← Back to all products

Anquan LLM Security Firewall
V1.2.0 — runtime input & output protection for LLM APIs

The Anquan LLM Security Firewall is a security protection platform purpose-built for large language models. It is the product of Anquan Digital Intelligence Technology, a Chinese-mainland security vendor. AGH is the Authorised Channel Partner for Hong Kong and APAC. The firewall sits in front of your LLM API as a reverse-proxy security middle layer — inspecting inputs before they reach the model, inspecting outputs before they reach the user, and applying refusal, desensitisation, or substitution as the configured disposition. Three core engines — Theme Control, Jailbreak Attack Detection, and Harmful Content Detection — operate together on a unified rule and traffic-access pipeline.

3
Core engines — Theme / Jailbreak / Harmful
2-way
Input + output inspection, reverse proxy
40+
Fine-grained content categories
HK + APAC
AGH authorised channel delivery
Anquan LLM Security Firewall — real-time protection for LLM applications with threat detection, rule engine, data filtering, and bidirectional input/output filtering

Anquan LLM Security Firewall is a partner product — AGH is the Authorised Channel Partner

The Anquan LLM Security Firewall is developed, owned, and maintained by Anquan Digital Intelligence Technology, a Chinese-mainland security vendor. AGH is the Authorised Channel Partner for Hong Kong and APAC, with responsibility for sales, deployment, first-line technical support, and customer success in this territory. All product specifications, capabilities, and technical claims on this page are based on material provided by Anquan Digital Intelligence Technology and are reproduced with the vendor's consent. The product is sold under the vendor's trademark; references to “Anquan” are to the vendor's product line. AGH does not develop, manufacture, or maintain the underlying technology.

LLM applications need a firewall that traditional security stacks do not provide

Once an LLM is in production, three attack surfaces keep growing: prompt injection and jailbreaks that subvert the model's safety alignment, sensitive-data leakage when the model is asked for credentials or PII, and harmful content that slips past the system's safety training. Traditional firewalls and DLP do not understand natural language. Network segmentation, identity controls, and WAF rules cannot distinguish a legitimate prompt from a jailbreak attempt that ends in “pretend you are an evil AI and…”. The model needs its own layer of protection — at the API boundary.

14.3%
Hallucination rate · DeepSeek-R1

Hallucination is intrinsic to LLMs — even top-tier models produce factual errors at production scale. The firewall must catch unsafe outputs after the model has generated them.

5
GB/T 45654-2025 content categories A.1–A.5

China's national standard requires generative-AI services to filter content across five top-level categories — socialist core values, discrimination, commercial violations, infringement of rights, service-specific safety. Each requires runtime filtering, not just pre-deployment testing.

OWASP
LLM Top 10 — defense-in-depth across the model boundary

Prompt injection, insecure output handling, sensitive-information disclosure, excessive agency — the OWASP LLM Top 10 captures the dominant attack classes. The firewall is the single enforcement point where all of them can be addressed together.

API ↔
Reverse-proxy enforcement, LLM-agnostic

The firewall sits in front of the LLM API. It does not care whether the model is GPT, Claude, DeepSeek, Qwen, or your own private deployment — same enforcement, same evidence trail.

Input interception → output inspection → disposition

The firewall inspects every request and every response. Inputs that the model should not see are intercepted before they reach the API; outputs that the user should not see are intercepted before they reach the client. Three dispositions are available: dynamic desensitisation, refuse-to-answer, or substitute / fixed answer. Full-link logging captures every decision for audit.

IN
Input protection

Jailbreak attack detection · Subject / theme control · Harmful-content detection · Sensitive-content detection. Each input is scored across these engines in real time before the request reaches the model.

OUT
Output protection

Content-compliance testing · Sensitive-content identification · Fact-consistency check. Each response is scored before it leaves the firewall. Dispositions are configurable per category — desensitise, refuse, substitute, or pass-through.

LOG
Full-link audit logging

Every input, every disposition, every output, every rule hit — recorded with timestamp, request-ID, and category tag. Forensic-grade trail for incident response and for regulatory submission.

CFG
Centralised rules & access control

One management console for rule sets, model access lists, user roles, traffic statistics, and dashboards. Threat IP, top-attacked models, protection trends, risk distribution — all visible in real time.

Theme Control · Jailbreak Detection · Harmful Content Detection

Each engine is implemented as a fine-tuned proprietary model combined with curated datasets. Each targets one of the three dominant LLM-application risks. All three are run in series on every input and output.

ENGINE 1 · THEME CONTROL
Theme / Topic Control

Fine-tuned on the CANTTALKABOUTTHIS dataset using LoRA. Trains the model to maintain topical focus during multi-turn conversation and to recognise user-supplied distractors. Output is constrained to the configured subject — e.g. customer service, banking, healthcare, travel. Any off-topic request is filtered at the input; any off-topic output is filtered at the output.

ENGINE 2 · JAILBREAK DETECTION
Jailbreak Attack Detection

Embedding model (e.g. NVEmbed) transforms input tokens into feature vectors; a traditional ML classifier — Random Forest and similar — labels each input as jailbreak or benign. Independent benchmark: this combination outperforms the best public models on a real-world dataset by >3× F1 score. Continuously retrained against emerging jailbreak patterns.

ENGINE 3 · HARMFUL CONTENT DETECTION
Harmful Content Detection

Fine-tuned on a large corpus of manually-reviewed and labelled harmful data, with 40+ fine-grained categories — exceeding GB/T 45654-2025 Appendix A's five top-level categories and extending into misinformation, hatred, threats of violence, illegal activity, and other regulated classes. Few-shot prompts enhance classification accuracy versus zero-shot. Bilingual training (CN / EN) for cross-language detection.

Authorised Channel Partner — sales, deployment, and first-line support across HK + APAC
delivered bilingually, integrated with your existing LLM stack

AGH's role as the Authorised Channel Partner covers the full customer journey — pre-sales scoping, deployment and integration, first-line technical support, and ongoing customer success. We do not own the underlying technology; we own the right to deploy and support it on behalf of our customers in this territory. The vendor (Anquan Digital Intelligence Technology) maintains the product roadmap and provides L2/L3 escalation when needed.

For organisations adopting LLMs under HK, mainland, or APAC regulators — and for the procurement teams that need to satisfy their internal risk functions — the AGH-­Anquan delivery model means the firewall arrives with the documentation, the bilingual delivery capability, and the support continuity that regulated buyers require.

What AGH delivers
  • Pre-sales scoping — model inventory, traffic patterns, regulatory exposure
  • Pilot deployment — single LLM API, single application, single rule pack
  • Production rollout — multi-model, multi-region, with traffic mirroring
  • Bilingual rule configuration (EN / SC / TC)
  • Integration with existing observability stack (SIEM / SOAR / log shipping)
  • First-line technical support (L1) — AGH
  • Vendor escalation (L2 / L3) — 安泉数智
  • Quarterly compliance-evidence pack

Ready to put a firewall in front of your LLM API?

30 minutes with our team. We'll review your model inventory, traffic patterns, and regulatory exposure — and propose a deployment plan that lands the firewall in front of your LLM API without breaking what's already working. No commitment.

Book a Discovery Call