published on Tuesday, Sep 15, 2026 by imperva
published on Tuesday, Sep 15, 2026 by imperva
Provides an Imperva AI Application Security policy resource.
A policy holds a set of guardrails that inspect traffic for an AI Application Security
application. Each guardrail runs in a specific phase - PROMPT (the request sent to
the model) or RESPONSE (the model’s reply) - and enforces an action (BLOCK,
ALERT, or MASK) when it triggers.
A policy is a child of an incapsula.AiApplicationSecurityApplication;
the backend allows a single policy per application.
Required guardrail sets. The backend enforces a minimum set of guardrails per deployment type and phase. A policy that omits any required guardrail is rejected at apply time with an
Invalid guardrail set for '<type>' deployment in '<phase>' phaseerror listing the missing guardrails. See Required guardrails by deployment type below.
Example Usage
The example below is a complete SDK policy: it includes the full required
guardrail set for both phases. For API and EDGE the RESPONSE phase requires
fewer guardrails (see the table below) - drop the MODERATION and
SYSTEM_PROMPT_LEAK guardrails for those types.
import * as pulumi from "@pulumi/pulumi";
import * as incapsula from "@pulumi/incapsula";
const sdkApp = new incapsula.AiApplicationSecurityApplication("sdk_app", {
accountId: 1234567,
name: "my-sdk-app",
applicationType: "SDK",
region: "US",
});
const sdkPolicy = new incapsula.AiApplicationSecurityPolicy("sdk_policy", {
accountId: 1234567,
applicationId: sdkApp.aiApplicationSecurityApplicationId,
name: "default-policy",
active: true,
guardrails: [
{
type: "PROMPT_INJECTION",
phase: "PROMPT",
mode: "BLOCK",
config: JSON.stringify({
threshold: 0.8,
message: "Your request was blocked by the AI Application Security.",
}),
},
{
type: "ZERO_SHOT_CLASSIFICATION",
phase: "PROMPT",
mode: "BLOCK",
config: JSON.stringify({
threshold: 0.85,
categories: [
"finance",
"legal",
],
message: "Your request was blocked by the AI Application Security.",
}),
},
{
type: "PII_STATIC",
phase: "PROMPT",
mode: "ALERT",
config: JSON.stringify({
enabledPatterns: [
"aws_access_key_id",
"bitcoin_bech32",
],
}),
},
{
type: "RATE_LIMIT",
phase: "PROMPT",
mode: "BLOCK",
config: JSON.stringify({
globalConfig: {
enabled: true,
maxTokens: 100000,
timeUnitInSec: 60,
},
userConfig: {
enabled: true,
maxTokens: 10000,
timeUnitInSec: 60,
},
promptLimitConfig: {
enabled: true,
maxCharacters: 4000,
},
message: "Rate limit exceeded.",
}),
},
{
type: "ZERO_SHOT_CLASSIFICATION",
phase: "RESPONSE",
mode: "BLOCK",
config: JSON.stringify({
threshold: 0.9,
categories: [
"finance",
"legal",
],
}),
},
{
type: "PII_STATIC",
phase: "RESPONSE",
mode: "BLOCK",
config: JSON.stringify({
enabledPatterns: ["autopilot_api_key"],
message: "Sensitive data was detected in the response.",
}),
},
{
type: "RATE_LIMIT",
phase: "RESPONSE",
mode: "ALERT",
config: JSON.stringify({
globalConfig: {
enabled: true,
maxTokens: 200000,
timeUnitInSec: 60,
},
userConfig: {
enabled: false,
maxTokens: 20000,
timeUnitInSec: 60,
},
promptLimitConfig: {
enabled: true,
maxCharacters: 8000,
},
}),
},
{
type: "MODERATION",
phase: "RESPONSE",
mode: "ALERT",
config: JSON.stringify({
threshold: 0.8,
}),
},
{
type: "SYSTEM_PROMPT_LEAK",
phase: "RESPONSE",
mode: "BLOCK",
},
],
});
import pulumi
import json
import pulumi_incapsula as incapsula
sdk_app = incapsula.AiApplicationSecurityApplication("sdk_app",
account_id=1234567,
name="my-sdk-app",
application_type="SDK",
region="US")
sdk_policy = incapsula.AiApplicationSecurityPolicy("sdk_policy",
account_id=1234567,
application_id=sdk_app.ai_application_security_application_id,
name="default-policy",
active=True,
guardrails=[
{
"type": "PROMPT_INJECTION",
"phase": "PROMPT",
"mode": "BLOCK",
"config": json.dumps({
"threshold": 0.8,
"message": "Your request was blocked by the AI Application Security.",
}),
},
{
"type": "ZERO_SHOT_CLASSIFICATION",
"phase": "PROMPT",
