Industry rulepacks
Pre-built, sector-tuned runtime protection. Pick your industry to see the sensitive data it protects, the threats it blocks, and the AI use cases it covers.
Choose your industry
Healthcare Compliance
Redact PHI, block clinical advice, and keep an audit trail on every request.
Learn moreLegal Knowledge
Tokenize matter identifiers, block unauthorized advice, and preserve privilege.
Learn moreBFSI Fraud
Redact account and card data, block sanction-evasion, and log every AI decision.
Learn moreRequest Pipeline
Every request passes through configurable guardrail and PII engines backed by industry-specific rulepacks. Block, warn, or redact, per tenant, per customer, per pattern.
Active Engines
Rulepacks run on a stack of detection engines — regex, ML classifiers, and PII recognition — evaluated on every request.
Basic Guardrails
30+ regex and heuristic patterns for common threats
ML Guardrails
ML-powered contextual threat detection
Injection Guard
Real-time prompt injection and data exfiltration detection
Content Safety
Multi-category content moderation
Moderation Engine
Policy-violation classification at inference speed
PII Engine
ML-based PII entity recognition and redaction
Basic PII
Email, Phone, SSN, Credit Card, IP, IBAN, and more
Detection Actions
Every rule resolves to one of three actions, applied before the provider is called.
Block
Request is rejected pre-execution. Provider is never called. Returns controlled error with reason.
Warn
Request proceeds with a risk signal attached. Event recorded in audit trail for review.
Redact
PII replaced with typed masks ([EMAIL], [SSN]) before model exposure. Rehydrated on output.
How Rulepacks Work
Rulepacks are versioned policy packages that define what to detect and what action to take. They are evaluated in runtime against the active engines and scope of each request.
Rulepack Structure
Each rulepack defines domain-specific policies and detection rules (for healthcare, financial, government, and more), with priority-based resolution across domains. Every rule carries a severity level, a confidence score, and an action (block, warn, allow). PII rulepacks additionally define entity types and redaction masks.
Per-Tenant Activation
Engines and rulepacks are activated individually per tenant and can be narrowed to individual customers, giving fine-grained control without duplicating configuration. Each activation carries an enabled flag, environment scope, and default setting.
Custom Rulepacks
Any tenant can create custom rulepacks via the AegisPlane API or console. New rules are scoped per tenant and loaded into the runtime engine on the next request. Individual patterns within any rulepack can be disabled or extended without touching the base pack, enabling surgical customisation at any granularity.
Encode your own rules, no generic-control lock-in
In addition to ready-to-use industry packs, AegisPlane lets each organization build custom rulepacks tailored to its own language, risk profile, and operating workflows. This is critical for companies with market-specific requirements, internal policy constraints, or differentiated business processes. Commercially, this means you are not locked into generic controls: you can evolve protection at the speed of your business while preserving consistency across products, regions, and regulatory contexts.
- Full customization aligned with business objectives.
- Higher adaptability to new risks and market expansion.
- Competitive differentiation through organization-specific governance.
Ready to get started
Protection built for your industry, live on day one
Healthcare, financial, legal, retail and more. Each rulepack encodes your sector's risks and PII (PHI, PAN/IBAN, privilege, payment data) as policy. Swap the base-URL; no code changes; every request scoped to your tenant from the first call.







