OpenSmartRoute provides a control plane for LLM routing that includes security properties like PII redaction and prompt sanitisation. The router applies these checks before sending prompts to the LLM judge, ensuring sensitive information is handled safely. This guide explains how to configure and use these features.
Security and Redaction in the Router
The router's integrity is a security property. It combines a heuristic and a learned detector for confounder gadgets that reroute queries. An injection-risk scorer and PII redaction are part of the InputGuard component. This guard runs before signals and ensures the LLM judge sees a fenced, sanitised prompt. The system also supports AES-GCM state, content-free logs, and hash-chained audit trails to complete the security model.
Using the Moderation API for PII Detection
You can screen prompts before spending on a model using the POST /v1/moderations endpoint. This endpoint accepts a string or a list of strings and returns results in the OpenAI moderation shape. The router's own guards analyze the input for specific categories, including pii. When PII is detected, the flag_pii field is set to true, which also raises the overall flagged status. The opensmartroute block in the result details lists the specific reasons and PII types found. This approach avoids provider calls and is metered only by the required route scope.
Configuring PII Redaction Middleware
For self-hosted deployments, you can configure PII redaction directly in the application code. The opensmartroute.security module provides the GuardMiddleware class. By initializing it with redact=True, you enable gadget defence and PII redaction within the router's middleware stack. This middleware runs automatically as part of the request lifecycle, ensuring that sensitive data is stripped from prompts before they are processed.
Data Flow and Privacy
Understanding where data goes is critical for security compliance. The flow diagram illustrates the path of request text and metadata:
flowchart LR
subgraph you[Your Side]
A[Your Application]
end
subgraph platform[Hosted Platform]
G[API Gateway]
R[Router]
X[Executor]
end
subgraph out[Model Providers]
P[Provider APIs]
end
A --> G
G --> R
R --> X
X --> P
P --> X
R -. decision .-> DB
X -. usage, outcome .-> DB



