BYG Support and Compatibility
An evaluated or selected gateway is not automatically supported. A BYG adapter must have a registered release record, passing contract and conformance suites, a pinned clean-cluster test, an integration guide, and runnable examples before Safe Zone makes a support claim.
Current matrix
| Gateway | Maturity | Tested version | Request and response | Streaming | Native attachment |
|---|---|---|---|---|---|
| Envoy Gateway | Preview supported reference | 1.8.3; Gateway API 1.5.1 | ALLOW, AUDIT_ONLY, MASK, BLOCK for supported payloads | Portable AsyncAudit; Windowed mask and halt; no zero-leakage claim | TSZGuardrailPolicy to EnvoyExtensionPolicy |
| Envoy AI Gateway | Deferred and unverified | Not established | Not claimed | Not claimed | Not claimed |
| Kong Gateway and KIC | Selected for validation | Not established | Not claimed | Not claimed | Adapter not shipped |
| APISIX, NGINX, Traefik, Istio | Planned evaluation | Not established | Not claimed | Not claimed | Adapter not shipped |
| Managed cloud gateways | Demand-gated evaluation | Product and tier specific | Not claimed | Not claimed | Adapter not shipped |
Envoy AI Gateway
Envoy AI Gateway support is intentionally deferred. Do not reuse the Envoy Gateway examples as a production support claim. Promotion requires a pinned environment proving all of the following:
- Safe Zone runs at the intended filter stage and cannot be bypassed by filter ordering.
- Request masking preserves provider transformations and model routing.
- Retries, fallback, authentication, quotas, and rate limiting remain correct.
- Token-usage and provider metadata stay intact and free of sensitive content.
- Unary and SSE requests work for every claimed provider route.
- Failure, timeout, cancellation, and overload behavior matches the configured policy.
Until that matrix passes, Envoy AI Gateway is unverified and unsupported.
API compatibility
TSZGuardrailPolicy uses security.thyris.ai/v1beta1 as its storage version
and continues serving the schema-compatible v1alpha1 API. The native schema
supports None and Windowed streaming. Portable AsyncAudit is deliberately
outside the frozen v1alpha1/v1beta1 schema and requires a future API version
before native exposure.
For exact adapter release evidence, consult the adapter release registry in the source repository.