Skip to content
aicoolies logo
LLM Guard logo

LLM Guard

Input and output security scanners for LLM applications

LLM Guard is an open-source security toolkit by Protect AI that provides 15 input scanners and 20 output scanners to protect LLM applications from prompt injection, PII leakage, toxic content, secrets exposure, and data exfiltration. Each scanner is modular and independent — pick the ones you need, configure thresholds, and chain them into a pipeline. The library works with any LLM and has been downloaded over 2.5 million times. MIT licensed, Python 3.9+.

About LLM Guard

LLM Guard sits as a middleware layer between your application and its language model, scanning both inbound prompts and outbound responses against configurable security rules. The 15 input scanners handle prompt injection detection using a fine-tuned DeBERTa model, PII anonymization that replaces names, emails, phone numbers, and credit card numbers with placeholders, toxicity filtering, secrets detection via Yelp's detect-secrets library, ban lists for competitors, substrings, topics, and code, invisible text detection for Unicode-based attacks, token limit enforcement, and language restriction. Each scanner returns a sanitized version of the text, a validity flag, and a risk score between 0 and 1.

The 20 output scanners cover the response side: deanonymization to restore PII placeholders after processing, bias detection, relevance scoring against the original prompt, factual consistency checking, malicious URL detection and reachability verification, sensitive data exposure prevention, no-refusal detection to catch when the model inappropriately refuses valid requests, language detection, and code output filtering by programming language. Scanners are composable through scan_prompt and scan_output functions that execute them in sequence with an optional fail_fast mode that stops at the first violation. The entire pipeline can be deployed as a standalone API server for team-wide use.

LLM Guard is engineered for cost-effective CPU inference — the team claims 5x lower inference costs on CPU compared to GPU — which matters for production deployments where scanning runs on every request. The toolkit integrates with any LLM framework including LangChain, Azure OpenAI, and Amazon Bedrock since it operates on text strings rather than model internals. Protect AI hosts an interactive playground on Hugging Face Spaces for testing scanners without installation. The latest release is v0.3.16, and while the release cadence has slowed from its initial rapid development, the scanner collection remains one of the most comprehensive open-source LLM security toolkits available.

Pricing & Platform Specs

Pricing Summary

Open-source security toolkit and LLM firewall under the MIT License ($0 software cost). Runs entirely self-hosted as a local Python package or containerized microservice without mandatory cloud dependencies or telemetry fees. Commercial Protect AI enterprise platforms (Guardian, Recon, ModelScan) are available under custom enterprise contracts.

full pricing breakdown →

Supported Platforms

Python 3.9+, pip, standalone API server, CPU-optimized inference

Explore categories, tags & use cases

Security scanner for MCP servers against tool poisoning attacks

MCP-Scan is a security tool that scans MCP servers for vulnerabilities including tool poisoning, prompt injection, cross-origin escalation, and rug pull attacks. Acquired by Snyk in 2026, it is the first dedicated security scanner for the MCP ecosystem. It analyzes tool descriptions, permissions, and behavior patterns to detect malicious or compromised MCP servers before they can exploit AI agents.

Open Source

Autonomous AI pentester for web apps and APIs

Shannon is an autonomous white-box AI pentesting tool for web applications and APIs. It analyzes authorized source code, identifies attack vectors, attempts proof-by-exploitation, and produces remediation-ready reports. Shannon Lite is AGPL-3.0 for local use, while Shannon Pro is the commercial Keygraph platform for continuous security testing.

freemiumOpen Source

Side-by-Side Comparisons

LLM Guard logo
LLM Guard
vs
Guardrails AI logo
Guardrails AI

LLM Guard vs Guardrails AI: Runtime Scanning or Structured Output Guards?

Guardrails AI is the stronger default when a team needs reusable validators, structured-output enforcement, and repair loops across agent and RAG workflows. LLM Guard is still the sharper fit for teams that want lightweight request-and-response scanner middleware around prompt injection, secrets, toxicity, and PII risk.

LLM GuardGuardrails AI
ModelScan logo
ModelScan
vs
LLM Guard logo
LLM Guard
vs
garak logo
garak

ModelScan vs LLM Guard vs Garak — AI Model Security Comparison

AI model security addresses threats at different layers of the ML lifecycle. ModelScan from Protect AI detects malicious code embedded in serialized model files before deployment, protecting against model supply chain attacks. LLM Guard acts as a real-time firewall for LLM applications, scanning prompts and responses to block injection attacks and data leakage. Garak is an LLM vulnerability scanner that probes models for weaknesses through automated red-teaming and adversarial testing.

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is LLM Guard?

LLM Guard is an open-source security toolkit by Protect AI that provides 15 input scanners and 20 output scanners to protect LLM applications from prompt injection, PII leakage, toxic content, secrets exposure, and data exfiltration. Each scanner is modular and independent — pick the ones you need, configure thresholds, and chain them into a pipeline. The library works with any LLM and has been downloaded over 2.5 million times. MIT licensed, Python 3.9+.

Is LLM Guard free?

Yes — LLM Guard is free to use. Open-source security toolkit and LLM firewall under the MIT License ($0 software cost). Runs entirely self-hosted as a local Python package or containerized microservice without mandatory cloud dependencies or telemetry fees. Commercial Protect AI enterprise platforms (Guardian, Recon, ModelScan) are available under custom enterprise contracts.

Is LLM Guard open source?

Yes — LLM Guard is open source.

Is LLM Guard still maintained?

Yes — LLM Guard is active. Its listing was last verified on September 6, 2026.

What are the best LLM Guard alternatives?

The first editor-selected LLM Guard alternatives are MCP-Scan, Shannon.