Skip to content

AI data loss prevention for Go

Users paste sensitive data into AI prompts – card numbers, phone numbers, home addresses, and whole résumés – often without realizing the risk. Once that data reaches your AI provider it can end up in logs, training pipelines, or model outputs, well outside your control.

Arcjet sensitive info detection scans prompt content inside your application, before it reaches the AI provider. Detection runs locally in your own environment, so the raw text never leaves your app: only the decision – whether sensitive data was found – is reported to Arcjet. When something is detected you choose what happens next: block the request, strip the data, or warn the user.

The built-in analyzer detects email, phone, IP, and card numbers. For names, addresses, SSNs, and other types, set Backend to the Rampart module. For more information about those types, see On-device detection with Rampart.

main.go
package main
import (
"encoding/json"
"log"
"net/http"
"os"
"github.com/arcjet/arcjet-go"
)
var aj = must(arcjet.NewClient(arcjet.Config{
Key: os.Getenv("ARCJET_KEY"),
Rules: []arcjet.Rule{
arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{
Mode: arcjet.ModeLive,
Deny: []arcjet.EntityType{
arcjet.SensitiveInfoCreditCardNumber,
arcjet.SensitiveInfoEmail,
},
}),
},
}))
type chatRequest struct {
Message string `json:"message"`
}
func chat(w http.ResponseWriter, r *http.Request) {
var body chatRequest
if err := json.NewDecoder(r.Body).Decode(&body); err != nil {
http.Error(w, "bad request", http.StatusBadRequest)
return
}
decision, err := aj.Protect(
r.Context(),
r,
arcjet.WithSensitiveInfoValue(body.Message),
)
if err != nil {
log.Printf("arcjet: %v", err)
} else if decision.IsDenied() && decision.Reason.IsSensitiveInfo() {
http.Error(w, "Sensitive information detected – remove it from your prompt", http.StatusBadRequest)
return
}
_ = json.NewEncoder(w).Encode(map[string]string{"reply": "..."})
}
func main() {
http.HandleFunc("/chat", chat)
log.Fatal(http.ListenAndServe(":8000", nil))
}
func must[T any](v T, err error) T {
if err != nil {
log.Fatal(err)
}
return v
}

Sensitive info detection runs through a detection backend – the engine that scans the text and identifies entities. There are two:

  • Built-in engine (default). A WebAssembly engine bundled with the SDK. It detects four structured types – card numbers, email addresses, phone numbers, and IP addresses – runs anywhere the SDK runs (including edge runtimes), and needs no extra dependencies.
  • Rampart backend (optional). An on-device named-entity-recognition (NER) model that adds the free-form PII people actually paste into prompts – names, street addresses, and government or financial identifiers. This is often the more valuable engine for AI data loss prevention, because that is exactly the data a structured-pattern matcher can’t catch.

Both engines run entirely on your own infrastructure. Nothing is sent to a third party for analysis, which is what makes this safe to put in front of an AI provider in the first place.

Use deny to list the entity types to block, or allow to block everything except the types you list (the two are mutually exclusive). Tune the list to your app – for a support bot that legitimately collects phone numbers, leave PHONE_NUMBER out of deny:

arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{
Mode: arcjet.ModeLive, // Blocks requests. Use ModeDryRun to log only.
Deny: []arcjet.EntityType{
arcjet.SensitiveInfoCreditCardNumber,
arcjet.SensitiveInfoEmail,
},
})

The built-in engine detects CREDIT_CARD_NUMBER, PHONE_NUMBER, EMAIL, and IP_ADDRESS. See the entity detection table for every type each backend supports, and for defining your own custom detectors.

The built-in types cover structured data. The optional Rampart backend adds names, addresses, and government or financial identifiers.

Install the nested module and pass rampart.New as the rule’s Backend. Create the backend once at startup:

Terminal window
go get github.com/arcjet/arcjet-go/sensitiveinfo/rampart
main.go
package main
import (
"log"
"net/http"
"os"
"github.com/arcjet/arcjet-go"
"github.com/arcjet/arcjet-go/sensitiveinfo/rampart"
)
var backend = must(rampart.New(rampart.Options{}))
var aj = must(arcjet.NewClient(arcjet.Config{
Key: os.Getenv("ARCJET_KEY"),
Rules: []arcjet.Rule{
arcjet.SensitiveInfo(arcjet.SensitiveInfoOptions{
Mode: arcjet.ModeLive,
Deny: []arcjet.EntityType{
arcjet.SensitiveInfoGivenName,
arcjet.SensitiveInfoSurname,
arcjet.SensitiveInfoEmail,
arcjet.SensitiveInfoSSN,
},
Backend: backend,
}),
},
}))
func handler(w http.ResponseWriter, r *http.Request) {
message := r.FormValue("message")
decision, err := aj.Protect(r.Context(), r, arcjet.WithSensitiveInfoValue(message))
if err != nil {
log.Printf("arcjet: %v", err)
}
if decision.Reason.IsSensitiveInfo() {
http.Error(w, "Please remove personal information", http.StatusBadRequest)
return
}
w.WriteHeader(http.StatusNoContent)
}
func must[T any](v T, err error) T {
if err != nil {
log.Fatal(err)
}
return v
}

The model weights are bundled (~15 MB) so nothing is fetched at runtime. Inference is pure Go and runs on the request path. The default MaxInputChars is 4096. Phone numbers are left to the model because their digit shape overlaps with financial and government identifiers. For options and the full entity list, see the Rampart reference.

Pass the text to scan as sensitiveInfoValue (JS) / sensitive_info_value (Python) / WithSensitiveInfoValue (Go). For a chat endpoint this is usually the user’s most recent message. Pass the full conversation history instead if you want to scan every message, not only the most recent one – PII can appear earlier in the exchange.

Set mode to "DRY_RUN" (JS) / Mode.DRY_RUN (Python) / ModeDryRun (Go) to log detections without blocking any requests. Run this in production for a while to audit what PII actually shows up in your prompts, then switch to live mode once you’re confident in the entity list.

Sensitive info detection controls what data reaches your AI provider. Pair it with the other AI protection layers for full coverage: