Skip to Content
Solution PlaysPlay 30: Play 30 β€” AI Security Hardening πŸ”’

Play 30 β€” AI Security Hardening πŸ”’

Multi-layer defense against prompt injection, jailbreak, and data exfiltration.

Wrap any AI application with 8 security layers covering the full OWASP LLM Top 10. Input sanitization, prompt injection classifiers, content safety, PII masking, output validation, data exfiltration prevention, and audit logging β€” all in a composable middleware architecture.

Quick Start

cd solution-plays/30-ai-security-hardening az deployment group create -g $RG -f infra/main.bicep -p infra/parameters.json code . # Use @builder for defense layers, @reviewer for red-teaming, @tuner for FP reduction

Defense Architecture (8 Layers)

πŸ“ See architecture.md for full data flow, service roles, security architecture, and scaling tables.

Input β†’ L1:Sanitize β†’ L2:Injection β†’ L3:ContentSafety β†’ L4:PII β†’ LLM β†’ L5:Grounding β†’ L6:Exfiltration β†’ L7:Safety β†’ L8:Audit β†’ Output

OWASP LLM Top 10 Coverage

IDThreatDefense
LLM01Prompt InjectionClassifier + delimiter isolation
LLM02Insecure OutputOutput validation + sanitization
LLM06Sensitive DisclosurePII masking + output filtering
LLM07Insecure PluginTool input validation
LLM08Excessive AgencyAction allowlists

Key Metrics

  • Injection block: β‰₯95% Β· False positive: <5% Β· Data leakage: 0% Β· Overhead: <500ms

Composability

Works as middleware for any FrootAI play:

  • Play 01 + Play 30 = Secure RAG
  • Play 04 + Play 30 = Secure Voice AI
  • Play 07 + Play 30 = Secure Multi-Agent

DevKit (AI Security-Focused)

PrimitiveWhat It Does
3 agentsBuilder (defense layers/injection/validation), Reviewer (red-team/OWASP/pen-test), Tuner (sensitivity/FP/patterns)
3 skillsDeploy (104 lines), Evaluate (101 lines), Tune (101 lines)
4 prompts/deploy (defense layers), /test (attack vectors), /review (red-team), /evaluate (injection resilience)

Cost

πŸ’° See cost.json for full pricing breakdown with SKUs, notes, and optimization tips.

ServicePurposeDevProdEnterprise
Content SafetyMulti-category moderation + Prompt Shields$0$75$300
Azure OpenAIRed team simulation, adversarial testing$40$200$800
Container AppsSecurity proxy + red team runner$10$100$300
Cosmos DBSecurity event store, audit log$5$30$160
Key VaultAPI keys, mTLS certs, encryption keys$1$5$15
App InsightsBlock rates, injection attempts, false positives$0$30$120
Log AnalyticsSecurity audit logs, compliance reports$0$20$75
Defender for CloudCloud security posture, threat detection$0$15$40
Total$56$475$1,810

πŸ“– Full docs Β· 🌐 frootai.dev/solution-plays/30-ai-security-hardeningΒ 

FAI Manifest

FieldValue
Play30-ai-security-hardening
Version1.0.0
KnowledgeT2-Responsible-AI, R3-Deterministic-AI, T3-Production-Patterns, F1-GenAI-Foundations
WAF Pillarssecurity, reliability, responsible-ai, operational-excellence
Groundednessβ‰₯ 85%
Safety0 violations max
Last updated on