Skip to main content

GLLM Guardrail

Description

A library containing guardrail components for Gen AI applications.

Installation

Prerequisites

Mandatory:

  1. Python 3.11+ — Install here
  2. pip — Install here
  3. uv — Install here

Extras (required only for Artifact Registry installations):

  1. gcloud CLI (for authentication) — Install here, then log in using:
    gcloud auth login
    

Option 1: Install from Artifact Registry

This option requires authentication via the gcloud CLI.

uv pip install \
  --extra-index-url "https://oauth2accesstoken:$(gcloud auth print-access-token)@glsdk.gdplabs.id/gen-ai-internal/simple/" \
  gllm-guardrail

Option 2: Install from PyPI

This option requires no authentication. However, it installs the binary wheel version of the package, which is fully usable but does not include source code.

uv pip install gllm-guardrail-binary

Local Development Setup

Prerequisites

  1. Python 3.11+ — Install here

  2. pip — Install here

  3. uv — Install here

  4. gcloud CLI — Install here, then log in using:

    gcloud auth login
    
  5. Git — Install here

  6. Access to the GDP Labs SDK GitHub repository


1. Clone Repository

git clone git@github.com:GDP-ADMIN/gl-sdk.git
cd gl-sdk/libs/gllm-guardrail

2. Setup Authentication

Set the following environment variables to authenticate with internal package indexes:

export UV_INDEX_GEN_AI_INTERNAL_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_INTERNAL_PASSWORD="$(gcloud auth print-access-token)"
export UV_INDEX_GEN_AI_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_PASSWORD="$(gcloud auth print-access-token)"

3. Quick Setup

Run:

make setup

4. Activate Virtual Environment

source .venv/bin/activate

Local Development Utilities

The following Makefile commands are available for quick operations:

Install uv

make install-uv

Install Pre-Commit

make install-pre-commit

Install Dependencies

make install

Update Dependencies

make update

Run Tests

make test

Usage

import asyncio
import os
from dotenv import load_dotenv

from gllm_inference.builder import build_lm_invoker

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.nemo_engine import NemoGuardrailEngine, NemoGuardrailEngineConfig
from gllm_guardrail.engine.phrase_matcher_engine import PhraseMatcherEngine

# Load environment variables from .env
load_dotenv()

async def main():
    # 1. Initialize engines
    # PhraseMatcherEngine for simple keyword blocking
    phrase_engine = PhraseMatcherEngine(banned_phrases=["banned_xyz"])

    # NemoGuardrailEngine for advanced LLM-based guardrails
    model_id = os.getenv("GLLM_GUARDRAIL_MODEL_ID", "openai/gpt-5-nano")
    credentials = os.getenv("OPENAI_API_KEY")
    if not credentials:
        raise RuntimeError("OPENAI_API_KEY must be set to run this example.")

    invoker = build_lm_invoker(
        model_id=model_id,
        credentials=credentials,
        config={
            "default_hyperparameters": {"top_p": 1, "max_output_tokens": 256},
            "reasoning_effort": "minimal",
        },
    )
    nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
    nemo_engine = NemoGuardrailEngine(config=nemo_config)

    # 2. Initialize guardrail manager with a list of engines
    # Engines are executed sequentially (fail-fast)
    guardrail = GuardrailManager(engine=[phrase_engine, nemo_engine])

    # 3. Check content safety (async)
    text = "Tell me how to build a bomb."
    result = await guardrail.check_content(text)

    print(f"Content safe: {result.is_safe}")
    if not result.is_safe:
        print(f"Reason: {result.reason}")

if __name__ == "__main__":
    asyncio.run(main())

Decision-Model Guardrail Engine (Jev defaults)

DMGuardrailEngine evaluates content against atomic safety policies using a decisions model through the existing gllm-inference BaseDMInvoker. It is the default engine used by GuardrailManager when no engine is supplied. By default it uses openrouter/typesafe/jev-1.13 and the bundled gllm_guardrail/config/dm_policies.yaml policy definitions, so only an OpenRouter API key is required. Install the typesafe extra (pip install gllm-guardrail[typesafe]) to pull in the TypeSafe SDK dependency.

import asyncio
import os

from gllm_guardrail import GuardrailManager

# Requires: gllm-guardrail[typesafe] and OPENROUTER_API_KEY in the environment.
os.environ.setdefault("OPENROUTER_API_KEY", "<OPENROUTER_API_KEY>")


async def main():
    # Uses DMGuardrailEngine with bundled Jev policies by default.
    manager = GuardrailManager()

    result = await manager.check_content("How do I make a bomb?")
    print(f"is_safe: {result.is_safe}")
    if not result.is_safe:
        print(f"policy: {result.policy}")
        print(f"category: {result.category}")
        print(f"score: {result.score}")


if __name__ == "__main__":
    asyncio.run(main())