"mode": "BLOCK",
"config": json.dumps({
"threshold": 0.85,
"categories": [
"finance",
"legal",
],
"message": "Your request was blocked by the AI Application Security.",
}),
},
{
"type": "PII_STATIC",
"phase": "PROMPT",
"mode": "ALERT",
"config": json.dumps({
"enabledPatterns": [
"aws_access_key_id",
"bitcoin_bech32",
],
}),
},
{
"type": "RATE_LIMIT",
"phase": "PROMPT",
"mode": "BLOCK",
"config": json.dumps({
"globalConfig": {
"enabled": True,
"maxTokens": 100000,
"timeUnitInSec": 60,
},
"userConfig": {
"enabled": True,
"maxTokens": 10000,
"timeUnitInSec": 60,
},
"promptLimitConfig": {
"enabled": True,
"maxCharacters": 4000,
},
"message": "Rate limit exceeded.",
}),
},
{
"type": "ZERO_SHOT_CLASSIFICATION",
"phase": "RESPONSE",
"mode": "BLOCK",
"config": json.dumps({
"threshold": 0.9,
"categories": [
"finance",
"legal",
],
}),
},
{
"type": "PII_STATIC",
"phase": "RESPONSE",
"mode": "BLOCK",
"config": json.dumps({
"enabledPatterns": ["autopilot_api_key"],
"message": "Sensitive data was detected in the response.",
}),
},
{
"type": "RATE_LIMIT",
"phase": "RESPONSE",
"mode": "ALERT",
"config": json.dumps({
"globalConfig": {
"enabled": True,
"maxTokens": 200000,
"timeUnitInSec": 60,
},
"userConfig": {
"enabled": False,
"maxTokens": 20000,
"timeUnitInSec": 60,
},
"promptLimitConfig": {
"enabled": True,
"maxCharacters": 8000,
},
}),
},
{
"type": "MODERATION",
"phase": "RESPONSE",
"mode": "ALERT",
"config": json.dumps({
"threshold": 0.8,
}),
},
{
"type": "SYSTEM_PROMPT_LEAK",
"phase": "RESPONSE",
"mode": "BLOCK",
},
])
package main
import (
"encoding/json"
"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
sdkApp, err := incapsula.NewAiApplicationSecurityApplication(ctx, "sdk_app", &incapsula.AiApplicationSecurityApplicationArgs{
AccountId: pulumi.Float64(1234567),
Name: pulumi.String("my-sdk-app"),
ApplicationType: pulumi.String("SDK"),
Region: pulumi.String("US"),
})
if err != nil {
return err
}
tmpJSON0, err := json.Marshal(map[string]interface{}{
"threshold": 0.8,
"message": "Your request was blocked by the AI Application Security.",
})
if err != nil {
return err
}
json0 := string(tmpJSON0)
tmpJSON1, err := json.Marshal(map[string]interface{}{
"threshold": 0.85,
"categories": []string{
"finance",
"legal",
},
"message": "Your request was blocked by the AI Application Security.",
})
if err != nil {
return err
}
json1 := string(tmpJSON1)
tmpJSON2, err := json.Marshal(map[string]interface{}{
"enabledPatterns": []string{
"aws_access_key_id",
"bitcoin_bech32",
},
})
if err != nil {
return err
}
json2 := string(tmpJSON2)
tmpJSON3, err := json.Marshal(map[string]interface{}{
"globalConfig": map[string]interface{}{
"enabled": true,
"maxTokens": 100000,
"timeUnitInSec": 60,
},
"userConfig": map[string]interface{}{
"enabled": true,
"maxTokens": 10000,
"timeUnitInSec": 60,
},
"promptLimitConfig": map[string]interface{}{
"enabled": true,
"maxCharacters": 4000,
},
"message": "Rate limit exceeded.",
})
if err != nil {
return err
}
json3 := string(tmpJSON3)
tmpJSON4, err := json.Marshal(map[string]interface{}{
"threshold": 0.9,
"categories": []string{
"finance",
"legal",
},
})
if err != nil {
return err
}
json4 := string(tmpJSON4)
tmpJSON5, err := json.Marshal(map[string]interface{}{
"enabledPatterns": []string{
"autopilot_api_key",
},
"message": "Sensitive data was detected in the response.",
})
if err != nil {
return err
}
json5 := string(tmpJSON5)
tmpJSON6, err := json.Marshal(map[string]interface{}{
"globalConfig": map[string]interface{}{
"enabled": true,
"maxTokens": 200000,
"timeUnitInSec": 60,
},
"userConfig": map[string]interface{}{
"enabled": false,
"maxTokens": 20000,
"timeUnitInSec": 60,
},
"promptLimitConfig": map[string]interface{}{
"enabled": true,
"maxCharacters": 8000,
},
})
if err != nil {
return err
}
json6 := string(tmpJSON6)
tmpJSON7, err := json.Marshal(map[string]interface{}{
"threshold": 0.8,
})
if err != nil {
return err
}
json7 := string(tmpJSON7)
