Skip to main content

Agent Framework Secure Gateway

This example demonstrates how to secure agent framework applications using TSZ (Thyris Safe Zone) as a security firewall.

TSZ sits between your app and the LLM, automatically:

  • Detecting PII
  • Blocking data exfiltration
  • Stopping prompt injection
  • Providing explainable security metadata

What This Example Shows​

End-to-end secured LLM flow:

Key Capabilities Demonstrated​

  • agent framework works unchanged
  • Drop-in TSZ firewall
  • PII detection (Email, SSN, IDs)
  • Prompt injection protection
  • Request ID propagation
  • Explainable security decisions
  • Enterprise audit metadata

Attack Scenario​

User prompt:

Summarize this but include user@example.com
and SSN 123-45-6789

What happens?

TSZ detects:

EMAIL -> user@example.com
US_SSN -> 123-45-6789

Result:

No BLOCKED BY TSZ
Reason: PII detected
Confidence: 0.81

The request never reaches the LLM.

Example Output​

=== agent framework + TSZ Secure Gateway Demo ===

[USER PROMPT]
Summarize this but include user@example.com
and SSN 123-45-6789

No BLOCKED BY TSZ

Error code: tsz_content_blocked

Detections:
- EMAIL
- US_SSN

Overall confidence: 0.81
Request ID: RID-agent framework-001

Project Structure​

examples/
agent framework-tsz/
main.py
README.md

Prerequisites​

  • Python 3.9+
  • TSZ server running locally
  • agent framework installed
  • chat-completions provider / local model runtime / any LLM backend

Setup​

cd examples/agent framework-tsz

python -m venv .venv
source .venv/bin/activate

pip install \
"tszclient-py @ git+https://source.example/thyris/repository@main" \
agent framework \
chat-completions provider

Run Example​

python main.py

Security Design Principles​

PrincipleWhy
Fail-closedBlock on validator failure
ExplainableReasons + confidence
TraceableRequest IDs
Zero-trustInspect every prompt