Your rules,
attached to a key.
A custom LLM guardrail policy is a named set of rules, such as banned terms, regex patterns, topic limits and thresholds, that you attach to an AiDren proxy key. Rules run on prompts and responses on top of the built-in judge, and you can shadow-test a draft against real traffic before you enforce it.
Custom LLM guardrail policy, per API key
Named policies, evaluated both ways.
A policy is a named bundle of rules. It runs on the prompt and on the response; the worst verdict wins. The built-in judge still runs underneath — a policy adds to it, it does not replace it.
-
1
Build a policy
Combine term, regex, topic, threshold, and system-prompt-leak rules. Your regex runs in re2-wasm, so a bad pattern cannot hang the proxy.
-
2
Attach it to keys
One policy, many keys. Change it once and every key using it picks up the change. Matches emit
policy:<kinds>events. -
3
Shadow-test first
The Policy Impact Simulator runs a draft against a key’s real live traffic without ever enforcing it, tallying what each rule would have flagged, per rule.
Five rule types, mixed freely
Everything below can live in a single named policy.
- Term — block or flag an exact phrase.
- Regex — your own pattern, run safely in re2-wasm.
- Topic — flag a subject your model should not discuss.
- Threshold — cap message length or another numeric limit.
- System-prompt-leak — catch your instructions echoed back.
policy:<kinds>events — every match logged with the rule kinds that fired.- Impact Simulator — a live shadow test against real traffic, with a per-rule breakdown and a staleness nudge.
Related: Output & data-leak scanning · Team accounts · AiDren vs LLM Guard · How AiDren compares →
Attach a policy to any key.
A real screen from a live AiDren account.
Can I set my own rules instead of just the built-in judge?
Yes. Custom policies let you attach term, regex, topic, and threshold rules to any proxy key: block a specific phrase, cap message length, flag a topic your model shouldn't discuss. The built-in judge still runs underneath; a policy adds to it, it doesn't replace it.
Do you scan the model's responses too, not just the prompt?
Yes. Output scanning checks every response for system-prompt leaks and common data-leak patterns, including emails, card numbers, IBANs, phone numbers, API keys, and private keys, before it reaches your app. You choose per key whether a hit gets redacted or the whole response blocked, and whether prompts get the same check.
How much latency does AiDren add?
The proxy layer itself adds about 5 ms. On top of that, requests that need screening get one classification call — usually 200–500 ms, which runs before your request reaches OpenAI, Anthropic, or Mistral, so it overlaps nothing. Short, clearly-benign messages skip the classification call entirely. Model-file scans and egress reports add nothing to your chat traffic.
What happens after the trial?
Your 14-day trial needs no card up front and covers 25,000 checked requests. When it ends, upgrade to keep your proxy running — if you don't, AiDren pauses your traffic rather than silently letting it through unprotected.
What kinds of rule can a policy contain?
Five: contains a term, matches a regex, covers a topic, exceeds a limit (message count, input length or PII matches), and leaks the system prompt. Each rule chooses its own action: monitor, redact or block, depending on the rule type.
Can I test a policy before enforcing it?
Yes. A shadow test evaluates every request on a key against the draft policy in parallel with the live one. The shadow never blocks or changes anything; it only tallies what it would have done, so you can see the impact before you promote it.
Guardrails you write,
enforced per key.
Get the full stack free for 14 days. No card, no sales call, no SDK rewrite.
Start protecting requests