: Web servers dominate our view of the Web today. Security provided by them has been implemented with varying degrees of success. Web servers are frequently successfully attacked, with subsequent loss of corporate loss of face or revenue. Recent legislation has increased the importance of ensuring that only approved users gain access to information, which often implies filtering content served by applications. While content filtering can be implemented at the application level, this paper describes an innovative architecture for policy-based filtering that can be integrated with existing web applications.