18 open-source AI Security vendors.
Open-source software for AI Security that you can self-host, with auditable source code — regardless of the developer's headquarters.
- Arize AI / PhoenixNon-EU vendor
Arize AI (Berkeley, US) builds the Arize AX platform and the open-source Phoenix library for LLM observability and evaluation, with an EU data-residency option.
United States
- DeepchecksNon-EU vendor
Open-source ML validation platform from Israeli company Deepchecks (Tel Aviv) providing comprehensive data and model testing from research to production.
Israel
- Evidently AINon-EU vendor
Open-source ML and LLM observability framework for evaluating, testing, and monitoring AI systems and data pipelines with 100+ built-in metrics; backed by a real company, not a controlling-company-free project.
United States
- Garak (NVIDIA)Non-EU vendor
Open-source LLM vulnerability scanner from NVIDIA's AI Red Team probing for hallucinations, data leakage, prompt injection, and jailbreaks across 50+ probe modules. Controlled by NVIDIA, not a community-governed project.
United States
- GiskardEU sovereign
French open-source platform for AI testing, red-teaming and guardrails.
France
- Guardrails AINon-EU vendor
Open-source Python framework for validating and structuring LLM outputs with 50+ pre-built validators and an optional managed service with observability dashboards.
United States
- Langkit (WhyLabs)Self-hosted / open source
LangKit is WhyLabs' open-source toolkit for monitoring LLMs, extracting signals such as toxicity, PII, sentiment and jailbreak detection from prompts and responses; WhyLabs discontinued its commercial platform but LangKit remains available as open source.
United States · owner in United States
- Llama Guard (Meta)Non-EU vendor
LLM-based safety classifier from Meta with customisable content moderation for text and image understanding across modalities. Controlled by Meta (Llama Community License), not a community-governed project.
United States
- LLM Guard (Protect AI)Self-hosted / open source
LLM Guard is an open-source security toolkit from Protect AI (now part of Palo Alto Networks) offering input/output scanners against prompt injection, data leakage and harmful language in LLM applications.
United States · owner in United States
- Mistral ShieldstralSelf-hosted / open source
3B-parameter policy-adaptive safety classifier released by Mistral AI (France) under Apache 2.0 as open weights, for on-device content moderation. Mistral AI is a real company, so not a controlling-company-free project despite the open licence.
France
- NVIDIA NeMo GuardrailsNon-EU vendor
Open-source toolkit from NVIDIA for adding programmable guardrails to LLM conversational systems, with support for self-hosted deployments. Controlled by NVIDIA, not a community-governed project.
United States
- Portkey AISelf-hosted / open source
Portkey AI (San Francisco, US; acquired by Palo Alto Networks in 2026 for Prisma AIRS) is an open-source AI gateway with 60+ guardrails against jailbreaks, prompt injection and PII leakage.
United States · owner in United States
- Presidio (Microsoft)Self-hosted / open source
Presidio is Microsoft's open-source framework for detecting, redacting and anonymizing personal data (PII) in text, images and structured data, widely used to prevent PII leakage in LLM pipelines.
United States · owner in United States
- Project AsagoSelf-hosted / open source
Red Hat-initiated open-source project (August 2026, Apache 2.0) translating NIST AI RMF, OWASP LLM Top 10 and EU AI Act requirements into technical governance controls for AI agents; participants include Red Hat, NVIDIA, IBM Research, MIT Lincoln Laboratory, Microsoft and the Alan Turing Institute — no single controlling party.
United States
- PromptfooNon-EU vendor
Open-source MIT-licensed LLM evaluation and red-teaming framework for testing prompts, models, and RAG pipelines, backed by a real VC-funded company.
United States
- PyRIT (Microsoft)Non-EU vendor
Open-source Python Risk Identification Tool from Microsoft enabling red team exercises to proactively identify risks in generative AI systems with multi-modal attack support. Controlled by Microsoft, not a community-governed project.
United States
- TaoQ AISelf-hosted / open source
Applied AI research and engineering company specialising in AI security, agent red-teaming, and EU AI Act conformity with open-source security testing frameworks for intelligent systems.
Netherlands
- VigilSelf-hosted / open source
Vigil is an open-source Python library and REST API (by researcher deadbits/Adam Swanda) that scans LLM prompts and responses for prompt injection, jailbreaks and prompt leakage; experimental alpha status with limited active maintenance.
United States