Policy Configuration
There are different policy groups, each with specific environment variables and header keys, which can be tailored to the specifications and requirements of your organization. Additionally, you can set the conviction severity levels to determine the appropriate threat level for your organization to trigger a conviction or a block. By default, the policy is to alert only for all detections (all blocks are set to False by default).
Policy configurations can in most (not all) cases additionally be sent at runtime via an additional request header. As stated above, please note that the headers will override deployment-level policy settings, enabling unique policies for different use cases within a single LLM proxy deployment.
Global
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Prompt Injection
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the description.
Prompt Injection Scan Types
QUICK- Only run the classifier on a single pass with 512 tokens.FULL- Run classifier with multiple passes. This will strip certain characters and run the classifier on each line. Additional latency is added when using a FULL scan and increases with the size of input.
Examples
The following are examples for using keys that include variables.
Prompt Injection Allow
The following is an example config/vaules.yaml where the prompts “digital key” and “digitaler Schlüssel” are allowed.
Denial of Service
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Personal Identifiable Information (PII)
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
LLM Entity Types
ALL
ENABLED BY DEFAULT
STRICT
Code Detection
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Guardrail
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Language Detection
Attackers attempting to do prompt injection may use multiple languages. HiddenLayer’s language detector provides more visibility into your AI usage and helps control potentially malicious behavior. It runs on input prompts only.
The language detector has two components:
- When enabled, it predicts whether a prompt is one of the top 20 most spoken languages, or returns unknown.
- It allows you to select a set of supported languages, which lets only those languages through.
HiddenLayer’s prompt injection model is trained and evaluated for seven languages: English, French, German, Italian, Japanese, Korean, and Spanish.
Using language detection can block all unsupported languages, providing an extra layer of security against prompt injection.
Examples
Allowed languages
Example environment keys
Example header key
Block input language detection
Example environment key
Example header key
Skip input language detection
Example environment key
Example header key
URL Detection
By default, the policy will be alert only for all detections.
Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Conviction Severity Level
With these variables, you can set the threat level that is required for the model to convict.