Safe Zone Documentation Guide
Use this page to choose the shortest documentation path for your role and integration goal.
Start Here
| Goal | Read |
|---|---|
| Understand the product and its security boundary | What Is Safe Zone? and Product Overview |
| Run a local instance and make the first detection call | Quick Start |
| Deploy a production environment | Deployment and Architecture and Security |
| Integrate through HTTP | API Reference |
| Integrate a Go service | Go Client |
| Integrate a Python service | Python Client |
| Use command-line scanning or administration | CLI Guide |
| Protect chat-completions traffic | Streaming Guardrails and Provider Configuration |
| Protect existing Envoy Gateway routes without application changes | Bring Your Gateway and Envoy Gateway Integration |
| Configure access and endpoint permissions | Authentication and Access Control |
| Manage patterns, lists, validators, and templates | Policy Management |
| Start from a runnable scenario | Examples |
| Review product changes by release | Changelog |
Recommended Paths
Application Developer
- Complete the Quick Start.
- Choose the API Reference, Go Client, or Python Client.
- Select an example close to the application's data flow.
- Decide how the application handles
blocked, redacted, and unavailable responses.
Platform and Operations
- Review Architecture and Security.
- Choose direct service integration or Bring Your Gateway.
- Configure an approved upstream model with Provider Configuration.
- Apply Authentication and Access Control.
- Follow the Deployment Guide, or the BYG-specific security and operations guide.
- Validate the dashboard and operational notes before production traffic.
Security and Policy Owner
- Review the data flow in Architecture and Security.
- Learn the confidence and decision fields in the API Reference.
- Define and test policies with Policy Management.
- Exercise adversarial cases using the red-team and data-exfiltration examples.
Integration Decision
Use /detect when the application controls the downstream call and needs a decision or redacted value first. Use /v1/chat/completions when an existing chat-completions client should send model traffic through Safe Zone as a gateway. Use BYG when an existing Envoy Gateway should enforce centrally attached policies without application changes. Use the CLI for operator workflows, local checks, and policy administration rather than customer-facing request paths.
For every option, propagate a non-sensitive request ID, stop downstream processing when blocked is true, and define the application's behavior when Safe Zone is unavailable.