Security for AI Applications
AI applications face unique security challenges that traditional tools weren’t built to handle. Oximy protects against these threats through two foundational concepts: Guardrails and Policies.Core Concepts
- Guardrails
- Policies
Real-time security controls that analyze requests and responses as they flow through your AI applications.How They Work:
- Pattern-based detection for structured threats
- Semantic analysis to understand context and intent
- Behavioral analysis to spot unusual patterns
- Contextual validation against your policies
Learn About Guardrails
Deep dive into how guardrails protect your applications
How They Work Together
1
Request Arrives
An AI request arrives at your application (via Gateway or Shield)
2
Policy Loads
The project loads its assigned policy, which specifies:
- Which guardrails are active
- Enforcement levels for each guardrail
- Custom detection settings
3
Guardrails Analyze
Active guardrails analyze the request through multiple layers:
- Pattern matching for known threats
- Semantic analysis for context understanding
- Behavioral analysis for unusual patterns
- Contextual validation against policies
4
Action Taken
Based on policy configuration:
- BLOCK: Stop the request, return error, log violation
- WARN: Sanitize content, log violation, allow to proceed
5
Protected Request
Only clean, policy-compliant content reaches the AI model
6
Response Checked
Model responses are analyzed by guardrails before returning
7
Safe Response
Compliant, sanitized data returns to your application
Protection by Environment
- Production
- Internal Tools
- Development
- Compliance
Maximum protection for customer-facing applicationsPolicy Configuration:
- All guardrails enabled
- BLOCK enforcement for critical threats
- High detection sensitivity
- Real-time alerting
- Comprehensive audit logging
- Public APIs
- Customer portals
- Production services
- Revenue-generating applications
Why This Architecture?
Consistency Across Products
Consistency Across Products
The same guardrails and policies work across Gateway, Guard, and Shield. Configure once, protect everywhere.
Flexibility by Environment
Flexibility by Environment
Production needs strict enforcement. Development needs visibility. Same guardrails, different policies.
Compliance Made Easy
Compliance Made Easy
Pre-built policies for HIPAA, PCI, GDPR, and other regulations. Customize as needed for your requirements.
Gradual Rollout
Gradual Rollout
Start with WARN in development. Monitor and tune. Move to BLOCK in production when you’re confident.
Multi-Layered Protection
Multi-Layered Protection
Four detection layers (pattern, semantic, behavioral, contextual) provide defense in depth against evolving threats.
Next Steps
1
Understand Guardrails
Learn how each guardrail type protects against specific threatsExplore Guardrails
2
Learn About Policies
See how to organize guardrails into reusable configurationsExplore Policies
3
Integrate Gateway
Put it all into practice with Oximy GatewayGateway Quickstart