Skip to main content

Layer 4: Governance & security

The same platform secures what you built: the model path, the user path, the tool path.

In this layer: AI Gateway, AI Security for Apps + WAF, Secure MCP.

These are the shields you can explore in Step 6 (optional). Full walkthroughs: Shield 1: AI Gateway, Shield 2: AI Security for Apps + WAF, Shield 3: Secure MCP.

AI Gateway​

What it is: Every model call through one control point: Guardrails, DLP, rate and spend limits, routing, logs.

Use it when: Shield 1: route your agent through agent-gateway and block injection and card numbers.

// wrangler.jsonc: "vars": { "AI_GATEWAY_ID": "agent-gateway" }
await env.AI.run(model, input, { gateway: { id: env.AI_GATEWAY_ID } });
// Guardrails block: error 2016 · DLP block: error 2029

Basics: AI Gateway · Guardrails · DLP

Advanced: Spend limits · Dynamic routing

AI Security for Apps + WAF​

What it is: The WAF reads prompts on endpoints labelled cf-llm: injection score, PII, unsafe and custom topics.

Use it when: Shield 2: block a prompt-injection or a staff-discount fishing attempt before it reaches your Worker.

# WAF custom rule expression (Security > Security rules)
(http.host eq "<TEAM_HOSTNAME>"
and cf.llm.prompt.injection_score lt 20)

Basics: AI Security for Apps · Get started

Advanced: Unsafe and custom topics · WAF custom rules

Secure MCP​

What it is: Access in front of your MCP server, an MCP server portal with only approved tools, Gateway and DLP on tool traffic.

Use it when: Shield 3 (bonus): the agent may call your tools, an unauthenticated caller may not.

Basics: MCP server portals · MCP governance

Advanced: Service tokens · Securing MCP servers