npm install tealtiger or pip install tealtiger, and your agents are secured.
Platform Architecture
TealTiger is built around five core components, each handling a distinct security concern. They compose together through a unified request pipeline, or work independently when you only need one capability.
Request Lifecycle
Understanding how a single request traverses the TealTiger stack is key to appreciating the depth of protection.
Decision object with a consistent contract — action, reason codes, risk score, and correlation ID. This means your application logic can handle any outcome uniformly, regardless of which component triggered it.
The Five Pillars
1. TealEngine — Deterministic Policy Enforcement
TealEngine evaluates security policies against every request and returns a deterministicDecision object. No probabilistic guessing — the same input always produces the same output.
Policy Rollout Modes allow gradual deployment without risk:

REPORT_ONLY to measure impact, promote to MONITOR to catch violations without blocking, then move to ENFORCE when confident. Mode resolution follows a strict hierarchy: policy-specific override → environment override → global default. Resolution completes in under 1ms.
Decision Contract — every evaluation returns:
2. TealGuard — Client-Side Security Guardrails
TealGuard runs content validation entirely in-process — no network calls, no latency spikes. Guardrails execute in parallel for maximum throughput:
- PII: emails, phone numbers, SSNs, credit card numbers, addresses
- Prompt injection and jailbreak patterns
- Content moderation (hate speech, violence, sexual content)
- Custom pattern matching via regex or policy rules
3. TealMonitor — Behavioral Anomaly Detection
TealMonitor establishes behavioral baselines for each agent and detects deviations in real time.
COST_BUDGET_EXCEEDED or MODEL_DOWNGRADED.
4. TealCircuit — Cascading Failure Prevention
TealCircuit implements the circuit breaker pattern to prevent one failing provider from taking down your entire system.
5. TealAudit — Compliance-Ready Audit Logging
TealAudit produces versioned, immutable audit events with security-by-default PII redaction.
HASH) ensures raw prompts and responses never appear in logs. PII detection runs automatically before any redaction. Debug mode (NONE) requires explicit opt-in and emits a warning.
Multi-Provider Coverage
TealTiger wraps 7 LLM providers with consistent security, giving you 95%+ market coverage through a unified interface.
Both TypeScript and Python SDKs have full feature parity across all 7 providers.
End-to-End Traceability
Every request carries anExecutionContext that propagates through all components automatically.

OWASP Top 10 for Agentic Applications
TealTiger v1.1.1 covers 7 out of 10 vulnerability categories through its SDK-only architecture:
Performance Profile
Framework Alignment
Get Started
TypeScript SDK
npm install tealtigerPython SDK
pip install tealtigerQuickstart
Get started in 5 minutes
API Reference
Complete API documentation

