Skip to main content

BYG Support and Compatibility

An evaluated or selected gateway is not automatically supported. A BYG adapter must have a registered release record, passing contract and conformance suites, a pinned clean-cluster test, an integration guide, and runnable examples before Safe Zone makes a support claim.

Current matrix​

GatewayMaturityTested versionRequest and responseStreamingNative attachment
Envoy GatewayPreview supported reference1.8.3; Gateway API 1.5.1ALLOW, AUDIT_ONLY, MASK, BLOCK for supported payloadsPortable AsyncAudit; Windowed mask and halt; no zero-leakage claimTSZGuardrailPolicy to EnvoyExtensionPolicy
Envoy AI GatewayDeferred and unverifiedNot establishedNot claimedNot claimedNot claimed
Kong Gateway and KICSelected for validationNot establishedNot claimedNot claimedAdapter not shipped
APISIX, NGINX, Traefik, IstioPlanned evaluationNot establishedNot claimedNot claimedAdapter not shipped
Managed cloud gatewaysDemand-gated evaluationProduct and tier specificNot claimedNot claimedAdapter not shipped

Envoy AI Gateway​

Envoy AI Gateway support is intentionally deferred. Do not reuse the Envoy Gateway examples as a production support claim. Promotion requires a pinned environment proving all of the following:

  • Safe Zone runs at the intended filter stage and cannot be bypassed by filter ordering.
  • Request masking preserves provider transformations and model routing.
  • Retries, fallback, authentication, quotas, and rate limiting remain correct.
  • Token-usage and provider metadata stay intact and free of sensitive content.
  • Unary and SSE requests work for every claimed provider route.
  • Failure, timeout, cancellation, and overload behavior matches the configured policy.

Until that matrix passes, Envoy AI Gateway is unverified and unsupported.

API compatibility​

TSZGuardrailPolicy uses security.thyris.ai/v1beta1 as its storage version and continues serving the schema-compatible v1alpha1 API. The native schema supports None and Windowed streaming. Portable AsyncAudit is deliberately outside the frozen v1alpha1/v1beta1 schema and requires a future API version before native exposure.

For exact adapter release evidence, consult the adapter release registry in the source repository.