_, err = incapsula.NewAiApplicationSecurityPolicy(ctx, "sdk_policy", &incapsula.AiApplicationSecurityPolicyArgs{
AccountId: pulumi.Float64(1234567),
ApplicationId: sdkApp.AiApplicationSecurityApplicationId,
Name: pulumi.String("default-policy"),
Active: pulumi.Bool(true),
Guardrails: incapsula.AiApplicationSecurityPolicyGuardrailArray{
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("PROMPT_INJECTION"),
Phase: pulumi.String("PROMPT"),
Mode: pulumi.String("BLOCK"),
Config: pulumi.String(json0),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("ZERO_SHOT_CLASSIFICATION"),
Phase: pulumi.String("PROMPT"),
Mode: pulumi.String("BLOCK"),
Config: pulumi.String(json1),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("PII_STATIC"),
Phase: pulumi.String("PROMPT"),
Mode: pulumi.String("ALERT"),
Config: pulumi.String(json2),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("RATE_LIMIT"),
Phase: pulumi.String("PROMPT"),
Mode: pulumi.String("BLOCK"),
Config: pulumi.String(json3),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("ZERO_SHOT_CLASSIFICATION"),
Phase: pulumi.String("RESPONSE"),
Mode: pulumi.String("BLOCK"),
Config: pulumi.String(json4),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("PII_STATIC"),
Phase: pulumi.String("RESPONSE"),
Mode: pulumi.String("BLOCK"),
Config: pulumi.String(json5),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("RATE_LIMIT"),
Phase: pulumi.String("RESPONSE"),
Mode: pulumi.String("ALERT"),
Config: pulumi.String(json6),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("MODERATION"),
Phase: pulumi.String("RESPONSE"),
Mode: pulumi.String("ALERT"),
Config: pulumi.String(json7),
},
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Type: pulumi.String("SYSTEM_PROMPT_LEAK"),
Phase: pulumi.String("RESPONSE"),
Mode: pulumi.String("BLOCK"),
},
},
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using System.Text.Json;
using Pulumi;
using Incapsula = Pulumi.Incapsula;
return await Deployment.RunAsync(() =>
{
var sdkApp = new Incapsula.AiApplicationSecurityApplication("sdk_app", new()
{
AccountId = 1234567,
Name = "my-sdk-app",
ApplicationType = "SDK",
Region = "US",
});
var sdkPolicy = new Incapsula.AiApplicationSecurityPolicy("sdk_policy", new()
{
AccountId = 1234567,
ApplicationId = sdkApp.AiApplicationSecurityApplicationId,
Name = "default-policy",
Active = true,
Guardrails = new[]
{
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "PROMPT_INJECTION",
Phase = "PROMPT",
Mode = "BLOCK",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["threshold"] = 0.8,
["message"] = "Your request was blocked by the AI Application Security.",
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "ZERO_SHOT_CLASSIFICATION",
Phase = "PROMPT",
Mode = "BLOCK",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["threshold"] = 0.85,
["categories"] = new[]
{
"finance",
"legal",
},
["message"] = "Your request was blocked by the AI Application Security.",
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "PII_STATIC",
Phase = "PROMPT",
Mode = "ALERT",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["enabledPatterns"] = new[]
{
"aws_access_key_id",
"bitcoin_bech32",
},
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "RATE_LIMIT",
Phase = "PROMPT",
Mode = "BLOCK",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["globalConfig"] = new Dictionary<string, object?>
{
["enabled"] = true,
["maxTokens"] = 100000,
["timeUnitInSec"] = 60,
},
["userConfig"] = new Dictionary<string, object?>
{
["enabled"] = true,
["maxTokens"] = 10000,
["timeUnitInSec"] = 60,
},
["promptLimitConfig"] = new Dictionary<string, object?>
{
["enabled"] = true,
["maxCharacters"] = 4000,
},
["message"] = "Rate limit exceeded.",
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "ZERO_SHOT_CLASSIFICATION",
Phase = "RESPONSE",
Mode = "BLOCK",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["threshold"] = 0.9,
["categories"] = new[]