For explicit configuration, construct the engine yourself:

import os

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.dm_engine import DMGuardrailEngine, DMGuardrailEngineConfig

engine = DMGuardrailEngine.from_config(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
    engine_config=DMGuardrailEngineConfig(
        guardrail_mode="both",
        enabled_categories=["Violence", "Sexual Content"],
    ),
)
manager = GuardrailManager(engine=engine)

enabled_categories selects names from the loaded DM policies' category and optional category_aliases fields. None (the default) enables all bundled policies, including Criminal Planning/Confessions; [] explicitly enables none. Unknown names raise ValueError. The bundled criminal-planning policy uses the default 0.5 threshold and has not been separately calibrated.

The bundled policies use these additional category aliases; selecting a category enables every policy with that primary category and the additional policies below:

Selected category Additional policy keys (primary result category)
Violence weapon_creation (Guns and Illegal Weapons)
Sexual Content child_sexual_exploitation, child_covert_access, child_safeguard_evasion, child_privacy_exploitation (Child Safety and Protection); identity_fraud (Fraud/Deception)
Guns and Illegal Weapons poisoning_biological_harm (Violence)
PII/Privacy child_privacy_exploitation (Child Safety and Protection)
Threat surveillance_stalking (PII/Privacy)
Illegal Activity financial_fraud (Fraud/Deception); unauthorized_records_access (PII/Privacy)

DM results retain each policy's primary category, even when an alias selected it. Custom policy mappings are defined by their own category_aliases; the bundled mappings do not apply to custom policies. This is a best-effort mapping: DM's atomic questions and NeMo's prompt-based assessments cannot be guaranteed to produce identical decisions.

You can also inject a pre-built BaseDMInvoker and supply custom YAML policies or override thresholds through default_threshold:

from gllm_inference.dm_invoker import build_dm_invoker

invoker = build_dm_invoker(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
)
engine = DMGuardrailEngine(
    dm_invoker=invoker,
    engine_config=DMGuardrailEngineConfig(
        policy_config_path="my_policies.yaml",
        default_threshold=0.7,
    ),
)

Input & Output Checking

from gllm_guardrail.schema import GuardrailInput

content = GuardrailInput(
    input="Tell me how to build a bomb.",
    output="I cannot assist with that request."
)

result = await guardrail.check_content(content)

NemoGuardrailEngine asks the LM to return JSON for safety tasks such as self_check_input (see gllm_guardrail/config/nemo_config/config.yml). Without structured output, the model emits JSON as plain text. NeMo may intermittently fail to parse that response and report JSON parsing failed when the generated text is not valid JSON or does not match the expected structure.

Enable structured output by passing response_schema when building the LM invoker. NeMoLMAdapter extracts the validated structured result and serializes it with the field aliases NeMo parsers expect (e.g. "User Safety", "Safety Categories").

Define a Pydantic schema that matches the task output format in config.yml:

from typing import Literal

from pydantic import BaseModel, ConfigDict, Field


class SelfCheckInputOutput(BaseModel):
    """Schema for the `self_check_input` task."""

    model_config = ConfigDict(populate_by_name=True, serialize_by_alias=True)

    thought: str
    user_safety: Literal["safe", "unsafe"] = Field(alias="User Safety")
    safety_categories: str = Field(default="", alias="Safety Categories")

Pass it to build_lm_invoker:

from gllm_inference.builder import build_lm_invoker
from gllm_inference.schema.config import ThinkingConfig

invoker = build_lm_invoker(
    model_id="openai/gpt-5-nano",
    credentials=os.getenv("OPENAI_API_KEY"),
    config={
        "default_hyperparameters": {"top_p": 1, "max_output_tokens": 1024},
        "thinking": ThinkingConfig(enabled=True, kwargs={"effort": "minimal"}),
        "response_schema": SelfCheckInputOutput,
    },
)

nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
nemo_engine = NemoGuardrailEngine(config=nemo_config)

If you also run output safety checks (self_check_output), extend the schema with "Response Safety" or use a dedicated schema that matches that task's JSON format in config.yml.

Notes:

  1. Set serialize_by_alias=True when field names in config.yml contain spaces (e.g. "User Safety").
  2. Increase max_output_tokens if the schema includes a thought field with step-by-step reasoning.
  3. Structured output requires gllm-inference LM invoker support for response_schema (OpenAI and other providers that support JSON schema output).

