enforce brand safety, regulatory requirements, and internal compliance policies.
Setup Steps
- 01Configure guardrail providers. Set up guardrail provider profiles through the dashboard or API. Configure credentials, detection thresholds, and category filters for each provider.
Configure guardrail providers # Via dashboard: Guardrails > Providers # Or via config.json { "guardrail_providers": [{ "id": "bedrock-prod", "type": "aws_bedrock", "region": "us-east-1", "guardrail_id": "your-guardrail-id", "version": "DRAFT" }] } - 02Create validation rules. Define when and how to validate requests using CEL expressions. Rules can apply to specific routes, models, virtual keys, or user attributes.
Create validation rules # Via dashboard: Guardrails > Configuration # Or via config.json { "guardrail_rules": [{ "id": "customer-safety", "condition": "request.path.startsWith('/v1/chat')", "input_profiles": ["bedrock-prod"], "output_profiles": ["patronus-ai"], "action": "BLOCK" }] } - 03Attach to requests. Apply guardrails via request headers or inline configuration. Bifrost validates inputs before sending to the model and outputs before returning to the client.
Attach to requests curl https://your-gateway/v1/chat/completions \ -H "x-bf-guardrail-id: customer-safety" \ -H "Authorization: Bearer vk-..." \ -d '{ "model": "gpt-4", "messages": [{"role": "user", "content": "..."}] }'
Response Types
- Pass (HTTP 200). Validation succeeded. Request processed normally with detailed guardrail metadata including processing times and rule results.
- Block (HTTP 446). Violations detected and request blocked. Response includes violation details, severity levels, and affected content excerpts for audit trails.
- Warning (HTTP 246). Violations detected but content modified (PII redacted) rather than blocked. Includes redaction counts and modification details.
200446246Enterprise Features
- Sampling control. Apply guardrails to a percentage of requests for performance optimization while maintaining statistical confidence.
- Async processing. Choose synchronous or asynchronous validation modes. Async reduces latency for non-critical checks.
- Defense-in-depth. Link multiple provider profiles to single rules for sequential validation and comprehensive protection.
- Comprehensive logging. Detailed audit trails capture every validation with timestamps, results, and violation details for compliance.
- Timeout configuration. Set maximum execution duration per rule to prevent guardrail latency from impacting user experience.
- Multi-region support. Deploy guardrails across 13 AWS regions. Azure Content Safety profiles can target region-specific endpoints for data residency compliance.
Use Cases
- Healthcare HIPAA compliance. Prevent PHI leakage in patient-facing chatbots. AWS Bedrock detects medical record numbers, health plan IDs, and clinical notes before they leave the model.
- Financial PII protection. Block credit card numbers, SSNs, and account details in banking applications. Multi-provider validation ensures no sensitive data escapes detection.
- Prompt injection defense. Protect against adversarial inputs attempting to override system instructions. GraySwan and Azure Prompt Shield detect mutation attempts and indirect attacks.
- Content moderation for UGC. Filter user-generated content in social platforms. Severity-based thresholds allow nuanced handling of hate speech, violence, and sexual content.
- Hallucination prevention. Validate factual accuracy in high-stakes applications like legal research or medical advice. Patronus AI detects unsupported claims and inconsistencies.
- Brand safety enforcement. Define custom organizational policies in natural language. Ensure model outputs align with brand voice, values, and regulatory requirements.
Compliance Frameworks
Bifrost Guardrails help organizations meet regulatory requirements with automated detection, redaction, and comprehensive audit trails.
- SOC 2 Type II. Comprehensive audit trails and access controls for guardrail enforcement.
- GDPR. Personal data protection and right-to-erasure compliance.
- ISO 27001. Information security management and certification alignment.
- HIPAA. PHI detection and redaction for healthcare applications.
Open Source & Enterprise
OSS Features
- 01Model Catalog. Access 8+ providers and 1000+ AI models through a unified interface. Also supports custom deployed models.
- 02Budgeting. Set spending limits and track costs across teams, projects, and models.
- 03Provider Fallback. Automatic failover between providers ensures 99.99% uptime for your applications.
