Skip to main content

Safe Zone Documentation Guide

Use this page to choose the shortest documentation path for your role and integration goal.

Start Here​

GoalRead
Understand the product and its security boundaryWhat Is Safe Zone? and Product Overview
Run a local instance and make the first detection callQuick Start
Deploy a production environmentDeployment and Architecture and Security
Integrate through HTTPAPI Reference
Integrate a Go serviceGo Client
Integrate a Python servicePython Client
Use command-line scanning or administrationCLI Guide
Protect chat-completions trafficStreaming Guardrails and Provider Configuration
Protect existing Envoy Gateway routes without application changesBring Your Gateway and Envoy Gateway Integration
Configure access and endpoint permissionsAuthentication and Access Control
Manage patterns, lists, validators, and templatesPolicy Management
Start from a runnable scenarioExamples
Review product changes by releaseChangelog

Application Developer​

  1. Complete the Quick Start.
  2. Choose the API Reference, Go Client, or Python Client.
  3. Select an example close to the application's data flow.
  4. Decide how the application handles blocked, redacted, and unavailable responses.

Platform and Operations​

  1. Review Architecture and Security.
  2. Choose direct service integration or Bring Your Gateway.
  3. Configure an approved upstream model with Provider Configuration.
  4. Apply Authentication and Access Control.
  5. Follow the Deployment Guide, or the BYG-specific security and operations guide.
  6. Validate the dashboard and operational notes before production traffic.

Security and Policy Owner​

  1. Review the data flow in Architecture and Security.
  2. Learn the confidence and decision fields in the API Reference.
  3. Define and test policies with Policy Management.
  4. Exercise adversarial cases using the red-team and data-exfiltration examples.

Integration Decision​

Use /detect when the application controls the downstream call and needs a decision or redacted value first. Use /v1/chat/completions when an existing chat-completions client should send model traffic through Safe Zone as a gateway. Use BYG when an existing Envoy Gateway should enforce centrally attached policies without application changes. Use the CLI for operator workflows, local checks, and policy administration rather than customer-facing request paths.

For every option, propagate a non-sensitive request ID, stop downstream processing when blocked is true, and define the application's behavior when Safe Zone is unavailable.