{
"finance",
"legal",
},
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "PII_STATIC",
Phase = "RESPONSE",
Mode = "BLOCK",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["enabledPatterns"] = new[]
{
"autopilot_api_key",
},
["message"] = "Sensitive data was detected in the response.",
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "RATE_LIMIT",
Phase = "RESPONSE",
Mode = "ALERT",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["globalConfig"] = new Dictionary<string, object?>
{
["enabled"] = true,
["maxTokens"] = 200000,
["timeUnitInSec"] = 60,
},
["userConfig"] = new Dictionary<string, object?>
{
["enabled"] = false,
["maxTokens"] = 20000,
["timeUnitInSec"] = 60,
},
["promptLimitConfig"] = new Dictionary<string, object?>
{
["enabled"] = true,
["maxCharacters"] = 8000,
},
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "MODERATION",
Phase = "RESPONSE",
Mode = "ALERT",
Config = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["threshold"] = 0.8,
}),
},
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Type = "SYSTEM_PROMPT_LEAK",
Phase = "RESPONSE",
Mode = "BLOCK",
},
},
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.incapsula.AiApplicationSecurityApplication;
import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
import com.pulumi.incapsula.AiApplicationSecurityPolicy;
import com.pulumi.incapsula.AiApplicationSecurityPolicyArgs;
import com.pulumi.incapsula.inputs.AiApplicationSecurityPolicyGuardrailArgs;
import static com.pulumi.codegen.internal.Serialization.*;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var sdkApp = new AiApplicationSecurityApplication("sdkApp", AiApplicationSecurityApplicationArgs.builder()
.accountId(1234567.0)
.name("my-sdk-app")
.applicationType("SDK")
.region("US")
.build());
var sdkPolicy = new AiApplicationSecurityPolicy("sdkPolicy", AiApplicationSecurityPolicyArgs.builder()
.accountId(1234567.0)
.applicationId(sdkApp.aiApplicationSecurityApplicationId())
.name("default-policy")
.active(true)
.guardrails(
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("PROMPT_INJECTION")
.phase("PROMPT")
.mode("BLOCK")
.config(serializeJson(
jsonObject(
jsonProperty("threshold", 0.8),
jsonProperty("message", "Your request was blocked by the AI Application Security.")
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("ZERO_SHOT_CLASSIFICATION")
.phase("PROMPT")
.mode("BLOCK")
.config(serializeJson(
jsonObject(
jsonProperty("threshold", 0.85),
jsonProperty("categories", jsonArray(
"finance",
"legal"
)),
jsonProperty("message", "Your request was blocked by the AI Application Security.")
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("PII_STATIC")
.phase("PROMPT")
.mode("ALERT")
.config(serializeJson(
jsonObject(
jsonProperty("enabledPatterns", jsonArray(
"aws_access_key_id",
"bitcoin_bech32"
))
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("RATE_LIMIT")
.phase("PROMPT")
.mode("BLOCK")
.config(serializeJson(
jsonObject(
jsonProperty("globalConfig", jsonObject(
jsonProperty("enabled", true),
jsonProperty("maxTokens", 100000),
jsonProperty("timeUnitInSec", 60)
)),
jsonProperty("userConfig", jsonObject(
jsonProperty("enabled", true),
jsonProperty("maxTokens", 10000),
jsonProperty("timeUnitInSec", 60)
)),
jsonProperty("promptLimitConfig", jsonObject(
jsonProperty("enabled", true),
jsonProperty("maxCharacters", 4000)
)),
jsonProperty("message", "Rate limit exceeded.")
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("ZERO_SHOT_CLASSIFICATION")
.phase("RESPONSE")
.mode("BLOCK")
.config(serializeJson(
jsonObject(
jsonProperty("threshold", 0.9),
jsonProperty("categories", jsonArray(
"finance",
"legal"
))
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("PII_STATIC")
.phase("RESPONSE")
.mode("BLOCK")
.config(serializeJson(
jsonObject(
jsonProperty("enabledPatterns", jsonArray("autopilot_api_key")),
jsonProperty("message", "Sensitive data was detected in the response.")
