Platform Feature • Data Classification & Guardrails

Real-Time AI Guardrails & PII Protection.
Prevent Hallucinations, Leaks & Toxic Content.

Protect your enterprise with deterministic input/output guardrails. Automatically mask sensitive PII (SSN, credit cards, health data), block prompt injection attacks, and enforce strict safety policies.

Describe your PII guardrail policy — RhinoAgents executes it
Real-Time PII Masking Prompt Injection Defense Toxicity & Safety Filters Deterministic Output Limits
100%
detection of credit card, SSN & phone PII
< 15ms
real-time guardrail evaluation overhead
Zero
prompt injection breaches recorded
Full
HIPAA, GDPR & PCI-DSS compliance
Live Inspection Preview

Live Scanner & Inspection Studio

Test how RhinoAgents scans multi-entity payloads with zero latency, flags regulatory violations, and executes per-category policy actions instantly.

RhinoGuard Engine // Live Stream Interceptor
12/12 Categories Active
6 sensitive spans in this sample
12/12 categories active
Coverage:
PCI-DSS 2
GLBA 1
CCPA 4
GDPR 5
HIPAA 1
BIPA 1
GDPR Art. 9 1
COPPA 1
SOC 2 1
Hi, this is John from Acme Property Group. My SSN is 412-08-6577, and please update my card on file: 4532 1188 2039 4433, exp 09/27. Reach me at or . Ship the thermostat to 118 Maple Ave, Austin TX 78701. Also, loop in Dr. Patel about my knee MRI results from last week. Oh — and I prefer eco-friendly HVAC filters going forward.
Configurable Matrix

12 Active Data Categories

Customize how every data category is handled across your AI agents and chatbots. Choose from 6 deterministic policy actions.

Financial & payment

PCI-DSS, GLBA & SOX Compliance

2 Categories
Payment card data Critical

PAN, CVV, expiry, cardholder name

Bank & routing details Critical

Account no, routing no, IBAN, SWIFT/BIC

Government & national IDs

National Identification & Tax Regimes

2 Categories
SSN / national ID Critical

SSN, SIN, Aadhaar, NIN, tax ID

Passport & driver's license High

Passport no, license no, license plate

Contact & personal identifiers

GDPR, CCPA & Privacy Shield

2 Categories
Email & phone High

Email address, mobile/landline number

Physical & mailing address High

Street address, ZIP, unit/apartment no

Special category data

HIPAA, BIPA & GDPR Article 9

3 Categories
Health information (PHI) Special category

MRN, diagnosis, prescriptions, visit notes

Biometric identifiers Special category

Face/voice/fingerprint templates, gait data

Children's data Special category

Age <13 signals, school name, guardian refs

Credentials & secrets

DevOps, API & Cyber Defense

1 Category
API keys & credentials Critical

API keys, passwords, OAuth tokens, private keys

Business context

Operational Telemetry & User Experience

2 Categories
Precise location & device ID Monitor

GPS coordinates, IMEI, device/IP address

Preferences & free text Monitor

Product preferences, project notes, general context

Action Engines

6 Policy Enforcement Modes

Deterministic execution engines built to handle every compliance requirement without breaking downstream agent workflows.

Tokenize Reversible Vault

Vaulted Tokenization

Replaces payment cards and high-risk secrets with cryptographic reference tokens. Swapped back inside a secure enclave without exposing raw data to LLMs.

// Raw Input: 4532 1188 2039 4433
// LLM Sees: tok_live_79a29e4b81c
Redact Permanent Removal

Permanent Redaction

Completely replaces government IDs, SSNs, and bank routing numbers with deterministic replacement tags before data touches transcripts or embeddings.

// Raw Input: SSN 412-08-6577
// LLM Sees: [REDACTED-SSN-****]
Mask Partial Obfuscation

Format-Preserving Mask

Preserves domain formatting, state/ZIP codes, and first/last characters for human verification and validation while obscuring personal identifiers.

// Raw Input: john.smith@company.com
// LLM Sees: j***h@company.com
Block Execution Halt

Hard Interception

Immediately halts message execution when critical violations (e.g. PHI health data, child data, API private keys) are identified.

// Violation: PHI Medical Notes
// Output: ERR_POLICY_BLOCK
Flag SIEM / SOC Telemetry

Telemetry Flagging

Allows the message to process seamlessly without altering context, while dispatching high-priority audit events to Splunk, Datadog, or SIEM queue.

// Inbound: GPS: 30.2672° N, 97.7431° W
// Action: Dispatched to SIEM
Allow Zero Friction

Clean Context Pass

Permits general business intent, project notes, product preferences, and unstructured domain feedback to pass directly with zero latency.

// Inbound: Prefer eco HVAC filters
// Action: Clean Context Passed
Universal Controls

Configure Across Your Entire AI Fleet

One unified guardrail policy system that enforces compliance everywhere your agents operate.

AI Agents

Sanitize prompts before reasoning loops, protect RAG knowledge embeddings, and mask outputs before external webhook calls.

Settings > AI Agents > Guardrails

AI Chatbots

Client-side and server-side filtering for website visitors. Tokenize credit cards and redact SSNs before CRM sync.

Settings > Chatbots > Security

Voice AI Agents

Stream-level speech-to-text tokenization so card data and national IDs are never saved in telephony audio recordings.

Settings > Voice > PII Shield

Live Inspection Preview

Interactive visual studio where compliance teams can dry-run sample prompts, inspect spans, and verify policies before rollout.

Settings > Live Inspection Studio
Common Inquiries

Frequently Asked Questions

Everything you need to know about implementing PII guardrails for enterprise AI agents.

How do Guardrails prevent sensitive data from training public LLM models?

Because guardrail inspection happens before prompts are dispatched to LLMs (OpenAI, Anthropic, Google Gemini, or local models), sensitive identifiers are transformed into vault tokens or redaction markers. The underlying LLM never sees or ingests the raw PII data.

Can our engineering team add custom regex or proprietary domain entities?

Yes. In addition to the 12 core categories, RhinoAgents allows you to define custom regex patterns, employee ID formats, internal part numbers, and custom keywords with custom severity ratings.

How does Vaulted Tokenization work when an agent needs to charge a card?

The agent receives a scoped token (e.g. tok_live_79a29e4b81c). When triggering a Stripe or payment gateway tool, the execution gateway swaps the token with encrypted card data within a PCI-DSS Level 1 compliant enclave without ever exposing the raw number to the LLM agent prompt.

Does RhinoAgents sign Business Associate Agreements (BAA) for HIPAA compliance?

Yes. For healthcare and enterprise customers handling Protected Health Information (PHI), RhinoAgents provides signed HIPAA BAAs, dedicated VPC deployments, and hardware security module (HSM) key isolation.

Get Started

Deploy Safe, Compliant AI Agents Today

Protect customer data, eliminate compliance risks, and empower your AI agents and chatbots to operate securely at enterprise scale.

Enterprise contracts available · Dedicated onboarding · SOC 2 · GDPR · HIPAA