CerbIA evaluates content through a configured pipeline:
loaders → preprocessors → SecurityGate (scanners → score aggregator → verdict)
| Component | Responsibility |
|---|---|
Produce entries from configured input sources. |
|
Transform or derive entries before scanning. |
|
Runs compatible scanners, applies their actions and severities, and returns a verdict for each entry. |
|
Inspect entry content and report a risk score, rationale, and optional match locations. |
|
Combine the severity-weighted scores of blocking findings for the gate. |
See Architecture for the complete entry lifecycle and result model.
Install the CLI and validate the repository’s example configuration:
pip install "cerbia[cli]"
cerbia validate examples/cli-usage/config.cerbia.yaml
cerbia scan --config examples/cli-usage/config.cerbia.yaml --text "A short message"
scan needs configured loaders or at least one --text or --file argument.
It exits 0 for safe results, 1 for unsafe results, and 2 for configuration
or handled execution failures. A missing --file path currently yields no
entry, which can result in a safe empty scan.
Continue with Configuration. Packages explains the optional ML, Presidio, and ProtectAI boundaries.