Skip to main content
There are different policy groups, each with specific environment variables and header keys, which can be tailored to the specifications and requirements of your organization. Additionally, you can set the conviction severity levels to determine the appropriate threat level for your organization to trigger a conviction or a block. By default, the policy is to alert only for all detections (all blocks are set to False by default). Policy configurations can in most (not all) cases additionally be sent at runtime via an additional request header. As stated above, please note that the headers will override deployment-level policy settings, enabling unique policies for different use cases within a single LLM proxy deployment.
Policy SettingsThe environment variables on this page are for policy configuration. If you use these during the Runtime deployment (values.yaml), it could impact making policy changes in the future. For example, if you set HL_LLM_BLOCK_UNSAFE: "true" as a deployment setting, this will affect your output if you try setting "block_unsafe": false in your policy because the deployment set it to true.

Global

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_BLOCK_MESSAGEn/aMessage was blocked.FalseThe message that displays when a message is blocked.
HL_LLM_BLOCK_UNSAFEX-LLM-Block-UnsafeFalseFalseIf overall verdict is true, the message will be blocked.
HL_LLM_BLOCK_UNSAFE_INPUTX-LLM-Block-Unsafe-InputFalseFalseIf unsafe input verdict is true, the message will be blocked.
HL_LLM_BLOCK_UNSAFE_OUTPUTX-LLM-Block-Unsafe-OutputFalseFalseIf unsafe output verdict is true, the message will be blocked.
HL_LLM_CHAT_COMPLETION_CONTEXT_WINDOWX-LLM-Chat-Completion-Context-WindowLASTFalseSize of chat completion window to perform analysis on FULL or LAST.

LAST - Only analyze the last message in a chat completion request.

FULL - Analyze all messages in a chat completion request.
HL_LLM_INCLUDE_BLOCK_MESSAGE_REASONSX-LLM-Include-Block-Message-ReasonsTrueFalseWhen enabled, the block message reasons will be included in the response.
HL_LLM_PROXY_ENABLE_PASSTHROUGH_STREAMINGX-LLM-Proxy-Enable-Passthrough-StreamingFalseFalseWhen enabled, the proxy will immediately start streaming the response back to the requester. Currently available for OpenAI.
HL_LLM_PROXY_ENABLE_HEADER_POLICYn/aTrueFalseEnable security rules to be set per request via HTTP headers.

Note: Recommended to set to False for production environments.
HL_LLM_PROXY_ENABLE_UNSECURED_ROUTE_PASSTHROUGHX-LLM-Proxy-Enable-Unsecured-Route-PassthroughTrueFalseWhen using Runtime Security as a reverse proxy, all transparent upstream requests passthrough for unsecured routes.
HL_LLM_PROXY_MAX_REQUEST_SIZE_BYTESX-LLM-Proxy-Max-Request-Size-Bytes1000000FalseThe maximum size for a request or a response, in bytes.
n/ax-requester-idRequesting IPFalseThe ID for the requester. This value takes precedence over hl-user-id, the requesting IP address (defined as the IP address communicating directly with the Runtime Security endpoint), and HL_LLM_PROXY_MLDR_DEFAULT_REQUESTER.
n/ahl-user-idNoneFalseThe ID for the HiddenLayer user. This value takes precedence over IP address and HL_LLM_PROXY_MLDR_DEFAULT_REQUESTER.
HL_LLM_PROXY_MLDR_DEFAULT_REQUESTERn/aUnknownFalseThe ID used if no other identification for the requester is found. The default is unknown.

Prompt Injection

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_PROMPT_INJECTION_DETECTIONX-LLM-Skip-Prompt-Injection-DetectionFalseFalseFlag to skip prompt injection detection.
HL_LLM_BLOCK_PROMPT_INJECTIONX-LLM-Block-Prompt-InjectionFalseFalseIf prompt injection category is true, the message will be blocked.
HL_LLM_PROMPT_INJECTION_SCAN_TYPEX-LLM-Prompt-Injection-Scan-TypeFULLFalseType of prompt injection scan to perform FULL or QUICK.
HL_LLM_PROXY_PROMPT_INJECTION_ALLOW_{{id}}X-LLM-Prompt-Injection-Allow-{{id}}n/aFalseOptional

Identifier for custom Prompt Injections Allowed Expression.

Note: {{id}} must contain only alpha-numeric characters without spaces.

