Canonical Engineering Manual #07|TinyCTO RAG Bible
Guardrails, Safety & Regulatory Governance
Indirect prompt injection defense, multi-tenant isolation, logit masking, and tamper-evident audit logs.
Canon Certified 15 min
#1. Threat Landscape in Retrieval Architectures
Retrieval-augmented pipelines introduce novel attack vectors that bypass traditional perimeter firewalls:
- Indirect Prompt Injection: Adversarial instructions embedded in third-party web pages or ingested PDFs that hijack the LLM when retrieved into context.
- Sensitive Data Leakage (PII / PHI): Unsanitized ingestion of private customer records or payment card numbers into shared vector spaces.
- Hallucination of Legal / Medical Facts: Emitting incorrect, plausible-sounding citations in regulated environments.
#2. Multi-Stage Protective Architecture
- Ingestion Barrier: Pre-indexing PII redaction and malware scanning.
- Retrieval Barrier: Multi-tenant cryptographic partition isolation.
- Context Barrier: Dual-turn delimiter encapsulation (XML tags) preventing tag breakout.
- Generation Barrier: GBNF grammar-guided logit masking to enforce strict JSON schemas and citation verification.
- Audit Logging: Appending SHA-256 tamper-evident hashes to immutable audit trails for ISO 42001 and EU AI Act compliance.
