Skip to main content

BYG Streaming

BYG streaming is an Envoy ext_proc response contract. It is separate from the header-controlled streaming modes of Safe Zone's legacy /v1/chat/completions gateway.

Mode comparison​

ModeDeliveryDecisionAppropriate use
AsyncAuditSSE bytes are forwarded unchanged.A bounded background worker emits post-stream AUDIT_ONLY visibility.Low-latency observation and staged rollout.
WindowedComplete SSE events are held in bounded windows before release.The held content can be allowed, masked, or blocked.Best-effort inline response enforcement.
Buffered non-streamingThe complete response is inspected before delivery.The entire response can be masked or blocked before any byte reaches the client.Strict no-leakage requirements.

AsyncAudit​

AsyncAudit preserves the delivered stream byte-for-byte. Safe Zone retains only bounded, event-aligned text for post-stream inspection and uses a bounded worker queue. Buffer or queue exhaustion preserves delivery and emits a safe degraded signal; content is not logged.

Because the client receives content before the decision exists, response MASK and BLOCK actions are invalid in this mode. Async audit is visibility, not enforcement.

This mode is currently available through portable compiled policies. It is not part of the frozen native v1alpha1/v1beta1 CRD schema.

Windowed enforcement​

Windowed parses complete SSE events and accumulates assistant deltas until the configured window_bytes target is reached. A small overlap catches matches split across event or window boundaries. Safe Zone inspects the held window before releasing its safe prefix.

On MASK, the protected event content is rewritten before delivery. On BLOCK, Safe Zone returns a safe terminal response and stops future SSE delivery. A downstream disconnect cancels inline work; deadlines and cancellation remain transport outcomes rather than guardrail-engine failures.

Important security boundary​

Windowed streaming is not a zero-leakage mode. Bytes released from an earlier safe window cannot be recalled if a later window causes a block. Use buffered non-streaming response enforcement whenever no response content may be released before the complete decision.

Runnable fixtures are available for async audit, windowed masking, and stream halt.