Skip to main content

Changelog

Notable Thyris Safe Zone product changes are listed here. Dates use the release publication date. SDK- or CLI-only tags remain separate version streams.

2.1.0 - 2026-09-07​

Bring Your Gateway​

  • Added the gateway-neutral BYG processing contract and the first supported preview adapter for Envoy Gateway v1.8.3 through Envoy ext_proc.
  • Added portable EnvoyExtensionPolicy and native controller-managed TSZGuardrailPolicy profiles.
  • Added deterministic target attachment and conflict handling, immutable policy snapshots, atomic activation, rollback, last-known-good retention, and Redis-backed version distribution.
  • Added request and response inspection for supported OpenAI Chat Completions, OpenAI Responses, Anthropic Messages, Gemini, embeddings, MCP, role, tool, and multimodal text fields.
  • Added ALLOW, AUDIT_ONLY, MASK, and BLOCK decisions with trusted route-owned policy identity and safe block responses.
  • Added portable bounded AsyncAudit, Windowed SSE masking, and best-effort stream halt. Async audit does not mutate delivery, and Windowed mode cannot retract bytes released from earlier windows.
  • Added stage-correct audit/SIEM events, PII-safe dynamic metadata, Prometheus metrics, OpenTelemetry tracing, cancellation, backpressure, graceful shutdown, and bounded resource controls.
  • Added Kind scenarios for inspection, masking, blocking, authentication, rate limiting, audit-only rollout, streaming, mTLS, NetworkPolicy, scaling, observability, and response enforcement.

Kubernetes and compatibility​

  • Graduated TSZGuardrailPolicy storage to v1beta1 while continuing to serve schema-compatible v1alpha1 manifests.
  • Kept portable AsyncAudit outside the frozen v1alpha1/v1beta1 native schema.
  • Established Envoy Gateway as the preview supported reference.
  • Deferred Envoy AI Gateway pending its pinned compatibility matrix.
  • Selected Kong Gateway with KIC as the next validation candidate without claiming shipped support.

Performance validation​

  • Added a paired protected-versus-unprotected regex-only benchmark with a configurable 20 ms BYG-added p95 target.
  • A paired result still must be recorded in an environment with k6; the release does not infer this target from end-to-end latency alone.

2.0.0 - 2026-08-14​

  • Added the initial management dashboard with overview, guardrail, pattern, configuration, and recent-event views.
  • Added dashboard API/configuration models, in-process metrics, and unit tests.
  • Added the production Helm package with PostgreSQL, Redis, service, ingress, autoscaling, disruption budget, Secret, and ServiceAccount templates.
  • Expanded deployment, dashboard, security-roadmap, licensing, and adoption documentation.

1.0.0 - 2026-04-23​

  • Added production HTTP authentication and authorization, protected cache reload, CORS and security headers, request limits, timeouts, validation, and rate limiting.
  • Added the first CLI release and expanded Go client management APIs.
  • Added Go and Python examples for red-team, exfiltration, audit/SIEM, LangChain, Ollama, streaming, secure RAG, and OpenTelemetry scenarios.
  • Corrected CLI and gateway end-to-end test behavior and synchronized the public API, provider, SDK, example, and Postman documentation.

0.2.0 - 2025-12-27​

  • Added native AWS Bedrock support for Anthropic Claude, Amazon Titan, Meta Llama, Mistral, and Cohere model families.
  • Added the shared provider abstraction, IAM configuration, provider guide, runnable Go example, and provider/configuration tests.

0.1.0 - 2025-12-15​

  • Published the initial Safe Zone service, guardrail APIs, OpenAI-compatible gateway, database schema, Docker packaging, and CI/test foundation.
  • Added the initial Go and Python clients, examples, contribution foundation, and release workflow.

See the Safe Zone releases for tags, release notes, and source archives.