Governed: A control you can show an auditor, not a line in a prompt.
A rule in a system prompt is a request. Ours is a gate in front of the model, with no second model in the loop.
Works with the clients you already run
28 have a recipe to paste, and anything else that speaks MCP works too.
Lock a topic, then try to talk your way past it.
Your wording, against the same guard engine the API runs, with no account and nothing to install. Pick a topic to lock, type a question, and read the verdict, including the topic a refusal matched and the tokens the guard read to decide.
A lock is a blocklist that matches the topic’s vocabulary rather than a keyword list, so a differently worded question in that vocabulary is still refused. Beyond the demo’s limits, the free tier includes 200 guard checks and needs no card.
Those four are the plain question, refused; the same question in other options vocabulary, refused too; the same question in plain words with none of that vocabulary, which gets through; and a neighbouring question that should not be refused. Type your own and see which side it lands on.
What a lock gets you
Refused before inference
A locked topic never reaches the model, so you're not billed for the completion and nothing off-policy gets generated.
Matches the topic, not a word list
A differently worded request in the topic's own vocabulary lands on the same lock, which is why the demo's second example is refused.
Bound to the API key
Policy travels with the credential, not the prompt. One base-URL change and every call is governed.
Auditable, not asserted
Show a reviewer what was refused, when, and on what basis. CSV and JSON on every plan; webhook and SIEM on Enterprise.
A control has three jobs. Two are measured, one is a record.
Stop what it should, let ordinary work through, and leave something an auditor can read. One test covers the first two.
Requests written to get past a rule
of 2,251 stopped before the model saw them: the same locked request reworded, reframed, split across sentences, or buried beside ordinary work. 50 crossed.
Ordinary work let through
benign controls allowed on the same corpus.
The record
written for every decision: the time, the topic matched, the policy version, the verdict, and how the match was made. The audit record stores no message text.
The 50. Most were a locked request riding inside an ordinary allowed one; the write-up says how many. Over-refusal. Roughly 1 in 7 unrelated queries trips a lock it should not.
64 regulated topics, not 14 harm categories.
Content guards answer "is this harmful?". A regulated business needs a different question answered: "is this about a topic we are not licensed to discuss?"
| Guard | Categories | Organized around |
|---|---|---|
| ShieldGemma · Azure Content Safety | 3–4 | harm |
| Qwen3Guard · Granite Guardian | 9 | harm |
| OpenAI Moderation · WildGuard | 13 | harm |
| Llama Guard 4 | 14 | harm |
| NemoGuard ContentSafety | 23 | harm |
| Tileward | 64 | regulated business topics |
| Tileward , plus the rest of the roster | 151 | everything else |
In Llama Guard's whole taxonomy, finance, medicine and law collapse into one bucket: S6, "Specialized Advice." We ship AML & KYC, options pricing, personal medical advice and 61 more regulated topics, each lockable on its own.
Llama Guard is free, and you should run it. A harm filter and a topic policy are not substitutes.
215 lockable tiles. These 64 are the regulated ones.
If you are here to check whether your topic is covered, this is the list — scan it rather than book a call. None of them needs a definition written by you.
The topics a licence, a regulator or a compliance officer turns on. Broken out below.
Programming languages, frameworks, the sciences, reasoning, general knowledge. Same lock, same audit record.
Every one independently switchable per API key. Build and above can add tiles of your own.
See all 64 regulated topics
Finance
AML & KYC, Client onboarding, Commodity trading, Conduct & surveillance, Corporate lending, Credit risk, Execution & trading, FX trading, Market risk, Operational risk, Options pricing, Personalized investment advice, Private equity & VC, Quant strategies, Regulatory reporting, Reporting & analytics, Structured products, Treasury & cash management
Safety
Biosecurity & bioweapons, Child safety, Fraud & scams, Hate & harassment, Self-harm & crisis, Sexual & adult content, Surveillance & stalking, Weapons & dangerous goods
Industries
Education, Energy & utilities, Entertainment & media, Manufacturing & supply chain, Pharma & life sciences, Real estate, Telecom & networks, Transportation & logistics
Legal
Data privacy & PII, Employment law, Intellectual property, Legal & contracts, Litigation & disputes, Personal legal advice
Healthcare
Clinical medicine, Health Insurance & Claims, Medical Devices, Personal medical advice, Public Health & Epidemiology
Business functions
Customer support, IT & data operations, Marketing, Product management, Sales
Tax & insurance
Insurance underwriting, Personal tax advice, Tax accounting
Civic & world
Geopolitics & diplomacy, News & current events, Political affairs
Content integrity
Copyright & piracy, Deepfakes & synthetic media, Misinformation & disinfo
Security
Cybersecurity defense, Exploits & malware
Public sector & HR
HR & employment, Public procurement
Technology
Software engineering
Start free. Compare plans in one place.
Governance is included in every complete Tileward plan and is also available on its own. Paid Governance plans start at $19/month; complete plans start at $39/month.
Bring us a topic you can't let the model discuss.
We'll lock it, try to get past it, and show you the record. Thirty minutes, an engineer, no deck.