Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

GLLM Guardrail

Description

A library containing guardrail components for Gen AI applications.

Installation

Prerequisites

Mandatory:

  1. Python 3.11+ — Install here
  2. pip — Install here
  3. uv — Install here

Extras (required only for Artifact Registry installations):

  1. gcloud CLI (for authentication) — Install here, then log in using:
    gcloud auth login
    

Option 1: Install from Artifact Registry

This option requires authentication via the gcloud CLI.

uv pip install \
  --extra-index-url "https://oauth2accesstoken:$(gcloud auth print-access-token)@glsdk.gdplabs.id/gen-ai-internal/simple/" \
  gllm-guardrail

Option 2: Install from PyPI

This option requires no authentication. However, it installs the binary wheel version of the package, which is fully usable but does not include source code.

uv pip install gllm-guardrail-binary

Local Development Setup

Prerequisites

  1. Python 3.11+ — Install here

  2. pip — Install here

  3. uv — Install here

  4. gcloud CLI — Install here, then log in using:

    gcloud auth login
    
  5. Git — Install here

  6. Access to the GDP Labs SDK GitHub repository


1. Clone Repository

git clone git@github.com:GDP-ADMIN/gl-sdk.git
cd gl-sdk/libs/gllm-guardrail

2. Setup Authentication

Set the following environment variables to authenticate with internal package indexes:

export UV_INDEX_GEN_AI_INTERNAL_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_INTERNAL_PASSWORD="$(gcloud auth print-access-token)"
export UV_INDEX_GEN_AI_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_PASSWORD="$(gcloud auth print-access-token)"

3. Quick Setup

Run:

make setup

4. Activate Virtual Environment

source .venv/bin/activate

Local Development Utilities

The following Makefile commands are available for quick operations:

Install uv

make install-uv

Install Pre-Commit

make install-pre-commit

Install Dependencies

make install

Update Dependencies

make update

Run Tests

make test

Usage

import asyncio
import os
from dotenv import load_dotenv

from gllm_inference.builder import build_lm_invoker

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.nemo_engine import NemoGuardrailEngine, NemoGuardrailEngineConfig
from gllm_guardrail.engine.phrase_matcher_engine import PhraseMatcherEngine

# Load environment variables from .env
load_dotenv()

async def main():
    # 1. Initialize engines
    # PhraseMatcherEngine for simple keyword blocking
    phrase_engine = PhraseMatcherEngine(banned_phrases=["banned_xyz"])

    # NemoGuardrailEngine for advanced LLM-based guardrails
    model_id = os.getenv("GLLM_GUARDRAIL_MODEL_ID", "openai/gpt-5-nano")
    credentials = os.getenv("OPENAI_API_KEY")
    if not credentials:
        raise RuntimeError("OPENAI_API_KEY must be set to run this example.")

    invoker = build_lm_invoker(
        model_id=model_id,
        credentials=credentials,
        config={
            "default_hyperparameters": {"top_p": 1, "max_output_tokens": 256},
            "reasoning_effort": "minimal",
        },
    )
    nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
    nemo_engine = NemoGuardrailEngine(config=nemo_config)

    # 2. Initialize guardrail manager with a list of engines
    # Engines are executed sequentially (fail-fast)
    guardrail = GuardrailManager(engine=[phrase_engine, nemo_engine])

    # 3. Check content safety (async)
    text = "Tell me how to build a bomb."
    result = await guardrail.check_content(text)

    print(f"Content safe: {result.is_safe}")
    if not result.is_safe:
        print(f"Reason: {result.reason}")

if __name__ == "__main__":
    asyncio.run(main())

Decision-Model Guardrail Engine (Jev defaults)

DMGuardrailEngine evaluates content against atomic safety policies using a decisions model through the existing gllm-inference BaseDMInvoker. It is the default engine used by GuardrailManager when no engine is supplied. By default it uses openrouter/typesafe/jev-1.13 and the bundled gllm_guardrail/config/dm_policies.yaml policy definitions, so only an OpenRouter API key is required. Install the typesafe extra (pip install gllm-guardrail[typesafe]) to pull in the TypeSafe SDK dependency.

import asyncio
import os

from gllm_guardrail import GuardrailManager

# Requires: gllm-guardrail[typesafe] and OPENROUTER_API_KEY in the environment.
os.environ.setdefault("OPENROUTER_API_KEY", "<OPENROUTER_API_KEY>")


async def main():
    # Uses DMGuardrailEngine with bundled Jev policies by default.
    manager = GuardrailManager()

    result = await manager.check_content("How do I make a bomb?")
    print(f"is_safe: {result.is_safe}")
    if not result.is_safe:
        print(f"policy: {result.policy}")
        print(f"category: {result.category}")
        print(f"score: {result.score}")


if __name__ == "__main__":
    asyncio.run(main())

