SafeZone is the monitored runtime environment that receives GuardRails-attested code. It offers secure access to internal systems via MCP servers and APIs, with full runtime monitoring, logging, and intelligent alerting. Policies from GuardRails are enforced in real time.
Core capabilities
Six building blocks that make SafeZone a secure, observable, and flexible runtime.
Secure executionContainerized isolation, resource limits, automatic cleanup and rollback. Dedicated or shared resources based on need.
Data sources and APIsMCP servers expose your backoffice data to AI tools like Claude Code or Cursor. RESTful API gateway with auth, masked data for dev, granular access control.
Monitoring and observabilityReal-time execution tracing, detailed audit logs, performance metrics, and alert rules for anomalies.
GuardRails enforcementPolicy enforcement on all API calls. Real-time blocking, rate limiting, automatic deactivation on rule violation.
SLA and performance99.5% uptime SLA on Standard (custom on Enterprise). Latency guarantees, auto-scaling, redundancy and failover.
Flexible hostingEntry and Standard on Partnersense Cloud (Azure, Nordic). Enterprise supports on-premises, hybrid, or multi-region.
Data flow in SafeZone
Every request follows six steps. Each is logged and auditable.
1. InputThe application places a request.
2. ValidationGuardRails checks against policies.
3. Data retrievalData fetched via MCP servers or APIs.
4. ProcessingCode runs in an isolated environment.
6. ResponseResult returned to the calling application.
Hosting and infrastructure
SafeZone is available in three tiers. Entry and Standard run on Partnersense Cloud. Enterprise can optionally include on-premises or hybrid deployment.
Entry
Database: Your own Supabase database (PostgreSQL, free tier). Best-effort availability.
Hosting: Partnersense Cloud
Backup: Source code via GitHub. No separate data backup (platform reads from source systems).