- 04MCP Gateway. Centralize all MCP tool connections, governance, security, and auth. Your AI can safely use MCP tools with centralized policy enforcement. [MCP Gateway resource]
- 05Virtual Key Management. Create different virtual keys for different use cases with independent budgets and access control.
- 06Unified Interface. One consistent API for all providers. Switch models without changing code.
- 07Drop-in Replacement. Replace your existing SDK with just one line change. Compatible with OpenAI, Anthropic, LiteLLM, Google GenAI, LangChain, and more. [Drop-in replacement docs]
- 08Built-in Observability. Out-of-the-box OpenTelemetry support. Built-in dashboard for quick visibility without complex setup.
- 09Community Support. Active Discord community with responsive support and regular updates.
Enterprise Features
- 01Governance. SAML support for SSO and role-based access control with policy enforcement for team collaboration. [Governance resource]
- 02Adaptive Load Balancing. Automatically optimizes traffic distribution across provider keys and models based on real-time performance metrics.
- 03Cluster Mode. High availability deployment with automatic failover and load balancing. Peer-to-peer clustering where every instance is equal.
- 04Alerts. Real-time notifications for budget limits, failures, and performance issues on Email, Slack, PagerDuty, Teams, Webhook, and more.
- 05Log Exports. Export and analyze request logs, traces, and telemetry data from Bifrost with enterprise-grade data export for compliance, monitoring, and analytics.
- 06Audit Logs. Comprehensive logging and audit trails for compliance and debugging.
- 07Vault Support. Secure API key management with HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault integration.
- 08VPC Deployment. Deploy Bifrost within your private cloud infrastructure with VPC isolation, custom networking, and enhanced security controls. [Enterprise deployment resource]
- 09Guardrails. Automatically detect and block unsafe model outputs with real-time policy enforcement and content moderation across all agents. [Guardrails resource]
FAQ
What are AI guardrails?
AI guardrails are checks that run on the prompts sent to a language model and on the responses it returns, and that allow, block, or modify content according to a policy. Bifrost runs them at the [AI gateway](https://www.getmaxim.ai/llm-gateway), so one set of rules covers every application and provider routed through it, including [MCP tool calls](https://www.getmaxim.ai/bifrost/mcp-gateway) made by agents.
What are examples of AI guardrails?
Common AI guardrails include PII redaction, prompt injection and jailbreak detection, secrets detection, toxicity filtering, hallucination detection, and organization-specific policies such as blocking definitive medical diagnoses. Bifrost supports each through its managed providers and external services such as AWS Bedrock Guardrails, Azure Content Safety, Google Model Armor, and Patronus AI.
What are the best guardrails for LLM apps?
The right combination depends on the risk being controlled: Secrets Detection and Custom Regex suit known formats, PII services such as Presidio suit personal data, and model-based services suit prompt injection and semantic policies. Bifrost links several profiles to one rule for layered checks, and [this comparison of guardrail platforms for prompt injection](https://docs.getbifrost.ai/enterprise/guardrails) covers the options further.
Do guardrails add latency to LLM requests?
Guardrails add the processing time of each linked profile, which Bifrost reports as processing_time_ms in the response metadata. Secrets Detection and Custom Regex run in-process with no external call, while external providers add a network round-trip. Sampling rates, per-rule timeouts, and asynchronous validation limit the effect on high-traffic endpoints.
Can Bifrost redact PII instead of blocking the request?
Bifrost redacts PII for providers that support Bifrost-managed redaction: Custom Regex, Secrets Detection, Microsoft Presidio, Azure AI Language PII, Check Point's AI Agent Security, and Singulr AI. The runtime_reversible mode replaces values with reversible placeholders, and [a walkthrough of PII and injection guardrails](https://docs.getbifrost.ai/enterprise/guardrails) shows the modes in practice.
How are guardrail rules scoped to teams, models, or tools?
Each rule carries a CEL expression evaluated against request metadata: model, provider, headers, [virtual key](https://www.getmaxim.ai/bifrost/resources/governance), team, customer, and user for LLM traffic, or MCP client, tool, and arguments for tool calls. A rule such as team == "team-platform" applies only to that team's requests, so guardrail policy follows the same identities used for [budgets](https://www.getmaxim.ai/bifrost/ai-governance).