Guardrails
AI you can put in front of customers.
Without holding your breath. Every message is screened on the way in and the way out — PII redacted before the model sees it, prompt-injection and off-topic detours blocked, every check logged. On-brand and compliant by default.
Checked in and out — secrets never reach the model or the screen.
What the model actually sees.
Personal data is swapped for typed tokens before the message reaches the model. The reply is written against the tokens; the real values never leave your workspace.
Hi, my email is elif.kaya@gmail.com and I paid with card 5412 7534 8891 0042 — can you check my refund?
Hi, my email is [EMAIL] and I paid with card [CARD] — can you check my refund?
2 values redacted before the model · restored only on your screen
01Layers
Three layers, on by default.
Redaction before the model, guardrails on the way in and out, one database schema per workspace. System guardrails ship on; you add your own per assistant.
Redaction
Email, phone, card, TC Kimlik, IBAN — detected and tokenised; the stream is buffered so nothing flashes mid-reply.
Two checkpoints
Content moderation, injection detection, off-topic routing and your own LLM rules — before the model and before the customer.
Isolation
A schema per workspace, an audit trail of every verdict, forget-user on request. KVKK and GDPR by default.

02Rules
Your rules, checked every turn.
Beyond the system guards, an assistant carries your own: what it may claim, what it must never do, when to hand off. A message that tries to override them is blocked and logged — the customer gets a polite no.

- Injection
- Pattern and LLM detectors catch instruction overrides before the model reasons on them.
- Off-topic
- Detours are routed back or handed off, never improvised.
- Audit trail
- Every verdict is kept per conversation; overrides can be scoped to a single chat.
Proof of control
One masked, one blocked, all logged.
Two messages from one conversation. The first has its email and card tokenised and passes. The second tries to override the instructions and is stopped at the input guard — the model never sees it.
- 1redact_pii12 msInputmessage #12 values → [EMAIL] [CARD]12 ms
- 2content_moderator8 msInputmessage #1pass8 ms
- 3llm_output_guard220 msInputreply #1pass · on-brand220 ms
- 4injection_detector6 msInputmessage #2blocked · 'ignore your instructions'6 ms
- 5audit_log3 msInput2 verdictsrecorded · conversation #88413 ms
Connected channels and stores
All integrations- Web widget
- Shopify
- Zendesk
- REST API
Ready to meet your AI agent?
Book a demo and we'll build a working agent on your real data — across WhatsApp, Instagram and your website. Live in days.