> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# RAG Guard: Protect Your Retrieval Pipeline and Vector Database

> RAG Guard enforces policy at the vector-database boundary — binding answers to authorized sources and blocking RAG poisoning and embedding-layer attacks.

RAG Guard protects the **data surface** at the point of retrieval. Where most guardrails inspect only the prompt, RAG Guard enforces policy at the vector-database boundary itself — on the retrieval traffic, not just the prompts that trigger it.

## What RAG Guard protects

The retrieval pipeline: the RAG corpus, the embeddings, and the vector database your application queries for context. This is a distinct attack surface from the model — poisoned retrieval content corrupts responses downstream without ever touching the prompt.

## Threats it stops

* **RAG & data poisoning** — documents submitted for embedding are scanned and quarantined before they reach the vector database; poisoned entries never reach the retrieval layer (`BG-12`).
* **Vector & embedding weaknesses** — source compliance, access rules, and data classification applied to retrieval traffic at the vector-database boundary (`BG-09`).
* **Misinformation / hallucination** — every factual span bound to a provenance-verified source; ungrounded output is rejected (`BG-09`).

## How it works

RAG Guard binds each statement in a response to a verifiable reference (domain/URL, timestamp, content-hash) and rejects answers that are not grounded in an authorized source. On the ingestion side, each chunk submitted for embedding is evaluated for jailbreak instructions, policy-overriding directives, and obfuscated payloads, and is committed to the index only if it passes provenance, schema, and moderation checks.

## Controls

RAG Guard runs `BG-09` and `BG-12`. See the [Controls Catalog](/concepts/controls-catalog) for each control's definition, scope, and benchmark.

## OWASP coverage

Addresses **LLM04 Data and Model Poisoning**, **LLM08 Vector and Embedding Weaknesses**, and **LLM09 Misinformation** from the [OWASP LLM Top 10](/resources/owasp-llm-top10).

## Related

<CardGroup cols={2}>
  <Card title="File Guard" icon="file-shield" href="/guards/file-guard">
    Screens the files that feed your retrieval corpus.
  </Card>

  <Card title="Context Guard" icon="brackets-curly" href="/guards/context-guard">
    Scores grounding and scope on the way out.
  </Card>

  <Card title="Controls Catalog" icon="list-check" href="/concepts/controls-catalog">
    The controls RAG Guard runs, in full detail.
  </Card>

  <Card title="AI Value Chain" icon="diagram-project" href="/concepts/ai-value-chain">
    Where the data surface sits in your stack.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.