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("RATE_LIMIT")
.phase("RESPONSE")
.mode("ALERT")
.config(serializeJson(
jsonObject(
jsonProperty("globalConfig", jsonObject(
jsonProperty("enabled", true),
jsonProperty("maxTokens", 200000),
jsonProperty("timeUnitInSec", 60)
)),
jsonProperty("userConfig", jsonObject(
jsonProperty("enabled", false),
jsonProperty("maxTokens", 20000),
jsonProperty("timeUnitInSec", 60)
)),
jsonProperty("promptLimitConfig", jsonObject(
jsonProperty("enabled", true),
jsonProperty("maxCharacters", 8000)
))
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("MODERATION")
.phase("RESPONSE")
.mode("ALERT")
.config(serializeJson(
jsonObject(
jsonProperty("threshold", 0.8)
)))
.build(),
AiApplicationSecurityPolicyGuardrailArgs.builder()
.type("SYSTEM_PROMPT_LEAK")
.phase("RESPONSE")
.mode("BLOCK")
.build())
.build());
}
}
resources:
sdkApp:
type: incapsula:AiApplicationSecurityApplication
name: sdk_app
properties:
accountId: 1.234567e+06
name: my-sdk-app
applicationType: SDK
region: US
sdkPolicy:
type: incapsula:AiApplicationSecurityPolicy
name: sdk_policy
properties:
accountId: 1.234567e+06
applicationId: ${sdkApp.aiApplicationSecurityApplicationId}
name: default-policy
active: true # --- PROMPT phase: SDK / API / EDGE all require these four ---
guardrails:
- type: PROMPT_INJECTION
phase: PROMPT
mode: BLOCK
config:
fn::toJSON:
threshold: 0.8
message: Your request was blocked by the AI Application Security.
- type: ZERO_SHOT_CLASSIFICATION
phase: PROMPT
mode: BLOCK
config:
fn::toJSON:
threshold: 0.85
categories:
- finance
- legal
message: Your request was blocked by the AI Application Security.
- type: PII_STATIC
phase: PROMPT
mode: ALERT
config:
fn::toJSON:
enabledPatterns:
- aws_access_key_id
- bitcoin_bech32
- type: RATE_LIMIT
phase: PROMPT
mode: BLOCK
config:
fn::toJSON:
globalConfig:
enabled: true
maxTokens: 100000
timeUnitInSec: 60
userConfig:
enabled: true
maxTokens: 10000
timeUnitInSec: 60
promptLimitConfig:
enabled: true
maxCharacters: 4000
message: Rate limit exceeded.
- type: ZERO_SHOT_CLASSIFICATION
phase: RESPONSE
mode: BLOCK
config:
fn::toJSON:
threshold: 0.9
categories:
- finance
- legal
- type: PII_STATIC
phase: RESPONSE
mode: BLOCK
config:
fn::toJSON:
enabledPatterns:
- autopilot_api_key
message: Sensitive data was detected in the response.
- type: RATE_LIMIT
phase: RESPONSE
mode: ALERT
config:
fn::toJSON:
globalConfig:
enabled: true
maxTokens: 200000
timeUnitInSec: 60
userConfig:
enabled: false
maxTokens: 20000
timeUnitInSec: 60
promptLimitConfig:
enabled: true
maxCharacters: 8000
- type: MODERATION
phase: RESPONSE
mode: ALERT
config:
fn::toJSON:
threshold: 0.8
- type: SYSTEM_PROMPT_LEAK
phase: RESPONSE
mode: BLOCK
Example coming soon!