For explicit configuration, construct the engine yourself:

import os

from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.dm_engine import DMGuardrailEngine, DMGuardrailEngineConfig

engine = DMGuardrailEngine.from_config(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
    engine_config=DMGuardrailEngineConfig(guardrail_mode="both"),
)
manager = GuardrailManager(engine=engine)

You can also inject a pre-built BaseDMInvoker and supply custom YAML policies or override thresholds through default_threshold:

from gllm_inference.dm_invoker import build_dm_invoker

invoker = build_dm_invoker(
    model_id="openrouter/typesafe/jev-1.13",
    credentials=os.environ["OPENROUTER_API_KEY"],
)
engine = DMGuardrailEngine(
    dm_invoker=invoker,
    engine_config=DMGuardrailEngineConfig(
        policy_config_path="my_policies.yaml",
        default_threshold=0.7,
    ),
)

Input & Output Checking

from gllm_guardrail.schema import GuardrailInput

content = GuardrailInput(
    input="Tell me how to build a bomb.",
    output="I cannot assist with that request."
)

result = await guardrail.check_content(content)

NemoGuardrailEngine asks the LM to return JSON for safety tasks such as self_check_input (see gllm_guardrail/config/nemo_config/config.yml). Without structured output, the model emits JSON as plain text. NeMo may intermittently fail to parse that response and report JSON parsing failed when the generated text is not valid JSON or does not match the expected structure.

Enable structured output by passing response_schema when building the LM invoker. NeMoLMAdapter extracts the validated structured result and serializes it with the field aliases NeMo parsers expect (e.g. "User Safety", "Safety Categories").

Define a Pydantic schema that matches the task output format in config.yml:

from typing import Literal

from pydantic import BaseModel, ConfigDict, Field


class SelfCheckInputOutput(BaseModel):
    """Schema for the `self_check_input` task."""

    model_config = ConfigDict(populate_by_name=True, serialize_by_alias=True)

    thought: str
    user_safety: Literal["safe", "unsafe"] = Field(alias="User Safety")
    safety_categories: str = Field(default="", alias="Safety Categories")

Pass it to build_lm_invoker:

from gllm_inference.builder import build_lm_invoker
from gllm_inference.schema.config import ThinkingConfig

invoker = build_lm_invoker(
    model_id="openai/gpt-5-nano",
    credentials=os.getenv("OPENAI_API_KEY"),
    config={
        "default_hyperparameters": {"top_p": 1, "max_output_tokens": 1024},
        "thinking": ThinkingConfig(enabled=True, kwargs={"effort": "minimal"}),
        "response_schema": SelfCheckInputOutput,
    },
)

nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
nemo_engine = NemoGuardrailEngine(config=nemo_config)

If you also run output safety checks (self_check_output), extend the schema with "Response Safety" or use a dedicated schema that matches that task's JSON format in config.yml.

Notes:

  1. Set serialize_by_alias=True when field names in config.yml contain spaces (e.g. "User Safety").
  2. Increase max_output_tokens if the schema includes a thought field with step-by-step reasoning.
  3. Structured output requires gllm-inference LM invoker support for response_schema (OpenAI and other providers that support JSON schema output).

Metadata

Release files for gllm-guardrail-binary 0.0.17b1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for gllm-guardrail-binary 0.0.17b1
File
gllm_guardrail_binary-0.0.17b1-cp313-cp313-win_amd64.whl CPython 3.13 CPython 3.13 Windows x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp313-cp313-manylinux_2_31_x86_64.whl CPython 3.13 CPython 3.13 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp313-cp313-macosx_13_0_arm64.whl CPython 3.13 CPython 3.13 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.17b1-cp312-cp312-win_amd64.whl CPython 3.12 CPython 3.12 Windows x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp312-cp312-manylinux_2_31_x86_64.whl CPython 3.12 CPython 3.12 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp312-cp312-macosx_13_0_arm64.whl CPython 3.12 CPython 3.12 macOS 13.0+ ARM64 Details
gllm_guardrail_binary-0.0.17b1-cp311-cp311-win_amd64.whl CPython 3.11 CPython 3.11 Windows x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp311-cp311-manylinux_2_31_x86_64.whl CPython 3.11 CPython 3.11 Linux glibc 2.31+ x86-64 Details
gllm_guardrail_binary-0.0.17b1-cp311-cp311-macosx_13_0_arm64.whl CPython 3.11 CPython 3.11 macOS 13.0+ ARM64 Details

