보안 엔지 니어를 위한 설정
적용 지점: SDK 및 Gateway (조직 전체) 지원 모드: Hosted Hybrid Local 플랜: Free Solo Teams
대상 독자
건물 밖으로 나가는 것에 책임을 지는 분입니다.
영어 원문 -- 번역은 기술 검토 대기 중입니다
AI tools are a new egress path, and you need deterministic prevention on enforcing surfaces, explicit coverage on every event, and a complete audit trail.
일반적으로 통제하려는 대상
영어 원문 -- 번역은 기술 검토 대기 중입니다
- Secret and PII egress. API keys, tokens, SSNs, and card numbers must never leave in a tool call or prompt.
- SDK, 게이트웨이, 코딩 어시스턴트 전반에서 공유하는 정책으로, 적용 여부는 호스트에서 추론하지 않고 이벤트별로 선언합니다.
영어 원문 -- 번역은 기술 검토 대기 중입니다
- Evidence. A durable, queryable trail of every decision that distinguishes “did not run” from “ran and found nothing.”
설치할 적용 지점
직접 제어하는 앱에는 SDK를, 그렇지 않은 앱 앞에는 Gateway를 사용해 하나의 정책을 작성하세요. 둘 다 도구 인수를 기본 제공 DLP 패턴(AWS 키, GitHub 토큰, SSN, 카드 번호 등)과 자동으로 대조하여 검사합니다. 차단(block)은 호출을 거부합니다. Claude Code와 Gemini CLI의 Python SDK 훅은 대신 일치한 부분을 그 자리에서 마스킹하고 호출을 계속 진행할 수 있습니다. 재작성된 도구 입력을 받을 수 없는 코딩 에이전트 적용 지점(Cursor, Kiro, Codex CLI, Antigravity)에서는 마스킹 규칙이 대신 거부(deny)가 됩니다. Gateway는 요청 경로와 응답 경로 모두에서 마스킹을 할 수 있지만, 기본적으로는 둘 다 하지 않고 탐지만 합니다. 설정 방법은 Gateway를 참고하세요.
pip install controlzero
시작용 정책
일반적인 LLM 및 도구 사용은 허용하되, DLP 규칙으로 시크릿/PII 유출은 차단합니다.
DLP block은 허용이 될 뻔한 결정보다 우선하므로, 그 외에는 허용적인 정책에서도 유출을 막습니다.
version: '1'
settings:
default_action: allow
default_on_missing: deny
default_on_tamper: quarantine
rules:
- id: allow-llm
allow: 'llm:generate'
reason: 'LLM use is permitted; DLP below stops leaks regardless.'
dlp_rules:
- id: block-internal-codes
pattern: 'PROJ-[A-Z]{3}-\d{6}'
category: custom
action: block
reason: 'Internal project codes must not leave the agent.'
영어 원문 -- 번역은 기술 검토 대기 중입니다
Built-in DLP patterns are always active; the rule above adds a custom one.
대시보드에서 더 폭넓은 DLP 규칙 세트를 구성하려면 DLP 규칙 설정을 참고하세요.
확인할 수 있는 내용
- DLP 차단은
decision: deny와DLP_BLOCKED사유 코드와 함께 감사 로그에 기록되어, 어떤 패턴이 어떤 호출에서 작동했는지 정확히 알려 줍니다. - 각 행은 해당 이벤트의 적용 범위를 선언합니다. 기능 매트릭스는 SDK 자체의 기능 선언에서 도출됩니다. 설치 환경에 대한 매트릭스를 내보내려면
controlzero coverage --json을 실행하세요(옵션 없는controlzero coverage는 호스트별 요약만 짧게 출력합니다).
영어 원문 -- 번역은 기술 검토 대기 중입니다
- Each plan defines an audit log retention window -- 7 days on Free, 90 days on Solo, and 365 days on Teams -- which is plan policy and is not applied yet (see the note below: retention is an organization setting that defaults to 30 days today). Query, filter, and export the logs for reviews.
- 관찰 전용으로 조직 전체에 먼저 배포하여, 차단을 시작하기 전에 실제 유출 시도를 측정하세요.
영어 원문 -- 번역은 기술 검토 대기 중입니다
Automatic deletion of audit records at the end of the window is not currently running on the production audit store, so audit records are kept longer than the window. Deletion will be switched on only after dated notice to affected organizations. When tiered audit retention takes effect, Free organizations created before then keep their existing 30-day window unless an owner changes it, and an owner can set a shorter window.
다음 단계
- 시크릿 및 PII 유출 차단 -- 표준 유출 방지 레시피.
- DLP 규칙 설정 -- 탐지 패턴을 만들고 조정하세요.
- DLP 적용 범위 -- 기본 제공 패턴 세트와 사용자 정의 정규식.
- 컴플라이언스 보고서 -- 감사 추적을 보고서로 만드세요.