LLM OUTPUT SCANNING

Check the response
before your app sees it.

LLM output scanning checks a model's response for things it should not return, such as the system prompt, email addresses, card numbers, IBANs, phone numbers, API keys and private keys, before your app sees it. AiDren scans every response, redacts the match or blocks the response (your choice per key), and works on streamed replies.

No card required ~5ms proxy overhead One-line setup
HOW IT WORKS

How LLM output scanning works
In, screened, out.

Output scanning runs on the response leg of the same proxy call. Non-streaming responses are buffered and scanned before your app sees them. Streaming responses are relayed live and scanned once they finish, so a match is logged and alerted but not removed; turn on buffering for the key if you need streamed responses redacted or blocked too.

  1. 1

    Pick a mode per key

    Off, monitor, or enforce. In monitor you see what would have been caught without changing a byte; in enforce, AiDren acts on it.

  2. 2

    Choose redact or block

    On a hit, either mask just the matched span and pass the rest through, or block the whole response and return an error your app can handle.

  3. 3

    Watch the events

    Every hit emits a redacted event on your Events page with the detector that fired. No response content is stored.

WHAT IT LOOKS FOR

Detectors on every response

Regex detectors run on every response, and — opt-in — on prompts too.

  • System-prompt leaks — your own instructions coming back out in the reply.
  • Email addresses
  • Payment card numbers
  • IBANs
  • Phone numbers
  • API keys
  • Private keys
  • Streaming or not: standard responses are scanned before delivery; streamed ones are scanned after they finish, or before delivery if you turn on buffering.
IN THE DASHBOARD

Set the mode and detectors per key.

app.aidren.co.uk/proxy-keys LIVE
AiDren proxy keys page showing per-key mode, output scanning, model-file scanning, and policy controls

A real screen from a live AiDren account.

FAQ

Questions,
answered plainly.

More in the API reference and on the pricing section.

Do you scan the model's responses too, not just the prompt?

Yes. Output scanning checks every response for system-prompt leaks and common data-leak patterns, including emails, card numbers, IBANs, phone numbers, API keys, and private keys, before it reaches your app. You choose per key whether a hit gets redacted or the whole response blocked, and whether prompts get the same check.

Do you see my data?

Your requests pass through AiDren to make a block/allow decision and are never stored beyond the decision log you see in your own dashboard. Your API keys are encrypted at rest and never logged in plain text.

How much latency does AiDren add?

The proxy layer itself adds about 5 ms. On top of that, requests that need screening get one classification call — usually 200–500 ms, which runs before your request reaches OpenAI, Anthropic, or Mistral, so it overlaps nothing. Short, clearly-benign messages skip the classification call entirely. Model-file scans and egress reports add nothing to your chat traffic.

Can I set my own rules instead of just the built-in judge?

Yes. Custom policies let you attach term, regex, topic, and threshold rules to any proxy key: block a specific phrase, cap message length, flag a topic your model shouldn't discuss. The built-in judge still runs underneath; a policy adds to it, it doesn't replace it.

What happens after the trial?

Your 14-day trial needs no card up front and covers 25,000 checked requests. When it ends, upgrade to keep your proxy running — if you don't, AiDren pauses your traffic rather than silently letting it through unprotected.

What is the difference between redact and block?

Redact masks only the matched span, for example a card number, and passes the rest of the response through. Block returns a proxy-block response instead of the model's reply. You choose per proxy key, and monitor mode lets you see what would have been caught before anything changes.

Does AiDren store my responses?

No. Each hit is logged as an event that names the kinds of data found and a count, never the matched values. Redacted values are removed inside AiDren and are not written anywhere.

Can it catch secrets that do not match a known pattern?

Detectors are pattern-based, so an unusual credential format may slip through. Add a custom regex or term rule to the key's policy to cover your own token formats.

RELATED GUIDES

Related guides

READY WHEN YOU ARE

Stop the leak
on the way out.

Get the full stack free for 14 days. No card, no sales call, no SDK rewrite.

Start protecting requests