Guardrail Rules

Configurable rules that evaluate every AI request and response.

Rule Types

TypeDescription
contains_piiDetects emails, phone numbers, SSNs, custom PII patterns
contains_secretDetects API keys, tokens, AWS keys, high-entropy strings
token_limit_exceededEnforces maximum token limits per request
model_allowlistRestricts which AI models can be used

Actions

ActionBehavior
allowLog the violation but allow the request
warnLog a warning and allow the request
blockBlock the request entirely
redactReplace matched spans with [REDACTED:pii] or [REDACTED:secret] before storage. The original text is never persisted. Redaction applies to what SignalVault stores โ€” it does not rewrite the payload sent to your provider. Via the SDK the request proceeds and you receive the decision; via the proxy a redact rule blocks rather than forwarding a partially-redacted prompt.

How Redaction Works

Redaction happens inside the ingest layer, before encryption โ€” raw text never reaches the database.

  • The redactions array in the API response lists the rule types that redacted content and how many matches each removed, for example [{"type": "contains_pii", "count": 2}]. It does not report locations โ€” SignalVault redacts what it stores, so there is nothing for your application to apply.
  • The dashboard prompt/response viewer shows the redacted version because the encrypted field stores the already-redacted text.
  • Redaction applies to both ai.request prompts and ai.response outputs.
  • When redaction fires, the raw messages / output keys are also removed from the stored JSONB payload.

Decision Hierarchy

When multiple rules fire, the strictest action wins: block > redact > warn > allow.

What a new app starts with

Every new app is created with a set of default rules already enabled, scoped to all environments. Most of them warn rather than block, so your first requests are logged and flagged without being rejected. If you are evaluating SignalVault and expect a request to be blocked, check this table first — a warn decision means the guardrail fired and allowed the request through, which is working as intended.

RuleDefault actionPlans
contains_piiwarnAll
contains_secretwarn on trial, block on paid plansAll
token_limit_exceededblockAll — 8 000 tokens
prompt_injectionblockGrowth and Enterprise

Secret detection starts as warn on the free trial deliberately: a first request that trips the entropy filter shows up as a violation to investigate rather than a 400 that looks like a broken integration. Promote it to block in the Rules tab once you are happy with what it catches. Every default can be edited, disabled or deleted.

Managing Rules

Rules are managed per-app in the dashboard under the Rules tab. You can create, edit, enable/disable, and delete rules. Each rule can be scoped to a specific environment or applied to all environments.