CerbIA

CerbIA is a Python library and command-line interface for reusable security gates around AI agents' inputs and outputs. Review prompts, files, instructions, configurations, and other agent interactions before application, CI/CD, or local use.

Define reviewable pipelines in YAML, then run the same gate in an application, from the command line, or in a deployment pipeline. The gate loads content, optionally preprocesses it, applies scanners, and aggregates findings into a risk verdict.

Get started

Install CerbIA with CLI support, validate the example configuration, and scan text:

pip install "cerbia[cli]"
cerbia validate examples/cli-usage/config.cerbia.yaml
cerbia scan --config examples/cli-usage/config.cerbia.yaml --text "A short message"

The commands above use the CLI example configuration. Follow the prerequisites to get ready, or read about CerbIA for its scope and limitations.

Use it where you work

  • Python library: evaluate agent interactions from application code with a native Python API.

  • Command line: scan text, files, and configurations locally with the cerbia command before deployment.

  • CI/CD pipelines: automate checks with the same CLI and declarative YAML configuration used during local development.

Declarative evaluation

YAML-first configuration makes a pipeline reviewable, versionable, and distributable. Each gate composes four stages:

  1. Load content from inline text or file inputs.

  2. Normalize extracted data before inspection.

  3. Inspect with pattern-based scanners and optional local ML integrations.

  4. Decide by aggregating risk into a block or allow verdict.

Extend it and run it anywhere

Add custom loaders, preprocessors, scanners, and score aggregators without forking the codebase. Configure fully qualified Python components and their initialization arguments in YAML. Register language-specific patterns for built-in scanners using ISO-639-1 language codes and the @i18n_pattern decorator; built-in packs support English, Spanish, and Galician.

For example, a custom scanner can be selected by its Python class path and configured with initialization arguments:

scanners:
  - scanner: your_package.components.CompanyPolicyScanner
    init_args:
      blocked_phrase: "internal only"

Layer fast pattern-based checks for suspicious instructions, secrets, PII, URLs, and hidden text with optional local ML-backed integrations for selected scenarios. Run the same declarative gate across applications, environments, and CI/CD pipelines.

Start scanning in three steps

Install CerbIA
pip install "cerbia[cli]"
Validate configuration
cerbia validate examples/cli-usage/config.cerbia.yaml
Scan content
cerbia scan --config examples/cli-usage/config.cerbia.yaml --text "A short message"

Free and open source

CerbIA is licensed under the Apache-2.0 License. Contributions that add scanners, preprocessors, and integrations are welcome.

Explore the source, report an issue, or contribute to CerbIA.

Important limitations

Scanner results are heuristic or model-based signals, not a security certification. Evaluate them for your threat model and retain defense-in-depth controls. Read the product overview before using the results to make security decisions.