Create AiApplicationSecurityPolicy Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new AiApplicationSecurityPolicy(name: string, args: AiApplicationSecurityPolicyArgs, opts?: CustomResourceOptions);@overload
def AiApplicationSecurityPolicy(resource_name: str,
args: AiApplicationSecurityPolicyArgs,
opts: Optional[ResourceOptions] = None)
@overload
def AiApplicationSecurityPolicy(resource_name: str,
opts: Optional[ResourceOptions] = None,
application_id: Optional[str] = None,
guardrails: Optional[Sequence[AiApplicationSecurityPolicyGuardrailArgs]] = None,
account_id: Optional[float] = None,
active: Optional[bool] = None,
ai_application_security_policy_id: Optional[str] = None,
description: Optional[str] = None,
name: Optional[str] = None)func NewAiApplicationSecurityPolicy(ctx *Context, name string, args AiApplicationSecurityPolicyArgs, opts ...ResourceOption) (*AiApplicationSecurityPolicy, error)public AiApplicationSecurityPolicy(string name, AiApplicationSecurityPolicyArgs args, CustomResourceOptions? opts = null)
public AiApplicationSecurityPolicy(String name, AiApplicationSecurityPolicyArgs args)
public AiApplicationSecurityPolicy(String name, AiApplicationSecurityPolicyArgs args, CustomResourceOptions options)
type: incapsula:AiApplicationSecurityPolicy
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "incapsula_ai_application_security_policy" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args AiApplicationSecurityPolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args AiApplicationSecurityPolicyArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args AiApplicationSecurityPolicyArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args AiApplicationSecurityPolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args AiApplicationSecurityPolicyArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var aiApplicationSecurityPolicyResource = new Incapsula.AiApplicationSecurityPolicy("aiApplicationSecurityPolicyResource", new()
{
ApplicationId = "string",
Guardrails = new[]
{
new Incapsula.Inputs.AiApplicationSecurityPolicyGuardrailArgs
{
Mode = "string",
Phase = "string",
Type = "string",
Active = false,
Config = "string",
},
},
AccountId = 0.0,
Active = false,
AiApplicationSecurityPolicyId = "string",
Description = "string",
Name = "string",
});
example, err := incapsula.NewAiApplicationSecurityPolicy(ctx, "aiApplicationSecurityPolicyResource", &incapsula.AiApplicationSecurityPolicyArgs{
ApplicationId: pulumi.String("string"),
Guardrails: incapsula.AiApplicationSecurityPolicyGuardrailArray{
&incapsula.AiApplicationSecurityPolicyGuardrailArgs{
Mode: pulumi.String("string"),
Phase: pulumi.String("string"),
Type: pulumi.String("string"),
Active: pulumi.Bool(false),
Config: pulumi.String("string"),
},
},
AccountId: pulumi.Float64(0),
Active: pulumi.Bool(false),
AiApplicationSecurityPolicyId: pulumi.String("string"),
Description: pulumi.String("string"),
Name: pulumi.String("string"),
})
resource "incapsula_ai_application_security_policy" "aiApplicationSecurityPolicyResource" {
lifecycle {
create_before_destroy = true
}
application_id = "string"
guardrails {
mode = "string"
phase = "string"
type = "string"
active = false
config = "string"
}
account_id = 0
active = false
ai_application_security_policy_id = "string"
description = "string"
name = "string"
}
var aiApplicationSecurityPolicyResource = new AiApplicationSecurityPolicy("aiApplicationSecurityPolicyResource", AiApplicationSecurityPolicyArgs.builder()
.applicationId("string")
.guardrails(AiApplicationSecurityPolicyGuardrailArgs.builder()
.mode("string")
.phase("string")
.type("string")
.active(false)
.config("string")
.build())
.accountId(0.0)
.active(false)
.aiApplicationSecurityPolicyId("string")
.description("string")
.name("string")
.build());
ai_application_security_policy_resource = incapsula.AiApplicationSecurityPolicy("aiApplicationSecurityPolicyResource",
application_id="string",
guardrails=[{
"mode": "string",
"phase": "string",
"type": "string",
"active": False,
"config": "string",
}],
account_id=float(0),
active=False,
ai_application_security_policy_id="string",
description="string",
name="string")
const aiApplicationSecurityPolicyResource = new incapsula.AiApplicationSecurityPolicy("aiApplicationSecurityPolicyResource", {
applicationId: "string",
guardrails: [{
mode: "string",
phase: "string",
type: "string",
active: false,
config: "string",
}],
accountId: 0,
active: false,
aiApplicationSecurityPolicyId: "string",
description: "string",
name: "string",
});
type: incapsula:AiApplicationSecurityPolicy
properties:
accountId: 0
active: false
aiApplicationSecurityPolicyId: string
applicationId: string
description: string
guardrails:
- active: false
config: string
mode: string
phase: string
type: string
name: string
AiApplicationSecurityPolicy Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The AiApplicationSecurityPolicy resource accepts the following input properties:
- Application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- Guardrails
List<Ai
Application Security Policy Guardrail> - One or more guardrail blocks (at least one). Each block supports:
- Account
Id double - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Active bool
- Whether the policy is active. Default:
true. - Ai
Application stringSecurity Policy Id - UUID of the policy.
- Description string
- Description of the policy. Up to 500 characters.
- Name string
- Name of the policy. 1-100 characters.
- Application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- Guardrails
[]Ai
Application Security Policy Guardrail Args - One or more guardrail blocks (at least one). Each block supports:
- Account
Id float64 - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Active bool
- Whether the policy is active. Default:
true. - Ai
Application stringSecurity Policy Id - UUID of the policy.
