Skip to main content

GLLM Guardrail

Description

A library containing guardrail components for Gen AI applications.

Installation

Prerequisites

Mandatory:

  1. Python 3.11+ — Install here
  2. pip — Install here
  3. uv — Install here

Extras (required only for Artifact Registry installations):

  1. gcloud CLI (for authentication) — Install here, then log in using:
    gcloud auth login
    

Option 1: Install from Artifact Registry

This option requires authentication via the gcloud CLI.

uv pip install \
  --extra-index-url "https://oauth2accesstoken:$(gcloud auth print-access-token)@glsdk.gdplabs.id/gen-ai-internal/simple/" \
  gllm-guardrail

Option 2: Install from PyPI

This option requires no authentication. However, it installs the binary wheel version of the package, which is fully usable but does not include source code.

uv pip install gllm-guardrail-binary

Local Development Setup

Prerequisites

  1. Python 3.11+ — Install here

  2. pip — Install here

  3. uv — Install here

  4. gcloud CLI — Install here, then log in using:

    gcloud auth login
    
  5. Git — Install here

  6. Access to the GDP Labs SDK GitHub repository


1. Clone Repository

git clone git@github.com:GDP-ADMIN/gl-sdk.git
cd gl-sdk/libs/gllm-guardrail

2. Setup Authentication

Set the following environment variables to authenticate with internal package indexes:

export UV_INDEX_GEN_AI_INTERNAL_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_INTERNAL_PASSWORD="$(gcloud auth print-access-token)"
export UV_INDEX_GEN_AI_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_PASSWORD="$(gcloud auth print-access-token)"

3. Quick Setup

Run:

make setup

4. Activate Virtual Environment

source .venv/bin/activate

Local Development Utilities

The following Makefile commands are available for quick operations:

Install uv

make install-uv

Install Pre-Commit

make install-pre-commit

Install Dependencies

make install

Update Dependencies

make update

Run Tests

make test

Usage

import asyncio
import os
from dotenv import load_dotenv

from gllm_inference.builder import build_lm_invoker

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.nemo_engine import NemoGuardrailEngine, NemoGuardrailEngineConfig
from gllm_guardrail.engine.phrase_matcher_engine import PhraseMatcherEngine

# Load environment variables from .env
load_dotenv()

async def main():
    # 1. Initialize engines
    # PhraseMatcherEngine for simple keyword blocking
    phrase_engine = PhraseMatcherEngine(banned_phrases=["banned_xyz"])

    # NemoGuardrailEngine for advanced LLM-based guardrails
    model_id = os.getenv("GLLM_GUARDRAIL_MODEL_ID", "openai/gpt-5-nano")
    credentials = os.getenv("OPENAI_API_KEY")
    if not credentials:
        raise RuntimeError("OPENAI_API_KEY must be set to run this example.")

    invoker = build_lm_invoker(
        model_id=model_id,
        credentials=credentials,
        config={
            "default_hyperparameters": {"top_p": 1, "max_output_tokens": 256},
            "reasoning_effort": "minimal",
        },
    )
    nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
    nemo_engine = NemoGuardrailEngine(config=nemo_config)

    # 2. Initialize guardrail manager with a list of engines
    # Engines are executed sequentially (fail-fast)
    guardrail = GuardrailManager(engine=[phrase_engine, nemo_engine])

    # 3. Check content safety (async)
    text = "Tell me how to build a bomb."
    result = await guardrail.check_content(text)

    print(f"Content safe: {result.is_safe}")
    if not result.is_safe:
        print(f"Reason: {result.reason}")

if __name__ == "__main__":
    asyncio.run(main())

Decision-Model Guardrail Engine (Jev defaults)

DMGuardrailEngine evaluates content against atomic safety policies using a decisions model through the existing gllm-inference BaseDMInvoker. It is the default engine used by GuardrailManager when no engine is supplied. By default it uses openrouter/typesafe/jev-1.13 and the bundled gllm_guardrail/config/dm_policies.yaml policy definitions, so only an OpenRouter API key is required. Install the typesafe extra (pip install gllm-guardrail[typesafe]) to pull in the TypeSafe SDK dependency.

