Rag.NET.Security 0.1.0

dotnet add package Rag.NET.Security --version 0.1.0
                    
NuGet\Install-Package Rag.NET.Security -Version 0.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Rag.NET.Security" Version="0.1.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Rag.NET.Security" Version="0.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Rag.NET.Security" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Rag.NET.Security --version 0.1.0
                    
#r "nuget: Rag.NET.Security, 0.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Rag.NET.Security@0.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Rag.NET.Security&version=0.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Rag.NET.Security&version=0.1.0
                    
Install as a Cake Tool

Rag.NET.Security

Prompt-injection defence in depth for Rag.NET: chunk and query sanitisers, retrieval guards, trust-level enforcement, prompt hardening, role-based chunk access (RBAC) and PII redaction — each an explicit opt-in layer around the pipeline.

Install

dotnet add package Rag.NET.Security

Setup

using Rag.NET.DependencyInjection;
using Rag.NET.Security;

services.AddRagNet(rag => rag
    .UseChunkSanitiser()     // strip injection patterns from ingested text
    .UseQuerySanitiser()     // and from incoming questions
    .UsePromptHardening());  // delimit untrusted context in the prompt

Example

PII redaction runs at ingestion, with the regex pattern set open for editing:

using Rag.NET.DependencyInjection;
using Rag.NET.Security;

services.AddRagNet(rag => rag
    .UsePiiDetection(o =>
    {
        o.Patterns.Remove(PiiPatterns.Ssn);   // drop a built-in pattern

        o.Patterns.Add(new PiiPattern          // add your own — Dutch BSN
        {
            Placeholder  = "[BSN]",
            RegexPattern = @"\b\d{9}\b",
        });
    }));

RBAC filters retrieved chunks by the caller's roles against each document's allowed_roles tag: rag.UseRbac() plus an ICallerContext implementation — or the ready-made ClaimsPrincipal binding in Rag.NET.Security.AspNetCore.

Full guide

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (1)

Showing the top 1 NuGet packages that depend on Rag.NET.Security:

Package Downloads
Rag.NET.Security.AspNetCore

ASP.NET Core integration for Rag.NET.Security — binds ICallerContext to ClaimsPrincipal.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.1.0 91 8/11/2026