# How zn works

The layers behind a zn verdict, what each one is good at, and when to use local or cloud checks.

Source: https://usezn.com/docs/concepts/

## The idea: a sacrificial layer

Galvanized steel is coated with zinc, which corrodes first so the steel underneath stays intact. zn plays the same role for agents: hostile input hits the gateway instead of your tools, credentials and data.

## Layers

| Layer | Where it runs | What it does | Latency |
| - | - | - | - |
| Rules | zn-gate (local) and the cloud gateway | Deterministic regex and structure checks: instruction overrides, sensitive paths, exfiltration patterns, obfuscation | under 0.1 ms p50 locally (inputs up to ~1k characters) |
| Galvanize-60M | Cloud gateway, or self-hosted | Neural classifier for paraphrased, multilingual and long-context attacks that rules miss | 11.52 ms p50 on CPU (benchmark) |
| Evidence | Both | Records each decision with a hash chain so you can audit it later | n/a |

In the cloud, every request goes through the rules and is also scored by Galvanize-60M in the same call; the request is blocked if either layer says so. The [Smart API Router](https://usezn.com/docs/api/router/) page has the details.

## Local or cloud?

- **Local (zn-gate):** free, offline, in-process. Best as a first filter on every prompt and tool argument, and for development machines.
- **Cloud API:** adds the neural model, the evidence vault and the dashboard. Best for production agents that handle untrusted content at scale.

Local checks never consume cloud quota. A common setup is zn-gate on every call, with the cloud API on inputs that come from outside your trust boundary.

## Verdicts and modes

- `allow`: no attack detected. Proceed.
- `block`: stop the tool call or drop the text before it reaches the model.

When you are rolling zn out, run in **shadow mode** first (`zn-gate init --shadow`): decisions are logged but nothing is dropped, so you can review them before enforcing.

## What zn does not do

zn is one boundary, not your whole security model. Keep identity, authorization, least-privilege tool scopes and human review for high-impact actions. zn makes the decision at the tool boundary explicit and auditable.
