# Llama Guard vs NVIDIA NeMo Guardrails

| Attribute | Llama Guard | NVIDIA NeMo Guardrails |
|---|---|---|
| **Vioscale score** | 53.3 (27% (low)) | 61.3 (34% (low)) |
| activity.commits_last_30d | 7 | 55 |
| adoption.dependent_repos | 0 | 0 |
| adoption.github_stars | 4,364 | 7,016 |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"on_prem":true,"self_hosted":true}` |
| description.long | A suite of input/output moderation models and security evaluation benchmarks designed to help developers build safer generative AI applications. Includes tools to detect prompt injection, jailbreaking attempts, and other violating content. | A Python library that protects language model-based chat applications from common vulnerabilities through modular guardrails. It supports input and output moderation, prompt injection and jailbreak detection, hallucination identification, RAG chunk validation, and integrates with multiple LLM frameworks and safety services. |
| features.capabilities | `{"iso_27001":false,"soc2_type_ii":false,"pricing_model":"free_open_source","architecture_model":"open_source_python_library","rag_retrieval_chunk_poisoning_defense":false,"prompt_injection_and_jailbreak_blocking":true,"inbound_pii_and_credit_card_masking_redaction":false,"streaming_token_interception_and_chunked_eval":false,"sub_50ms_latency_guarantees_for_proxy_routing":false,"custom_regex_and_deterministic_denylist_rulesets":false,"outbound_toxicity_and_competitor_mention_blocking":true,"zero_data_retention_and_prompt_privacy_guarantees":true,"hallucination_and_topical_off_brand_drift_detection":false}` | `{"iso_27001":false,"soc2_type_ii":false,"pricing_model":"free_open_source","architecture_model":"open_source_python_library","rag_retrieval_chunk_poisoning_defense":true,"prompt_injection_and_jailbreak_blocking":true,"inbound_pii_and_credit_card_masking_redaction":true,"streaming_token_interception_and_chunked_eval":true,"sub_50ms_latency_guarantees_for_proxy_routing":false,"custom_regex_and_deterministic_denylist_rulesets":true,"outbound_toxicity_and_competitor_mention_blocking":true,"zero_data_retention_and_prompt_privacy_guarantees":true,"hallucination_and_topical_off_brand_drift_detection":true}` |
| integrations.count | - | 11 |
| integrations.list | - | `[{"name":"OpenAI"},{"name":"LangChain"},{"name":"Hugging Face"},{"name":"vLLM"},{"name":"KServe"},{"name":"FMS"},{"name":"PrivateAI"},{"name":"Polygraf"},{"name":"NemoGuard"},{"name":"Nemotron"},{"name":"Patronus"}]` |
| language.primary | Python | Python |
| platform.support | `{"cli":true}` | `{"cli":true,"linux":true}` |
| pricing | `{"type":"open_source","summary":"Free and open source under MIT license","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-21T10:59:49.492Z"}` | `{"type":"open_source","summary":"Free, open-source","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-21T10:59:13.663Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | commercial |
| pricing.price_level | free | free |
| pricing.transparent | yes | yes |
| release.cadence_days | - | 39 |
| release.history | - | `[{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.23.0","date":"2026-07-01T16:22:19Z","type":"stable","version":"v0.23.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.22.0","date":"2026-05-22T20:25:31Z","type":"stable","version":"v0.22.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.21.0","date":"2026-03-12T13:22:49Z","type":"stable","version":"v0.21.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.20.0","date":"2026-01-22T08:44:24Z","type":"stable","version":"v0.20.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.19.0","date":"2025-12-03T17:27:00Z","type":"stable","version":"v0.19.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.18.0","date":"2025-11-06T20:06:41Z","type":"stable","version":"v0.18.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.17.0","date":"2025-10-09T16:45:35Z","type":"stable","version":"v0.17.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.16.0","date":"2025-09-05T19:55:08Z","type":"stable","version":"v0.16.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.15.0","date":"2025-08-08T11:22:08Z","type":"stable","version":"v0.15.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.14.1","date":"2025-07-08T18:50:24Z","type":"stable","version":"v0.14.1"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.14.0","date":"2025-06-11T18:58:04Z","type":"stable","version":"v0.14.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.13.0","date":"2025-03-25T18:25:34Z","type":"stable","version":"v0.13.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.12.0","date":"2025-02-26T18:10:50Z","type":"stable","version":"v0.12.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.11.1","date":"2025-01-16T22:25:48Z","type":"stable","version":"v0.11.1"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.11.0","date":"2024-11-19T13:54:31Z","type":"stable","version":"v0.11.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.10.1","date":"2024-10-02T18:38:56Z","type":"stable","version":"v0.10.1"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.10.0","date":"2024-09-27T21:47:53Z","type":"stable","version":"v0.10.0"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.9.1.1","date":"2024-07-26T11:09:15Z","type":"stable","version":"v0.9.1.1"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.9.1","date":"2024-07-25T12:02:16Z","type":"stable","version":"v0.9.1"},{"url":"https://github.com/NVIDIA-NeMo/Guardrails/releases/tag/v0.9.0","date":"2024-05-10T07:51:27Z","type":"stable","version":"v0.9.0"}]` |
| security.disclosure_policy | - | yes |
| security.scorecard | 5.9 | - |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fmeta-llama%2FPurpleLlama&per_page=100","last_12m":0,"max_severity":null}` | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2FNVIDIA%2FNeMo-Guardrails&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (AI Guardrails)

| Capability | Llama Guard | NVIDIA NeMo Guardrails |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Architecture model | Open source python library | Open source python library |
| Prompt injection and jailbreak blocking | ✓ | ✓ |
| Inbound pii and credit card masking redaction | ✗ | ✓ |
| Outbound toxicity and competitor mention blocking | ✓ | ✓ |
| Hallucination and topical off brand drift detection | ✗ | ✓ |
| Sub 50ms latency guarantees for proxy routing | ✗ | ✗ |
| Custom regex and deterministic denylist rulesets | ✗ | ✓ |
| Streaming token interception and chunked eval | ✗ | ✓ |
| Rag retrieval chunk poisoning defense | ✗ | ✓ |
| Zero data retention and prompt privacy guarantees | ✓ | ✓ |
| SOC2 type ii | ✗ | ✗ |
| ISO 27001 | ✗ | ✗ |
| Pricing model | Free open source | Free open source |

*Source: Vioscale. Generated 2026-09-01T17:22:58.410Z. "-" = undocumented, not absent.*
