Overview
Guard adds guardrails to your large language model (LLM) application. This page covers what Guard checks for and how to run it on prompts and responses.
What Guard protects against
Guard is part of the Python software development kit (SDK). You build an ordered list of guards, and each guard checks a piece of text for one kind of problem. Use Guard to stop leaked secrets, prompt-injection attempts, and malformed output before they reach the model or your users.
The SDK includes the following guards.
Guard | Checks | Runs on | Default action | Protects against |
| Personally identifiable information (PII) and secrets | Prompt and response |
| API keys, tokens, credentials, and personal data such as email addresses, phone numbers, Social Security numbers, card numbers, and IPv4 addresses |
| Prompt injection | Prompt |
| Instruction overrides, jailbreaks, system-prompt extraction, role impersonation, encoding bypasses, and delimiter abuse |
| Moderation | Prompt and response |
| Profanity and toxic or threatening language |
| Sensitive topics | Prompt and response |
| Violence, politics, substance use, mental health, discrimination, and adult content |
| Topic restriction | Prompt |
| Prompts outside a list of allowed topics, or inside a list of denied topics. You supply the classifier that labels the topic. |
| Output format | Response |
| Model output that isn't valid JSON or doesn't match a schema you provide |
| Your own check | Prompt and response, unless you choose one |
| Anything you define with a regular expression or a Python function |
Import the guard classes from acceldata_aio_tracer or from acceldata_aio_tracer.guard. For every parameter of each guard, see the Python SDK reference.
How it works
- You pick the guards and their order. Each guard has an action that sets what it does when it finds a problem:
allow: let the text through.warn: let the text through and record the finding.redact: let a rewritten copy of the text through. For example,PIIreplaces an email address with[REDACTED:email].deny: block the text.
- The guards run at a phase. The
preflightphase checks the prompt before the model call. Thepostflightphase checks the response after the model call. A guard that doesn't support the current phase is skipped. - The guards run in list order. When a guard redacts text, the guards after it receive the redacted text. When a guard returns
deny, the run stops and no later guard runs. - You get one overall result. The overall action is the most severe action any guard returned, from least to most severe:
allow,warn,redact,deny. - Each check is recorded. Every guard evaluation adds a
guard.evaluationevent to the current span of your trace and increments theguard.requestsmetric, if metrics are set up.
Turn on Guard
To turn Guard on, build a Pipeline and call evaluate on each prompt and response. Before you start, install the SDK as described in Instrument your code.
from acceldata_aio_tracer import PII, Moderation, Pipeline, PromptInjection
pipeline = Pipeline(guards=[PromptInjection(), PII(), Moderation()])
prompt = "My email is jane.doe@example.com. Summarize my last order."
result = pipeline.evaluate(prompt, phase="preflight")
if result.action.value == "deny":
raise RuntimeError(f"Prompt blocked: {result.explanation}")
if result.transformed_text is not None:
prompt = result.transformed_text
print(result.action.value)
print(prompt)
The PII guard finds the email address and redacts it, so the example prints:
redact
My email is [REDACTED:email]. Summarize my last order.
To check the model's response, call pipeline.evaluate(response_text, phase="postflight") with the response text.
The PipelineResult that evaluate returns has these fields:
action: the overall action.results: one result for each guard that ran.transformed_text: the final text, if a guard changed it. Otherwise,None.explanation: what each guard found, joined with semicolons.
Important
evaluate doesn't block anything by itself. Check result.action and stop the call yourself when it's deny.
Choose what happens when a guard fails
A pipeline is fail-open by default. If a guard raises an exception, its result counts as allow, and the SDK logs a warning such as Guard 'pii' raised during preflight evaluation; fail-open -> allow. To raise the guard's exception instead, create the pipeline with Pipeline(guards=[...], fail_open=False).

Have a suggestion?