Metadata-Version: 2.4
Name: policyaware
Version: 0.2.9
Summary: Policy-aware control plane for enterprise LLM, RAG, and AI agent applications.
Project-URL: Homepage, https://ktirupati.github.io/policyaware/
Project-URL: Documentation, https://ktirupati.github.io/policyaware/
Project-URL: Repository, https://github.com/ktirupati/policyaware
Project-URL: Issues, https://github.com/ktirupati/policyaware/issues
Project-URL: Discussions, https://github.com/ktirupati/policyaware/discussions
Project-URL: Feedback, https://docs.google.com/forms/d/e/1FAIpQLSc2QcQydjXZ0YF9bbVSpudoM5y8noxIP5jU-acVmjlyvf6Slg/viewform
Project-URL: Testimonials, https://github.com/ktirupati/policyaware/discussions/categories/show-and-tell
Project-URL: LinkedIn, https://www.linkedin.com/in/krishna-tirupati/
Project-URL: Changelog, https://github.com/ktirupati/policyaware/blob/main/CHANGELOG.md
Author: Krishna Kishor Tirupati
License-Expression: Apache-2.0
License-File: LICENSE
Keywords: agents,ai-gateway,audit,governance,guardrails,llm,llm-governance,mcp,model-routing,pii-redaction,policy,rag
Requires-Python: >=3.10
Requires-Dist: pydantic>=2.6
Requires-Dist: pyyaml>=6.0
Requires-Dist: rich>=13.7
Requires-Dist: typer>=0.12
Provides-Extra: all-ml
Requires-Dist: optimum[onnxruntime]>=1.17; extra == 'all-ml'
Requires-Dist: presidio-analyzer>=2.2; extra == 'all-ml'
Requires-Dist: presidio-anonymizer>=2.2; extra == 'all-ml'
Requires-Dist: spacy>=3.7; extra == 'all-ml'
Requires-Dist: torch>=2.2; extra == 'all-ml'
Requires-Dist: transformers>=4.40; extra == 'all-ml'
Provides-Extra: dev
Requires-Dist: pytest>=8.0; extra == 'dev'
Requires-Dist: ruff>=0.4; extra == 'dev'
Provides-Extra: full
Requires-Dist: boto3>=1.34; extra == 'full'
Requires-Dist: guardrails-ai>=0.5; extra == 'full'
Requires-Dist: nemoguardrails>=0.10; extra == 'full'
Requires-Dist: optimum[onnxruntime]>=1.17; extra == 'full'
Requires-Dist: presidio-analyzer>=2.2; extra == 'full'
Requires-Dist: presidio-anonymizer>=2.2; extra == 'full'
Requires-Dist: spacy>=3.7; extra == 'full'
Requires-Dist: torch>=2.2; extra == 'full'
Requires-Dist: transformers>=4.40; extra == 'full'
Provides-Extra: guardrails-ai
Requires-Dist: guardrails-ai>=0.5; extra == 'guardrails-ai'
Provides-Extra: ml
Requires-Dist: torch>=2.2; extra == 'ml'
Requires-Dist: transformers>=4.40; extra == 'ml'
Provides-Extra: nemo
Requires-Dist: nemoguardrails>=0.10; extra == 'nemo'
Provides-Extra: onnx
Requires-Dist: optimum[onnxruntime]>=1.17; extra == 'onnx'
Requires-Dist: transformers>=4.40; extra == 'onnx'
Provides-Extra: presidio
Requires-Dist: presidio-analyzer>=2.2; extra == 'presidio'
Requires-Dist: presidio-anonymizer>=2.2; extra == 'presidio'
Requires-Dist: spacy>=3.7; extra == 'presidio'
Provides-Extra: providers
Requires-Dist: boto3>=1.34; extra == 'providers'
Description-Content-Type: text/markdown

# PolicyAware AI Gateway

PyPI: [policyaware](https://pypi.org/project/policyaware/) |
Downloads: [Pepy stats](https://pepy.tech/project/policyaware) |
Python: 3.10+ |
License: [Apache-2.0](https://github.com/ktirupati/policyaware/blob/main/LICENSE) |
Docs: [GitHub Pages](https://ktirupati.github.io/policyaware/)

PolicyAware adds deny-by-default policy, PII redaction, MCP tool governance, model routing, runtime evaluation, and audit traces to LLM, RAG, and AI agent applications in minutes.

