Control & Trust·production

IAM.Secure

AI traffic inspection, DLP policies, prompt-injection protection and audit.

Key capabilities

  • Inline request and response inspection
  • DLP, masking, blocking and routing policy actions
  • Decision audit and security evidence

Step-by-step guides

Use cases

Start with the outcome: open a guide, prepare prerequisites, follow the steps and verify the success signals.

01 Create a DLP policy for AI trafficSensitive data is masked or blocked before it reaches the model.
Audience
Security engineer
Outcome
Sensitive data is masked or blocked before it reaches the model.

Before you start

  • Tenant and traffic source
  • Data-type inventory
  • Agreed mask or block action

Steps

  1. Create a policy setIn Policies, select tenant, channels and request/response direction.
  2. Add detectorsEnable the required PII/credential classifiers and tune exclusions using test data.
  3. Assign an actionFor each severity, choose allow, mask, block or route-to-local.
  4. Run a simulationTest safe and unsafe samples before enabling inline enforcement.
Verify the result

Simulation and live audit show the same rule id, expected action and redacted evidence.

If it does not work

For false positives, narrow scope and exceptions instead of disabling the policy.

02 Investigate a blocked request or prompt-injection eventThe analyst understands the source, rule, decision and related events without exposing secrets.
Audience
SOC analyst
Outcome
The analyst understands the source, rule, decision and related events without exposing secrets.

Before you start

  • Correlation id or time range
  • Incident and Audit access
  • Tenant scope

Steps

  1. Locate the eventFilter Incidents by tenant, action, severity and correlation id.
  2. Open evidenceReview classifier, matched-fragment hash, policy version and redaction state.
  3. Trace the chainFollow the correlation id to the Router decision and source product event.
  4. Record the conclusionAdd disposition, owner and remediation; never paste the source secret into a note.
Verify the result

The incident is closed with an owner, disposition and linked audit records.

If it does not work

If the chain breaks, verify correlation-id propagation in Router and the source product.

Application sections

Open detailed manual

Every application screen has a separate page with controls, safe example values, CLI/API alternatives and status-specific recovery steps.

Open detailed manual →

Role in the ecosystem

IAM.Secure checks incoming and outgoing AI traffic before data arrives into the model or downstream tool. The result of the inspection is a structured decision: allow, mask, route or block with an explanatory policy reason.

Main scenario

  1. The client passes the text or URL to dry-run/inline inspection.
  2. T0 rules perform fast deterministic checks.
  3. Classifiers evaluate DLP, injection, abuse and topic policy.
  4. Policy engine combines signals and selects action.
  5. The client receives a verdict and a secure audit reference.

Inline mode is used in real traffic, dry-run - for preliminary policy checks and demonstrations without accessing LLM.

Policy actions

ActionDestination
allowcontinue processing without conversion
maskremove or replace sensitive fragments
routeredirect the request to the agreed perimeter
blockcomplete request before downstream call

Integrations

Secure works before IAM.Router or a specific tool API. Identity context comes from IAM.Identity and IAM.Core may require a security verdict before capability invocation.

Data and audit

Raw secrets and PII should not end up in public logs. Audit stores the verdict, policy/version, request reference and applied actions. Masking should be reproducible, and blocking is distinguishable from provider failure.

Operation

Control the latency of each layer, the proportion of false positive/negative, the policy version, readiness of classifiers and fallback posture. If mandatory security component, the protected route must end with fail-closed.

Limit of responsibility

Secure is not a replacement for tenant authorization, network isolation, or storage encryption. It protects AI/content flow and complements rather than cancels regular security controls.