Rag.NET.Security
0.1.0
dotnet add package Rag.NET.Security --version 0.1.0
NuGet\Install-Package Rag.NET.Security -Version 0.1.0
<PackageReference Include="Rag.NET.Security" Version="0.1.0" />
<PackageVersion Include="Rag.NET.Security" Version="0.1.0" />
<PackageReference Include="Rag.NET.Security" />
paket add Rag.NET.Security --version 0.1.0
#r "nuget: Rag.NET.Security, 0.1.0"
#:package Rag.NET.Security@0.1.0
#addin nuget:?package=Rag.NET.Security&version=0.1.0
#tool nuget:?package=Rag.NET.Security&version=0.1.0
Rag.NET.Security
Prompt-injection defence in depth for Rag.NET: chunk and query sanitisers, retrieval guards, trust-level enforcement, prompt hardening, role-based chunk access (RBAC) and PII redaction — each an explicit opt-in layer around the pipeline.
Install
dotnet add package Rag.NET.Security
Setup
using Rag.NET.DependencyInjection;
using Rag.NET.Security;
services.AddRagNet(rag => rag
.UseChunkSanitiser() // strip injection patterns from ingested text
.UseQuerySanitiser() // and from incoming questions
.UsePromptHardening()); // delimit untrusted context in the prompt
Example
PII redaction runs at ingestion, with the regex pattern set open for editing:
using Rag.NET.DependencyInjection;
using Rag.NET.Security;
services.AddRagNet(rag => rag
.UsePiiDetection(o =>
{
o.Patterns.Remove(PiiPatterns.Ssn); // drop a built-in pattern
o.Patterns.Add(new PiiPattern // add your own — Dutch BSN
{
Placeholder = "[BSN]",
RegexPattern = @"\b\d{9}\b",
});
}));
RBAC filters retrieved chunks by the caller's roles against each document's
allowed_roles tag: rag.UseRbac() plus an ICallerContext implementation — or the
ready-made ClaimsPrincipal binding in Rag.NET.Security.AspNetCore.
Full guide
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- Microsoft.Data.Sqlite (>= 10.0.10)
- Microsoft.Extensions.AI.Abstractions (>= 10.8.3)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.10)
- Rag.NET (>= 0.1.0)
- Rag.NET.Abstractions (>= 0.1.0)
- SQLitePCLRaw.bundle_e_sqlite3 (>= 3.0.5)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Rag.NET.Security:
| Package | Downloads |
|---|---|
|
Rag.NET.Security.AspNetCore
ASP.NET Core integration for Rag.NET.Security — binds ICallerContext to ClaimsPrincipal. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0 | 91 | 8/11/2026 |