Policy on prompt content
Guardrails answer "should this be blocked?". Connect applies them at the point every request passes.
Content policies evaluate a request body against rules. Built-in detectors cover common secrets, including cloud access keys, repository tokens, private-key blocks, signed tokens and API keys, and common personal-data patterns such as email addresses, phone numbers and identifier formats. You can add your own patterns. A matching rule can redact the content, replacing it with a placeholder, before the request is forwarded, and can raise an alert.
Pattern-based detection is a safety net, not a guarantee. It will not catch every sensitive value, and it does not replace deciding which data a workload may send at all. Treat it as one layer alongside provider choice and, for sensitive workloads, self-hosted models.