1. Executive summary
Every LLM feature your company ships sends data to a company you do not control. Most security teams cannot say what left, who sent it, or whether it should have.
The answer is not to slow AI down. It is one checkpoint between your applications and every model, enforcing eight controls and producing audit evidence by default. This paper explains where the risk comes from, sets out those controls, maps them to frameworks such as NIST AI RMF, ISO/IEC 42001, the EU AI Act, GDPR, and India's DPDP Act, and gives you a quick way to score where you stand. Igris appears only in the final chapter.
2. The new data exit
LLM traffic has become one of the largest flows of sensitive data leaving the modern company, and usually the least watched. To a firewall it looks like ordinary HTTPS. Inside, it carries customer messages, retrieved documents, source code, and logs, and model responses can carry sensitive data straight back to users.
Figure 01
LLM traffic leaves through many paths, with no single log or policy
What goes into prompts
Your AI features
Model providers
← responses can carry sensitive data back
No single owner, no single log, no single place to apply policy
Sensitive text flows from many sources, through many AI features, to many providers, and responses flow back the same way. No single place sees all of it.
Three ways it happens every day
- The helpful customer types a full card number into a support chatbot, and the whole conversation lands in a provider's logs.
- The fast-moving engineer tests a new feature with real patient notes because the synthetic data looked too clean.
- The invisible team builds an assistant on a new provider with a personal API key, with no contract review and no log.
None of them are acting in bad faith. They are doing their jobs with the fastest tool available, which is exactly why the problem grows quietly.
Why existing tools miss it
Data loss prevention was built for files and email, and rarely sees server-to-provider API calls. Firewalls and API gateways see the traffic but not the meaning of a prompt. Provider guardrails cover one vendor only, and a quick internal proxy still leaves redaction, injection detection, key rotation, and audit reporting to build. What is missing is one layer that understands AI traffic, sits inline for every provider, and produces evidence by default.
3. The LLM threat landscape
Most LLM risk enters at three points: what goes into the model, what comes out of it, and what it is allowed to consume or do.
Figure 02
LLM risk enters at three points in every request
What goes in
What it uses and does
Not shown: LLM04 poisoning, a risk introduced in training
What comes out
Badges name the controls from chapter 4 that reduce each risk
The figure groups the OWASP Top 10 for LLM Applications by where each risk enters, and the badges show which of the eight controls reduce it. Eight of the ten can be reduced, fully or in part, at a single checkpoint in the request path. MITRE ATLAS adds the attacker's view, helping security teams map each detection to a known technique.
4. The 8 controls for LLM runtime security
Eight controls, enforced at one checkpoint in front of every model, close most of the gap between how fast teams ship AI and how well security can govern it.
They work as a set. The first three decide who may reach which model. The next three protect what flows through. The last two make everything visible and provable.
Figure 03
Eight controls: three decide access, three protect the traffic, two prove it
Access
Control 01
One gateway
Every provider, model, and team in one view
Control 02
Isolated keys
Apps never hold raw provider API keys
Control 03
Model allowlists
Deny by default, per connection
Protection
Control 04
Two-way redaction
Data masked before it leaves or returns
Control 05
Injection checks
Hidden instructions stopped inline
Control 06
Spend limits
Caps per connection stop runaway costs
Proof
Control 07
Audit trail
Every request and decision on record
Control 08
Anomaly alerts
Odd patterns alert responders, who can stop a session
Figure 04
Every request passes one checkpoint on the way in and on the way out
Before the model
After the model
Blocked
The developer sees why, and the event is logged
Audit trail and alerts
Controls 7, 8Every decision is recorded.
Unusual patterns raise an alert.
A request is checked three times before it reaches the model and once more before the answer reaches the user, and every decision lands in the audit trail.
5. Framework crosswalk
Dozens of AI frameworks exist, but they keep asking for the same five things: know your AI, control who uses it, protect the data, keep records, and respond fast when something goes wrong. Build those once, and the same evidence answers most audits.
The table maps each control to the clauses it supports across NIST AI RMF and the Cyber AI Profile, ISO/IEC 42001, 27001 and 27701, ETSI EN 304 223, the EU AI Act, GDPR, DORA, India's DPDP Act, AI Governance Guidelines and CERT-In Directions, plus SOC 2, HIPAA, PCI DSS, and GLBA. No tool makes you compliant on its own. The right layer supplies the controls, and the proof that they work.
A note on the EU AI Act. Articles 12, 14, and 15 apply in law to high-risk AI systems. For every other LLM use, they remain the clearest public benchmark of what responsible logging, oversight, and security look like, and enterprise buyers increasingly use them that way.
