> ## Documentation Index
> Fetch the complete documentation index at: https://trytilde.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Security middleware

> Screen every message into and out of an agent for PII, secrets, prompt injection, and unsafe content, or run your own guard script.

<Info>
  Security middleware is available in Tilde Enterprise today. It will be available soon in Tilde OSS and Tilde Cloud.
</Info>

Security middleware screens the text that flows into and out of an agent. You configure it for each agent. It runs inside the gateway and inside sidecars, so it applies whichever way traffic reaches the agent.

<img src="https://mintcdn.com/tilde/UIZH9VuZaVUMv6QU/images/security-middleware.drawio.svg?fit=max&auto=format&n=UIZH9VuZaVUMv6QU&q=85&s=d15bfa2ff4d9f1682ee984e7d629e137" alt="Security middleware pipeline: inbound messages pass through request guards before the agent, and agent replies pass through response guards before delivery, with each decision recorded as thread activity" width="1401" height="583" data-path="images/security-middleware.drawio.svg" />

<div className="zoom-hint"><Icon icon="magnifying-glass-plus" size={13} /> <em>Click to zoom</em></div>

## Where middleware runs

Middleware screens two directions.

| Direction | What it screens | When |
| - | - | - |
| **Request** | Human input: native chat posts and inbound provider messages, including email subjects. | After Tilde checks the sender's membership, and before the agent sees the message or anything is stored. |
| **Response** | Agent output: the text, HTML, subject, and caption of every message an agent sends. | Before the provider handler runs, so a blocked reply never leaves Tilde. |

## Guards

Six guards are available. You enable each guard separately for each direction.

| Guard | Detects | Actions |
| - | - | - |
| `pii` | Email addresses, credit card numbers, US social security numbers, IBANs, phone numbers, and IP addresses. With a model, also names, addresses, and dates. | Flag, redact, block |
| `secrets` | Private keys, AWS access keys, GitHub, Slack, Stripe, Google, OpenAI, and Anthropic keys, JWTs, bearer tokens, and generic `password=` style secrets. | Flag, redact, block |
| `jailbreak` | Prompt injection and jailbreak attempts. | Flag, block |
| `nsfw` | Sexual content. | Flag, block |
| `toxicity` | Hate, harassment, and abuse. | Flag, block |
| `custom` | Anything your script checks. | Flag, redact, block |

Pattern-based detection validates what it finds, such as card number and IBAN checksums, which keeps false positives low.

### Actions

* **Flag** records the finding and lets the text through.
* **Redact** replaces each matched span with its label, such as `[EMAIL_ADDRESS]`, and delivers the rest.
* **Block** stops the message. A blocked native post returns permission denied. A blocked provider message is never stored. A blocked reply fails the agent's tool call.

Each rule has an action and a confidence threshold. When several rules match, the strictest action wins. Guards run concurrently, so adding guards adds little latency.

## Configure middleware

You set an agent's guards in its **Security** tab, one rule for each guard and direction. Changes apply at once to the gateway and to the agent's sidecars, with no restart. The same policies are available through the management API.

## Write a custom guard <span className="alpha-tag">ALPHA</span>

A custom guard is one JavaScript function for each agent. Tilde calls it with the text and the direction, and it returns a list of findings.

```javascript Custom guard theme={"system"}
function guard(text, direction) {
  const findings = tilde.detectSecrets(text);
  const start = text.indexOf("PROJECT_ORCHID");
  if (start >= 0) {
    findings.push({ label: "INTERNAL_PROJECT", score: 1, start, end: start + 14 });
  }
  return findings;
}
```

Your function can call Tilde's built-in PII and secret detectors, so you extend them rather than replace them.

Custom guards run in a restricted sandbox with no file, network, or system access, and with strict time and memory limits.

## Guards fail closed

If a guard cannot reach a verdict, Tilde blocks the message. A guard failure never lets unscreened text through.

## What each decision records

Tilde records every decision, and you can review it in the agent's [Sessions](/docs/sessions) tab.

Each record names the guard, what it found, and its confidence. For custom guards it also identifies the exact script version that ran. It never contains the matched text, so your audit trail does not become a second copy of the sensitive data.
