AI data loss prevention for Go
Users paste sensitive data into AI prompts – card numbers, phone numbers, home addresses, and whole résumés – often without realizing the risk. Once that data reaches your AI provider it can end up in logs, training pipelines, or model outputs, well outside your control.
Arcjet sensitive info detection scans prompt content inside your application, before it reaches the AI provider. Detection runs locally in your own environment, so the raw text never leaves your app: only the decision – whether sensitive data was found – is reported to Arcjet. When something is detected you choose what happens next: block the request, strip the data, or warn the user.
Get started
Section titled “Get started”The built-in analyzer detects email, phone, IP, and card numbers. For names,
addresses, SSNs, and other types, set Backend to the Rampart module. For more
information about those types, see
On-device detection with Rampart.
package main
import ( "encoding/json" "log" "net/http" "os"
"github.com/arcjet/arcjet-go")
var aj = must(arcjet.NewClient(arcjet.Config{ Key: os.Getenv("ARCJET_KEY"), Rules: []arcjet.Rule{ arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{ Mode: arcjet.ModeLive, Deny: []arcjet.EntityType{ arcjet.SensitiveInfoCreditCardNumber, arcjet.SensitiveInfoEmail, }, }), },}))
type chatRequest struct { Message string `json:"message"`}
func chat(w http.ResponseWriter, r *http.Request) { var body chatRequest if err := json.NewDecoder(r.Body).Decode(&body); err != nil { http.Error(w, "bad request", http.StatusBadRequest) return }
decision, err := aj.Protect( r.Context(), r, arcjet.WithSensitiveInfoValue(body.Message), ) if err != nil { log.Printf("arcjet: %v", err) } else if decision.IsDenied() && decision.Reason.IsSensitiveInfo() { http.Error(w, "Sensitive information detected – remove it from your prompt", http.StatusBadRequest) return }
_ = json.NewEncoder(w).Encode(map[string]string{"reply": "..."})}
func main() { http.HandleFunc("/chat", chat) log.Fatal(http.ListenAndServe(":8000", nil))}
func must[T any](v T, err error) T { if err != nil { log.Fatal(err) } return v}How detection works
Section titled “How detection works”Sensitive info detection runs through a detection backend – the engine that scans the text and identifies entities. There are two:
- Built-in engine (default). A WebAssembly engine bundled with the SDK. It detects four structured types – card numbers, email addresses, phone numbers, and IP addresses – runs anywhere the SDK runs (including edge runtimes), and needs no extra dependencies.
- Rampart backend (optional). An on-device named-entity-recognition (NER) model that adds the free-form PII people actually paste into prompts – names, street addresses, and government or financial identifiers. This is often the more valuable engine for AI data loss prevention, because that is exactly the data a structured-pattern matcher can’t catch.
Both engines run entirely on your own infrastructure. Nothing is sent to a third party for analysis, which is what makes this safe to put in front of an AI provider in the first place.
Configure detection
Section titled “Configure detection”Choose which PII to block
Section titled “Choose which PII to block”Use deny to list the entity types to block, or allow to block everything
except the types you list (the two are mutually exclusive). Tune the list to
your app – for a support bot that legitimately collects phone numbers, leave
PHONE_NUMBER out of deny:
arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{ Mode: arcjet.ModeLive, // Blocks requests. Use ModeDryRun to log only. Deny: []arcjet.EntityType{ arcjet.SensitiveInfoCreditCardNumber, arcjet.SensitiveInfoEmail, },})The built-in engine detects CREDIT_CARD_NUMBER, PHONE_NUMBER, EMAIL, and
IP_ADDRESS. See the
entity detection table
for every type each backend supports, and for defining your own custom
detectors.
Detect names, addresses, and IDs
Section titled “Detect names, addresses, and IDs”The built-in types cover structured data. The optional Rampart backend adds names, addresses, and government or financial identifiers.
Install the nested module and pass rampart.New as the rule’s Backend.
Create the backend once at startup:
go get github.com/arcjet/arcjet-go/sensitiveinfo/rampartpackage main
import ( "log" "net/http" "os"
"github.com/arcjet/arcjet-go" "github.com/arcjet/arcjet-go/sensitiveinfo/rampart")
var backend = must(rampart.New(rampart.Options{}))
var aj = must(arcjet.NewClient(arcjet.Config{ Key: os.Getenv("ARCJET_KEY"), Rules: []arcjet.Rule{ arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{ Mode: arcjet.ModeLive, Deny: []arcjet.EntityType{ arcjet.SensitiveInfoGivenName, arcjet.SensitiveInfoSurname, arcjet.SensitiveInfoEmail, arcjet.SensitiveInfoSSN, }, Backend: backend, }), },}))
func handler(w http.ResponseWriter, r *http.Request) { message := r.FormValue("message") decision, err := aj.Protect(r.Context(), r, arcjet.WithSensitiveInfoValue(message)) if err != nil { log.Printf("arcjet: %v", err) } if decision.Reason.IsSensitiveInfo() { http.Error(w, "Please remove personal information", http.StatusBadRequest) return } w.WriteHeader(http.StatusNoContent)}
func must[T any](v T, err error) T { if err != nil { log.Fatal(err) } return v}The model weights are bundled (~15 MB) so nothing is fetched at runtime.
Inference is pure Go and runs on the request path. The default
MaxInputChars is 4096. Phone numbers are left to the model because their
digit shape overlaps with financial and government identifiers. For options and
the full entity list, see the
Rampart reference.
Choose what text to scan
Section titled “Choose what text to scan”Pass the text to scan as sensitiveInfoValue (JS) / sensitive_info_value
(Python) / WithSensitiveInfoValue (Go). For a chat endpoint this is usually
the user’s most recent message.
Pass the full conversation history instead if you want to scan every message,
not only the most recent one – PII can appear earlier in the exchange.
Test before you block
Section titled “Test before you block”Set mode to "DRY_RUN" (JS) / Mode.DRY_RUN (Python) / ModeDryRun (Go)
to log detections without blocking any requests. Run this in production for a
while to audit what PII actually shows up in your prompts, then switch to live
mode once you’re confident in the entity list.
Combine with other protections
Section titled “Combine with other protections”Sensitive info detection controls what data reaches your AI provider. Pair it with the other AI protection layers for full coverage:
- Prompt injection detection blocks hostile instructions and jailbreak attempts.
- AI abuse protection and AI budget control block automated clients and enforce per-user token budgets.
- Agent guards apply PII detection directly inside agent tool handlers and pipelines that don’t route through HTTP. A local policy input keeps the raw string in the SDK while reporting policy evidence to Arcjet.