Skip to content
aicoolies logo
NVIDIA logo

NeMo Guardrails

Programmable safety rails for LLM applications

NeMo Guardrails is NVIDIA's open-source toolkit for adding programmable safety rails to LLM applications. It supports five guardrail types — input, dialog, retrieval, execution, and output rails — covering content safety, jailbreak detection, topic control, PII masking, hallucination detection, and fact-checking. The toolkit uses Colang, a domain-specific language for defining conversational constraints, and integrates with OpenAI, Azure, Anthropic, HuggingFace, and LangChain/LangGraph.

About NeMo Guardrails

NeMo Guardrails is an open-source Python toolkit from NVIDIA with nearly 5,900 GitHub stars that adds programmable safety and control layers to LLM-based conversational systems. Rather than relying solely on model alignment, it provides explicit guardrails that intercept both user inputs and model outputs, applying configurable checks before anything reaches the end user. The toolkit defines five types of rails: input rails that can reject or alter user messages, dialog rails that control conversational flow using Colang (a domain-specific language for state machine-like dialogue definitions), retrieval rails for filtering RAG chunks, execution rails for validating tool calls, and output rails for screening final responses.

The pre-built guardrails cover the most critical LLM vulnerabilities: content safety moderation using NVIDIA's Nemotron Safety Guard models or third-party services like ActiveFence and Cisco AI Defense, jailbreak and prompt injection detection with NemoGuard JailbreakDetect, topic control to keep conversations within defined boundaries, PII detection and masking via GLiNER integration, fact-checking against knowledge bases, and hallucination detection through AlignScore. The IORails engine supports parallel execution of multiple guardrails to minimize latency. A recent integration with Fiddler Guardrails adds low-latency hosted models for additional safety checks. LangGraph integration enables applying guardrails to multi-agent workflows.

NeMo Guardrails works with major LLM providers including OpenAI, Azure OpenAI, Anthropic, Google, and HuggingFace models, plus NVIDIA NIM for local inference. The server exposes an OpenAI-compatible API with a v1/models endpoint, and a GuardrailsMiddleware enables integration with LangChain agents. For production deployments, NVIDIA offers NeMo Guardrails as a microservice container image designed for Kubernetes with Helm charts. The toolkit includes evaluation tools for measuring accuracy of content moderation, fact-checking, and jailbreak detection. Python 3.10 through 3.13 is supported, with installation via pip.

Pricing & Platform Specs

Pricing Summary

100% open-source software (Apache-2.0, $0) developed by NVIDIA. Free to self-host and deploy locally or as a containerized microservice alongside any LLM provider or NVIDIA NIM.

full pricing breakdown →

Supported Platforms

Python 3.10-3.13, pip, Docker/Kubernetes microservice, OpenAI-compatible API

Explore categories, tags & use cases

LLM vulnerability scanner and red teaming kit

Agentic Security is an open-source vulnerability scanner for LLM agent workflows that tests AI systems against jailbreaks, fuzzing, and multimodal attacks. It probes weaknesses across text, image, and audio inputs through multi-step jailbreak simulations, randomized stress testing, and reinforcement learning-powered adaptive attacks. The toolkit connects directly to LLM APIs for high-volume real-world attack scenarios, helping developers identify and patch safety gaps before deployment.

Open Source

Agentic AI security posture management

Trent AI is a specialized security platform for agentic AI applications providing AI Security Posture Management that compounds with every development cycle. Scans, judges, mitigates, and evaluates AI agent security detecting threats traditional tools miss including prompt injection attacks, tool misuse, unintended autonomous actions, data exfiltration through agent chains, and privilege escalation. Offers continuous assessment with remediation plan execution through Claude Code.

paid

Microsoft’s public-preview runtime governance toolkit for policy, identity, sandboxing, audit, and MCP security around AI agents.

Agent Governance Toolkit is Microsoft’s MIT-licensed public-preview toolkit for governing AI agent runtimes. It adds policy enforcement, zero-trust identity, execution sandboxing, audit, reliability, and MCP security-gateway patterns around tool calls and autonomous actions, helping platform teams move beyond prompt-only guardrails while preserving architecture review requirements.

Open SourceTelemetry

Side-by-Side Comparisons

Guardrails AI logo
Guardrails AI
vs
NVIDIA logo
NeMo Guardrails

Guardrails AI vs NeMo Guardrails — Output Validation Framework vs Conversational Flow Control

Guardrails AI and NVIDIA NeMo Guardrails both add safety layers to LLM applications, but they solve different problems. Guardrails AI validates structured inputs and outputs with 50+ composable validators. NeMo Guardrails controls conversational flow using Colang DSL to define what topics a bot can discuss and how it responds. Understanding this distinction is critical for choosing the right safety layer for your LLM application.

Guardrails AINeMo Guardrails
ps-fuzz logo
ps-fuzz
vs
garak logo
garak
vs
NVIDIA logo
NeMo Guardrails

ps-fuzz vs Garak vs NeMo Guardrails — Prompt Injection Testing & LLM Security Tools Compared

As LLM-powered applications become production staples, prompt injection and jailbreak attacks represent some of the most dangerous threat vectors. Developers need tools that can systematically test their systems against these attacks before deployment. This comparison examines three distinct approaches to LLM security: ps-fuzz for targeted prompt fuzzing, Garak for comprehensive vulnerability scanning, and NeMo Guardrails for runtime protection and enforcement.

ps-fuzzgarakNeMo Guardrails

Community experience

Sources & verification

Sources checked
Content verified

Verification dates are editorial checks. Routine CMS saves and automatic updatedAt timestamps do not advance them.

FAQ

What is NeMo Guardrails?

NeMo Guardrails is NVIDIA's open-source toolkit for adding programmable safety rails to LLM applications. It supports five guardrail types — input, dialog, retrieval, execution, and output rails — covering content safety, jailbreak detection, topic control, PII masking, hallucination detection, and fact-checking. The toolkit uses Colang, a domain-specific language for defining conversational constraints, and integrates with OpenAI, Azure, Anthropic, HuggingFace, and LangChain/LangGraph.

Is NeMo Guardrails free?

Yes — NeMo Guardrails is open source and free to use. 100% open-source software (Apache-2.0, $0) developed by NVIDIA. Free to self-host and deploy locally or as a containerized microservice alongside any LLM provider or NVIDIA NIM.

Is NeMo Guardrails open source?

Yes — NeMo Guardrails is open source.

Is NeMo Guardrails still maintained?

Yes — NeMo Guardrails is active. Its listing was last verified on September 6, 2026.

What are the best NeMo Guardrails alternatives?

The first editor-selected NeMo Guardrails alternatives are Agentic Security, Trent AI, Agent Governance Toolkit.