Skip to main content

Data & Adversarial Risks

V2 console

This card lives in Policy Engine > LLM Gateway at web.quilr.ai/policy. Edits join the shared draft and take effect once you review and publish a revision.

Decide what happens when PII, PHI, financial data, secrets, prompt attacks or your own custom detections appear in a model request or response.

Data & Adversarial Risks card collapsed, showing Detection rules and Sensitivity profile rows

Sections​

Data & Adversarial Risks card expanded with the priority banner and the Detection rules section

SectionWhat it holdsEmpty state
Detection rulesWhich data types are found, how many times, and the action.Nothing is redacted or blocked; findings are still detected and reported.
Sensitivity profileDetection sensitivity per category, subcategory actions, and scan scope for the whole request.Engine defaults: every category detects at the engine's default sensitivity.

Applies on assistants, bedrock, chat, copilot, embeddings, rerank, responses, sdk_check, stt, text, tts and vertex.

Detection rule settings​

Add rule opens the New data rule dialog.

New data rule dialog with a detection line, action and stage buttons, and the Scan tool-call arguments option

SettingOptionsDefaultNotes
Data typesWhole category, individual types, or custom detectionsNoneChoose types... lists every category. Several types on one line match any of them.
Findings thresholdat least N1Per line.
ActionMonitor, Partial redact, Redact, BlockMonitorBlock on any line stops the whole request.
StageRequest, Response, BothRequestResponse redaction and blocking need the full response; streamed responses are scanned and tagged, not changed.
Tool boundaryScan tool-call argumentsOffJudges each tool call's arguments on their own. Only Monitor and Block apply.
SeverityNot set, Very low, Low, Medium, High, Critical, Very criticalNot setReported for dashboards, exports and alerts. Never changes the action.
More optionsPriority, extra rules, metadata and content conditions, raw QuilrQL-Opens the full editor.

Add more detection lines to one rule with + Add line. Each line keeps its own types, threshold, action and stage.

Example​

block_request_secretsrequest

runs on requestpriority 900

Whendata foundis any ofAuth & Secrets
Then
Sensitive data actionblock
Risk levelcritical

Start new detections on monitor, review activity, then raise the action.

Scoping and precedence​

  • Applies to: Everyone, People, Smart group, Application, App tag, Requested model, Provider, API surface, Environment, Prompt complexity, Prompt text, Tool, Source network, or Except.... Every chip must match; values accept * and ?.
  • Everyone is priority 500. Narrower scopes win over it.
  • Highest priority wins per data type. At equal priority the more restrictive action wins.
  • redact and partial-redact rewrite only the findings their own rule selected.

More examples, the full data type catalog and multi-rule configurations: LLM Gateway Policies.

Legacy app setting​

Replaces the data risks, adversarial risks and precision detections parts of an app's Security Guardrails. Custom detections themselves are still defined per app under Custom Intents.