PolicyAware AI Gateway is an open-source control plane for governed AI execution across enterprise LLM, RAG, AI agent, and MCP-style tool workflows. It enforces organizational, legal, security, cost, and routing policy before requests reach models or tools, then evaluates outputs for safety, quality, compliance, and auditability.

Documentation site: https://ktirupati.github.io/policyaware/

Capability docs: [docs/capabilities.md](https://github.com/ktirupati/policyaware/blob/main/docs/capabilities.md)
Ready-to-use YAML policies: [docs/capabilities/ready-to-use-yaml.md](https://github.com/ktirupati/policyaware/blob/main/docs/capabilities/ready-to-use-yaml.md)
Comparison guide: [PolicyAware vs guardrails vs AI gateway vs model router](https://github.com/ktirupati/policyaware/blob/main/docs/comparison.md)
Alternatives guide: [PolicyAware alternatives for guardrails, AI gateways, model routers, and MCP governance](https://ktirupati.github.io/policyaware/alternatives.html)
Demo outputs: [captured terminal output for runnable examples](https://github.com/ktirupati/policyaware/blob/main/docs/demo-outputs.md)
Changelog: [release history](https://github.com/ktirupati/policyaware/blob/main/CHANGELOG.md)

## What It Provides

- Policy enforcement for RBAC, context, tenant, region, compliance, budgets, tokens, latency, and model constraints.
- PII, PHI, secrets, and sensitive-data detection with redaction actions.
- Multi-provider model routing with fallbacks by policy, task type, risk, cost, availability, and quality.
- Runtime evaluation for safety, policy compliance, grounding, citations, and leakage.
- Risk-tier classification with explainable reason codes.
- MCP/tool governance for connector-level and action-level permissions.
- Optional NeMo Guardrails and Guardrails AI adapter orchestration for full-stack guardrails.
- Full request/response trace, explainable decisions, replay-ready audit logs, and exportable JSONL records.
- Python SDK, CLI, YAML policies, local development mode, and integration shims.
- Fast local code scanning with a user-friendly HTML governance report for PII, PHI, secrets, direct LLM calls, provider routing, tool governance, autonomous agents, RAG grounding, data residency, cost controls, policy YAML, configuration risks, and audit gaps.

## Author

Created and maintained by **Krishna Kishor Tirupati**.

Project links:

- PyPI: [policyaware](https://pypi.org/project/policyaware/)
- GitHub: [ktirupati/policyaware](https://github.com/ktirupati/policyaware)
- Documentation: [PolicyAware AI Gateway Docs](https://ktirupati.github.io/policyaware/)
- LinkedIn: [Krishna Tirupati](https://www.linkedin.com/in/krishna-tirupati/)

## Feedback And Testimonials

Using PolicyAware in a project, prototype, enterprise AI workflow, security review, or governance evaluation?

Please share feedback, use cases, feature requests, and testimonials through the channels below:

- Private structured feedback form: [PolicyAware User Feedback And Testimonials](https://docs.google.com/forms/d/e/1FAIpQLSc2QcQydjXZ0YF9bbVSpudoM5y8noxIP5jU-acVmjlyvf6Slg/viewform)
- Public discussions: [GitHub Discussions](https://github.com/ktirupati/policyaware/discussions)
- Testimonials and user stories: [Show and Tell](https://github.com/ktirupati/policyaware/discussions/categories/show-and-tell)
- Issues and bugs: [GitHub Issues](https://github.com/ktirupati/policyaware/issues)

Helpful feedback includes what you built, which PolicyAware feature you used, what risk or governance gap it helped identify, and what should improve next.

Please do not share secrets, private prompts, PHI, PII, customer data, or confidential internal details.

## Contributing And Roadmap

PolicyAware welcomes focused contributions from developers, AI platform engineers, security engineers, and governance practitioners.

