Open Source
Self-hosted runtimeSelf-host the open-source runtime and enforce policy in your stack. The full detection engine runs in your boundary, with no account and no metering.
AI Security Platform
ZNYX secures the whole AI request path - inputs, retrieval, tool calls, agent steps, and outputs - behind one engine. It runs in your infrastructure on every plan, so your prompts, PII, and secrets stay inside your own boundary.
Self-hosted · in your VPC
ZNYX
runtime + sidecar
Data stays in boundary
Definition
An AI security platform inspects and governs the full request path of LLM and agentic applications - inputs, retrieved context, tool calls, agent steps, and outputs - enforcing policy in real time and producing audit-ready evidence. ZNYX runs this protection inside your own boundary, independent of any single cloud or model vendor, so sensitive data never has to leave your environment to be secured.
The platform
Each pillar is part of the same self-hosted engine. Compose them into policies and apply protection wherever your AI runs.
Inputs, outputs & streams
Inspect every prompt, response, and token stream through a deterministic to ML to LLM-judge engine with a fail-closed scorecard gate.
Plans, steps & memory
Govern agents and the tools they call across retrieval, agent-plan, agent-step, and memory-write evaluation stages.
Proof you can hand auditors
Turn every decision into audit-ready evidence - coverage scorecards, detector quality metrics, and model cards.
Ship changes with confidence
Benchmark detectors, watch for drift, roll out model versions safely, and trace every request end to end.
One console
Author a policy, watch the detector waterfall, and export the evidence, without leaving your boundary. The runtime stays in your infrastructure on every plan.
Request path
Point tools filter a single prompt. ZNYX applies policy at every stage a request moves through - from the user's input to the streamed response.
Screen incoming prompts for injection, jailbreak, PII, secrets, toxicity, and policy topics before the model ever sees them.
Evaluate retrieved context and embedding/vector integrity to catch poisoned documents and indirect prompt injection (OWASP LLM09).
Scan MCP and tool manifests for supply-chain risk and guard tool outputs before they re-enter the model loop.
Check agent plans and individual steps for excessive agency, and enforce denial-of-wallet budgets across the run.
Apply an egress/DLP gate, enforce JSON schemas, and evaluate responses in real time over SSE streaming.
Data residency
The detection runtime is open source and runs in your environment. An in-VPC inference sidecar keeps ML and LLM-judge models in your boundary too, so prompts, PII, and secrets are inspected without being shipped to a third party.
Runs in your environment
The open-source runtime and an in-boundary inference sidecar evaluate prompts, outputs, tool payloads, and ML/judge models inside your VPC.
What the hosted console sees
Operational metadata by default: trace id, policy decision, detector summary, latency, and scope, not prompt and response bodies.
Enterprise option
Self-host the control plane as well for fully private, air-gappable deployment.
Deployment tiers
Starter, Growth, and Enterprise run the exact same security engine - only where the control plane lives and how teams operate it differs.
Self-host the open-source runtime and enforce policy in your stack. The full detection engine runs in your boundary, with no account and no metering.
The hosted console on its free tier: policy versioning, traces, and evidence for one project, at 10,000 evaluations a month.
Add the hosted control plane for centralized policies, evidence, traces, and team workflows - inspection still runs in your VPC.
Self-host the control plane too for a fully private, air-gappable deployment with SSO/SAML, SCIM, MFA, and data residency.
FAQ
How the platform secures LLMs and agents, how it differs from other open-source guardrails, and how self-hosting keeps your data in your boundary.
Pull the open-source runtime, drop it into your stack, and start enforcing policy in minutes, free, forever. Add the hosted control plane when you want centralized policies, evidence, traces, and team workflows.