- Description string
- Description of the policy. Up to 500 characters.
- Name string
- Name of the policy. 1-100 characters.
- application_
id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- guardrails list(object)
- One or more guardrail blocks (at least one). Each block supports:
- account_
id number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active bool
- Whether the policy is active. Default:
true. - ai_
application_ stringsecurity_ policy_ id - UUID of the policy.
- description string
- Description of the policy. Up to 500 characters.
- name string
- Name of the policy. 1-100 characters.
- application
Id String - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- guardrails
List<Ai
Application Security Policy Guardrail> - One or more guardrail blocks (at least one). Each block supports:
- account
Id Double - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active Boolean
- Whether the policy is active. Default:
true. - ai
Application StringSecurity Policy Id - UUID of the policy.
- description String
- Description of the policy. Up to 500 characters.
- name String
- Name of the policy. 1-100 characters.
- application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- guardrails
Ai
Application Security Policy Guardrail[] - One or more guardrail blocks (at least one). Each block supports:
- account
Id number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active boolean
- Whether the policy is active. Default:
true. - ai
Application stringSecurity Policy Id - UUID of the policy.
- description string
- Description of the policy. Up to 500 characters.
- name string
- Name of the policy. 1-100 characters.
- application_
id str - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- guardrails
Sequence[Ai
Application Security Policy Guardrail Args] - One or more guardrail blocks (at least one). Each block supports:
- account_
id float - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active bool
- Whether the policy is active. Default:
true. - ai_
application_ strsecurity_ policy_ id - UUID of the policy.
- description str
- Description of the policy. Up to 500 characters.
- name str
- Name of the policy. 1-100 characters.
- application
Id String - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- guardrails List<Property Map>
- One or more guardrail blocks (at least one). Each block supports:
- account
Id Number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active Boolean
- Whether the policy is active. Default:
true. - ai
Application StringSecurity Policy Id - UUID of the policy.
- description String
- Description of the policy. Up to 500 characters.
- name String
- Name of the policy. 1-100 characters.
Outputs
All input properties are implicitly available as output properties. Additionally, the AiApplicationSecurityPolicy resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing AiApplicationSecurityPolicy Resource
Get an existing AiApplicationSecurityPolicy resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: AiApplicationSecurityPolicyState, opts?: CustomResourceOptions): AiApplicationSecurityPolicy@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[float] = None,
active: Optional[bool] = None,
ai_application_security_policy_id: Optional[str] = None,
application_id: Optional[str] = None,
description: Optional[str] = None,
guardrails: Optional[Sequence[AiApplicationSecurityPolicyGuardrailArgs]] = None,
name: Optional[str] = None) -> AiApplicationSecurityPolicyfunc GetAiApplicationSecurityPolicy(ctx *Context, name string, id IDInput, state *AiApplicationSecurityPolicyState, opts ...ResourceOption) (*AiApplicationSecurityPolicy, error)public static AiApplicationSecurityPolicy Get(string name, Input<string> id, AiApplicationSecurityPolicyState? state, CustomResourceOptions? opts = null)public static AiApplicationSecurityPolicy get(String name, Output<String> id, AiApplicationSecurityPolicyState state, CustomResourceOptions options)resources: _: type: incapsula:AiApplicationSecurityPolicy get: id: ${id}import {
to = incapsula_ai_application_security_policy.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Account
Id double - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Active bool
- Whether the policy is active. Default:
true. - Ai
Application stringSecurity Policy Id - UUID of the policy.
- Application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- Description string
- Description of the policy. Up to 500 characters.
- Guardrails
List<Ai
Application Security Policy Guardrail> - One or more guardrail blocks (at least one). Each block supports:
- Name string
- Name of the policy. 1-100 characters.
- Account
Id float64 - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Active bool
- Whether the policy is active. Default:
true. - Ai
Application stringSecurity Policy Id - UUID of the policy.
- Application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- Description string
- Description of the policy. Up to 500 characters.
- Guardrails
[]Ai
Application Security Policy Guardrail Args - One or more guardrail blocks (at least one). Each block supports:
- Name string
- Name of the policy. 1-100 characters.
- account_
id number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active bool
- Whether the policy is active. Default:
true. - ai_
application_ stringsecurity_ policy_ id - UUID of the policy.
- application_
id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- description string
- Description of the policy. Up to 500 characters.
