Go from zero to audit-ready in 30 minutes. This runbook walks you through enabling every compliance feature ACAI offers.
Policy templates are pre-built compliance configurations that match specific frameworks. Applying one sets up PII detection rules, content safety thresholds, and audit retention in one click.
Guardrails enforce rules on every API request. The policy template pre-fills sensible defaults, but you can tune them.
| Guardrail | What It Does | Where |
|---|---|---|
| PII Detection | Detects and redacts names, SSNs, emails, phone numbers, medical record numbers | Guardrails → Config |
| Content Safety | Blocks hate speech, violence, self-harm, and sexual content | Guardrails → Config |
| Prompt Injection | Detects attempts to override system prompts or exfiltrate data | Guardrails → Config |
| Data Classification | Enforces which data sensitivity levels can flow to which backends | Backends |
Every request through ACAI is logged with a correlation ID, token counts, policy decisions, and PII scan results. Verify it works:
Prevent runaway spend with per-key limits and rate limiting.
This is the payoff. Compliance reports compile your guardrail configuration, audit log summaries, and policy enforcement evidence into a format your auditor expects.
Before handing evidence to your auditor, walk through this checklist:
You're audit-ready.
Generate your first compliance report and download the evidence export.