What Context Guard protects
The application layer: the responses the model produces and the scope it is allowed to operate within. Improperly handled output is one of the most common ways an LLM turns a harmless prompt into a downstream exploit — unescaped markup that runs in a browser, generated code that executes on a server, or a confidently wrong answer outside the assistant’s remit.Threats it stops
- Improper output handling — output schemas validated (
BG-17), executable HTML and scriptable payloads neutralized (BG-06,BG-22), and generated code screened (BG-19) before anything renders or executes. - Scope violation — out-of-scope topics refused or redirected against admin-defined boundaries (
BG-26). - Misinformation & IP — ungrounded or out-of-scope claims rewritten to a compliant equivalent or declined; brand and IP checks score whatever remains (
BG-16).
How it works
Context Guard applies the same policy engine to outputs that Prompt Guard applies to inputs. Responses are context-aware encoded (HTML, attribute, URL, JS), structured outputs are validated against their schema, and out-of-scope content is resolved to allow, deny, mask, or rewrite — preserving user intent where a compliant rewrite is possible rather than simply blocking.Controls
Context Guard runsBG-06, BG-16, BG-17, BG-19, BG-22, and BG-26. See the Controls Catalog for each control’s definition, scope, and benchmark.
OWASP coverage
Addresses LLM05 Improper Output Handling and LLM09 Misinformation from the OWASP LLM Top 10.Related
Prompt Guard
Secures the input boundary before the model runs.
RAG Guard
Grounds answers in authorized sources upstream of output checks.
Controls Catalog
The controls Context Guard runs, in full detail.
Policy Configuration
Define scope boundaries and output policies.