# Llama Guard vs Rebuff

| Attribute | Llama Guard | Rebuff |
|---|---|---|
| **Vioscale score** | 53.3 (27% (low)) | 27.4 (31% (low)) |
| activity.commits_last_30d | 7 | 0 |
| adoption.dependent_repos | 0 | 1 |
| adoption.github_stars | 4,364 | 1,521 |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true}` |
| description.long | A suite of input/output moderation models and security evaluation benchmarks designed to help developers build safer generative AI applications. Includes tools to detect prompt injection, jailbreaking attempts, and other violating content. | A framework that protects AI systems from prompt injection attacks through four defense mechanisms: input heuristics, LLM-based analysis, vector database pattern recognition, and canary token detection. Currently in alpha/prototype stage. |
| features.capabilities | `{"iso_27001":false,"soc2_type_ii":false,"pricing_model":"free_open_source","architecture_model":"open_source_python_library","rag_retrieval_chunk_poisoning_defense":false,"prompt_injection_and_jailbreak_blocking":true,"inbound_pii_and_credit_card_masking_redaction":false,"streaming_token_interception_and_chunked_eval":false,"sub_50ms_latency_guarantees_for_proxy_routing":false,"custom_regex_and_deterministic_denylist_rulesets":false,"outbound_toxicity_and_competitor_mention_blocking":true,"zero_data_retention_and_prompt_privacy_guarantees":true,"hallucination_and_topical_off_brand_drift_detection":false}` | `{"architecture_model":"managed_cloud_inline_proxy","prompt_injection_and_jailbreak_blocking":true,"custom_regex_and_deterministic_denylist_rulesets":true,"zero_data_retention_and_prompt_privacy_guarantees":false}` |
| integrations.count | - | 3 |
| integrations.list | - | `[{"name":"OpenAI"},{"name":"Supabase"},{"name":"Pinecone"}]` |
| language.primary | Python | TypeScript |
| license.spdx | - | Apache-2.0 |
| market.availability | - | `{"primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | `{"cli":true}` | `{"cli":true,"web":true}` |
| pricing | `{"type":"open_source","summary":"Free and open source under MIT license","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-21T10:59:49.492Z"}` | `{"type":"usage","summary":"Free tier available; credit-based usage pricing for scale","currency":"USD","freeTier":true,"sourceUrl":"https://github.com/pricing","retrievedAt":"2026-08-21T11:05:02.545Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | commercial | commercial |
| pricing.price_level | free | low |
| pricing.transparent | yes | no |
| release.history | - | `[{"url":"https://github.com/protectai/rebuff/releases/tag/v0.1.1","date":"2024-01-20T01:11:48Z","type":"stable","version":"v0.1.1"},{"url":"https://github.com/protectai/rebuff/releases/tag/v0.1.0","date":"2024-01-20T01:03:53Z","type":"stable","version":"v0.1.0"},{"url":"https://github.com/protectai/rebuff/releases/tag/v0.0.6","date":"2024-01-20T00:48:23Z","type":"stable","version":"v0.0.6"}]` |
| security.scorecard | 5.9 | - |
| security.vulnerabilities | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fmeta-llama%2FPurpleLlama&per_page=100","last_12m":0,"max_severity":null}` | `{"count":0,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=pypi&package_name=rebuff&per_page=100","last_12m":0,"max_severity":null}` |

## Capabilities (AI Guardrails)

| Capability | Llama Guard | Rebuff |
|---|:--:|:--:|
| **Capabilities** |  |  |
| Architecture model | Open source python library | Managed cloud inline proxy |
| Prompt injection and jailbreak blocking | ✓ | ✓ |
| Inbound pii and credit card masking redaction | ✗ | - |
| Outbound toxicity and competitor mention blocking | ✓ | - |
| Hallucination and topical off brand drift detection | ✗ | - |
| Sub 50ms latency guarantees for proxy routing | ✗ | - |
| Custom regex and deterministic denylist rulesets | ✗ | ✓ |
| Streaming token interception and chunked eval | ✗ | - |
| Rag retrieval chunk poisoning defense | ✗ | - |
| Zero data retention and prompt privacy guarantees | ✓ | ✗ |
| SOC2 type ii | ✗ | - |
| ISO 27001 | ✗ | - |
| Pricing model | Free open source | - |

*Source: Vioscale. Generated 2026-09-01T17:30:43.921Z. "-" = undocumented, not absent.*
