AI GuardrailsUnclaimed

Llama Guard

Also known as
llama-guard

What is Llama Guard?

A suite of input/output moderation models and security evaluation benchmarks designed to help developers build safer generative AI applications. Includes tools to detect prompt injection, jailbreaking attempts, and other violating content.

Independently observed

Llama Guard pricing

We don't have Llama Guard's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Open sourceFree tier

Free and open source under MIT license

What Llama Guard does

The capabilities that matter for ai guardrails, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Capabilities
Architecture model
Open source python library
Prompt injection and jailbreak blocking
Inbound pii and credit card masking redaction
Outbound toxicity and competitor mention blocking
Hallucination and topical off brand drift detection
Sub 50ms latency guarantees for proxy routing
Custom regex and deterministic denylist rulesets
Streaming token interception and chunked eval
Rag retrieval chunk poisoning defense
Zero data retention and prompt privacy guarantees
SOC2 type ii
ISO 27001
Pricing model
Free open source
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
Deployment
  • Self-hosted

Security & compliance

Known vulnerabilities: 0 (0 in the last 12 months) sourcea count reflects scale & disclosure, not quality

Llama Guard alternatives

Other ai guardrails we track, ranked by the same independent score.

All Llama Guard alternatives, ranked →

Compare Llama Guard

Side by side against other ai guardrails, attribute by attribute, with a source on every value.

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Llama Guard, not the verdict.

Balanced composite 53 / 100
low · 27%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Pricing transparency800.086.7
Price level1000.055.2
Capabilities580.084.9
Development activity280.092.7
Security score590.042.5
Stars690.031.8
Reliability00.070.0-
Integrations00.090.0-
Dependent projects00.060.0
Release cadence00.050.0-
Security posture00.070.0-
Package downloads00.140.0-
Developer Q&A activity00.060.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Activity

AttributeValueEvidence
Commits last 30d7mediumsource · 2026-08-26 · 65%

Adoption

AttributeValueEvidence
Github stars4,364highsource · 2026-08-26 · 90%
Dependent repos0highsource · 2026-08-26 · 85%

Features

AttributeValueEvidence
CapabilitiesIso 27001: No · Soc2 type ii: No · Pricing model: free_open_source · Architecture model: open_source_python_library · Rag retrieval chunk poisoning defense: No · Prompt injection and jailbreak blocking: Yesmediumsource · 2026-08-21 · 60%

Language

AttributeValueEvidence
PrimaryPythonhighsource · 2026-08-26 · 90%

Pricing

AttributeValueEvidence
Modelcommercialmediumsource · 2026-08-26 · 70%
Free tierYesmediumsource · 2026-08-21 · 60%
Price levelfreemediumsource · 2026-08-21 · 60%
TransparentYesmediumsource · 2026-08-21 · 60%

Security

AttributeValueEvidence
Scorecard5.9highsource · 2026-08-26 · 90%
VulnerabilitiesCount: 0 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=go&package_name=github.com%2Fmeta-llama%2FPurpleLlama&per_page=100 · Last 12m: 0highsource · 2026-08-26 · 90%