Skip to main content

The catalog is fixed: eight detectors, listed under Detectors → Catalog. Pick one, name it, configure it, then reference that instance from a policy.

Data loss prevention

PII and secrets. The only detector that can mask in flight.

Content security

Jailbreaks, toxicity, moderation, documents, and URLs.

Agent and MCP

Indirect prompt injection in tool-sourced content.

The catalog

Sides is which directions a detector supports. Masks marks the one detector that can rewrite the payload, which is what makes the Transform action available.

Data loss prevention

Content security

Agent & MCP security

How much there is to configure

Most of these have a single setting. Knowing which is which saves you opening each one: Protection Sensitivity is three preset cards — Permissive, Balanced (recommended), Strict — not a number you type.

How the catalog, detectors, and policies fit together

  • A catalog detector is a fixed capability. You cannot change what it looks for, only how it is tuned.
  • A detector is a named, reusable instance you create from a catalog entry. It is detection-only — it never decides what happens.
  • A policy references detectors in rules that set the action — Monitor, Block, Transform — and the phase, Input or Output.
  • Data Loss Prevention is the only detector where Transform is valid. Selecting Transform for any other detector is rejected when you save the policy.
One detector can be referenced by many policies, which is the point: tune it once, enforce it differently per collector.