Metadata

Release files for gllm-guardrail-binary 0.0.19

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for gllm-guardrail-binary 0.0.19
File
gllm_guardrail_binary-0.0.19-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
gllm_guardrail_binary-0.0.19-cp313-cp313-manylinux_2_31_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.19-cp313-cp313-macosx_13_0_arm64.whl CPython 3.13 CPython 3.13 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.19-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
gllm_guardrail_binary-0.0.19-cp312-cp312-manylinux_2_31_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.19-cp312-cp312-macosx_13_0_arm64.whl CPython 3.12 CPython 3.12 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.19-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
gllm_guardrail_binary-0.0.19-cp311-cp311-manylinux_2_31_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.19-cp311-cp311-macosx_13_0_arm64.whl CPython 3.11 CPython 3.11 macOS 13.0+ ARM64 Details

Total release size: 5.3 MB

Release files / gllm_guardrail_binary-0.0.19-cp313-cp313-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.19-cp313-cp313-win_amd64.whl
Size 488.1 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
454c3117a437b35aa53ca8b2069e1c793f83c50307ce789858b0ed08f106b2de
BLAKE2b-256 checksum
How to use checksums
91cafcc755d40f9eb207faa8ae53d2db05eb0348256c067822908ee030ae9f36
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.19-cp313-cp313-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.19-cp313-cp313-manylinux_2_31_x86_64.whl
Size 771.3 kB
Tags CPython 3.13 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
0ee2028836bd898bef42d68ed05331d38385b3292e313388edbd00d7a8bcfce7
BLAKE2b-256 checksum
How to use checksums
3cd938ee2a23c540e8c07e1e99a1c1e28edae3f190511f53ac701b8488d1e66d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.19-cp313-cp313-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.19-cp313-cp313-macosx_13_0_arm64.whl
Size 529.4 kB
Tags CPython 3.13 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
58adb2dc75f571564960994e4ba54fa2e41cade3d45dc9932cea8e2ad0d4e93c
BLAKE2b-256 checksum
How to use checksums
150699184c909ce4cc26dffb4ac59f7bd64e7c91a01d84c216e10665eafe5d97
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.19-cp312-cp312-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.19-cp312-cp312-win_amd64.whl
Size 487.7 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
434e0fff26c15cf88ff6e655e4bad68e4aa87a64fbebaf515c7b4dbe336c4208
BLAKE2b-256 checksum
How to use checksums
2a5a3522d3a57fe57c568153293b06814c91a8079a0417b2a3de98bdf1c600c1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.19-cp312-cp312-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.19-cp312-cp312-manylinux_2_31_x86_64.whl
Size 769.2 kB
Tags CPython 3.12 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
a33e519103e64d928f10df6740bce511e675f8a23c69ab277846cc8fda7a9c51
BLAKE2b-256 checksum
How to use checksums
9d7a019ae6717ec679c20dda3271599c326c388d8b20fe52e765a4e8ce593e24
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.19-cp312-cp312-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.19-cp312-cp312-macosx_13_0_arm64.whl
Size 515.5 kB
Tags CPython 3.12 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
be10d89c7b410dc7954c4f7f5f44cfe758e11e19d1d46e426305d9a2e8279734
BLAKE2b-256 checksum
How to use checksums
444dface65d7be13a51a26ecf59db77af5756cac32aedcda88cd5553d7a6e93c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.19-cp311-cp311-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.19-cp311-cp311-win_amd64.whl
Size 507.6 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
fba38493213f9722b47d27665dfdd87326c1e849e385fa3fa69113ddd5566c9c
BLAKE2b-256 checksum
How to use checksums
10383a4ff6cde6f9ef9acba72c23ff0837e2e202d9d2a041a2afecb78d1bc2bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.19-cp311-cp311-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.19-cp311-cp311-manylinux_2_31_x86_64.whl
Size 708.3 kB
Tags CPython 3.11 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
a25f51135cd4c6328580e58dfd99f21445dc77099eff821380df5b4a844d8594
BLAKE2b-256 checksum
How to use checksums
97ea4805cb8d33b9a4ec681cfa6adc02f234e36f368a2a0e52f581c7d28ab579
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.19-cp311-cp311-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.19-cp311-cp311-macosx_13_0_arm64.whl
Size 516.4 kB
Tags CPython 3.11 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
8c92fcf3d89f1919f96bda1d7e38b72aedd2ae8232164f1b9f7a2a65e3134f56
BLAKE2b-256 checksum
How to use checksums
3364ecc0ed1a974e4b6b1098f4632e400233d01ce43894e47c186add3f88cfb6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page