Back to docs

Core Concepts

Interceptor Rules

BLAZLE evaluates each request against two layers of rules: built-in static rules and your organization's custom regex rules.

Built-in Rules

Built into the engine and applied to every request. Examples:

AWS Access Key

Catastrophic

PEM Private Key

Catastrophic

GitHub Personal Access Token

Major

Slack Webhook URL

Major

Database Connection String

Major

Generic API Key / Credential

Moderate

PII (Email)

Minor

PII (Credit Card)

Major

Obfuscation & Evasion Protection

Attackers and prompt-injection payloads often try to hide secrets and instructions through encoding, look-alike characters or splitting. BLAZLE normalizes every payload before evaluation, so disguised secrets and instructions are caught the same way as plain ones.

Custom Rules

Create organization-specific rules via the dashboard or API:

POST /api/v1/admin/rules
{
  "name": "Internal Service Token",
  "pattern": "svc_[a-zA-Z0-9]{32}",
  "action": "block"   // "block" | "log" | "redact"
}