Skip to main content

TSZ (Thyris Safe Zone)

TSZ (Thyris Safe Zone) is a PII Detection and Guardrails System engineered by Thyris.AI. It acts as a zero‑trust layer between your data and external systems, ensuring that sensitive information, Personal Identifiable Information (PII), secrets, and proprietary data, never leaves your secure perimeter unintentionally.

TSZ provides real‑time scanning, redaction, and blocking capabilities so that you can safely integrate LLMs and third‑party APIs into your existing applications.

Features​

  • Real‑time detection of PII, secrets and sensitive patterns
  • Redaction with context‑preserving placeholders (for example, [EMAIL], [CREDIT_CARD])
  • Configurable guardrails using patterns, validators and templates
  • Allowlist and blocklist management
  • Hot reloading of rules via APIs
  • High‑performance implementation in Go with Redis caching
  • Native managed model service integration – Use managed model family, managed model family, open model family, model provider, and model provider models directly
  • Multi-provider AI support – chat-completions-compatible endpoints (chat-completions provider, managed chat provider, local model runtime) and managed model service
  • chat-completions-compatible LLM gateway – Drop-in replacement for chat-completions provider API with built-in guardrails
  • Bring Your Gateway (BYG) – Protect existing Envoy Gateway routes through ext_proc with portable or native policies
  • CLI Tool – Full management and scanning from the command line (pkg/tsz-cli)

Getting Started​

For all user and customer‑facing documentation, see the docs/ directory:

  • What is TSZ? – Conceptual and product overview
    docs/WHAT_IS_TSZ.md
  • Product Overview (executive friendly) –
    docs/PRODUCT_OVERVIEW.md
  • Quick Start Guide – Run TSZ locally and call /detect
    docs/QUICK_START.md
  • Deployment Guide – Deploy TSZ to Kubernetes with Helm
    docs/DEPLOYMENT.md
  • API Reference (Enterprise) – Full REST API documentation
    docs/API_REFERENCE.md
  • Architecture & Security Overview – Architecture, data flows, security controls
    docs/ARCHITECTURE_SECURITY.md
  • Bring Your Gateway – Envoy Gateway integration, compatibility, streaming, and operations BYG documentation
  • Changelog – Product release history Safe Zone changelog
  • Postman Collection – Ready‑to‑use collection
    docs/TSZ_Postman_Collection.json

If you are evaluating TSZ for the first time, we recommend the following order:

  1. docs/WHAT_IS_TSZ.md
  2. docs/PRODUCT_OVERVIEW.md
  3. docs/QUICK_START.md
  4. Choose direct API integration or Bring Your Gateway.
  5. docs/DEPLOYMENT.md
  6. docs/API_REFERENCE.md

For a more detailed map of the documentation set, see docs/README.md.

Client Libraries (SDKs)​

TSZ provides official client libraries for common stacks:

  • Go client (tszclient-go) – for Go services that want a typed wrapper around /detect and the LLM gateway.
    See: pkg/tszclient-go/README.md.

  • CLI (tsz) – Command-line interface for scanning and administration.
    See: pkg/tsz-cli/README.md.

  • Python client (tszclient_py / package tszclient-py) – for Python services that prefer a small requests-based helper instead of calling HTTP manually. Install from source repository:

    pip install "tszclient-py @ git+https://source.example/thyris/repository@main"

    If TSZ auth is enabled, pass api_key in TSZConfig (or set TSZ_AUTH_TOKEN in the demo).

    A runnable example lives under examples/python-sdk-demo.

    See the Python Client Guide for detection, gateway, and error-handling examples.

Configuration Guides​

Dashboard (Web UI)​

A lightweight, read-only web dashboard is available under web/, giving a visual view of PII detection patterns, guardrails, recent request activity, and safe (non-sensitive) configuration values - without needing to call the API directly.

Status: initial version, currently runnable in development mode only. See docs/DASHBOARD_PRODUCTION_NOTES.md for open questions around production deployment (containerization strategy, default enabled/disabled state) pending maintainer input.

Running Locally​

  1. Start the TSZ backend (see Quick Start above), so it is reachable at http://localhost:8080.
  2. In a separate terminal:
cd web
npm install
npm run dev
  1. Open http://localhost:5173 in a browser.

Requests from the dashboard are proxied to the backend during development (see web/vite.config.ts); no backend URL is hardcoded in the frontend code.

What It Shows​

  • Overview – system status (health/readiness) and request counters since the last backend restart
  • Patterns – currently configured PII detection patterns
  • Guardrails – currently active AI-based validation rules
  • Events – a log of recent requests (allowed/blocked, and why), since the last backend restart
  • Configuration – a read-only, allowlisted view of safe configuration values (secrets, tokens, and credentials are never exposed)

Note on data persistence: request counters and recent events are kept in memory only and reset whenever the backend restarts. This is a deliberate initial-version trade-off - see internal/metrics/store.go for details.

Testing​

cd web
npm run test

Testing​

TSZ includes a comprehensive test suite with 55+ tests covering unit, integration, and end-to-end scenarios:

# Run all tests
go test ./tests/... -v

# Run specific test suites
go test ./tests/unit/... # Unit tests (no dependencies)
go test ./tests/integration/... # Integration tests (requires TSZ + DB + Redis)
go test ./tests/e2e/... # End-to-end tests (full system)

Test Coverage:

  • Unit Tests (40+): Core business logic, AI providers, configuration, caching
  • Integration Tests (15+): API endpoints, error handling, concurrent requests
  • E2E Tests (5): Full system workflows, streaming, health checks

For detailed information about the test suite, see tests/README.md.

Contributing​

We welcome community contributions.

  • Please read our Contributing Guide for details on how to set up a development environment, run tests and propose changes.
  • By participating in this project, you agree to follow our Code of Conduct.
  • For reporting security issues, do not open a public source repository issue. Instead, follow the process described in our Security Policy.

License​

This project is licensed under the Apache License 2.0. Unless otherwise noted, all contributions to this repository are licensed under the same terms.