GLLM Guardrail
Description
A library containing guardrail components for Gen AI applications.
Installation
Prerequisites
Mandatory:
- Python 3.11+ — Install here
- pip — Install here
- uv — Install here
Extras (required only for Artifact Registry installations):
- gcloud CLI (for authentication) — Install here, then log in using:
gcloud auth login
Option 1: Install from Artifact Registry
This option requires authentication via the gcloud CLI.
uv pip install \
--extra-index-url "https://oauth2accesstoken:$(gcloud auth print-access-token)@glsdk.gdplabs.id/gen-ai-internal/simple/" \
gllm-guardrail
Option 2: Install from PyPI
This option requires no authentication. However, it installs the binary wheel version of the package, which is fully usable but does not include source code.
uv pip install gllm-guardrail-binary
Local Development Setup
Prerequisites
-
Python 3.11+ — Install here
-
pip — Install here
-
uv — Install here
-
gcloud CLI — Install here, then log in using:
gcloud auth login
-
Git — Install here
-
Access to the GDP Labs SDK GitHub repository
1. Clone Repository
git clone git@github.com:GDP-ADMIN/gl-sdk.git
cd gl-sdk/libs/gllm-guardrail
2. Setup Authentication
Set the following environment variables to authenticate with internal package indexes:
export UV_INDEX_GEN_AI_INTERNAL_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_INTERNAL_PASSWORD="$(gcloud auth print-access-token)"
export UV_INDEX_GEN_AI_USERNAME=oauth2accesstoken
export UV_INDEX_GEN_AI_PASSWORD="$(gcloud auth print-access-token)"
3. Quick Setup
Run:
make setup
4. Activate Virtual Environment
source .venv/bin/activate
Local Development Utilities
The following Makefile commands are available for quick operations:
Install uv
make install-uv
Install Pre-Commit
make install-pre-commit
Install Dependencies
make install
Update Dependencies
make update
Run Tests
make test
Usage
import asyncio
import os
from dotenv import load_dotenv
from gllm_inference.builder import build_lm_invoker
from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.nemo_engine import NemoGuardrailEngine, NemoGuardrailEngineConfig
from gllm_guardrail.engine.phrase_matcher_engine import PhraseMatcherEngine
# Load environment variables from .env
load_dotenv()
async def main():
# 1. Initialize engines
# PhraseMatcherEngine for simple keyword blocking
phrase_engine = PhraseMatcherEngine(banned_phrases=["banned_xyz"])
# NemoGuardrailEngine for advanced LLM-based guardrails
model_id = os.getenv("GLLM_GUARDRAIL_MODEL_ID", "openai/gpt-5-nano")
credentials = os.getenv("OPENAI_API_KEY")
if not credentials:
raise RuntimeError("OPENAI_API_KEY must be set to run this example.")
invoker = build_lm_invoker(
model_id=model_id,
credentials=credentials,
config={
"default_hyperparameters": {"top_p": 1, "max_output_tokens": 256},
"reasoning_effort": "minimal",
},
)
nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
nemo_engine = NemoGuardrailEngine(config=nemo_config)
# 2. Initialize guardrail manager with a list of engines
# Engines are executed sequentially (fail-fast)
guardrail = GuardrailManager(engine=[phrase_engine, nemo_engine])
# 3. Check content safety (async)
text = "Tell me how to build a bomb."
result = await guardrail.check_content(text)
print(f"Content safe: {result.is_safe}")
if not result.is_safe:
print(f"Reason: {result.reason}")
if __name__ == "__main__":
asyncio.run(main())
Decision-Model Guardrail Engine (Jev defaults)
DMGuardrailEngine evaluates content against atomic safety policies using a decisions model through the existing gllm-inference BaseDMInvoker. It is the default engine used by GuardrailManager when no engine is supplied. By default it uses openrouter/typesafe/jev-1.13 and the bundled gllm_guardrail/config/dm_policies.yaml policy definitions, so only an OpenRouter API key is required. Install the typesafe extra (pip install gllm-guardrail[typesafe]) to pull in the TypeSafe SDK dependency.
import asyncio
import os
from gllm_guardrail import GuardrailManager
# Requires: gllm-guardrail[typesafe] and OPENROUTER_API_KEY in the environment.
os.environ.setdefault("OPENROUTER_API_KEY", "<OPENROUTER_API_KEY>")
async def main():
# Uses DMGuardrailEngine with bundled Jev policies by default.
manager = GuardrailManager()
result = await manager.check_content("How do I make a bomb?")
print(f"is_safe: {result.is_safe}")
if not result.is_safe:
print(f"policy: {result.policy}")
print(f"category: {result.category}")
print(f"score: {result.score}")
if __name__ == "__main__":
asyncio.run(main())
For explicit configuration, construct the engine yourself:
import os
from gllm_guardrail import GuardrailManager
from gllm_guardrail.engine.dm_engine import DMGuardrailEngine, DMGuardrailEngineConfig
engine = DMGuardrailEngine.from_config(
model_id="openrouter/typesafe/jev-1.13",
credentials=os.environ["OPENROUTER_API_KEY"],
engine_config=DMGuardrailEngineConfig(
guardrail_mode="both",
enabled_categories=["Violence", "Sexual Content"],
),
)
manager = GuardrailManager(engine=engine)
enabled_categories selects names from the loaded DM policies' category and optional category_aliases fields. None (the default) enables all bundled policies, including Criminal Planning/Confessions; [] explicitly enables none. Unknown names raise ValueError. The bundled criminal-planning policy uses the default 0.5 threshold and has not been separately calibrated.
