# Smart API Router

How a request moves through rules, the Galvanize-60M model and the optional local guard.

Source: https://usezn.com/docs/api/router/

Every call to `POST /analyze` goes through the Smart API Router. It runs two layers in the same request and combines them; a third, optional layer runs on your side.

## Layer 1: rules

Deterministic regex and structure checks for instruction overrides, sensitive paths, exfiltration patterns and obfuscation. High-confidence matches decide immediately. Self-hosted in zn-gate, this layer takes under 0.1 ms p50 for inputs up to about 1,000 characters.

## Layer 2: Galvanize-60M

The neural model scores every request in band, so paraphrased, multilingual and long inputs are covered even when no rule matches. Production threshold: 0.95. Measured CPU inference: 11.52 ms p50. The verdict is `block` if either layer blocks.

| Model property | Value |
| - | - |
| Architecture | 4-layer ModernBERT, security pooling (3,072 dims) |
| Context | up to 8,192 tokens |
| Runtime | INT8 ONNX |
| Tool false-positive rate | 1.00% (benchmark, September 2026) |

Benchmark details and comparisons: [Galvanize-60M](https://usezn.com/docs/galvanize/).

## Layer 3: local guard (optional)

`npx -y zn-gate mcp` (or the SDK) runs the rules on your machine before anything leaves it. Local checks are free and never count against cloud quota. The Galvanize-60M weights are on Hugging Face under Apache-2.0 if you want to self-host the model too.

## Which layer decided?

Read `decided_by` in the response (`rules`, `ml`, or a fallback value) and the `X-ZN-Router-Level` header. Every analyzed request runs the neural model and counts against your plan, whichever layer decided.
