🗃️ Contributing to Guardrails
3 items
📄️ Team Bring-Your-Own Guardrails
Team-based guardrails let developers register a guardrail for their team via the API; an admin then reviews and approves or rejects it in the LiteLLM UI. Only Generic Guardrail API guardrails can be registered this way.
Aim Security
Quick Start
Akto
Use Akto as a guardrail provider, enabling runtime security for all LLM traffic routed through the proxy. Akto is purpose-built to secure autonomous and agentic AI systems that inspects every request and response inline, risk-scores interactions, and enforces policy decisions to block harmful actions, data exposure, and unsafe behavior before they can occur.
📄️ Alice
The Alice guardrail screens prompts and model responses against policies you configure in Alice. On every call it forwards the request to Alice, which decides what in the payload is worth evaluating and answers with a verdict the guardrail enforces: allow the call, block it, replace flagged text, or record a detection and let the call through.
Aporia
Use Aporia to detect PII in requests and profanity in responses
Azure Content Safety Guardrail
LiteLLM supports Azure Content Safety guardrails via the Azure Content Safety API.
Bedrock Guardrails
If you haven't set up or authenticated your Bedrock provider yet, see the Bedrock Provider Setup & Authentication Guide.
Context Compression (Compresr)
Compresr compresses LLM context against the question being asked. It keeps the tokens that matter for the answer and drops the rest. As a LiteLLM guardrail, it compresses tool outputs, retrieved documents, database results, and RAG payloads before they reach the model, so you get the same answers at a fraction of the input tokens.
Conduct Guard
The Conduct guardrail sends each prompt to your Conduct workspace before the model is called. Conduct evaluates the user text against the rules configured for the tool the guardrail is registered under and returns a verdict. Blocking verdicts (block, approval) reject the request with a 400 and the rule id. Non-blocking verdicts (warning, advisory) let the request through and are recorded as guardrail_flagged in LiteLLM's guardrail logs, spend logs, and the Admin UI request detail.
CrowdStrike AIDR
The CrowdStrike AIDR guardrail uses configurable detection policies to identify
Custom Code Guardrail
Write custom guardrail logic using Python-like code that runs in a sandboxed environment.
Custom Guardrail
Use this if you want to write code to run a custom guardrail
DynamoAI Guardrails
LiteLLM supports DynamoAI guardrails for content moderation and policy enforcement on LLM inputs and outputs.
EnkryptAI Guardrails
LiteLLM supports EnkryptAI guardrails for content moderation and safety checks on LLM inputs and outputs.
Gray Swan Cygnal Guardrail
Use Gray Swan Cygnal to continuously monitor conversations for policy violations, indirect prompt injection (IPI), jailbreak attempts, and other safety risks.
Guardrails AI
Use Guardrails AI (guardrailsai.com) to add checks to LLM output.
HiddenLayer Guardrails
LiteLLM ships with a native integration for HiddenLayer. The proxy sends every request/response to HiddenLayer’s /detection/v1/interactions endpoint so you can block or redact unsafe content before it reaches your users.
IBM Guardrails
LiteLLM works with IBM's FMS Guardrails for content safety. You can use it to detect jailbreaks, PII, hate speech, and more.
Javelin Guardrails
Javelin provides AI safety and content moderation services with support for prompt injection detection, trust & safety violations, and language detection.
Lakera AI
Supported endpoints: The Lakera v2 integration only supports the chat completions endpoint (/v1/chat/completions). It is not supported for the Responses API, /v1/messages, MCP, A2A, or other proxy endpoints.
Lasso Security
Use Lasso Security to protect your LLM applications from prompt injection attacks, harmful content generation, and other security threats through input and output validation.
LLM-as-a-Judge
Overview
📄️ LLM Shield Proxy
The LLM Shield Proxy guardrail replaces personal data in each request with realistic stand-in values before it reaches the model, then puts the original values back into the reply. The stand-ins and the values behind them are held in a session vault inside your own LLM Shield Proxy deployment, so the provider never receives the originals while the caller still sees them.
Microsoft Agent 365 Guardrail
Sends every MCP tool call to the Microsoft Agent 365 evaluation API before LiteLLM runs it. Microsoft Defender returns allow or block, and the call is recorded on the Microsoft side under the signed-in user
Microsoft Purview Guardrail
LiteLLM supports Microsoft Purview DLP policies via the Microsoft Graph processContent API.