import asyncio
import os

from gllm_guardrail import GuardrailManager

# Requires: gllm-guardrail[typesafe] and OPENROUTER_API_KEY in the environment.
os.environ.setdefault("OPENROUTER_API_KEY", "<OPENROUTER_API_KEY>")


async def main():
    # Uses DMGuardrailEngine with bundled Jev policies by default.
    manager = GuardrailManager()

    result = await manager.check_content("How do I make a bomb?")
    print(f"is_safe: {result.is_safe}")
    if not result.is_safe:
        print(f"policy: {result.policy}")
        print(f"category: {result.category}")
        print(f"score: {result.score}")


if __name__ == "__main__":
    asyncio.run(main())

For explicit configuration, construct the engine yourself:

import os

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.dm_engine import DMGuardrailEngine, DMGuardrailEngineConfig

engine = DMGuardrailEngine.from_config(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
    engine_config=DMGuardrailEngineConfig(guardrail_mode="both"),
)
manager = GuardrailManager(engine=engine)

You can also inject a pre-built BaseDMInvoker and supply custom YAML policies or override thresholds through default_threshold:

from gllm_inference.dm_invoker import build_dm_invoker

invoker = build_dm_invoker(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
)
engine = DMGuardrailEngine(
    dm_invoker=invoker,
    engine_config=DMGuardrailEngineConfig(
        policy_config_path="my_policies.yaml",
        default_threshold=0.7,
    ),
)

Input & Output Checking

from gllm_guardrail.schema import GuardrailInput

content = GuardrailInput(
    input="Tell me how to build a bomb.",
    output="I cannot assist with that request."
)

result = await guardrail.check_content(content)

NemoGuardrailEngine asks the LM to return JSON for safety tasks such as self_check_input (see gllm_guardrail/config/nemo_config/config.yml). Without structured output, the model emits JSON as plain text. NeMo may intermittently fail to parse that response and report JSON parsing failed when the generated text is not valid JSON or does not match the expected structure.

Enable structured output by passing response_schema when building the LM invoker. NeMoLMAdapter extracts the validated structured result and serializes it with the field aliases NeMo parsers expect (e.g. "User Safety", "Safety Categories").

Define a Pydantic schema that matches the task output format in config.yml:

from typing import Literal

from pydantic import BaseModel, ConfigDict, Field


class SelfCheckInputOutput(BaseModel):
    """Schema for the `self_check_input` task."""

    model_config = ConfigDict(populate_by_name=True, serialize_by_alias=True)

    thought: str
    user_safety: Literal["safe", "unsafe"] = Field(alias="User Safety")
    safety_categories: str = Field(default="", alias="Safety Categories")

Pass it to build_lm_invoker:

from gllm_inference.builder import build_lm_invoker
from gllm_inference.schema.config import ThinkingConfig

invoker = build_lm_invoker(
    model_id="openai/gpt-5-nano",
    credentials=os.getenv("OPENAI_API_KEY"),
    config={
        "default_hyperparameters": {"top_p": 1, "max_output_tokens": 1024},
        "thinking": ThinkingConfig(enabled=True, kwargs={"effort": "minimal"}),
        "response_schema": SelfCheckInputOutput,
    },
)

nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
nemo_engine = NemoGuardrailEngine(config=nemo_config)

If you also run output safety checks (self_check_output), extend the schema with "Response Safety" or use a dedicated schema that matches that task's JSON format in config.yml.

Notes:

  1. Set serialize_by_alias=True when field names in config.yml contain spaces (e.g. "User Safety").
  2. Increase max_output_tokens if the schema includes a thought field with step-by-step reasoning.
  3. Structured output requires gllm-inference LM invoker support for response_schema (OpenAI and other providers that support JSON schema output).