Note: The Allow list takes priority over the Block list.
HL_LLM_PROXY_PROMPT_INJECTION_ALLOW_{{id}}_SUBSTRINGX-LLM-Prompt-Injection-Allow-{{id}}-Substringn/aFalseThe substring whose occurrences are redacted from the text analyzed by the prompt injection classifier, mapped to its identifier. This is an exact string match. It does not treat the overall prompt as benign—only removes matched substrings from classifier input.

Note: {{id}} must contain only alpha-numeric characters without spaces.

Caution: Take care when choosing the substring. A substring that is a commonly used word or phrase could exclude more of the prompt from analysis than intended.
HL_LLM_PROXY_PROMPT_INJECTION_ALLOW_{{id}}_EXPRESSIONX-LLM-Prompt-Injection-Allow-{{id}}-Expressionn/aFalseSame role as HL_LLM_PROXY_PROMPT_INJECTION_ALLOW_{{id}}_SUBSTRING, but the value is a regular expression; each match is excluded from the text analyzed by the prompt injection classifier.

Note: {{id}} must contain only alpha-numeric characters without spaces.

Caution: Broad or loosely written patterns can exclude large portions of the prompt from analysis.
HL_LLM_PROXY_PROMPT_INJECTION_BLOCK_{{id}}X-LLM-Prompt-Injection-Block-{{id}}n/aFalseOptional

Identifier for custom Prompt Injections Blocklist Expression.

Note: {{id}} must contain only alpha-numeric characters without spaces.

Note: The Allow list takes priority over the Block list.
HL_LLM_PROXY_PROMPT_INJECTION_BLOCK_{{id}}_SUBSTRINGX-LLM-Prompt-Injection-Block-{{id}}-Substringn/aFalseThe substring to indicate a prompt is malicious if detected as an input, mapped to its identifier. This is a string match.

Note: {{id}} must contain only alpha-numeric characters without spaces.

Caution: Take care when creating the substring to allow. A substring that is a commonly used word or phrase could block more than expected.
HL_LLM_PROMPT_INJECTION_CLASSIFICATION_THRESHOLDX-LLM-Prompt-Injection-Classification-ThresholddefaultFalseControls the threshold for prompt injection classification. The default value is default. The high setting requires a higher classification to trigger a detection, resulting in fewer prompt injection detections. Accepted values: default or high.

Prompt Injection Scan Types

  • QUICK - Only run the classifier on a single pass with 512 tokens.
  • FULL - Run classifier with multiple passes. This will strip certain characters and run the classifier on each line. Additional latency is added when using a FULL scan and increases with the size of input.

Examples

The following are examples for using keys that include variables. Prompt Injection Allow The following is an example config/vaules.yaml where the prompts “digital key” and “digitaler Schlüssel” are allowed.

Denial of Service

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_INPUT_DOS_DETECTIONX-LLM-Skip-Input-DOS-DetectionFalseFalseFlag to skip the LLM denial of service detection.
HL_LLM_BLOCK_INPUT_DOS_DETECTIONX-LLM-Block-Input-DOS-DetectionFalseFalseIf the LLM denial of service category is true, the message will be blocked.
HL_LLM_INPUT_DOS_DETECTION_THRESHOLDX-LLM-Input-DOS-Detection-Threshold4096FalseThreshold for input denial of service detection.

Personal Identifiable Information (PII)

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_REDACT_INPUT_PIIX-LLM-Redact-Input-PIIFalseFalseFlag to redact input before sending to the LLM.
HL_LLM_SKIP_INPUT_PII_DETECTIONX-LLM-Skip-Input-PII-DetectionFalseFalseFlag to skip input PII detection.
HL_LLM_BLOCK_INPUT_PIIX-LLM-Block-Input-PIIFalseFalseIf input PII category is true, message will be blocked.
HL_LLM_SKIP_OUTPUT_PII_DETECTIONX-LLM-Skip-Output-PII-DetectionFalseFalseFlag to skip output PII detection.
HL_LLM_BLOCK_OUTPUT_PIIX-LLM-Block-Output-PIIFalseFalseIf output PII category is true, message will be blocked.
HL_LLM_REDACT_OUTPUT_PIIX-LLM-Redact-Output-PIIFalseFalseFlag to redact output before sending to the caller.

