Skip to main content

Bring Your Gateway

Bring Your Gateway (BYG) lets Safe Zone protect LLM traffic at an existing API gateway. Applications keep calling their normal gateway route; Envoy sends the request and response through Safe Zone by using the External Processing (ext_proc) protocol.

BYG is available in Safe Zone 2.1.0. The first supported reference adapter is Envoy Gateway v1.8.3 with Gateway API v1.5.1.

When to use BYG​

Use BYG when platform teams want to enforce one guardrail policy across existing gateway routes without changing every application or SDK. Safe Zone can inspect supported request and response fields and return one of four decisions:

DecisionResult
ALLOWForward the supported payload unchanged.
AUDIT_ONLYForward it unchanged and emit a safe audit decision.
MASKReplace detected content before forwarding it.
BLOCKStop the transaction and return a safe response.

Safe Zone protects supported text fields in OpenAI Chat Completions and Responses, Anthropic Messages, Gemini requests, embeddings input, and MCP text payloads. Unsupported or malformed bodies follow the policy's explicit fail-open or fail-closed behavior.

Integration profiles​

ProfilePolicy and attachmentBest fit
Portable previewCreate the compiled policy with tsz-policy, attach an EnvoyExtensionPolicy, and overwrite the trusted X-TSZ-Policy header at the gateway.Evaluation or a manually managed route.
Native managedApply a TSZGuardrailPolicy; tsz-controller reconciles the policy snapshot, attachment, and route binding.Multi-route Kubernetes environments.

Use only one profile for an external processor deployment. Portable mode uses TSZ_POLICY_RESOLUTION_MODE=header; native mode uses attribute. Do not mix the identity sources per route.

The native API stores policies as security.thyris.ai/v1beta1. Existing schema-compatible v1alpha1 manifests remain served.

Request flow​

Envoy remains responsible for routing, authentication, rate limiting, retries, and provider credentials. Safe Zone owns guardrail inspection and its policy decision. Client-provided policy headers are never authoritative; the gateway must overwrite them before external processing.

Streaming guarantees​

BYG has two distinct SSE modes:

  • AsyncAudit forwards content unchanged and performs bounded, post-stream audit processing. It provides visibility, not enforcement, so MASK and BLOCK response actions are rejected in this mode.
  • Windowed holds complete SSE events in bounded windows before inspection. It can mask the held window or halt future delivery on BLOCK, but it cannot retract bytes released from earlier safe windows.

Use buffered non-streaming response inspection when a route requires a strict no-leakage guarantee. See BYG streaming for the full contract.

Start here​

  1. Review the support and compatibility matrix.
  2. Follow the Envoy Gateway integration guide.
  3. Select the portable or native profile for the whole processor deployment.
  4. Run the matching repository examples before enabling production traffic.
  5. Review security and operations, including failure behavior, mTLS, NetworkPolicy, metrics, and tracing.

The source repository contains the versioned Helm deployment, the local Kind fixtures, and runnable BYG scenarios.