Metadata

Release files for gllm-guardrail-binary 0.0.17

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for gllm-guardrail-binary 0.0.17
File
gllm_guardrail_binary-0.0.17-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
gllm_guardrail_binary-0.0.17-cp313-cp313-manylinux_2_31_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17-cp313-cp313-macosx_13_0_arm64.whl CPython 3.13 CPython 3.13 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.17-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
gllm_guardrail_binary-0.0.17-cp312-cp312-manylinux_2_31_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17-cp312-cp312-macosx_13_0_arm64.whl CPython 3.12 CPython 3.12 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.17-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
gllm_guardrail_binary-0.0.17-cp311-cp311-manylinux_2_31_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17-cp311-cp311-macosx_13_0_arm64.whl CPython 3.11 CPython 3.11 macOS 13.0+ ARM64 Details

Total release size: 5.2 MB

Release files / gllm_guardrail_binary-0.0.17-cp313-cp313-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17-cp313-cp313-win_amd64.whl
Size 476.0 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
a083840fee621e0bd6550787ab089ba2f97fa941eea1bf2da8d592b606b2e918
BLAKE2b-256 checksum
How to use checksums
e8fbfe232c5caa9a5b9b0cea9b28c43b93574a2653bb47b2f2641ea6a6d68afb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17-cp313-cp313-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17-cp313-cp313-manylinux_2_31_x86_64.whl
Size 755.4 kB
Tags CPython 3.13 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
b50fb00cef334e15844c5144fdc641a696396a1e9765ded676acb664c320f907
BLAKE2b-256 checksum
How to use checksums
f989d1c7127ec33f4b2fb54241de81d8d05c7392faa1cc6ad659609fc21ae485
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17-cp313-cp313-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17-cp313-cp313-macosx_13_0_arm64.whl
Size 518.8 kB
Tags CPython 3.13 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
4af7cfe81a45e701277eade10d838c7fa1e9d63d56ac7083e098ed1156ec7fd2
BLAKE2b-256 checksum
How to use checksums
d8e30c58538690d0c3b5525f5c8d00d325f971757a0d14b1157a80fd115f6e3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17-cp312-cp312-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17-cp312-cp312-win_amd64.whl
Size 475.7 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
a6fa23d0b40370d67daf7a977c7079d9a4087a73c7a68397328806a7003ac5af
BLAKE2b-256 checksum
How to use checksums
cf717610b6116568bb48b07f9aca2e6c12d36436f1c22ef8be28af1f20adf484
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17-cp312-cp312-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17-cp312-cp312-manylinux_2_31_x86_64.whl
Size 754.0 kB
Tags CPython 3.12 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
ee007781a975360666bec02ea282ebee0fb0b843099c4fd7caee40e7dedf23f6
BLAKE2b-256 checksum
How to use checksums
464e0c45c8eeb1d6095309f2fc9ffe2982b59b6bfcbebf50d265e631e4b5eb8b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17-cp312-cp312-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17-cp312-cp312-macosx_13_0_arm64.whl
Size 502.4 kB
Tags CPython 3.12 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
b85e9149332d6117be6d4ee898ce3a702201bed1c4a87524f2d20ece6c7bb0c3
BLAKE2b-256 checksum
How to use checksums
f392e0d42b44bb80963c6a6688d030abf7f86066b0a55eb16c32a4e09bdf7353
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17-cp311-cp311-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17-cp311-cp311-win_amd64.whl
Size 496.1 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
7972fe60e41105e42c60f7ae9569ccca68353ad6279798a8d57647d90d3a67c3
BLAKE2b-256 checksum
How to use checksums
e66cfa28675d51aba73899c0b7ef465812cd6e426dc1803dffbeb00911bd08f9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17-cp311-cp311-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17-cp311-cp311-manylinux_2_31_x86_64.whl
Size 692.4 kB
Tags CPython 3.11 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
77d1e678a4725f5ccf13dd7e3265f7c65f3a16553bf5dd18f548b4d1c109654e
BLAKE2b-256 checksum
How to use checksums
ac34d7148b4c60b2c440a11f152982ef6d57f08b032d9cda2e01b7e84ff8cb18
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17-cp311-cp311-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17-cp311-cp311-macosx_13_0_arm64.whl
Size 503.7 kB
Tags CPython 3.11 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
9c3dcd840cbe8103f9006296f97abb113b10003297c9bcbd3ef9bdae77d7d88c
BLAKE2b-256 checksum
How to use checksums
41b2a42f930a6cac710f244cad337cc550e83e81b18945bb853fce19e00228a5
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page