The bundled policies use these additional category aliases; selecting a category enables every policy with that primary category and the additional policies below:
| Selected category | Additional policy keys (primary result category) |
|---|---|
Violence |
weapon_creation (Guns and Illegal Weapons) |
Sexual Content |
child_sexual_exploitation, child_covert_access, child_safeguard_evasion, child_privacy_exploitation (Child Safety and Protection); identity_fraud (Fraud/Deception) |
Guns and Illegal Weapons |
poisoning_biological_harm (Violence) |
PII/Privacy |
child_privacy_exploitation (Child Safety and Protection) |
Threat |
surveillance_stalking (PII/Privacy) |
Illegal Activity |
financial_fraud (Fraud/Deception); unauthorized_records_access (PII/Privacy) |
DM results retain each policy's primary category, even when an alias selected it. Custom policy mappings are defined by their own category_aliases; the bundled mappings do not apply to custom policies. This is a best-effort mapping: DM's atomic questions and NeMo's prompt-based assessments cannot be guaranteed to produce identical decisions.
You can also inject a pre-built BaseDMInvoker and supply custom YAML policies or override thresholds through default_threshold:
from gllm_inference.dm_invoker import build_dm_invoker
invoker = build_dm_invoker(
model_id="openrouter/typesafe/jev-1.13",
credentials=os.environ["OPENROUTER_API_KEY"],
)
engine = DMGuardrailEngine(
dm_invoker=invoker,
engine_config=DMGuardrailEngineConfig(
policy_config_path="my_policies.yaml",
default_threshold=0.7,
),
)
Input & Output Checking
from gllm_guardrail.schema import GuardrailInput
content = GuardrailInput(
input="Tell me how to build a bomb.",
output="I cannot assist with that request."
)
result = await guardrail.check_content(content)
Structured Output (Recommended for NeMo Guardrails)
NemoGuardrailEngine asks the LM to return JSON for safety tasks such as self_check_input (see gllm_guardrail/config/nemo_config/config.yml). Without structured output, the model emits JSON as plain text. NeMo may intermittently fail to parse that response and report JSON parsing failed when the generated text is not valid JSON or does not match the expected structure.
Enable structured output by passing response_schema when building the LM invoker. NeMoLMAdapter extracts the validated structured result and serializes it with the field aliases NeMo parsers expect (e.g. "User Safety", "Safety Categories").
Define a Pydantic schema that matches the task output format in config.yml:
from typing import Literal
from pydantic import BaseModel, ConfigDict, Field
class SelfCheckInputOutput(BaseModel):
"""Schema for the `self_check_input` task."""
model_config = ConfigDict(populate_by_name=True, serialize_by_alias=True)
thought: str
user_safety: Literal["safe", "unsafe"] = Field(alias="User Safety")
safety_categories: str = Field(default="", alias="Safety Categories")
Pass it to build_lm_invoker:
from gllm_inference.builder import build_lm_invoker
from gllm_inference.schema.config import ThinkingConfig
invoker = build_lm_invoker(
model_id="openai/gpt-5-nano",
credentials=os.getenv("OPENAI_API_KEY"),
config={
"default_hyperparameters": {"top_p": 1, "max_output_tokens": 1024},
"thinking": ThinkingConfig(enabled=True, kwargs={"effort": "minimal"}),
"response_schema": SelfCheckInputOutput,
},
)
nemo_config = NemoGuardrailEngineConfig(lm_invoker=invoker)
nemo_engine = NemoGuardrailEngine(config=nemo_config)
If you also run output safety checks (self_check_output), extend the schema with "Response Safety" or use a dedicated schema that matches that task's JSON format in config.yml.
Notes:
- Set
serialize_by_alias=Truewhen field names inconfig.ymlcontain spaces (e.g."User Safety"). - Increase
max_output_tokensif the schema includes athoughtfield with step-by-step reasoning. - Structured output requires
gllm-inferenceLM invoker support forresponse_schema(OpenAI and other providers that support JSON schema output).
