> ## Documentation Index
> Fetch the complete documentation index at: https://docs.beyondguard.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Proxies and Endpoints: AI Proxy and Context Proxy

> Configure the AI Proxy gateway and the LLM-free Context Proxy — endpoints, the sensitivity threshold, the Input/Output/Prompt check layers, and file inspection.

BeyondGuard inspects AI traffic through two proxy types you configure in the control plane: the **AI Proxy** (an OpenAI-compatible gateway to your models) and the **Context Proxy** (a lightweight inspector for content that never touches an LLM).

<iframe src="https://www.youtube.com/embed/Zskl3XLr7Ck" title="YouTube video player" frameborder="0" className="w-full aspect-video rounded-xl" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen />

## AI Proxy

The AI Proxy is an intermediary layer that receives requests in **OpenAI API format**, applies your security policies, then converts and securely forwards them to the selected LLM provider. It lets you integrate with different providers in a controlled, centralized way, and you can configure and test settings through the Chat interface.

### Endpoint settings

Under an endpoint's **General Settings** you define:

* **Endpoint name**, **target URL**, and **model** — with a **Fetch Models** action that retrieves the available models from the provider so you can select one in a click.
* **Active/passive status** and creation date.
* **Rate limiting** — per-second and per-minute request limits, so you can cap traffic in line with your usage policy for both security and cost control.

### Sensitivity threshold

Every query is scored by BeyondGuard's security model, which produces a **confidence value**. That value is compared against a configurable **Sensitivity Threshold** to classify the query as `SAFE` or `UNSAFE`.

<Info>
  For example, a query with a confidence value of 0.6 is classified `SAFE` when the threshold is set to 0.7, and is allowed through. Lower the threshold for stricter control in high-security environments; raise it to preserve operational fluidity where workflows are more tolerant. The ideal value depends on your risk appetite and internal policy.
</Info>

### Check layers

Every query is evaluated across three layers so that policies apply end to end:

* **Input Check** — analyzes the user's text for direct risks: prompt injection, PII/PHI/CII, token limits, Unicode obfuscation, XSS, invalid JSON, brand/keyword filtering, toxicity, and dangerous code.
* **Output Check** — applies the same policy sets to the model's response, so only safe content is returned. Several modules run **bidirectionally** (input and output), including dangerous-code detection, output schema validation, toxicity, PII/PHI/CII, RAG source compliance, and IP-violation protection.
* **Prompt Check** — protects the integrity of system, assistant, and meta-prompts: system-prompt-leakage protection, safety-system-prompt enforcement, and the customizable Safety Wrapper.

These map directly to the [six Guards](/concepts/guards) and the [Controls Catalog](/concepts/controls-catalog).

### File operations

The **File Operations** section applies the same security policies to uploaded files — MIME-type checking, metadata validation, and content inspection (prompt injection, PII, Unicode sanitization, brand/keyword filtering, toxicity, and dangerous-code detection) — so file contents are scanned exactly like user inputs.

## Context Proxy

The **Context Proxy** inspects clear-text content **without sending it to any LLM**. It evaluates text, requests, or operational data against your security rules — activating controls such as prompt injection, PII, token control, Unicode sanitizer, and CII — and decides whether the content is safe or risky.

Because it needs no model to operate, it's ideal for:

* **Closed or air-gapped networks** where LLM usage is prohibited or restricted — content is security-checked first, and only safe content moves to the next workflow step.
* **RAG pre-filtering** — detecting whether a query is risky before it is sent to your data sources.
* **Zero external data leakage** — internal text is validated against KVKK, GDPR, or internal protocols without sharing any data with external systems, which matters most in finance, public sector, defense, and healthcare.

## Related

<CardGroup cols={2}>
  <Card title="Policies & Multi-Policy" icon="sliders" href="/platform/policies">
    Assign versioned policy sets to each endpoint.
  </Card>

  <Card title="Token Management" icon="key" href="/platform/token-management">
    Issue and scope endpoint access tokens.
  </Card>

  <Card title="Data Protection" icon="user-shield" href="/platform/data-protection">
    Configure PII, PHI, and CII operations.
  </Card>

  <Card title="Guard Gateway API" icon="code" href="/api-reference/guard-gateway">
    The API these endpoints expose.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.