Bedrock-Guardrail-Firewall logo

Bedrock-Guardrail-Firewall

2Free

Stop unsafe AI traffic before it spreads with enterprise PII redaction, prompt-injection defense, grounding checks, tamper-evident auditing, and...

Quick Facts

Pricing
Free
4
views
0
favorites
Added
Aug 2026
Official URL
github.com

Tool overview

Overview

Bedrock Guardrail Firewall is a privacy-first enforcement layer for generative AI systems. It combines deterministic local controls, optional Microsoft Presidio analysis, and the Amazon Bedrock ApplyGuardrail API without invoking a foundation model. The production runtime remains a single Python file: orchestrator.py . Policy, documentation, tests, and repository automation are kept separate so the runtime stays portable and auditable. The system evaluates user input, candidate output, and retrieval context. It can sanitize detected sensitive data before optional Bedrock Guardrails calls, and a local review, escalation, or block decision prevents live content transmission. After optional cloud processing, Bedrock-transformed content is size-checked and re-evaluated by local privacy, policy, and grounding controls. The runtime returns one of five actions: allow, sanitize, queue_for_review, escalate, or block. Sanitized content is released only for allow and sanitize recommendations. AWS safety modes include disabled, preview, and live. The CLI requires both --aws-mode live and --enable-live-aws . Policy profiles include balanced, production, and offline_test. The project is intended as a policy enforcement point around application traffic, not a network firewall, web application firewall, IAM system, malware scanner, factuality oracle, or replacement for human approval. A caller must honor the returned action, content-release flag, and capability restrictions.

Features

  • AI assistant
  • Natural language interface
  • Workflow automation

Tags

generative-ai
ai-security
amazon-bedrock
aws
aws-govcloud
ai
ai assistant
automation

Use Cases

  • Teams use Bedrock Guardrail Firewall to inspect user input, candidate output, and retrieval context.

  • Teams use Bedrock Guardrail Firewall to sanitize sensitive data before optional Bedrock Guardrails calls.

  • Teams use Bedrock Guardrail Firewall to prevent live content transmission when a local review, escalation, or block decision occurs.

  • Teams use Bedrock Guardrail Firewall to route enterprise reviews through optional Amazon SQS queues.

  • Teams use Bedrock Guardrail Firewall to protect audit evidence with optional Amazon S3 Object Lock and KMS encryption.

  • Teams use Bedrock Guardrail Firewall to run offline checks with no AWS calls and no AWS client creation.

  • Teams use Bedrock Guardrail Firewall to enforce a production profile that requires both Presidio and live Bedrock Guardrails and fails closed when either is unavailable.

  • Teams use Bedrock Guardrail Firewall to create tamper-evident local audit events with a SHA-256 hash chain and optional AWS KMS signatures.

User Reviews

No reviews yet. Be the first to share your experience!

Rankings & collections