Get started

How zn works

The layers behind a zn verdict, what each one is good at, and when to use local or cloud checks.

View .md

The idea: a sacrificial layer

Galvanized steel is coated with zinc, which corrodes first so the steel underneath stays intact. zn plays the same role for agents: hostile input hits the gateway instead of your tools, credentials and data.

Layers

Layer Where it runs What it does Latency
Rules zn-gate (local) and the cloud gateway Deterministic regex and structure checks: instruction overrides, sensitive paths, exfiltration patterns, obfuscation under 0.1 ms p50 locally (inputs up to ~1k characters)
Galvanize-60M Cloud gateway, or self-hosted Neural classifier for paraphrased, multilingual and long-context attacks that rules miss 11.52 ms p50 on CPU (benchmark)
Evidence Both Records each decision with a hash chain so you can audit it later n/a

In the cloud, every request goes through the rules and is also scored by Galvanize-60M in the same call; the request is blocked if either layer says so. The Smart API Router page has the details.

Local or cloud?

  • Local (zn-gate): free, offline, in-process. Best as a first filter on every prompt and tool argument, and for development machines.
  • Cloud API: adds the neural model, the evidence vault and the dashboard. Best for production agents that handle untrusted content at scale.

Local checks never consume cloud quota. A common setup is zn-gate on every call, with the cloud API on inputs that come from outside your trust boundary.

Verdicts and modes

  • allow: no attack detected. Proceed.
  • block: stop the tool call or drop the text before it reaches the model.

When you are rolling zn out, run in shadow mode first (zn-gate init --shadow): decisions are logged but nothing is dropped, so you can review them before enforcing.

What zn does not do

zn is one boundary, not your whole security model. Keep identity, authorization, least-privilege tool scopes and human review for high-impact actions. zn makes the decision at the tool boundary explicit and auditable.