HL_LLM_REDACT_TYPE

X-LLM-Redact-Type

ENTITY

False

Type of redaction to perform ENTITY (ex [PHONE_NUMBER]) / STRICT (ex [REDACTED])

  • ENTITY - Redaction will be done with the entity type identified. The company phone number is <PHONE_NUMBER>.
  • STRICT - Redaction will be made with the word REDACTED. The company phone number is [REDACTED].
HL_LLM_ENTITY_TYPEX-LLM-Entity-TypeSTRICTFalseEntity Groups ALL / STRICT. See LLM Entity Types for a list of available types.
HL_LLM_PROXY_PII_ALLOW_{{id}}X-LLM-PII-Allow-{{id}}n/aFalse
  • Optional
  • Identifier for custom PII Allowlist Expression.
  • Note: {{id}} must contain only alpha-numeric characters without spaces.
  • Note: The Allow list takes priority over the Block list.
HL_LLM_PROXY_PII_ALLOW_{{id}}_EXPRESSIONX-LLM-Proxy-PII-Allow-{{id}}-Expressionn/aFalse
  • The expression to allow if detected as PII, mapped to its identifier. This is a string match.
  • Note: {{id}} must contain only alpha-numeric characters without spaces.
  • Note: The Allow list takes priority over the Block list.
HL_LLM_PROXY_PII_CUSTOM_{{name}}X-LLM-PII-Custom-{{name}}NoneFalseName of custom PII recognizer. If Name is supplied, expression must also be provided under same name.
HL_LLM_PROXY_PII_CUSTOM_{{name}}_ENTITYX-LLM-PII-Custom-{{name}}-EntityFalseThe entity to replace custom PII with, if found.
HL_LLM_PROXY_PII_CUSTOM_((name))_EXPRESSIONX-LLM-PII-Custom-((name))-ExpressionNoneFalseThe regex expression used to find custom PII.
HL_LLM_OVERRIDE_INPUT_PII_ENTITIESX-LLM-Override-Input-PII-EntitiesNoneFalseOverride list of input PII entities that should be looked for in the text.
HL_LLM_OVERRIDE_OUTPUT_PII_ENTITIESX-LLM-Override-Output-PII-EntitiesNoneFalseOverride list of output PII entities that should be looked for in the text.
HL_LLM_PII_INPUT_ENTITY_CONFIDENCE_THRESHOLDX-LLM-PII-Input-Entity-Confidence-ThresholdMediumFalseThe minimum confidence threshold for detecting an entity in inputs. Accepted values: low, medium, or high.
HL_LLM_PII_OUTPUT_ENTITY_CONFIDENCE_THRESHOLDX-LLM-PII-Output-Entity-Confidence-ThresholdMediumFalseThe minimum confidence threshold for detecting an entity in outputs. Accepted values: low, medium, or high.
HL_LLM_PII_INPUT_ENTITY_ENABLE_CONTEXTX-LLM-PII-Input-Entity-Enable-ContextFalseFalseWhether to incorporate context of surrounding words in to the confidence score is enabled. This can increase latency is response times.
HL_LLM_PII_OUTPUT_ENTITY_ENABLE_CONTEXTX-LLM-PII-Output-Entity-Enable-ContextFalseFalseWhether to incorporate context of surrounding words in to the confidence score is enabled. This can increase latency is response times.

LLM Entity Types

ALL
ENABLED BY DEFAULT
STRICT

Code Detection

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_INPUT_CODE_DETECTIONX-LLM-Skip-Input-Code-DetectionFalseFalseFlag to skip code detection.
HL_LLM_BLOCK_INPUT_CODE_DETECTIONX-LLM-Block-Input-Code-DetectionFalseFalseIf the input code detection category is true, the message will be blocked.
HL_LLM_SKIP_OUTPUT_CODE_DETECTIONX-LLM-Skip-Output-Code-DetectionFalseFalseFlag to skip code detection.
HL_LLM_BLOCK_OUTPUT_CODE_DETECTIONX-LLM-Block-Output-Code-DetectionFalseFalseIf the output code detection category is true, the message will be blocked.
HL_LLM_TIMEOUT_INPUT_CODE_SECONDSX-LLM-Timeout-Input-Code-SecondsFalseFalseThe number of seconds the code detector should run for an individual request before timing out. Accepted value: integer (example: 10).
HL_LLM_TIMEOUT_INPUT_CODE_IS_DETECTIONX-LLM-Timeout-Input-Code-Is-DetectionFalseFalseWhen the code detector times out, should the time out be considered a positive detection for code. Accepted values: true or false.
HL_LLM_TIMEOUT_OUTPUT_CODE_SECONDSX-LLM-Timeout-Output-Code-SecondsFalseFalseThe number of seconds the code detector should run for an individual request before timing out. Accepted value: integer (example: 10).
HL_LLM_TIMEOUT_OUTPUT_CODE_IS_DETECTIONX-LLM-Timeout-Output-Code-Is-DetectionFalseFalseWhen the code detector times out, should the time out be considered a positive detection for code. Accepted values: true or false.

