Changelog
Notable Thyris Safe Zone product changes are listed here. Dates use the release publication date. SDK- or CLI-only tags remain separate version streams.
2.1.0 - 2026-09-07
Bring Your Gateway
- Added the gateway-neutral BYG processing contract and the first supported
preview adapter for Envoy Gateway v1.8.3 through Envoy
ext_proc. - Added portable
EnvoyExtensionPolicyand native controller-managedTSZGuardrailPolicyprofiles. - Added deterministic target attachment and conflict handling, immutable policy snapshots, atomic activation, rollback, last-known-good retention, and Redis-backed version distribution.
- Added request and response inspection for supported OpenAI Chat Completions, OpenAI Responses, Anthropic Messages, Gemini, embeddings, MCP, role, tool, and multimodal text fields.
- Added
ALLOW,AUDIT_ONLY,MASK, andBLOCKdecisions with trusted route-owned policy identity and safe block responses. - Added portable bounded
AsyncAudit, Windowed SSE masking, and best-effort stream halt. Async audit does not mutate delivery, and Windowed mode cannot retract bytes released from earlier windows. - Added stage-correct audit/SIEM events, PII-safe dynamic metadata, Prometheus metrics, OpenTelemetry tracing, cancellation, backpressure, graceful shutdown, and bounded resource controls.
- Added Kind scenarios for inspection, masking, blocking, authentication, rate limiting, audit-only rollout, streaming, mTLS, NetworkPolicy, scaling, observability, and response enforcement.
Kubernetes and compatibility
- Graduated
TSZGuardrailPolicystorage tov1beta1while continuing to serve schema-compatiblev1alpha1manifests. - Kept portable
AsyncAuditoutside the frozen v1alpha1/v1beta1 native schema. - Established Envoy Gateway as the preview supported reference.
- Deferred Envoy AI Gateway pending its pinned compatibility matrix.
- Selected Kong Gateway with KIC as the next validation candidate without claiming shipped support.
Performance validation
- Added a paired protected-versus-unprotected regex-only benchmark with a configurable 20 ms BYG-added p95 target.
- A paired result still must be recorded in an environment with
k6; the release does not infer this target from end-to-end latency alone.
2.0.0 - 2026-08-14
- Added the initial management dashboard with overview, guardrail, pattern, configuration, and recent-event views.
- Added dashboard API/configuration models, in-process metrics, and unit tests.
- Added the production Helm package with PostgreSQL, Redis, service, ingress, autoscaling, disruption budget, Secret, and ServiceAccount templates.
- Expanded deployment, dashboard, security-roadmap, licensing, and adoption documentation.
1.0.0 - 2026-04-23
- Added production HTTP authentication and authorization, protected cache reload, CORS and security headers, request limits, timeouts, validation, and rate limiting.
- Added the first CLI release and expanded Go client management APIs.
- Added Go and Python examples for red-team, exfiltration, audit/SIEM, LangChain, Ollama, streaming, secure RAG, and OpenTelemetry scenarios.
- Corrected CLI and gateway end-to-end test behavior and synchronized the public API, provider, SDK, example, and Postman documentation.
0.2.0 - 2025-12-27
- Added native AWS Bedrock support for Anthropic Claude, Amazon Titan, Meta Llama, Mistral, and Cohere model families.
- Added the shared provider abstraction, IAM configuration, provider guide, runnable Go example, and provider/configuration tests.
0.1.0 - 2025-12-15
- Published the initial Safe Zone service, guardrail APIs, OpenAI-compatible gateway, database schema, Docker packaging, and CI/test foundation.
- Added the initial Go and Python clients, examples, contribution foundation, and release workflow.
See the Safe Zone releases for tags, release notes, and source archives.