IAM.Secure
AI traffic inspection, DLP policies, prompt-injection protection and audit.
Key capabilities
- Inline request and response inspection
- DLP, masking, blocking and routing policy actions
- Decision audit and security evidence
Step-by-step guides
Use cases
Start with the outcome: open a guide, prepare prerequisites, follow the steps and verify the success signals.
01 Create a DLP policy for AI trafficSensitive data is masked or blocked before it reaches the model.
- Audience
- Security engineer
- Outcome
- Sensitive data is masked or blocked before it reaches the model.
Before you start
- Tenant and traffic source
- Data-type inventory
- Agreed mask or block action
Steps
- Create a policy setIn Policies, select tenant, channels and request/response direction.
- Add detectorsEnable the required PII/credential classifiers and tune exclusions using test data.
- Assign an actionFor each severity, choose allow, mask, block or route-to-local.
- Run a simulationTest safe and unsafe samples before enabling inline enforcement.
Simulation and live audit show the same rule id, expected action and redacted evidence.
For false positives, narrow scope and exceptions instead of disabling the policy.
02 Investigate a blocked request or prompt-injection eventThe analyst understands the source, rule, decision and related events without exposing secrets.
- Audience
- SOC analyst
- Outcome
- The analyst understands the source, rule, decision and related events without exposing secrets.
Before you start
- Correlation id or time range
- Incident and Audit access
- Tenant scope
Steps
- Locate the eventFilter Incidents by tenant, action, severity and correlation id.
- Open evidenceReview classifier, matched-fragment hash, policy version and redaction state.
- Trace the chainFollow the correlation id to the Router decision and source product event.
- Record the conclusionAdd disposition, owner and remediation; never paste the source secret into a note.
The incident is closed with an owner, disposition and linked audit records.
If the chain breaks, verify correlation-id propagation in Router and the source product.
Open detailed manual
Every application screen has a separate page with controls, safe example values, CLI/API alternatives and status-specific recovery steps.
Role in the ecosystem
IAM.Secure checks incoming and outgoing AI traffic before data arrives into the model or downstream tool. The result of the inspection is a structured decision: allow, mask, route or block with an explanatory policy reason.
Main scenario
- The client passes the text or URL to dry-run/inline inspection.
- T0 rules perform fast deterministic checks.
- Classifiers evaluate DLP, injection, abuse and topic policy.
- Policy engine combines signals and selects action.
- The client receives a verdict and a secure audit reference.
Inline mode is used in real traffic, dry-run - for preliminary policy checks and demonstrations without accessing LLM.
Policy actions
| Action | Destination |
|---|---|
allow | continue processing without conversion |
mask | remove or replace sensitive fragments |
route | redirect the request to the agreed perimeter |
block | complete request before downstream call |
Integrations
Secure works before IAM.Router or a specific tool API. Identity context comes from IAM.Identity and IAM.Core may require a security verdict before capability invocation.
Data and audit
Raw secrets and PII should not end up in public logs. Audit stores the verdict, policy/version, request reference and applied actions. Masking should be reproducible, and blocking is distinguishable from provider failure.
Operation
Control the latency of each layer, the proportion of false positive/negative, the policy version, readiness of classifiers and fallback posture. If mandatory security component, the protected route must end with fail-closed.
Limit of responsibility
Secure is not a replacement for tenant authorization, network isolation, or storage encryption. It protects AI/content flow and complements rather than cancels regular security controls.
Verified entry points
- Landing
- https://iamsecure.ru/en/
- Application
- https://app.iamsecure.ru/
- Portfolio
- https://iamgroup.ru/en/