Bring Your Gateway
Bring Your Gateway (BYG) lets Safe Zone protect LLM traffic at an existing API
gateway. Applications keep calling their normal gateway route; Envoy sends the
request and response through Safe Zone by using the External Processing
(ext_proc) protocol.
BYG is available in Safe Zone 2.1.0. The first supported reference adapter is Envoy Gateway v1.8.3 with Gateway API v1.5.1.
When to use BYG
Use BYG when platform teams want to enforce one guardrail policy across existing gateway routes without changing every application or SDK. Safe Zone can inspect supported request and response fields and return one of four decisions:
| Decision | Result |
|---|---|
ALLOW | Forward the supported payload unchanged. |
AUDIT_ONLY | Forward it unchanged and emit a safe audit decision. |
MASK | Replace detected content before forwarding it. |
BLOCK | Stop the transaction and return a safe response. |
Safe Zone protects supported text fields in OpenAI Chat Completions and Responses, Anthropic Messages, Gemini requests, embeddings input, and MCP text payloads. Unsupported or malformed bodies follow the policy's explicit fail-open or fail-closed behavior.
Integration profiles
| Profile | Policy and attachment | Best fit |
|---|---|---|
| Portable preview | Create the compiled policy with tsz-policy, attach an EnvoyExtensionPolicy, and overwrite the trusted X-TSZ-Policy header at the gateway. | Evaluation or a manually managed route. |
| Native managed | Apply a TSZGuardrailPolicy; tsz-controller reconciles the policy snapshot, attachment, and route binding. | Multi-route Kubernetes environments. |
Use only one profile for an external processor deployment. Portable mode uses
TSZ_POLICY_RESOLUTION_MODE=header; native mode uses attribute. Do not mix
the identity sources per route.
The native API stores policies as security.thyris.ai/v1beta1. Existing
schema-compatible v1alpha1 manifests remain served.
Request flow
Envoy remains responsible for routing, authentication, rate limiting, retries, and provider credentials. Safe Zone owns guardrail inspection and its policy decision. Client-provided policy headers are never authoritative; the gateway must overwrite them before external processing.
Streaming guarantees
BYG has two distinct SSE modes:
AsyncAuditforwards content unchanged and performs bounded, post-stream audit processing. It provides visibility, not enforcement, soMASKandBLOCKresponse actions are rejected in this mode.Windowedholds complete SSE events in bounded windows before inspection. It can mask the held window or halt future delivery onBLOCK, but it cannot retract bytes released from earlier safe windows.
Use buffered non-streaming response inspection when a route requires a strict no-leakage guarantee. See BYG streaming for the full contract.
Start here
- Review the support and compatibility matrix.
- Follow the Envoy Gateway integration guide.
- Select the portable or native profile for the whole processor deployment.
- Run the matching repository examples before enabling production traffic.
- Review security and operations, including failure behavior, mTLS, NetworkPolicy, metrics, and tracing.
The source repository contains the versioned Helm deployment, the local Kind fixtures, and runnable BYG scenarios.