Skip to main content
A Guard is a purpose-built security module deployed at a specific node of the AI value chain. Unlike bolt-on filters or model-level fine-tuning, each Guard operates structurally independently from the models it protects — its security decisions are made outside the model’s own reasoning process, so a compromised or manipulated model cannot talk its way past a Guard. BeyondGuard’s six Guards together cover every layer of your AI stack, from the moment data enters your retrieval pipeline to the moment a response reaches your users.

How Guards work

Every Guard follows the same core pipeline: inspect → evaluate → act. When an interaction reaches a protected layer, the Guard intercepts it before it proceeds. It evaluates the interaction against your configured policies — checking for known threat signatures, contextual anomalies, scope boundaries, and compliance rules — using a purpose-built security model that produces a confidence score. Based on that score and your thresholds, the Guard resolves the interaction to one of four enforcement outcomes: Allow, Deny, Mask, or Rewrite, each written to the audit log with a reason code. This pipeline runs at every node independently. A Guard at the MCP/Tool layer does not rely on the Prompt Guard having already caught a threat upstream — it makes its own determination based on what it can observe at its own layer.

The six Guards

Prompt Guard

Inspects every prompt and retrieved context before inference. Stops prompt injection, jailbreaks, system prompt leakage, and sensitive-data disclosure.

Context Guard

Treats model responses as untrusted input to the rest of your stack. Validates output schemas, neutralizes script and markup, and enforces topic scope.

RAG Guard

Protects the retrieval pipeline and vector database. Binds answers to authorized sources and blocks RAG poisoning and embedding-layer attacks.

File Guard

Screens every uploaded and ingested file. Catches embedded instructions, malicious active content, and poisoned documents before they reach the model.

Agent Guard

Monitors autonomous agent behavior across the whole reasoning chain. Catches plan deviation, memory poisoning, and infinite loops.

MCP Guard

Validates every tool call and MCP server interaction. Blocks tool poisoning, parameter injection, and schema violations under deny-by-default.

Guards, controls, and outcomes

A Guard is a deployment surface; a control is an individual check that runs within one or more Guards. When you enable a Guard, you turn on the controls that belong to it — for example, Prompt Guard runs the prompt-injection, system-prompt-leakage, and PII-masking controls. Every fired control resolves to one of the four outcomes above.

Guard modes

Each Guard can run in one of two modes, set independently per Guard. Observation mode logs and reports every detection without blocking any interaction. Traffic flows through uninterrupted, but every threat event is captured, categorized, and surfaced in your control plane. Observation mode is the right starting point for any new deployment — it lets you understand your threat surface, tune your policies, and build confidence in detections before you commit to enforcement. Enforcement mode actively applies the outcome. A blocked prompt injection is denied before it reaches the model; sensitive data is masked before it leaves; an out-of-scope response is rewritten to a policy-compliant equivalent. Switching a Guard to enforcement should follow a period of observation-mode calibration so your policies reflect your environment and you aren’t blocking legitimate traffic.

Combining Guards

Guards work together across the value chain, but each one makes its security decisions independently. This structural independence is intentional: a threat that slips through one layer — whether from a novel attack technique or a misconfigured policy — still faces inspection at every subsequent layer. Defense in depth is built into the architecture. You do not need to deploy all six Guards at once. Start with the layers that carry the most risk for your specific deployment. Many teams begin with Prompt Guard and Context Guard to secure the input and output boundaries, then expand to RAG, File, Agent, and MCP Guards as their retrieval, agent, and tool integrations mature.
Start with Prompt Guard in observation mode to baseline your threat surface before moving to enforcement. The detections you collect in the first few days give you the data you need to write accurate, low-noise policies.