Guardrail

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_GUARDRAIL_DETECTIONX-LLM-Skip-Guardrail-DetectionFalseFalseFlag to skip guardrail detection.
HL_LLM_SKIP_GUARDRAIL_CLASSIFICATION_DETECTIONFalseFalseFlag to skip guardrail classification
HL_LLM_BLOCK_GUARDRAIL_DETECTIONX-LLM-Block-Guardrail-DetectionFalseFalseIf the guardrail detection category is false, the message will be blocked.

Language Detection

Attackers attempting to do prompt injection may use multiple languages. HiddenLayer’s language detector provides more visibility into your AI usage and helps control potentially malicious behavior. It runs on input prompts only. The language detector has two components:
  • When enabled, it predicts whether a prompt is one of the top 20 most spoken languages, or returns unknown.
  • It allows you to select a set of supported languages, which lets only those languages through.
Supported languages
  • HiddenLayer’s prompt injection model is trained and evaluated for seven languages: English, French, German, Italian, Japanese, Korean, and Spanish.
  • Using language detection can block all unsupported languages, providing an extra layer of security against prompt injection.
  • The algorithm requires a minimum of 40 characters to recognize and block unsupported languages.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_INPUT_LANGUAGE_DETECTIONX-LLM-Skip-Input-Language-DetectionTrueFalseSkips input language detection and allows the prompt to be analyzed.
HL_LLM_BLOCK_INPUT_LANGUAGE_DETECTIONX-LLM-Block-Input-Language-DetectionFalseFalse

Blocks inputs that are not on the allowed language list.

See HL_LLM_INPUT_ALLOWED_LANGUAGES for allowed languages.

HL_LLM_INPUT_ALLOWED_LANGUAGESX-LLM-Input-Allowed-Languagesn/aFalse

Allows languages included in your allowed list to be analyzed by the prompt injection model.

When multiple languages are included in the input, Runtime Security will choose a language it identifies as principal and classify it as such.

The default language values are: en, es, fr, it, de, ja, ko for English, Spanish, French, Italian, German, Japanese and Korean. So not setting this variable means the default languages are used.

Expand to see languages

AR - Arabic

BN - Bengali

DE - German

EN - English

ES - Spanish

FR - French

HI - Hindi

ID - Indonesian

IT - Italian

JA - Japanese

KO - Korean

MR - Marathi

PA - Punjabi

PT - Portuguese

RU - Russian

TA - Tamil

TE - Telugu

TR - Turkish

UR - Urdu

VI - Vietnamese

ZH - Chinese

Examples

Allowed languages

Example environment keys
Example header key

Block input language detection

Example environment key
Example header key

Skip input language detection

Example environment key
Example header key

URL Detection

By default, the policy will be alert only for all detections. Most configuration settings are true or false, with false being the default setting. For configurations with different settings, the settings are identified in the Description.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_SKIP_INPUT_URL_DETECTIONX-LLM-Skip-Input-URL-DetectionFalseFalseFlag to skip input URL detection.
HL_LLM_SKIP_OUTPUT_URL_DETECTIONX-LLM-Skip-Output-URL-DetectionFalseFalseFlag to skip output URL detection.

Conviction Severity Level

With these variables, you can set the threat level that is required for the model to convict.
Environment KeyHeader KeyDefaultRequiredDescription
HL_LLM_PROXY_CONVICTION_SEVERITY_GUARDRAILX-LLM-Conviction-Severity-Guardrail”Low”FalseSets severity for Guardrail conviction category. Accepted values: “Low”, “Medium”, “High”
HL_LLM_PROXY_CONVICTION_SEVERITY_DATA_LEAKAGEX-LLM-Conviction-Severity-Data-Leakage”Medium”FalseSets severity for Data Leakage conviction category. Accepted values: “Low”, “Medium”, “High”
HL_LLM_PROXY_CONVICTION_SEVERITY_PROMPT_INJECTIONX-LLM-Conviction-Severity-Prompt-Injection”High”FalseSets severity for Prompt Injection conviction category. Accepted values: “Low”, “Medium”, “High”
HL_LLM_PROXY_CONVICTION_SEVERITY_DENIAL_OF_SERVICEX-LLM-Conviction-Severity-Denial-Of-Service”High”FalseSets severity for Denial-of-Service conviction category. Accepted values: “Low”, “Medium”, “High”
HL_LLM_PROXY_CONVICTION_SEVERITY_MODALITY_RESTRICTIONX-LLM-Conviction-Severity-Modality-Restriction”Medium”FalseSets severity for Modality Restriction conviction category. Accepted values: “Low”, “Medium”, “High”