FastFence
Security policies between your agents and their models or tools.
FastFence is a local AI control layer with authenticated HTTP, OpenAI-compatible and MCP interfaces. It combines deterministic rules with real Laya/Qwen text assessment, applies input and output controls, reserves per-identity resource budgets, and records sanitized decisions. The management console lets you review policy changes, test requests and inspect activity.
Documentation · Getting started · Manual testing · API reference
Run locally
Requirements: macOS or Linux, Python 3.12 and a running Ollama service. Git and sh are needed by the installer for the pinned external Laya engine; no FastFence checkout is needed.
mkdir fastfence-local
cd fastfence-local
python3.12 -m venv .venv
source .venv/bin/activate
python -m pip install fastfence uv
fastfence init --anonymization
fastfence setup-laya
ollama pull qwen3:4b
ollama pull qwen3:0.6b
fastfence doctor
fastfence serve
Open http://127.0.0.1:8000, then Connection. Use local-admin from
state/credentials.json to manage policies and local-agent to make protected
requests. Tokens are randomly generated, private, and kept only in browser page
memory after you enter them. Management credentials cannot invoke agent operations.
The default policy uses Laya with Qwen3:4b to assess input and output text; Qwen3:0.6b is the separate protected completion model. Missing or failed assessment blocks the request. Nothing silently substitutes a deterministic-only classifier. Model assessment adds inference latency; local rules run before it.
For OCR of images and multipage PDFs:
fastfence setup-ocr
fastfence doctor --full
Restart after installing optional components or changing .env. OCR converts
attachments into inspected Markdown; it does not modify image or PDF pixels.
Make a protected request
This reads your local agent credential without writing it into shell history:
python - <<'PY'
import json
from pathlib import Path
import httpx
credentials = json.loads(Path("state/credentials.json").read_text())
response = httpx.post(
"http://127.0.0.1:8000/api/models/complete",
headers={"Authorization": "Bearer " + credentials["local-agent"]},
json={"model": "qwen3:0.6b", "prompt": "Hello", "max_output_tokens": 64},
timeout=120,
)
response.raise_for_status()
print(response.json())
PY
The result includes the decision, reason, request ID, active policy version,
semantic provider/score and whether the completion model ran. Find that request
in Activity. MCP clients connect to http://127.0.0.1:8000/mcp/; OpenAI clients
use http://127.0.0.1:8000/v1 with the same agent token. See integration examples.
Change a policy
- Open Policies and edit configuration or describe a rule in your own words.
- For a Laya-authored rule, inspect its scope, proposed changes and generated tests.
- Review the diff, run the tests and activate the reviewed version.
- Try your own inputs in Test requests and inspect the recorded decisions.
Laya has two roles: it drafts reviewable deterministic rules and assesses actual
request/response text when semantic.provider: laya is active. Trusted natural-language
assessment instructions belong in semantic.instructions. A precise restriction
such as forbidden letters should use a deterministic text rule; model judgments
are approximate and need evaluation for your policy.
The active policy is config/policy.yaml; valid higher versions hot-reload without
restarting. .env contains deployment settings. Reviewed generated tests are saved
in config/policy-tests.yaml. Invalid updates retain the last valid snapshot.
Connect business tools
The product includes no simulated business handlers. Implement ToolsPort,
inject the adapter with create_app(settings, tools=adapter), and allowlist its
operations and roles in policy. An allowlist without a connected adapter fails closed.
The opt-in business-tools example runs simulated search, tenant memory and payment preparation in a separate server and state directory. It illustrates adapter composition and does not handle real payments.
Update and verify
Stop the gateway, activate its virtual environment, then run:
python -m pip install --upgrade fastfence
fastfence doctor
fastfence serve
Reload the browser. Your working directory's configuration and private state are independent of the installed package; preserve and back them up. Initialization is repeatable and retains valid existing credentials and keys.
Download runnable examples, extract them into examples/ in your installation directory, and run python examples/protected_request.py --prompt 'Hello'. The documentation embeds the complete source for REST, named Laya policies, FastMCP, OpenAI SDK and public/private-key anonymization.
Repository development and automated suite instructions belong in Contributing. For product verification follow Manual testing.
Operating scope
Budgets and audit retention are bounded, in-memory and per process. Restarting clears them; replicas do not share a global quota. Identity configuration and optional anonymization keys are startup inputs, not a conversation database. Reversible anonymization requires an intact authenticated token, the correct key and explicit restoration permission. Keep keys and credentials private and backed up.
Model judgments can miss attacks or block legitimate text. Deterministic checks cover specific configured patterns, permissions and limits, not universal attack detection. Irreversible business actions require adapter-specific authorization and transaction controls. Architecture · Policies · Settings · Evaluation.
Licensed under Apache 2.0; see NOTICE. Dependencies retain their own licenses. Documentation uses MkDocs Material and GitHub Pages at fastfence.dev.
Metadata
Release files for fastfence 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| fastfence-0.1.1.tar.gz | 153.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| fastfence-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 356.1 kB
Release files / fastfence-0.1.1.tar.gz
| Download URL | fastfence-0.1.1.tar.gz |
|---|---|
| Size | 153.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
edffdf4302bc65dc7b1695e1f007e2ebe7b899545f35a180bf0375b719801eaf
|
|
BLAKE2b-256 checksum How to use checksums |
862bfa0d8973e9e7b30075ced41626bd70d53888b848d71f0247719c885d8545
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency logRelease files / fastfence-0.1.1-py3-none-any.whl
| Download URL | fastfence-0.1.1-py3-none-any.whl |
|---|---|
| Size | 203.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5cb6365176b8a6e4c8b89278b83a6f34b62f27c1f6f2cf791d1a9be8a977042c
|
|
BLAKE2b-256 checksum How to use checksums |
ddcd86eb37fa07060dd0a85c17ad0b5caf047ad6c7b7df1d299ec80f726e706d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 3, 2026.
Transparency log