- Identify: map data flows and find sensitive items (PII, financial information, proprietary data).
- Filter / Mask: redact or tokenize sensitive fields (names, account numbers, secrets).
- Limit: scope the context you send to models — chunk retrievals and avoid sending raw documents.
- Monitor: log and audit who calls models, prompts issued, and responses generated — while protecting any logged sensitive data.

Input filtering and prompt-sanitization
Logging every model invocation is useful for observability, but it creates risk if prompts or responses contain sensitive data. One important defensive control is input filtering — sanitize and validate user prompts in your application layer before calling Bedrock. Below is a simple Python example that demonstrates a string-match approach: two indicator lists (harmful_keywords, injection_phrases) and a function is_safe_input that blocks inputs containing those indicators. This basic method is intentionally minimal to illustrate the concept; treat it as one layer of defense.
Prompt-injection detection example
Prompt injection is an adversarial technique where a malicious user crafts input that tries to override system instructions, reveal hidden data, or manipulate model behavior. The following focused example flags common injection phrases:is_prompt_injection returns True, block or escalate the request; otherwise continue. Apply the same precaution to any retrieved RAG context: filter and redact chunks before including them in prompts.
These examples show straightforward string-matching rules. For production systems, add complementary techniques such as regex checks, tokenization-aware matching, semantic classifiers, named-entity detection, and specialized PII detectors. Combine multiple detectors and human review for high-risk flows.
What benefits to expect
Implementing these controls reduces the likelihood of disclosing sensitive information in prompts or model outputs. It also supports regulatory compliance (for example, GDPR, HIPAA, PCI DSS), strengthens governance over AI workflows, and improves customer trust.
Practical checklist and controls
Use this checklist when designing Bedrock workflows:- Identify and classify sensitive data types across your pipeline.
- Apply masking, redaction, tokenization, or anonymization before transmission.
- Limit RAG context: chunk documents, and only send relevant, sanitized fragments.
- Validate and sanitize model outputs before returning them to users.
- Log model invocations but redact or mask PII in logs and control who can access them.
- Combine automated detectors with human review for high-risk requests.
Key practice: least privilege for data
Only pass the minimum data required for the model to complete the task — no more, no less. For especially sensitive fields (customer records, credit cards, secrets), apply redaction, tokenization, or anonymization prior to transmission. Effective sanitization requires knowing what sensitive data looks like and where it appears in your workflow. Sanitization should occur at every level:- Validate user input before sending to Bedrock.
- Sanitize retrieved context returned by RAG systems before including in prompts.
- Filter and validate model outputs before returning them to end users.

Careful with logs: model invocation logs can contain PII or other sensitive data. Mask or redact sensitive fields before persisting logs, and control access to log storage.
Links and references
- Kubernetes Documentation — general ops reference
- GDPR overview
- HIPAA information
- PCI DSS standards