Skip to main content

DlpCfg

Struct DlpCfg 

Source
pub struct DlpCfg {
Show 20 fields pub mode: String, pub redact_style: String, pub scan_request: bool, pub scan_response: bool, pub stream_redact: bool, pub reversible: bool, pub detect_email: bool, pub detect_credit_card: bool, pub luhn_validate_credit_card: bool, pub detect_secrets: bool, pub detect_ssn: bool, pub detect_phone: bool, pub detect_iban: bool, pub detect_high_entropy: bool, pub detect_prompt_injection: bool, pub entropy_min_len: usize, pub entropy_threshold: f64, pub gazetteer_terms: Vec<String>, pub custom_patterns: Vec<String>, pub ner: NerCfg,
}
Expand description

Edge-DLP settings ([llm.dlp]). When mode is not off, request and/or response bodies are scanned for PII and secrets; the mode decides what happens on a finding (report / block / redact). See crate::dlp.

Fields§

§mode: String

off | report | block | redact. Default off.

§redact_style: String

How a span is rewritten in redact mode: full ([REDACTED:<cat>], default) | mask (keep last 4) | hash (stable opaque token). See crate::dlp::RedactStyle.

§scan_request: bool

Scan the inbound request body (the prompt). Default true.

§scan_response: bool

Scan the (buffered) response body and, in report mode, streamed frames. Default true.

§stream_redact: bool

In redact mode, also rewrite streamed SSE frames (not just buffered bodies). Deterministic detectors only — NER never runs on the stream. Off by default: streaming redaction can only rewrite spans the carry buffer fully contains, so enable it deliberately. See crate::dlp.

§reversible: bool

Reversible masking (redact mode only). When on, an inbound finding is replaced with a stable placeholder token (<edgeguard-<cat>-<n>>) instead of an irreversible [REDACTED] tag, and the placeholder→original map is kept for the request so the response is unmasked (buffered and streamed) back to the original value. The provider never sees the PII; the client gets its own data back — the round-trip an unmask keyed on shared state gets wrong. Off by default. When on, the response is unmasked rather than re-scanned/redacted (restore, not detect).

§detect_email: bool

Built-in detectors.

§detect_credit_card: bool

Detect card numbers. Pair with luhn_validate_credit_card to require a valid checksum, which removes most false positives from ordinary long digit strings.

§luhn_validate_credit_card: bool

Require the Luhn checksum before flagging a digit run as a card (cuts false positives). Default true.

§detect_secrets: bool

AWS keys, provider-style xx-… keys, and private-key blocks.

§detect_ssn: bool

US SSN (NNN-NN-NNNN). Default true.

§detect_phone: bool

Phone numbers. Off by default — false-positives on ordinary numeric runs.

§detect_iban: bool

IBAN account numbers. Off by default — false-positives on uppercase+digit tokens.

§detect_high_entropy: bool

High-entropy token sweep (catch-all). Off by default — can false-positive.

§detect_prompt_injection: bool

Prompt-injection / jailbreak heuristics for agent traffic (a small, high-precision built-in deny set — “ignore previous instructions”, “reveal your system prompt”, etc.), reported under the prompt_injection category. Off by default (opt-in, report-first) since instructions to a model are legitimate traffic; enable and watch the counter before moving to block.

§entropy_min_len: usize

Minimum token length the entropy sweep considers.

§entropy_threshold: f64

Per-character Shannon-entropy threshold (bits) for the entropy sweep.

§gazetteer_terms: Vec<String>

Dictionary deny-list: literal terms matched case-insensitively (Aho-Corasick), reported under the gazetteer category. The fast, many-term path for known names / codenames / identifiers.

§custom_patterns: Vec<String>

Extra regexes (linear-time regex syntax), all reported under the custom category.

§ner: NerCfg

Optional ML NER family ([llm.dlp.ner]). Requires the ner cargo feature; catches person/address/org spans regex can’t. See NerCfg.

Trait Implementations§

Source§

impl Clone for DlpCfg

Source§

fn clone(&self) -> DlpCfg

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for DlpCfg

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for DlpCfg

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for DlpCfg
where DlpCfg: Default,

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more