Skip to main content
Security middleware is available in Tilde Enterprise today. It will be available soon in Tilde OSS and Tilde Cloud.
Security middleware screens the text that flows into and out of an agent. You configure it for each agent. It runs inside the gateway and inside sidecars, so it applies whichever way traffic reaches the agent. Security middleware pipeline: inbound messages pass through request guards before the agent, and agent replies pass through response guards before delivery, with each decision recorded as thread activity
Click to zoom

Where middleware runs

Middleware screens two directions.

Guards

Six guards are available. You enable each guard separately for each direction. Pattern-based detection validates what it finds, such as card number and IBAN checksums, which keeps false positives low.

Actions

  • Flag records the finding and lets the text through.
  • Redact replaces each matched span with its label, such as [EMAIL_ADDRESS], and delivers the rest.
  • Block stops the message. A blocked native post returns permission denied. A blocked provider message is never stored. A blocked reply fails the agent’s tool call.
Each rule has an action and a confidence threshold. When several rules match, the strictest action wins. Guards run concurrently, so adding guards adds little latency.

Configure middleware

You set an agent’s guards in its Security tab, one rule for each guard and direction. Changes apply at once to the gateway and to the agent’s sidecars, with no restart. The same policies are available through the management API.

Write a custom guard ALPHA

A custom guard is one JavaScript function for each agent. Tilde calls it with the text and the direction, and it returns a list of findings.
Custom guard
Your function can call Tilde’s built-in PII and secret detectors, so you extend them rather than replace them. Custom guards run in a restricted sandbox with no file, network, or system access, and with strict time and memory limits.

Guards fail closed

If a guard cannot reach a verdict, Tilde blocks the message. A guard failure never lets unscreened text through.

What each decision records

Tilde records every decision, and you can review it in the agent’s Sessions tab. Each record names the guard, what it found, and its confidence. For custom guards it also identifies the exact script version that ran. It never contains the matched text, so your audit trail does not become a second copy of the sensitive data.