본문으로 건너뛰기
이 페이지는 기계 번역이며 충분한 검토를 거치지 않았습니다. 영어 원문이 기준입니다. 보안, 개인정보 보호, 데이터 처리, 규정 준수 및 라이선스에 관한 설명은 기술 검토가 끝날 때까지 영어로 유지됩니다. 영어 원문 보기

보안 엔지니어를 위한 설정

적용 지점: SDK 및 Gateway (조직 전체) 지원 모드: Hosted Hybrid Local 플랜: Free Solo Teams

대상 독자​

건물 밖으로 나가는 것에 책임을 지는 분입니다.

영어 원문 -- 번역은 기술 검토 대기 중입니다

AI tools are a new egress path, and you need deterministic prevention on enforcing surfaces, explicit coverage on every event, and a complete audit trail.

일반적으로 통제하려는 대상​

영어 원문 -- 번역은 기술 검토 대기 중입니다

  • Secret and PII egress. API keys, tokens, SSNs, and card numbers must never leave in a tool call or prompt.
  • SDK, 게이트웨이, 코딩 어시스턴트 전반에서 공유하는 정책으로, 적용 여부는 호스트에서 추론하지 않고 이벤트별로 선언합니다.

영어 원문 -- 번역은 기술 검토 대기 중입니다

  • Evidence. A durable, queryable trail of every decision that distinguishes “did not run” from “ran and found nothing.”

설치할 적용 지점​

직접 제어하는 앱에는 SDK를, 그렇지 않은 앱 앞에는 Gateway를 사용해 하나의 정책을 작성하세요. 둘 다 도구 인수를 기본 제공 DLP 패턴(AWS 키, GitHub 토큰, SSN, 카드 번호 등)과 자동으로 대조하여 검사합니다. 차단(block)은 호출을 거부합니다. Claude Code와 Gemini CLI의 Python SDK 훅은 대신 일치한 부분을 그 자리에서 마스킹하고 호출을 계속 진행할 수 있습니다. 재작성된 도구 입력을 받을 수 없는 코딩 에이전트 적용 지점(Cursor, Kiro, Codex CLI, Antigravity)에서는 마스킹 규칙이 대신 거부(deny)가 됩니다. Gateway는 요청 경로와 응답 경로 모두에서 마스킹을 할 수 있지만, 기본적으로는 둘 다 하지 않고 탐지만 합니다. 설정 방법은 Gateway를 참고하세요.

pip install controlzero

시작용 정책​

일반적인 LLM 및 도구 사용은 허용하되, DLP 규칙으로 시크릿/PII 유출은 차단합니다. DLP block은 허용이 될 뻔한 결정보다 우선하므로, 그 외에는 허용적인 정책에서도 유출을 막습니다.

version: '1'
settings:
default_action: allow
default_on_missing: deny
default_on_tamper: quarantine
rules:
- id: allow-llm
allow: 'llm:generate'
reason: 'LLM use is permitted; DLP below stops leaks regardless.'
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'

영어 원문 -- 번역은 기술 검토 대기 중입니다

Built-in DLP patterns are always active; the rule above adds a custom one.

대시보드에서 더 폭넓은 DLP 규칙 세트를 구성하려면 DLP 규칙 설정을 참고하세요.

확인할 수 있는 내용​

  • DLP 차단은 decision: deny와 DLP_BLOCKED 사유 코드와 함께 감사 로그에 기록되어, 어떤 패턴이 어떤 호출에서 작동했는지 정확히 알려 줍니다.
  • 각 행은 해당 이벤트의 적용 범위를 선언합니다. 기능 매트릭스는 SDK 자체의 기능 선언에서 도출됩니다. 설치 환경에 대한 매트릭스를 내보내려면 controlzero coverage --json을 실행하세요(옵션 없는 controlzero coverage는 호스트별 요약만 짧게 출력합니다).

영어 원문 -- 번역은 기술 검토 대기 중입니다

  • Each plan defines an audit log retention window -- 7 days on Free, 90 days on Solo, and 365 days on Teams -- which is plan policy and is not applied yet (see the note below: retention is an organization setting that defaults to 30 days today). Query, filter, and export the logs for reviews.
  • 관찰 전용으로 조직 전체에 먼저 배포하여, 차단을 시작하기 전에 실제 유출 시도를 측정하세요.

영어 원문 -- 번역은 기술 검토 대기 중입니다

Audit retention is the configured window, not yet enforced deletion

Automatic deletion of audit records at the end of the window is not currently running on the production audit store, so audit records are kept longer than the window. Deletion will be switched on only after dated notice to affected organizations. When tiered audit retention takes effect, Free organizations created before then keep their existing 30-day window unless an owner changes it, and an owner can set a shorter window.

다음 단계​