BYG Streaming
BYG streaming is an Envoy ext_proc response contract. It is separate from
the header-controlled streaming modes of Safe Zone's legacy
/v1/chat/completions gateway.
Mode comparison
| Mode | Delivery | Decision | Appropriate use |
|---|---|---|---|
AsyncAudit | SSE bytes are forwarded unchanged. | A bounded background worker emits post-stream AUDIT_ONLY visibility. | Low-latency observation and staged rollout. |
Windowed | Complete SSE events are held in bounded windows before release. | The held content can be allowed, masked, or blocked. | Best-effort inline response enforcement. |
| Buffered non-streaming | The complete response is inspected before delivery. | The entire response can be masked or blocked before any byte reaches the client. | Strict no-leakage requirements. |
AsyncAudit
AsyncAudit preserves the delivered stream byte-for-byte. Safe Zone retains
only bounded, event-aligned text for post-stream inspection and uses a bounded
worker queue. Buffer or queue exhaustion preserves delivery and emits a safe
degraded signal; content is not logged.
Because the client receives content before the decision exists, response
MASK and BLOCK actions are invalid in this mode. Async audit is visibility,
not enforcement.
This mode is currently available through portable compiled policies. It is not part of the frozen native v1alpha1/v1beta1 CRD schema.
Windowed enforcement
Windowed parses complete SSE events and accumulates assistant deltas until
the configured window_bytes target is reached. A small overlap catches
matches split across event or window boundaries. Safe Zone inspects the held
window before releasing its safe prefix.
On MASK, the protected event content is rewritten before delivery. On
BLOCK, Safe Zone returns a safe terminal response and stops future SSE
delivery. A downstream disconnect cancels inline work; deadlines and
cancellation remain transport outcomes rather than guardrail-engine failures.
Important security boundary
Windowed streaming is not a zero-leakage mode. Bytes released from an earlier safe window cannot be recalled if a later window causes a block. Use buffered non-streaming response enforcement whenever no response content may be released before the complete decision.
Runnable fixtures are available for async audit, windowed masking, and stream halt.