Total release size: 5.2 MB

Release files / gllm_guardrail_binary-0.0.17b1-cp313-cp313-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp313-cp313-win_amd64.whl
Size 476.0 kB
Tags CPython 3.13 Windows x86-64
SHA-256 checksum
How to use checksums
bf0863595ce3f80818f63b182699f822ba6a887358200103007d50a2b7a25a2c
BLAKE2b-256 checksum
How to use checksums
a8e3b0557c01b5ba762af7ca327d63da75f010592e6af477828541dd72e1f140
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17b1-cp313-cp313-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp313-cp313-manylinux_2_31_x86_64.whl
Size 755.4 kB
Tags CPython 3.13 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
db238e9a2a94a8c192179db86b97f40fbbec468b8e87c0e2e54c36136f0e426a
BLAKE2b-256 checksum
How to use checksums
cb252a7af9d920117eae4aade73ce49a7adea68c8b085f1b0d9156ee9e5e4cc1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17b1-cp313-cp313-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp313-cp313-macosx_13_0_arm64.whl
Size 518.8 kB
Tags CPython 3.13 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
581ca92cd5234a37a3487899312eb6bf896dc94a3a956095bf593a9b248c9dfe
BLAKE2b-256 checksum
How to use checksums
53094def7342d59a8b8149fbb84e562cc55d62cda901332484fd5fe11bd998cd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17b1-cp312-cp312-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp312-cp312-win_amd64.whl
Size 475.7 kB
Tags CPython 3.12 Windows x86-64
SHA-256 checksum
How to use checksums
52f345c258e0491e2b290b174fda0a9b87cb4d2b8a2fa1dc10e01e492db1b50b
BLAKE2b-256 checksum
How to use checksums
8fbfacdde49055b575e03aa4f0552d7769279cd9ddc8a8079f6a87938cf78572
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17b1-cp312-cp312-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp312-cp312-manylinux_2_31_x86_64.whl
Size 754.1 kB
Tags CPython 3.12 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
e400012b33229b0b402f8fb36170bd8f59a7a67f08df6bd732a10375b492e2c1
BLAKE2b-256 checksum
How to use checksums
9ee3087232aad8c2b4dc233be1a946a74c7b18ace3ae4b459ca3f80043fa221f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17b1-cp312-cp312-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp312-cp312-macosx_13_0_arm64.whl
Size 502.4 kB
Tags CPython 3.12 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
935e4396f81e5b3f6711c4afb28e5d35f9e0f51d23c07707fa26fe10e3e11be0
BLAKE2b-256 checksum
How to use checksums
d22f95fa66014f49fdeeb7f6d91d5c0452247e68cb436c939ff39a34aa986aac
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17b1-cp311-cp311-win_amd64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp311-cp311-win_amd64.whl
Size 496.1 kB
Tags CPython 3.11 Windows x86-64
SHA-256 checksum
How to use checksums
3e65cfa5110f92b95b7a226974d96c6fb19173bc924bc642ce55e0c4a17de3ec
BLAKE2b-256 checksum
How to use checksums
dee49b7f8315a9b577c61b7156c4f1f5eccb47f61f45835019a316818e935be9
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log

Release files / gllm_guardrail_binary-0.0.17b1-cp311-cp311-manylinux_2_31_x86_64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp311-cp311-manylinux_2_31_x86_64.whl
Size 692.4 kB
Tags CPython 3.11 Linux glibc 2.31+ x86-64
SHA-256 checksum
How to use checksums
186394badfa51109113b7e1f0d6e2ad990c3015dd0357a312040f2bb9e3546b2
BLAKE2b-256 checksum
How to use checksums
a07537a454d19d43987b83e1964f69f19916af8fac9844c2e70f47c77d5ccd98
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.8.24

Release files / gllm_guardrail_binary-0.0.17b1-cp311-cp311-macosx_13_0_arm64.whl

Download URL gllm_guardrail_binary-0.0.17b1-cp311-cp311-macosx_13_0_arm64.whl
Size 503.7 kB
Tags CPython 3.11 macOS 13.0+ ARM64
SHA-256 checksum
How to use checksums
026987d92ceda566d138ca293d48687034688093abaaf4f7d58ad120688c451c
BLAKE2b-256 checksum
How to use checksums
a16292e7e9b4117890e93127889c79048b19c7111eef76120d53fb1a724a5f59
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page