# HiddenLayer vs Rebuff

| Attribute | HiddenLayer | Rebuff |
|---|---|---|
| **Vioscale score** | 55.2 (30% (low)) | 38.8 (27% (low)) |
| activity.commits_last_30d | - | 0 |
| adoption.dependent_repos | - | 1 |
| adoption.github_stars | - | 1,521 |
| deployment.options | `{"cloud":true,"hybrid":true,"on_prem":true}` | `{"cloud":true}` |
| description.long | A security platform that discovers AI assets, validates model supply chains against vulnerabilities and backdoors, simulates adversarial attacks on AI systems, and enforces runtime protections against inference attacks, model extraction, and model theft without requiring access to proprietary model data. | A framework that protects AI systems from prompt injection attacks through four defense mechanisms: input heuristics, LLM-based analysis, vector database pattern recognition, and canary token detection. Currently in alpha/prototype stage. |
| features.capabilities | `{"iso_27001":true,"soc2_type_ii":true,"architecture_model":"managed_cloud_inline_proxy","rag_retrieval_chunk_poisoning_defense":true,"prompt_injection_and_jailbreak_blocking":true,"zero_data_retention_and_prompt_privacy_guarantees":true}` | `{"architecture_model":"managed_cloud_inline_proxy","prompt_injection_and_jailbreak_blocking":true,"custom_regex_and_deterministic_denylist_rulesets":true,"zero_data_retention_and_prompt_privacy_guarantees":false}` |
| integrations.count | 11 | 3 |
| integrations.list | `[{"name":"CI/CD"},{"name":"MLOps"},{"name":"Data Pipelines"},{"name":"SIEM/SOAR"},{"name":"Microsoft Azure"},{"name":"AWS"},{"name":"Google Cloud Platform"},{"name":"TensorFlow"},{"name":"PyTorch"},{"name":"Microsoft AI Studio"},{"name":"Truefoundry AI Gateway"}]` | `[{"name":"OpenAI"},{"name":"Supabase"},{"name":"Pinecone"}]` |
| language.primary | - | TypeScript |
| license.spdx | - | Apache-2.0 |
| market.availability | - | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | - | `{"cli":true,"web":true}` |
| pricing | - | `{"type":"usage","summary":"Free tier available; credit-based usage pricing for scale","currency":"USD","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-21T11:05:02.545Z"}` |
| pricing.free_tier | - | yes |
| pricing.model | commercial | commercial |
| pricing.price_level | - | low |
| pricing.transparent | - | no |
| release.history | - | `[{"url":"https://github.com/protectai/rebuff/releases/tag/v0.1.1","date":"2024-01-20T01:11:48Z","type":"stable","version":"v0.1.1"},{"url":"https://github.com/protectai/rebuff/releases/tag/v0.1.0","date":"2024-01-20T01:03:53Z","type":"stable","version":"v0.1.0"},{"url":"https://github.com/protectai/rebuff/releases/tag/v0.0.6","date":"2024-01-20T00:48:23Z","type":"stable","version":"v0.0.6"}]` |
| security.iso27001 | yes | - |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=rebuff&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (AI Guardrails)

| Capability | HiddenLayer | Rebuff |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Architecture model | Managed cloud inline proxy | Managed cloud inline proxy |
| Prompt injection and jailbreak blocking | ✓ | ✓ |
| Inbound pii and credit card masking redaction | - | - |
| Outbound toxicity and competitor mention blocking | - | - |
| Hallucination and topical off brand drift detection | - | - |
| Sub 50ms latency guarantees for proxy routing | - | - |
| Custom regex and deterministic denylist rulesets | - | ✓ |
| Streaming token interception and chunked eval | - | - |
| Rag retrieval chunk poisoning defense | ✓ | - |
| Zero data retention and prompt privacy guarantees | ✓ | ✗ |
| SOC2 type ii | ✓ | - |
| ISO 27001 | ✓ | - |
| Pricing model | - | - |

*Source: Vioscale. Generated 2026-09-01T20:19:33.629Z. "-" = undocumented, not absent.*
