AI Proxy
The AI Proxy is an intermediary layer that receives requests in OpenAI API format, applies your security policies, then converts and securely forwards them to the selected LLM provider. It lets you integrate with different providers in a controlled, centralized way, and you can configure and test settings through the Chat interface.Endpoint settings
Under an endpoint’s General Settings you define:- Endpoint name, target URL, and model — with a Fetch Models action that retrieves the available models from the provider so you can select one in a click.
- Active/passive status and creation date.
- Rate limiting — per-second and per-minute request limits, so you can cap traffic in line with your usage policy for both security and cost control.
Sensitivity threshold
Every query is scored by BeyondGuard’s security model, which produces a confidence value. That value is compared against a configurable Sensitivity Threshold to classify the query asSAFE or UNSAFE.
For example, a query with a confidence value of 0.6 is classified
SAFE when the threshold is set to 0.7, and is allowed through. Lower the threshold for stricter control in high-security environments; raise it to preserve operational fluidity where workflows are more tolerant. The ideal value depends on your risk appetite and internal policy.Check layers
Every query is evaluated across three layers so that policies apply end to end:- Input Check — analyzes the user’s text for direct risks: prompt injection, PII/PHI/CII, token limits, Unicode obfuscation, XSS, invalid JSON, brand/keyword filtering, toxicity, and dangerous code.
- Output Check — applies the same policy sets to the model’s response, so only safe content is returned. Several modules run bidirectionally (input and output), including dangerous-code detection, output schema validation, toxicity, PII/PHI/CII, RAG source compliance, and IP-violation protection.
- Prompt Check — protects the integrity of system, assistant, and meta-prompts: system-prompt-leakage protection, safety-system-prompt enforcement, and the customizable Safety Wrapper.
File operations
The File Operations section applies the same security policies to uploaded files — MIME-type checking, metadata validation, and content inspection (prompt injection, PII, Unicode sanitization, brand/keyword filtering, toxicity, and dangerous-code detection) — so file contents are scanned exactly like user inputs.Context Proxy
The Context Proxy inspects clear-text content without sending it to any LLM. It evaluates text, requests, or operational data against your security rules — activating controls such as prompt injection, PII, token control, Unicode sanitizer, and CII — and decides whether the content is safe or risky. Because it needs no model to operate, it’s ideal for:- Closed or air-gapped networks where LLM usage is prohibited or restricted — content is security-checked first, and only safe content moves to the next workflow step.
- RAG pre-filtering — detecting whether a query is risky before it is sent to your data sources.
- Zero external data leakage — internal text is validated against KVKK, GDPR, or internal protocols without sharing any data with external systems, which matters most in finance, public sector, defense, and healthcare.
Related
Policies & Multi-Policy
Assign versioned policy sets to each endpoint.
Token Management
Issue and scope endpoint access tokens.
Data Protection
Configure PII, PHI, and CII operations.
Guard Gateway API
The API these endpoints expose.