- Contributing guide: [CONTRIBUTING.md](https://github.com/ktirupati/policyaware/blob/main/CONTRIBUTING.md)
- Roadmap: [ROADMAP.md](https://github.com/ktirupati/policyaware/blob/main/ROADMAP.md)
- Good first issues: [GOOD_FIRST_ISSUES.md](https://github.com/ktirupati/policyaware/blob/main/GOOD_FIRST_ISSUES.md)
- Security policy: [SECURITY.md](https://github.com/ktirupati/policyaware/blob/main/SECURITY.md)
- Adoption and impact tracking: [ADOPTION.md](https://github.com/ktirupati/policyaware/blob/main/ADOPTION.md)
- Curated testimonials: [TESTIMONIALS.md](https://github.com/ktirupati/policyaware/blob/main/TESTIMONIALS.md)

## Quick Start

```bash
pip install policyaware
policyaware about
policyaware feedback
policyaware dev simulate
policyaware risk classify "Email jane@example.com about a patient diagnosis" --domain healthcare
policyaware scan ./mylocalfolder
policyaware scan ./mylocalfolder --json policyaware-scan-report.json --fail-on high
policyaware scan ./mylocalfolder --sarif policyaware.sarif
policyaware scan ./mylocalfolder --markdown policyaware-scan-report.md
policyaware scan ./mylocalfolder --baseline policyaware-baseline.json
policyaware scan ./mylocalfolder --config examples/policyaware-scan.yaml
policyaware scan ./mylocalfolder --diff --diff-base origin/main
policyaware scan ./mylocalfolder --format html,json,sarif,markdown
policyaware guards list examples/full-stack-guardrails/policy.yaml
```

Optional full-stack guardrails:

```bash
pip install "policyaware[nemo]"
pip install "policyaware[guardrails-ai]"
pip install "policyaware[full]"
```

For local development from this repository:

```bash
pip install -e ".[dev]"
policyaware policy test examples/policies/basic.yaml
policyaware policy validate examples/policies/basic.yaml
policyaware risk classify "Summarize this patient diagnosis" --domain healthcare
policyaware tools check examples/policies/tool-governance.yaml --agent code_assistant --connector github --action create_pr
policyaware eval run examples/evals/support_rag.yaml
policyaware scan . --out policyaware-scan-report.html
policyaware scan . --include ".py,.yaml,.json" --exclude "tests,fixtures"
policyaware scan . --write-baseline policyaware-baseline.json
policyaware scan . --config examples/policyaware-scan.yaml --format html,json,sarif,markdown
```

For copy-pasteable end-to-end examples, see [Working Examples](https://github.com/ktirupati/policyaware/blob/main/docs/working-examples.md).

Local code scan docs: [policyaware scan](https://github.com/ktirupati/policyaware/blob/main/docs/local-code-scan.md)

## Copy-Paste Examples

- [FastAPI LLM policy middleware](https://github.com/ktirupati/policyaware/tree/main/examples/fastapi-llm-policy-middleware): protect a FastAPI `/chat` endpoint with policy checks before model execution.
- [LangChain policy guardrails](https://github.com/ktirupati/policyaware/tree/main/examples/langchain-policy-guardrails): wrap a chain-style LLM call with deny-by-default policy, PII redaction, and secret blocking.
- [MCP tool permission gateway](https://github.com/ktirupati/policyaware/tree/main/examples/mcp-tool-permission-gateway): govern connector-level and action-level tool permissions for agent workflows.
- [PII redaction policy](https://github.com/ktirupati/policyaware/tree/main/examples/pii-redaction-policy): inspect and redact sensitive text before model execution.
- [Regulated RAG assistant](https://github.com/ktirupati/policyaware/tree/main/examples/regulated-rag-assistant): require citations and stricter controls for healthcare-style RAG.
- [Provider routing by risk](https://github.com/ktirupati/policyaware/tree/main/examples/provider-routing-by-risk): route public-safe requests to low-cost models and high-risk requests to approved models.
- [Audit trace viewer](https://github.com/ktirupati/policyaware/tree/main/examples/audit-trace-viewer): write audit traces and generate a local HTML trace viewer.
- [Approval workflow hooks](https://github.com/ktirupati/policyaware/tree/main/examples/approval-workflow-hooks): send high-risk requests to approval instead of calling a model.
- [Local code scan](https://github.com/ktirupati/policyaware/blob/main/docs/local-code-scan.md): scan local AI app code and generate an HTML governance report.
- [Full-stack guardrails](https://github.com/ktirupati/policyaware/tree/main/examples/full-stack-guardrails): orchestrate NeMo Guardrails, Guardrails AI, or custom validators as input/output guards.

Captured terminal output for the runnable examples is available in [docs/demo-outputs.md](https://github.com/ktirupati/policyaware/blob/main/docs/demo-outputs.md).

