What is TSZ (Thyris Safe Zone)?
TSZ (Thyris Safe Zone) is an AI‑powered guardrails and data security gateway built by Thyris.AI. It is designed to protect sensitive information while enabling organizations to safely adopt Generative AI, LLMs and third‑party APIs.
At its core, TSZ acts as a zero‑trust, policy enforcement layer that sits between your applications and external systems. Every request or response that crosses this boundary can be inspected, redacted, blocked or enriched according to your security and compliance policies.
1. Why TSZ Exists
Modern AI and API‑driven systems introduce new classes of risk:
- PII and secrets leakage through prompts, logs or model outputs
- Prompt injection and jailbreak attacks targeting LLM pipelines
- Toxic or non‑compliant outputs (hate speech, medical/financial advice, regulatory violations)
- Unstructured, invalid responses that break downstream systems (JSON that isn’t JSON, missing fields, wrong types)
Traditional security controls (WAFs, regex filters, static DLP tools) are not sufficient on their own. They either:
- Miss context‑dependent risks, or
- Generate too many false positives, or
- Cannot understand AI‑generated content.
TSZ addresses this gap with a hybrid engine:
- Deterministic rules (high‑performance regex patterns, allowlists, blocklists)
- AI‑powered semantic analysis (LLM‑backed validators and guardrails)
- Structured format enforcement (JSON schema / format validation)
2. Key Capabilities
2.1 PII & Secrets Detection
TSZ detects and classifies sensitive entities such as:
- Email addresses, phone numbers, names
- Credit card numbers, bank details
- API keys, access tokens, secrets
- Organization‑specific or domain‑specific identifiers
Each detection receives a confidence score and an explanation describing how the score was derived (regex vs AI, thresholds, etc.).
2.2 Redaction & Masking
Before data leaves your environment, TSZ can redact sensitive values using placeholders, while preserving context for downstream systems (especially LLMs):
user@example.com->[EMAIL]4111 1111 1111 1111->[CREDIT_CARD]
This allows you to:
- Keep conversations meaningful for LLMs
- Prevent raw PII or secrets from ever reaching external providers
2.3 AI‑Powered Guardrails
TSZ integrates with AI models to perform semantic checks that go beyond keywords, for example:
- Toxic / abusive language
- Financial or medical advice
- Brand safety and tone of voice
- Domain‑specific safety rules (e.g. “no competitor mentions”)
Policies are expressed as validators that can be:
- BUILTIN (predefined rules)
- REGEX (pattern‑based)
- SCHEMA (JSON/XML schema validation)
- AI_PROMPT (LLM‑backed guardrail with a prompt)
2.4 Structured Response Enforcement
For AI applications that expect structured outputs (JSON, typed objects, etc.), TSZ can validate that responses conform to a pre‑defined format before they reach your application.
This prevents:
- Application crashes due to invalid JSON
- Silent failures caused by missing or wrongly typed fields
2.5 Templates & Reusable Policies
TSZ supports guardrail templates – portable bundles of patterns and validators that can be imported with a single API call. Example templates:
- PII Starter Pack
- Compliance Pack (PCI/GDPR)
- AI Safety Pack (toxicity, unsafe content)
Templates make it easy to:
- Share policies across teams and environments
- Bootstrap a new deployment within minutes
2.6 Runtime Security Controls
TSZ now includes runtime HTTP security controls for production hardening:
- Authentication and RBAC middleware for non-public endpoints
- Request size limits and endpoint timeouts
- Security response headers and fail-secure CORS policy
- Global and endpoint-level rate limiting
These controls are configurable via environment variables and should be enabled with least-privilege settings in production.
2.7 Bring Your Gateway
Safe Zone 2.1.0 can protect existing Envoy Gateway routes through Envoy's
External Processing (ext_proc) protocol. Platform teams attach a portable or
native policy at the gateway while applications continue using their existing
route. Supported request and response content can be allowed, audited, masked,
or blocked. See Bring Your Gateway.
3. How TSZ Fits in Your Architecture
TSZ is typically deployed as a microservice inside your VPC or private network:
- Your application sends incoming user input or outgoing AI responses to TSZ via the
/detectAPI. - TSZ runs:
- Fast pattern checks (regex, allowlist/blocklist)
- Optional AI guardrails (toxicity, safety, domain rules)
- Optional structure/format validation
- TSZ returns:
- Redacted text
- Detection metadata and breakdown
- Guardrail results
- A
blockedflag and an optional human‑readablemessage
Your application then decides how to proceed:
- If
blocked = true-> reject the operation or ask the user to revise content. - If
blocked = false-> useredacted_textto call an LLM or external API.
Alternatively, BYG places tsz-ext-proc beside an existing Envoy Gateway. The
gateway invokes Safe Zone before forwarding a supported request and again on
the response path, so policy enforcement does not require an application SDK
change.
4. Who Uses TSZ?
TSZ is designed for organizations that:
- Handle regulated data (financial, healthcare, education, government)
- Require strong data residency and data minimization guarantees
- Need to integrate LLMs securely into existing applications
- Want to standardize guardrails across multiple teams and products
Common use cases:
- Secure prompt and response filtering for LLM chatbots
- Pre‑processing and redaction of logs or customer support tickets
- Centralized guardrail layer for multiple AI applications
- Compliance enforcement for content generation pipelines
5. Next Steps
If you are new to TSZ, we recommend the following path:
- Read the Quick Start to run TSZ locally with Docker.
- Explore the API – import the TSZ Postman Collection and call
/detect. - Review Architecture & Security for a deeper technical view.
- Integrate with your stack – follow the API Reference for production integration details.
- For existing gateway routes, review Bring Your Gateway and its support matrix.
For a high-level, executive-oriented overview, see the TSZ Product Overview.