- guardrails list(object)
- One or more guardrail blocks (at least one). Each block supports:
- name string
- Name of the policy. 1-100 characters.
- account
Id Double - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active Boolean
- Whether the policy is active. Default:
true. - ai
Application StringSecurity Policy Id - UUID of the policy.
- application
Id String - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- description String
- Description of the policy. Up to 500 characters.
- guardrails
List<Ai
Application Security Policy Guardrail> - One or more guardrail blocks (at least one). Each block supports:
- name String
- Name of the policy. 1-100 characters.
- account
Id number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active boolean
- Whether the policy is active. Default:
true. - ai
Application stringSecurity Policy Id - UUID of the policy.
- application
Id string - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- description string
- Description of the policy. Up to 500 characters.
- guardrails
Ai
Application Security Policy Guardrail[] - One or more guardrail blocks (at least one). Each block supports:
- name string
- Name of the policy. 1-100 characters.
- account_
id float - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active bool
- Whether the policy is active. Default:
true. - ai_
application_ strsecurity_ policy_ id - UUID of the policy.
- application_
id str - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- description str
- Description of the policy. Up to 500 characters.
- guardrails
Sequence[Ai
Application Security Policy Guardrail Args] - One or more guardrail blocks (at least one). Each block supports:
- name str
- Name of the policy. 1-100 characters.
- account
Id Number - Numeric identifier of the account that owns the application. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- active Boolean
- Whether the policy is active. Default:
true. - ai
Application StringSecurity Policy Id - UUID of the policy.
- application
Id String - UUID of the AI Application Security application this policy belongs to. Cannot be changed after the resource is created.
- description String
- Description of the policy. Up to 500 characters.
- guardrails List<Property Map>
- One or more guardrail blocks (at least one). Each block supports:
- name String
- Name of the policy. 1-100 characters.
Supporting Types
AiApplicationSecurityPolicyGuardrail, AiApplicationSecurityPolicyGuardrailArgs
- Mode string
- Enforcement mode. One of
BLOCK,ALERT,MASK. - Phase string
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - Type string
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - Active bool
- Whether this guardrail is active. Default:
true. - Config string
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- Mode string
- Enforcement mode. One of
BLOCK,ALERT,MASK. - Phase string
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - Type string
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - Active bool
- Whether this guardrail is active. Default:
true. - Config string
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- mode string
- Enforcement mode. One of
BLOCK,ALERT,MASK. - phase string
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - type string
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - active bool
- Whether this guardrail is active. Default:
true. - config string
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- mode String
- Enforcement mode. One of
BLOCK,ALERT,MASK. - phase String
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - type String
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - active Boolean
- Whether this guardrail is active. Default:
true. - config String
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- mode string
- Enforcement mode. One of
BLOCK,ALERT,MASK. - phase string
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - type string
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - active boolean
- Whether this guardrail is active. Default:
true. - config string
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- mode str
- Enforcement mode. One of
BLOCK,ALERT,MASK. - phase str
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - type str
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - active bool
- Whether this guardrail is active. Default:
true. - config str
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
- mode String
- Enforcement mode. One of
BLOCK,ALERT,MASK. - phase String
- Phase the guardrail runs in. One of
PROMPT,RESPONSE. The valid phases depend ontype(see below). - type String
- Guardrail type. One of
PROMPT_INJECTION,PII_STATIC,MODERATION,ZERO_SHOT_CLASSIFICATION,RATE_LIMIT,SYSTEM_PROMPT_LEAK. - active Boolean
- Whether this guardrail is active. Default:
true. - config String
- Guardrail-specific configuration as a JSON-encoded object. Default:
"{}". Usejsonencode({...}). See Guardrail config reference for the fields each type accepts. Do not set atypekey insideconfig- the provider injects the guardrail'stypeautomatically.
Import
AI Application Security policy can be imported using its policy_id, optionally prefixed with the account_id:
$ pulumi import incapsula:index/aiApplicationSecurityPolicy:AiApplicationSecurityPolicy example 3f2504e0-4f89-41d3-9a0c-0305e82c3301
$ pulumi import incapsula:index/aiApplicationSecurityPolicy:AiApplicationSecurityPolicy example 1234567/3f2504e0-4f89-41d3-9a0c-0305e82c3301
When the account_id is omitted from the import ID it is taken from the account of the API credentials.
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- incapsula imperva/terraform-provider-incapsula
- License
- Notes
- This Pulumi package is based on the
incapsulaTerraform Provider.
published on Tuesday, Sep 15, 2026 by imperva