Skip to main content
A guardrail inspects the traffic passing through the gateway and either lets it through, refuses it, or rewrites it. Six of them are available, and they differ in ways that matter before you pick one.

The one limit shared by all of them

A streamed response cannot be inspected or blocked as it is being written. The words are already reaching the reader by the time a detector would decide. Put a guardrail on the request leg, or on non-streamed responses, when you need it to actually stop something. On a streaming application, a response-side guardrail observes; it does not protect.

Choosing one

Four questions usually settle it. Do you already run TrustGuard? Then reach for its guardrail. Its findings line up with Telemetry alerts, so a detection here becomes part of the same picture as everything else you watch. No provider’s moderation API can do that. Do you need the content cleaned rather than the request refused? TrustGuard, Bedrock and Model Armor can rewrite the content in place and let the call continue. Azure and OpenAI Moderation return a score, so all they can do is allow or refuse. Is the rule something you can write down exactly? An internal hostname, a ticket reference, a key prefix — that is Regex Replace. It calls nothing, scores nothing, and does exactly what the pattern says. For anything needing judgement, you want one of the others. Do you already own the policy somewhere else? Bedrock and Model Armor reuse a guardrail or template you built in your own cloud account, so the definition lives in one place rather than two. That is their real argument, and the cost is a setup that happens in the provider’s console before this one is any use.

Two things worth knowing before you commit

Only TrustGuard keeps traffic flowing when it cannot be used — unreachable, too slow, refusing the gateway’s credentials, or not configured on the gateway. It forwards the call uninspected and records it as Failed Open, unless you set it to fail closed. Every other provider-backed guardrail here refuses the call in Enforce when its provider is unreachable, so an outage at the provider becomes an outage for your application. Decide which of those you want before you put a guardrail in front of production traffic. Azure never sees the model’s answer. It runs on requests only. If what you need to inspect is what the model said, this is not the one.

Combining them

A chain may hold several, and they run in policy-priority order. TrustGuard on the request and a Bedrock guardrail anonymising sensitive data on the response is a common pair: the first refuses what should not go out, the second cleans what comes back. A guardrail that rewrites content changes what any guardrail after it sees.