Review policy results
Apply rules to model identifiers, API routes, request-declared tool names, selected request content, request-declared maximum-output-token fields, request-declared streaming, and UTC operating windows.
EYZEC Gateway is a local-first protection layer for supported OpenAI-compatible and Anthropic API traffic. It checks each routed request against company rules before an upstream connection and records allowed, denied, and log-only decisions in a hash-linked local evidence store.
Apply rules to model identifiers, API routes, request-declared tool names, selected request content, request-declared maximum-output-token fields, request-declared streaming, and UTC operating windows.
Bind the gateway-generated request ID, route, matched rule, active-policy hash, request and response hashes, upstream status, and observer-produced timestamps.
Re-verify the local evidence chain from stored bytes and detect rollback or rotation relative to the saved local checkpoint.
An initial evaluation should use an internal or operational workflow—such as an analyst assistant, service copilot, document summarizer, or finance-operations tool—whose request boundary can be stated precisely.
The built-in Financial Services profile is an alternative complete policy—not a composable pack. It classifies declared high-impact financial tool names, request-declared streaming, request-declared maximum-output-token fields above the configured cap, and requests outside configured routes or exact identifier lists as DENY. Its shipped exact model lists are empty; the tool-using ALLOW path also requires an exact tool-name list. Until every required exact list for at least one complete ALLOW path is configured, requests continue to receive policy DENY results. The current Gateway distribution records those policy results and forwards the requests. Technical or evidence failures can still stop forwarding; there is no active-enforcement switch in this distribution.