## Articles

- [PolicyAware vs Guardrails vs AI Gateways vs Model Routers](https://dev.to/ktirupati/policyaware-vs-guardrails-vs-ai-gateways-vs-model-routers-the-comparison-every-ai-engineer-needs-289p)
- [Build a Policy-Aware AI Gateway in Python](https://dev.to/ktirupati/build-a-policy-aware-ai-gateway-in-python-data-protection-policy-enforcement-with-policyaware-462h)
- [Stop Shipping AI Features Without Guardrails](https://medium.com/@krishna.k.tirupati/stop-shipping-ai-features-without-guardrails-build-safer-ai-apps-with-policyaware-8bfd8509e4fb)

```python
from policyaware import Gateway, GatewayRequest

gateway = Gateway.from_policy_file("examples/policies/basic.yaml")

response = gateway.chat(
    GatewayRequest(
        tenant="acme",
        app="claims-assistant",
        user={"id": "u_123", "role": "claims_adjuster"},
        context={"region": "us", "task_type": "summarization", "risk": "low"},
        messages=[{"role": "user", "content": "Summarize claim ACME-42."}],
    )
)

print(response.content)
print(response.policy.decision)
print(response.policy.reason_codes)
print(response.trace_id)
```

## Architecture

```text
Application / Agent / RAG App
        |
        v
PolicyAware SDK / Middleware
        |
        v
Identity + Context Resolver
        |
        v
Policy Decision Engine -> Data Protection Engine -> Model Router -> Provider/Tool
        |
        v
Runtime Evaluation -> Audit Trace -> Response
```

## Repository Layout

```text
src/policyaware/
  audit.py              Request traces and audit export records
  cli.py                policyaware CLI
  data_protection.py    PII/PHI/secret detection and redaction
  evals.py              Offline and runtime evaluation primitives
  gateway.py            Main SDK facade
  models.py             Core typed contracts
  policy.py             Deny-by-default policy engine
  providers.py          Provider abstraction and local simulated provider
  routing.py            Policy-aware model routing
  integrations/         FastAPI, Flask, LangChain, LlamaIndex shims
examples/
  policies/
  evals/
tests/
```

## Policy Example

```yaml
id: basic_enterprise_policy
default: deny

rules:
  - name: allow_low_risk_support
    effect: allow
    when:
      user.role_in: ["support_agent", "claims_adjuster"]
      request.risk_in: ["low", "medium"]
      data.contains_secrets: false

  - name: redact_pii_for_non_privileged_users
    effect: transform
    action: redact
    when:
      data.contains_pii: true
      user.role_not_in: ["privacy_admin", "compliance_officer"]

  - name: require_approval_for_high_risk
    effect: require_approval
    when:
      request.risk: "high"
```

## Development Status

This is a production-grade starter framework: the core extension points and executable behavior are present, while provider integrations, enterprise identity adapters, dashboard UI, and long-term storage can be expanded by contributors.

## v0.2 MVP Capabilities

- Deterministic risk classification: low, medium, high, critical.
- Explainable policy decisions with reason codes and remediation.
- Replayable audit trace snapshots.
- Audit bundle generation.
- Tool governance policies for MCP-style connectors and actions.
- Governance-aware eval report schema.
- Provider adapters for OpenAI-compatible APIs, Azure OpenAI, Anthropic, Bedrock, Vertex AI, Ollama, and vLLM.
- Optional ML signal integrations for Presidio PII detection, ProtectAI prompt-injection detection, and custom Transformers domain/risk classifiers.
- Optional NeMo Guardrails and Guardrails AI adapters for full-stack guardrail orchestration.
- Fast local code scanner and HTML recommendation report.
- SQLite audit storage and static trace viewer.
- Prometheus text and OpenTelemetry-shaped JSON exporters.
- File and webhook approval hooks.
- Executable golden dataset policy checks.

## Third-Party ML Models

Optional ML integrations may download third-party models at runtime. PolicyAware does not bundle model weights. Review and accept the license or access terms for any model you configure, especially gated Hugging Face models.

## Recommended GitHub Topics

For discovery, use repository topics such as `llm`, `ai-gateway`, `llm-governance`, `guardrails`, `rag`, `mcp`, `ai-agents`, `pii-redaction`, `model-routing`, `audit`, `python`, and `open-source`.

## License

Apache-2.0
