BazaarLinkBazaarLink
Sign in
Organization content filtering

Keep sensitive prompts in view
before they reach a model

Set organization-owned rules for requests sent through BazaarLink. Choose what to redact, block, or flag before the model call.

Set up content filtering

This covers requests sent through BazaarLink. Third-party applications that do not send through BazaarLink are outside this control.

A rule set you can inspect
Rule types
keyword + regex
Add built-in templates or your own patterns.
Actions
redact · block · flag
When matches overlap, block is most restrictive.
Audit trail
Security log
Rule hits are written to the organization audit log.

What organizations can control

Built-in sensitive-data templates

Choose from 11 templates for API keys, tokens, private keys, card numbers, IDs, passports, email, phone, and IP patterns.

Prompt-injection patterns

The prompt-injection group contains 25 patterns, including Chinese-language patterns. Three anti-evasion detectors are also available.

Custom rules

Add organization-owned keyword or regex rules, enable or disable them, and choose the action for each rule.

Safe pattern checks

Unsafe or unsupported regex forms are rejected during save instead of being accepted as active rules.

Test before you ship

The organization settings tab includes a dry-run tool that uses the guarded matcher with sample text.

Model access stays separate

A separate model allowlist can limit which models an organization, team, or member may call.

Where the organization check is wired

The shared organization check runs before model dispatch on the customer-content surfaces that use it.

Chat Completions checks organization-key content before model dispatch, including BYOK and BYOC traffic.

Messages checks organization-key text and tool content before dispatch.

Responses checks string input, message text, and function-call/result items before dispatch.

The same shared check is also present for embeddings, image generation, audio, evaluations, and video submissions.

Important boundary

Configuration lookup
If an internal read of the filter configuration fails, the current hot path treats the filter as disabled and does not filter that request.
Structured content
Only string content selected for each endpoint is scanned; structured or multimodal values pass through as defined by that endpoint.
Model access
Model allowlists are a separate organization, team, and member control; an empty list means no restriction at that layer.

Frequently asked questions

Does this cover third-party applications?

Only when the request is sent through BazaarLink. An application that sends directly elsewhere is not covered by these organization rules.

What does each action do?

A flag is recorded in the security audit log and leaves the request unchanged. Redact replaces matched text. Block rejects the request before the model call.

Can I try a pattern before saving?

Yes. The organization settings Content Filter tab includes Test your patterns and uses the same guarded engine.

What happens if something goes wrong?

A configuration read failure currently falls back to disabled and no filtering. Matcher and evaluation failures are handled conservatively by blocking.

Start with the rules your organization needs

Open the Content Filter settings page to select templates, add patterns, and test them with sample text.

Open Content Filter settings
Support
Support
Hi! How can we help you?
Send a message and we'll get back to you soon.