6. The LLM Security Maturity Model
Most teams shipping their first AI features start at level one or two, and moving up a single level removes the risks that keep security leaders awake.
Figure 05
Each maturity level builds on the one below it
Level 01
Ungoverned
Direct calls, own keys
No inventory of AI
Level 02
Visible
One known path
Problems seen late
Level 03
Controlled
Policies decide access
Data masked, threats stopped inline
Level 04
Evidenced
Records made automatically
Audit is an export
Maturity grows from left to right; no level can be skipped →
Each step up removes a class of risk: level two ends blind spots, level three stops harm inline, and level four turns every control into proof.
Score yourself
Tick each statement that is true for your organization today.
How to read your score. Zero or one tick: Level 1, Ungoverned. Two or three: Level 2, Visible. Four or five: Level 3, Controlled. All six: Level 4, Evidenced.
7. Industry playbooks
The eight controls apply everywhere, but each industry has one risk that matters more than the rest, and that risk decides where to start.
8. A three-phase rollout
The fastest path to secure AI is not a big-bang project but three phases, each delivering value on its own: see everything, control everything, then prove everything.
Figure 06
Three phases, each delivering value on its own
Phase 01
See
- Gateway with log-and-allow rules
- Keys moved behind the gateway
- Full inventory built
Phase 02
Control
- Redact the riskiest data
- Allowlists for production
- Injection checks and budgets
Phase 03
Prove
- Alerts to Slack and webhooks
- On-demand PDF reports
- Framework-mapped evidence
Start with visibility to earn trust; controls then land smoothly
Each phase stands on its own: stop after Phase 1 and you still have the first complete picture of your AI traffic.
9. Buyer's checklist
Before choosing any LLM security platform, ask these eight questions; a strong vendor answers each one with a demo, not a slide.
- Does it cover every model provider we use, and new ones as we add them?
- Can developers adopt it through configuration, without rewriting code?
- Are provider keys encrypted, and can we rotate them without downtime?
- Is it deny-by-default, so nothing reaches a model without a policy?
- Does it inspect responses as well as prompts, including our own data patterns?
- How does it detect prompt injection, and what happens when it does?
- Can a responder see every request and stop a session immediately?
- Can it export evidence mapped to our frameworks, and can we retain it for as long as our auditors need?
10. How Igris delivers this
Igris puts all eight controls into one platform that sits between your applications and every model provider, and your developers adopt it through configuration rather than code rewrites.
Two Igris products carry this paper's controls. Igris Guard is a transparent proxy between your users and any LLM, built on a unified gateway with one OpenAI-compatible API across 50+ chat providers, plus any OpenAI-compatible or self-hosted endpoint such as Ollama. Igris Lens streams every event into one queryable timeline, with real-time alerts, risk heatmaps, and audit-ready reports.
Figure 07
Igris sits between every application and every model, and records it all
Your applications
No code rewrites
on the unified LLM gateway
Igris Guard
- 01Identity and virtual keys
- 02Policy match
- 03PII and injection checks
- 04Model call and audit
50+ model providers
Igris Lens
- Events and incidents in one timeline
- Risk heatmaps and cost by model and user
- Kill switch for agent sessions
Real-time alerts
Slack, Discord, webhooks
Reports and evidence
PDF reports, CSV and JSON
Guard enforces policy on every request in both directions, and Lens turns every decision into alerts, reports, and audit evidence.
Every control, mapped
Developers adopt Igris through SDK adapters for OpenAI and Anthropic, with Google models reachable through the OpenAI-compatible API, so existing code keeps working. Security leaders get one risk dashboard and PDF compliance reports, and every proxied request is captured in the audit trail.
See it on your own traffic
The best way to judge any of this is on your own AI traffic. Book a demo at igrisecurity.com and we will walk through the eight controls live, starting with Phase 1: see everything.
Sources
- Standards and frameworks: NIST AI Risk Management Framework, NIST AI 600-1, NIST IR 8596 Cyber AI Profile (preliminary draft), ISO/IEC 42001, ISO/IEC 27001, ISO/IEC 27701, ETSI EN 304 223
- Threat references: OWASP Top 10 for LLM Applications, MITRE ATLAS
- European Union: EU AI Act, GDPR, DORA
- India: DPDP Rules (obligations phasing in through 2027), India AI Governance Guidelines, CERT-In Directions
- Industry and assurance: SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS, GLBA Safeguards