Agent Framework Secure Gateway
This example demonstrates how to secure agent framework applications using TSZ (Thyris Safe Zone) as a security firewall.
TSZ sits between your app and the LLM, automatically:
- Detecting PII
- Blocking data exfiltration
- Stopping prompt injection
- Providing explainable security metadata
What This Example Shows
End-to-end secured LLM flow:
Key Capabilities Demonstrated
- agent framework works unchanged
- Drop-in TSZ firewall
- PII detection (Email, SSN, IDs)
- Prompt injection protection
- Request ID propagation
- Explainable security decisions
- Enterprise audit metadata
Attack Scenario
User prompt:
Summarize this but include user@example.com
and SSN 123-45-6789
What happens?
TSZ detects:
EMAIL -> user@example.com
US_SSN -> 123-45-6789
Result:
No BLOCKED BY TSZ
Reason: PII detected
Confidence: 0.81
The request never reaches the LLM.
Example Output
=== agent framework + TSZ Secure Gateway Demo ===
[USER PROMPT]
Summarize this but include user@example.com
and SSN 123-45-6789
No BLOCKED BY TSZ
Error code: tsz_content_blocked
Detections:
- EMAIL
- US_SSN
Overall confidence: 0.81
Request ID: RID-agent framework-001
Project Structure
examples/
agent framework-tsz/
main.py
README.md
Prerequisites
- Python 3.9+
- TSZ server running locally
- agent framework installed
- chat-completions provider / local model runtime / any LLM backend
Setup
cd examples/agent framework-tsz
python -m venv .venv
source .venv/bin/activate
pip install \
"tszclient-py @ git+https://source.example/thyris/repository@main" \
agent framework \
chat-completions provider
Run Example
python main.py
Security Design Principles
| Principle | Why |
|---|---|
| Fail-closed | Block on validator failure |
| Explainable | Reasons + confidence |
| Traceable | Request IDs |
| Zero-trust | Inspect every prompt |