How It Works

A compliance layer that sits between your app and its AI model.

Every AI response passes through ZeroDrift before reaching your users. Policies evaluate in real time. Violations are rewritten. Your users never see the original output.

28ms Median p99 intercept latency across production deployments
94% Policy violation catch rate across 15 early-access deployments
1 URL Change needed to route through ZeroDrift, no SDK required
REST Compatible with the same schema as your upstream model API
System Architecture

One intercept layer. Zero changes to your model calls.

ZeroDrift operates as a transparent proxy. Your application sends requests and receives responses in the same format it always has. ZeroDrift evaluates and rewrites in the middle.

Your App any language request ZERODRIFT Policy Engine evaluate rewrite if needed proxy AI Model GPT-4 / Claude / etc raw response clean response AUDIT LOG Original response Policy triggered Rewrite applied Timestamp + version logged median p99: 28ms intercept
Policy Engine

Write policies in plain language. Version and test them without downtime.

Policies define what constitutes a violation and what action to take. Each rule specifies a condition, a severity, and either a block or rewrite action. Multiple policies can be active simultaneously and evaluated in priority order.

  • Plain-language rule authoring with a structured YAML format, no regex required for common cases
  • Policy versioning with named environments (staging, production) and instant rollback to any prior version
  • Shadow mode lets you run a new policy set against live traffic without affecting output until you promote it
  • Audience-aware rules activate stricter policies based on user attributes passed in the request context
policy.yaml YAML
version: "2.1"
environment: production
rules:

  # Block direct financial advice
  - id: fin-advice-block
    priority: 1
    condition: contains_financial_advice
    action: rewrite
    rewrite_template: safe_advice_disclaimer
    severity: high

  # Block PII in response
  - id: pii-redact
    priority: 2
    condition: response_contains_pii
    action: block
    fallback: "generic_error_message"
    severity: critical

  # Stricter rules for minors audience
  - id: audience-minor
    priority: 3
    audience: minor
    condition: contains_adult_content
    action: block
    severity: critical
integration.py Python
import openai

# Before: direct model call
# client = openai.OpenAI()

# After: route through ZeroDrift
client = openai.OpenAI(
    base_url="https://api.zerdorift.com/v1",
    api_key="your-zerodrift-api-key",
    default_headers={
        "X-ZDR-Policy-Env": "production",
        "X-ZDR-Audience": user.audience_type,
    }
)

# Same call syntax, no other changes
response = client.chat.completions.create(
    model="gpt-4o",
    messages=[
        {"role": "system", "content": system_prompt},
        {"role": "user", "content": user_input},
    ]
)

# ZeroDrift intercept metadata in headers
zdr_action = response.headers.get("X-ZDR-Action")
# "pass" | "rewrite" | "block"
Drop-In Integration

One URL change. Compatible with any language or framework.

ZeroDrift uses the same OpenAI-compatible request and response schema as the upstream model. If you already call the model, you can route through ZeroDrift by changing one base URL and adding your API key. No SDK changes. No new abstractions.

The same pattern works with LangChain, LlamaIndex, any direct HTTP client, or your own internal gateway. ZeroDrift passes requests through unchanged and only modifies responses when a policy triggers.

Intercept metadata arrives as response headers so your application can log, route, or alert based on what ZeroDrift did, without parsing the body.

Performance

Compliance that does not slow your product down.

The latency concern is the reason most teams delay compliance infrastructure. These numbers are measured at the proxy layer across 15 production deployments, not in a benchmark environment.

28ms Median p99 intercept latency
94% Policy violation catch rate
99.9% Proxy uptime across pilot period

Based on 90-day early-access pilot across 15 enterprise deployments. Latency measured at ZeroDrift proxy layer, excluding upstream model response time.

Common Questions

How the product actually works.

ZeroDrift proxies any OpenAI-compatible API endpoint. That includes OpenAI GPT models, Anthropic Claude via the OpenAI-compatible layer, and self-hosted models running through compatible wrappers. If the model accepts standard chat completion requests, ZeroDrift can intercept the responses. We are expanding native adapters for other schemas based on early-access demand.
ZeroDrift buffers the full streaming response before running policy evaluation, then re-streams the clean output to your application. The added latency from buffering is included in the 28ms figure. For use cases where streaming latency is critical, there is a partial-evaluation mode that checks the first 300 tokens before the buffer completes, though this does not cover multi-sentence violations that span token boundaries.
You configure a failover behavior per deployment: pass-through (responses reach users unfiltered), block all (responses are blocked until the proxy recovers), or cached fallback (a static compliant response is returned). The Growth tier targets 99.5% uptime with a contractual SLA. Enterprise tiers include multi-region failover with a dedicated on-call escalation path.
By default, ZeroDrift logs original responses only for requests that triggered a policy action (rewrites and blocks). Pass-through responses are not stored unless you enable full logging. Enterprise customers can configure log retention periods and apply field-level encryption to PII before storage. All log data is retained in the region of your choice and subject to our data processing agreement.
Yes. Rewrite templates are defined in your policy configuration and can include static replacement text, dynamic tokens from the original response context, and conditional branching based on which rule triggered. The Growth tier includes up to 20 custom rewrite templates. Enterprise allows unlimited templates with a review workflow where compliance staff can approve new rewrites before they go live.
The dashboard provides a searchable log with filtering by policy triggered, action taken, date range, and endpoint. The audit export API returns structured JSON or CSV. Webhooks push intercept events to your own SIEM or compliance tooling in real time. The audit trail format was reviewed and accepted by legal teams at three early-access companies as sufficient for their internal compliance documentation.