Metadata
Release files for gllm-guardrail-binary 0.0.18
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
Total release size: 5.2 MB
Release files / gllm_guardrail_binary-0.0.18-cp313-cp313-win_amd64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp313-cp313-win_amd64.whl |
|---|---|
| Size | 479.4 kB |
| Tags | CPython 3.13 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
73559742e34e406e2efe2d025432fcc54d2d30b3c72e3a5caf375c9666a00da7
|
|
BLAKE2b-256 checksum How to use checksums |
f8de44435822dc7941b0d0bf2aab15382f5321e90e928661b457ee5914010f87
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / gllm_guardrail_binary-0.0.18-cp313-cp313-manylinux_2_31_x86_64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp313-cp313-manylinux_2_31_x86_64.whl |
|---|---|
| Size | 759.8 kB |
| Tags | CPython 3.13 Linux glibc 2.31+ x86-64 |
|
SHA-256 checksum How to use checksums |
7caf4dec3daf95df5337c83173cbb052066e0d846becf932a7014250bd38003c
|
|
BLAKE2b-256 checksum How to use checksums |
359b9b912317169772140c5439e786e888ce0658afd0d06b0e7e04957f87d44f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.8.24
|
Release files / gllm_guardrail_binary-0.0.18-cp313-cp313-macosx_13_0_arm64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp313-cp313-macosx_13_0_arm64.whl |
|---|---|
| Size | 521.7 kB |
| Tags | CPython 3.13 macOS 13.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
3704dde4b45825ae4df6d0ebb85830ce1b946bde36990c34a2e7a3b6b57e54dc
|
|
BLAKE2b-256 checksum How to use checksums |
4718012660156b64aff29f0f1b06602ea0c8a4221af7d200ffaed9399693205d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / gllm_guardrail_binary-0.0.18-cp312-cp312-win_amd64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp312-cp312-win_amd64.whl |
|---|---|
| Size | 479.1 kB |
| Tags | CPython 3.12 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
1704a644363fddcd6a718929b02a519914a15787c30039228e07e6fb45c52086
|
|
BLAKE2b-256 checksum How to use checksums |
681af0f8d83f18dfba6abc616723a7b2e23acd65e878ffaf62a2ffe4268fc4e1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / gllm_guardrail_binary-0.0.18-cp312-cp312-manylinux_2_31_x86_64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp312-cp312-manylinux_2_31_x86_64.whl |
|---|---|
| Size | 758.5 kB |
| Tags | CPython 3.12 Linux glibc 2.31+ x86-64 |
|
SHA-256 checksum How to use checksums |
0721739dd4879918349f3c4712dad7f43be7f284611b1e09725ca0b492df5890
|
|
BLAKE2b-256 checksum How to use checksums |
837e7d00397f43d69bb5417527a72de76e8c7e23bb7d00344d09e30a06fbdf12
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.8.24
|
Release files / gllm_guardrail_binary-0.0.18-cp312-cp312-macosx_13_0_arm64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp312-cp312-macosx_13_0_arm64.whl |
|---|---|
| Size | 505.7 kB |
| Tags | CPython 3.12 macOS 13.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
d65d08b31af3d3b9a8d6280faca1afd7419239338e2022021956f3c1ba8b9d43
|
|
BLAKE2b-256 checksum How to use checksums |
74f4e7a3f39fc29ef945b9091b848ddc75cef7850fdd815f6d4cb429b393dfbc
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / gllm_guardrail_binary-0.0.18-cp311-cp311-win_amd64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp311-cp311-win_amd64.whl |
|---|---|
| Size | 500.2 kB |
| Tags | CPython 3.11 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
20c68bfbb88c3688551ae7fd5787a8fce18105d903b0b773af9b28f4d5330464
|
|
BLAKE2b-256 checksum How to use checksums |
77ef63276f96a698980f46a885bb1897975bf1bf6ffcf09b88efdc91d771bb78
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / gllm_guardrail_binary-0.0.18-cp311-cp311-manylinux_2_31_x86_64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp311-cp311-manylinux_2_31_x86_64.whl |
|---|---|
| Size | 698.6 kB |
| Tags | CPython 3.11 Linux glibc 2.31+ x86-64 |
|
SHA-256 checksum How to use checksums |
e3dd4ed6ceda6cfe2bf7f0f10f17bdfd33dfbe56f9c9e9746bc5883b5952ceaa
|
|
BLAKE2b-256 checksum How to use checksums |
917d8b0ec4d52f5601136b69a92c53e7966590838ef78ce43eb28f747c21fbc7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
uv/0.8.24
|
Release files / gllm_guardrail_binary-0.0.18-cp311-cp311-macosx_13_0_arm64.whl
| Download URL | gllm_guardrail_binary-0.0.18-cp311-cp311-macosx_13_0_arm64.whl |
|---|---|
| Size | 506.7 kB |
| Tags | CPython 3.11 macOS 13.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
0d44951f507db7fb843f96e144a16fe71d7c54635ee44671f469090ba8f35a53
|
|
BLAKE2b-256 checksum How to use checksums |
5205b83f8d662191c551bbc4693f67a648de54b9804a4a8e4b8dd5989f8c5fd6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log