Rate Limits
Guardrail endpoints on a platform deployment are not subject to a fixed request-rate limit. Throughput is governed by the resources provisioned for your Fiddler deployment; contact your Fiddler representative for sizing guidance.Understanding Centor Model Scores
Fiddler Centor Models return scores in the range of 0 to 1. These scores represent the model’s confidence that the input belongs to the target class (e.g., toxicity, hallucination).- Higher scores (closer to 1): Higher confidence that the input belongs to the target class
- Lower scores (closer to 0): Lower confidence that the input belongs to the target class
- Lower thresholds: Catch more true positives but include more false positives
- Higher thresholds: Reduce false positives, but might miss some true positives
- Start with the default threshold
- Monitor both missed detections and false alarms
- Adjust gradually based on which type of error is more problematic for your application
Safety Model
The safety guardrail accepts a large but fixed maximum input length. Inputs that exceed the limit return HTTP 413 — contact your Fiddler representative for the limit that applies to your environment.
- Jailbreaking
- Illegal content
- Hateful content
- Harassment
- Racism
- Sexism
- Violence
- Sexual content
- Harmful content
- Unethical content
- Roleplaying
Centor Model for Faithfulness
The faithfulness guardrail accepts large
context and response inputs, each up to a fixed maximum length. Inputs that exceed a limit return HTTP 413 — contact your Fiddler representative for the limits that apply to your environment.- Response: the text generated by your generative application
- Context Documents: the reference text that the application response must remain faithful to
Centor Model for PII/PHI (Sensitive Information Detection)
The PII/PHI guardrail accepts a large but fixed maximum input length. Inputs that exceed the limit return HTTP 413 — contact your Fiddler representative for the limit that applies to your environment.
- PII Detection (default): 12 high-precision entity types including personal, financial, and government identifiers
- PII_ALL Detection: All 27 supported PII entity types for maximum coverage
- PHI Detection: 7 healthcare-specific entity types for HIPAA compliance
- Custom Entity Detection: Organization-specific sensitive data patterns
- High Performance: 0.1 confidence threshold with top-1024 entity filtering
- Comprehensive Coverage: 12 default PII entities (
PII), 27 full-coverage PII entities (PII_ALL), and 7 PHI entity types - Custom Entities: Define organization-specific sensitive patterns
- Detailed Output: Returns entity text, type, confidence score, and character positions
PII Default (12 Entities)
- Personal Identifiers: person, date_of_birth
- Contact Information: email, phone_number, address, postal_code
- Financial Data: credit_card_number, iban
- Government IDs: social_security_number, drivers_license_number
- Digital Identifiers: ip_address, website
PII_ALL Full Coverage (27 Entities)
Includes all 12 default PII entities above, plus these 15 extended entities:
- Contact Information: email_address, mobile_phone_number, landline_phone_number, fax_number
- Financial Data: credit_card_expiration_date, cvv, cvc, bank_account_number, account_number
- Government IDs: passport_number, tax_identification_number, license_plate_number, cpf, cnpj
- Digital Identifiers: digital_signature
The default
PII set is curated for high precision. Use PII_ALL when you need the broadest possible detection — for example, scanning for passport numbers or tax IDs. See the PII & PHI Tutorial for details.- Medical Information: medication, medical_condition
- Insurance Data: health_insurance_number, health_insurance_id_number, national_health_insurance_number
- Healthcare Identifiers: birth_certificate_number, serial_number
- Lower thresholds (< 0.1): Catch more potential sensitive data but may include more false positives
- Higher thresholds (> 0.1): Reduce false positives but might miss some valid sensitive information
Secret Detection
This guardrail detects secrets, credentials, and API keys in text — covering ~42 known credential formats across LLM providers, cloud platforms, source control, messaging, and developer tools. Strings that look like secrets but don’t match a known format are labeledPossible Secret.
Secret Detection uses a lightweight, deterministic detection engine purpose-built for speed, delivering sub-millisecond latency.
The guardrail requires a single string input and outputs an array of detected secrets, each with a type label and character positions for precise redaction. Unlike the score-based guardrails above, no thresholding is required — each returned entry is a detection.
Secret Detection OpenAPI Spec