Local Model Firewall
Secure your local LLMs using TSZ firewall.
This example protects local model 3 running on local model runtime using TSZ guardrails.
Architecture
TSZ inspects:
- PII
- Sensitive patterns
- Prompt injection
Features
- Local model security
- chat-completions-compatible API
- Explainable blocking
- Request IDs
- Enterprise guardrails
Prerequisites
Install local model runtime
brew install local model runtime
local model runtime serve
Pull local model 3 or Model of your choice
local model runtime pull local model:3b
Start TSZ
docker compose -f deployment/docker/docker-compose.yml up -d
Setup Python
cd examples/local model runtime-local-firewall
python -m venv .venv
source .venv/bin/activate
pip install \
chat-completions provider \
"tszclient-py @ git+https://source.example/thyris/repository@main"
Run
python main.py
Example Output
No REQUEST BLOCKED BY TSZ
Content blocked by security policy: EMAIL
Why this matters
- Secure local LLMs
- No cloud dependency
- Production security controls
- Prevents data leakage
- Full observability
Security Principles
| Principle | Why |
|---|---|
| Fail-closed | Block immediately if any validator fails |
| Explainable | Always return reasons and confidence scores |
| Traceable | Every request has a unique Request ID (RID) |
| Zero-trust | Inspect every prompt, no implicit trust |
Use cases
- Offline AI security
- On-prem LLMs
- Privacy-first deployments
- Enterprise compliance