Home Why What How Simulator Documentation Contact Us hello@rytqlk.com
Get Started
Flit / Docs / Security & DLP

Security & DLP Guardrails

Flit protects corporate boundaries with real-time data loss prevention (DLP), PII redaction, prompt injection defenses, enterprise SSO, and cryptographic session isolation.

1. In-Flight Data Loss Prevention (Microsoft Presidio)

Flit integrates official Microsoft Presidio Analyzer and Anonymizer (v2.2.362) microservices directly into the gateway pre- and post-call execution pipelines via overlays/docker-compose.presidio.yml:

Guardrail Parameter Supported Settings Enforcement Semantics
Directional Scope input OR output Flit enforces strictly independent directional instances; combined both instances are rejected to guarantee clean lifecycle removal.
Enforcement Action MASK or BLOCK MASK replaces sensitive entities with synthetic anonymized tokens; BLOCK aborts the request before any token leaves the enterprise perimeter.
Recognized Entities Standard PII / Financial / Health Credit cards, SSN, email addresses, phone numbers, IP addresses, and custom entity recognizers.
Activation Mode Server-Enforced default_on The gateway adapter strips the guardrails field from client payloads, guaranteeing that end-users cannot bypass corporate DLP policies.

2. Enterprise SSO & Identity Architecture

Administrative and browser-based access is protected by enterprise identity standards:

  • Microsoft Entra ID (Azure AD): Built-in OpenID Connect (OIDC) SSO integration. Configured via MICROSOFT_TENANT_ID, MICROSOFT_CLIENT_ID, and redirect endpoints. Automatically reconciles Entra claims with pre-provisioned Flit accounts.
  • Local Administrator Security: Local admin accounts are stored in PostgreSQL with brute-force lockout protection (5 failed attempts locks the account for 15 minutes) and mandatory password rotation on first login.
  • Encrypted Session Cookies: Web application sessions are serialized into HttpOnly, SameSite=Lax cookies encrypted using a 32-byte Fernet key (AES-128 in CBC mode with HMAC SHA-256).
  • Cryptographic CSRF Protection: All state-mutating requests (such as creating keys, modifying classifier rules, or altering team budgets) require a verified anti-forgery token passed in the X-Aquila-CSRF header.
  • Comprehensive Audit Logging: Every administrative action is permanently recorded in the admin_audit_log table with actor ID, action verb, target entity, and timestamp.