Integrations
Date: October 4, 2026
WonderFence plugs into the frameworks, runtimes and gateways your AI applications already use. Every integration on this page sends content to the same WonderFence evaluate API and enforces the same enforcement policies you configure in the platform, so a policy change applies everywhere at once.
Agent frameworks
Strands hooks fire before and after each model call and each tool call. Register one hook provider and Alice evaluates the model input, the tool arguments, the tool result and the model output. Block cancels the call with a reason the model can see; mask rewrites the content in place.
A LangChain AgentMiddleware subclass. wrapmodelcall evaluates the latest human message before the model and the AI message after it; wraptoolcall evaluates tool arguments before execution and tool output after. Block raises, mask rewrites the message content.
A small safety monitor you call from your own graph nodes: check the prompt before the model node runs, the response after it, and tool input and output around tool execution. Fits any StateGraph without changing its shape.
The parlant-alice package registers Alice as the moderation service in a Parlant server. Customer messages are evaluated before the agent sees them, agent replies before the customer does. Blocked customer messages arrive as "censored" so a guideline can respond politely.
Agent runtimes
A Lambda subscribed to the AgentCore runtime log group. With message content capture on, ADOT writes every GenAI message as its own log record; a subscription filter forwards them, the Lambda rebuilds one evaluation unit per model call and sends the user prompt, tool arguments, tool results and model output to Alice. Verdicts land in CloudWatch and, optionally, as spans inside the agent trace. Nothing in the agent changes and nothing is blocked.
Turn on Bedrock model invocation logging, point it at S3 or CloudWatch, and let a Lambda forward each logged prompt and response to Alice. Findings, case management and user-level workflows such as a three-strikes rule then run in the Alice platform, next to any Amazon Bedrock Guardrails verdicts you already have. No change to the application; evaluation happens after the fact.
Alice connects to Microsoft Copilot Studio as an Environment Security Provider (ESP), Microsoft's external threat-detection interface. Enabled once per Power Platform environment, it covers every agent in it: Copilot Studio calls Alice as an agent is about to run a tool, Alice evaluates the tool call, and a blocked tool call is suppressed live. Only tool calls are evaluated; Copilot Studio does not expose user prompts or agent responses to external security providers.
Dynamics 365 Contact Center agents run on the same framework as custom Copilot Studio agents, so they connect the same way: Alice is registered as an Environment Security Provider (ESP) for the Power Platform environment, Dynamics 365 calls Alice as an agent is about to run a tool, Alice evaluates the tool call, and a blocked tool call is suppressed live. Only tool calls are evaluated; the security provider interface does not expose user prompts or agent responses.
AI gateways
LiteLLM Proxy ships an Alice guardrail. It forwards each prompt before the model call and each completion after it; Alice returns ALLOW, BLOCK, MASK or DETECT and the proxy enforces it. Which policies apply is decided per virtual key, so one proxy serves many applications.
A Portkey guardrail plugin. Add your Alice API key once under Integrations, create an Evaluate check with your application id, and attach it as an input or output guardrail in any Portkey config. Portkey enforces the verdict: block, mask the flagged spans, or record and pass.
Register Alice once as a Unity Catalog HTTP Connection, then attach it as an External policy to a governed model. The gateway calls Alice before the model (modelcall) and after it (modelresult), receives ALLOW or DENY, and enforces inline. Start in Log mode, flip to Enforce when the verdicts match your intent.
Alice runs on a Kong AI Gateway through Kong's built-in ai-custom-guardrail plugin, a declarative HTTP callout: Kong sends the text it selected to Alice and enforces the verdict that comes back. Nothing custom runs in the gateway, so the whole integration is one decK config block. With request_body sent, Alice reads the conversation itself and screens the newest turn together with its tool calls and tool results.
Omnigent governs agents built on Claude Code, Codex, Pi or custom harnesses through a policy layer. This policy adapts the Alice client into that contract: every request, response, tool call and tool result is evaluated at runtime and the verdict is enforced by the runner. Omnigent secures what the agent does; Alice secures what it is told and what it says.
AgentCore Gateway runs a Lambda interceptor around every MCP call it proxies to a tool server: once on the request (tool arguments) and once on the response (tool result). The interceptor below is the scaffold that receives both hooks, holds the Alice client, and returns the transformed body the gateway forwards. Prompts and model responses never pass through the gateway, so they are out of scope here.
Conversational AI platforms
Planned on the Alice TypeScript SDK, because Cognigy runs custom code in Node.js sandboxes. An Endpoint Transformer will guard every message in and out of an endpoint with handleInput and handleOutput. A custom Extension node will drop into a single flow and let the builder branch on the verdict. Both evaluate synchronously and support block and mask in each direction.
A plugin for IBM Mellea pipelines, no pipeline rewrite. It hooks GENERATIONPRECALL, GENERATIONPOSTCALL, TOOLPREINVOKE and TOOLPOSTINVOKE and sends each surface to Alice. The tool_output hook is the one that catches indirect prompt injection: text returned by tools, files and URLs is evaluated before it re-enters the model. Audit mode records every verdict; enforce mode halts the pipeline on BLOCK and rewrites writable fields on MASK.
SDKs, API and evaluation
The wonderfence-sdk package wraps the Alice evaluate API. Every call returns an action (BLOCK, MASK, DETECT or NO_ACTION), the masked or block text, and the detections that fired, so your code decides what to do next.
Every SDK and gateway integration on this page ends up at the same evaluate endpoint. If your stack is not covered, call it directly from any language with an API key and an application id.
An MLflow scorer that sends each row of an evaluation dataset to Alice and records the verdict as feedback. Compare models or prompt versions on safety the same way you compare them on quality.
A TypeScript client for the Alice evaluate API. One client instance serves many applications because appId is passed per request. Built for Node.js sandboxes such as Cognigy extensions and serverless functions.