Amazon Bedrock guardrails with no sensitive information filter for PII
What does ZopNight detect here?
ZopNight flags Amazon Bedrock guardrails whose `sensitiveInformationPolicy` provides no PII protection. Model calls protected only by such a guardrail can pass names, email addresses or account numbers straight through. ZopNight reads the guardrail's DRAFT version, raises this as a high-severity security finding and shows no dollar saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1615 |
| Category | security |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | PII protection not configured in the sensitive information policy |
| Source | ZopNight |
| Permissions used | bedrock:ListGuardrails · bedrock:GetGuardrail |
Where it applies
What a sensitive information filter does
Bedrock Guardrails can detect personally identifiable information in prompts and responses using
sensitive information filters.
You choose from built-in PII types, such as names, addresses and ages, and can add your own regex
patterns. For each one you pick a mode: Block, which rejects the whole request or response and returns
your configured message, or Mask, which replaces the detected value with its type, for example
{NAME}. A guardrail without this filter can still block topics or harmful content, but it lets
personal data through untouched.
Inspecting a guardrail’s PII settings
aws bedrock list-guardrails --query 'guardrails[].[id,name,version,status]' --output table
aws bedrock get-guardrail --guardrail-identifier gr-abc123 \ --query 'sensitiveInformationPolicy'An empty or missing sensitiveInformationPolicy means there are no PII entities and no regexes.
GetGuardrail returns
the DRAFT version when you do not pass --guardrail-version; add it to check a published version.
What triggers the finding
ZopNight reads each guardrail’s configuration and records whether PII protection is enabled. The finding fires only when that record says it is disabled. It is a configuration check with no metric or window.
Gaps in what ZopNight can see
If the configuration read did not happen, ZopNight raises nothing. The read uses the DRAFT version, which is the working copy and normally at least as protective as anything published. When applications are pinned to an older published version, what is live can differ from the DRAFT, so the finding describes the working copy. Check which version your applications actually call.
Risk rather than savings
There is no dollar saving here. The exposure is personal data in prompts, retrieved documents or model output reaching logs, users or other systems without redaction, which can breach privacy obligations.
Adding PII protection
- Open the guardrail in the Bedrock console and add a sensitive information filter with the PII types your workload handles, plus regexes for internal identifiers.
- Choose Block for data that must never appear, or Mask where the rest of the text is still useful.
- Publish a new version, since applications should call a numbered version rather than DRAFT:
aws bedrock create-guardrail-version --guardrail-identifier gr-abc123 - Point agents and applications at the new version number.