Google Cloud Model Armor
LiteLLM supports Google Cloud Model Armor guardrails via the Model Armor API.
Noma Security
Use Noma Security to protect your LLM applications with AI content moderation and safety guardrails.
📄️ Onyx Security
Quick Start
OpenAI Moderation
Overview
Pangea
The Pangea guardrail uses configurable detection policies (called recipes) from its AI Guard service to identify and mitigate risks in AI application traffic, including:
PANW Prisma AIRS
LiteLLM supports PANW Prisma AIRS (AI Runtime Security) guardrails via the Prisma AIRS Scan API. This integration provides Security-as-Code for AI applications using Palo Alto Networks' AI security platform.
PII, PHI Masking - Presidio
Overview
📄️ Pillar Security
Pillar Security integrates with LiteLLM Proxy via the Generic Guardrail API, providing AI security scanning for your LLM applications.
In-memory Prompt Injection Detection
LiteLLM Supports the following methods for detecting prompt injection attacks
PromptGuard
Use PromptGuard to protect your LLM applications with prompt injection detection, PII redaction, topic filtering, entity blocklists, and hallucination detection. PromptGuard is self-hostable with drop-in proxy integration.
Qostodian Nexus by Qohash
Qohash is a pioneer of zero-copy data security, the only model designed to secure petabytes of unstructured data in large enterprises. Enterprises run dozens of AI models, copilots, and autonomous agents, all hungry for data. Qostodian Nexus is the single control layer that governs every interaction. It knows your data. It enforces your policies. It scales from prompt inspection to LLM output data governance, interrogating all agentic, human, SaaS and API interactions with one control plane and a consistent set of policies. Nexus scans prompts and responses using deterministic classification policies and LLM-as-a-judge checks, returning an explicit enforcement decision (ALLOW, LOG, REDACT or BLOCK).
📄️ Qualifire
Use Qualifire to evaluate LLM outputs for quality, safety, and reliability. Detect prompt injections, hallucinations, PII, harmful content, and validate that your AI follows instructions.
RepelloAI Argus
Use RepelloAI Argus to scan prompts and responses against the policies you configure per asset in the Repello dashboard. Argus is a cloud-hosted API; prompts are scanned on precall and model responses on postcall, and the policies enforced for a request come from the asset you point the guardrail at.
Rubrik Guardrail
Use Rubrik's moderation and logging integration to screen prompts and responses against an external policy service and batch-log all LLM requests/responses.
✨ Secret Detection/Redaction (Enterprise-only)
❓ Use this to REDACT API Keys, Secrets sent in requests to an LLM.
Sensitive Data Routing (Built-in Guardrail)
Built-in guardrail that detects sensitive data in a request and reroutes it to an on-premise model instead of blocking or redacting it. No external dependencies required.
Straiker
The Straiker guardrail applies runtime AI security to traffic routed through LiteLLM. On every call it inspects the prompt and the response, including tool definitions and tool calls, and can block or redact before content reaches the model or the client.
LiteLLM Tool Permission Guardrail
LiteLLM provides the LiteLLM Tool Permission Guardrail that lets you control which tool calls a model is allowed to invoke, using configurable allow/deny rules. This offers fine-grained, provider-agnostic control over tool execution (e.g., OpenAI Chat Completions toolcalls, Anthropic Messages tooluse, MCP tools).
📄️ Relevance-Based Compaction (TypeSafe / Jev)
TypeSafe's Jev model judges whether each completed tool exchange is still relevant to the current task. As a LiteLLM guardrail, it blanks out tool results Jev scores below a relevance threshold before the request reaches the model, so dead context stops consuming input tokens. Unlike summarizing compressors, this is all-or-nothing per exchange: a result is either kept verbatim or replaced with a removal notice.
📄️ Vigil Guard
Use Vigil Guard as a LiteLLM proxy guardrail to evaluate chat input and model output before it is returned to your application.
XecGuard
Use XecGuard (CyCraft) to protect your LLM applications with multi-policy scanning (prompt injection, harmful content, PII, system-prompt enforcement, skills protection) and RAG context grounding validation. XecGuard is a cloud-hosted AI security gateway, so there are no self-hosting requirements.
Zscaler AI Guard
Overview