RI

Policy engine

Guardrails as code

Policies compile to the runtime gateway and evaluate inline on every prompt, tool call and completion. Turning a policy off is itself a logged, attributable governance event.

Open rule builder

Policies published

12

compiled to gateway 2026.07.3

Currently enforcing

11

1 disabled

Evaluations / 30d

2.61M

mean added latency 54 ms p99

Policy triggers / 30d

2,874

blocks, masks and escalations

POL-001 · All egress

No customer PII outside India

criticalOwner · CISO148 triggers / 30d

When

  • payload matches PAN / Aadhaar / account recognisers
  • destination region ≠ ap-south-1

Then

  • block request
  • raise critical finding
  • notify DPO
Enforcing inline at the gatewayInspect rule →

POL-002 · Servicing agents

No account closure without approval

criticalOwner · Head of Operations62 triggers / 30d

When

  • tool = accounts.close
  • actor is agent

Then

  • park for human approval
  • log to ledger
Enforcing inline at the gatewayInspect rule →
highOwner · Model Risk37 triggers / 30d

When

  • decision = decline
  • reason codes missing

Then

  • block response
  • return adverse-action template
Enforcing inline at the gatewayInspect rule →
criticalOwner · CISO91 triggers / 30d

When

  • endpoint not in sanctioned registry

Then

  • block
  • revoke session token
Enforcing inline at the gatewayInspect rule →
criticalOwner · Payments Risk214 triggers / 30d

When

  • amount > ₹10,00,000
  • initiated by agent

Then

  • escalate to approver
  • SLA 30 min
Enforcing inline at the gatewayInspect rule →

POL-006 · All prompts & logs

PII masking required

highOwner · DPO1,830 triggers / 30d

When

  • recogniser hit on stored payload

Then

  • mask in transit
  • mask in ledger
Enforcing inline at the gatewayInspect rule →

POL-007 · All channels

Sensitive prompts blocked

highOwner · AppSec76 triggers / 30d

When

  • prompt classified restricted-topic

Then

  • block
  • coach user
Enforcing inline at the gatewayInspect rule →

POL-008 · Retrieval + tools

Prompt injection protection

criticalOwner · AppSec268 triggers / 30d

When

  • injection classifier score > 0.72

Then

  • strip untrusted segment
  • block on repeat
Enforcing inline at the gatewayInspect rule →

POL-009 · Customer-facing

Toxicity detection

mediumOwner · Customer Experience44 triggers / 30d

When

  • toxicity > 0.4 on output

Then

  • rewrite
  • warn agent
Enforcing inline at the gatewayInspect rule →

POL-010 · All channels

Jailbreak detection

highOwner · Red Team59 triggers / 30d

When

  • known jailbreak signature
  • role-play override attempt

Then

  • block
  • open security case
Enforcing inline at the gatewayInspect rule →

POL-011 · AML agents

Narrative grounding required

mediumOwner · Financial Crime33 triggers / 30d

When

  • citation coverage < 80%

Then

  • warn
  • attach source list
Enforcing inline at the gatewayInspect rule →

POL-012 · Wealth copilots

Suitability disclosure on advice

mediumOwner · Wealth Compliance12 triggers / 30d

When

  • output contains product recommendation

Then

  • append disclosure
  • log consent
Disabled — evaluations logged onlyInspect rule →