Get started
How zn works
The layers behind a zn verdict, what each one is good at, and when to use local or cloud checks.
The idea: a sacrificial layer
Galvanized steel is coated with zinc, which corrodes first so the steel underneath stays intact. zn plays the same role for agents: hostile input hits the gateway instead of your tools, credentials and data.
Layers
| Layer | Where it runs | What it does | Latency |
|---|---|---|---|
| Rules | zn-gate (local) and the cloud gateway | Deterministic regex and structure checks: instruction overrides, sensitive paths, exfiltration patterns, obfuscation | under 0.1 ms p50 locally (inputs up to ~1k characters) |
| Galvanize-60M | Cloud gateway, or self-hosted | Neural classifier for paraphrased, multilingual and long-context attacks that rules miss | 11.52 ms p50 on CPU (benchmark) |
| Evidence | Both | Records each decision with a hash chain so you can audit it later | n/a |
In the cloud, every request goes through the rules and is also scored by Galvanize-60M in the same call; the request is blocked if either layer says so. The Smart API Router page has the details.
Local or cloud?
- Local (zn-gate): free, offline, in-process. Best as a first filter on every prompt and tool argument, and for development machines.
- Cloud API: adds the neural model, the evidence vault and the dashboard. Best for production agents that handle untrusted content at scale.
Local checks never consume cloud quota. A common setup is zn-gate on every call, with the cloud API on inputs that come from outside your trust boundary.
Verdicts and modes
allow: no attack detected. Proceed.block: stop the tool call or drop the text before it reaches the model.
When you are rolling zn out, run in shadow mode first (zn-gate init --shadow): decisions are logged but nothing is dropped, so you can review them before enforcing.
What zn does not do
zn is one boundary, not your whole security model. Keep identity, authorization, least-privilege tool scopes and human review for high-impact actions. zn makes the decision at the tool boundary explicit and auditable.