Back to vendors
G

Guardrails AI

Visit site
Entry priceOpen source (Apache 2.0) · hosted products by conversationFull pricing detail

Open source framework for validating and correcting LLM inputs and outputs with guards built from a hub of prebuilt validators, plus Snowglobe, a simulation product that stress-tests agents with synthetic users before launch.

Guardrails AI makes the open source Guardrails framework and Snowglobe, a simulation product for testing agents. Harvey, the legal AI company, announced its acquisition of Guardrails AI on September 8, 2026, with the co-founders and team joining Harvey's product and engineering organization; guardrailsai.com still offers both products.

Guardrails is a Python framework, Apache 2.0 licensed, that runs input and output guards around LLM calls to detect, quantify and mitigate specific risks, and helps generate structured data. Guards are built from validators in the Guardrails Hub, a catalog covering PII, jailbreaks, prompt injection, toxicity, bias, competitor mentions, provenance, format checks and more, each with an on-fail action.

A Guard can call 100+ models through its LiteLLM integration with the customer's own keys, runs in the application or as a self-hosted Guardrails Server, and emits OpenTelemetry traces and metrics on guard and validator performance to Grafana, Splunk or any OTLP endpoint. The free hosted remote inference service for validators ended in August 2026.

Snowglobe simulates realistic synthetic users against a customer's agent, generating evaluation datasets aimed at edge cases so teams can quantify failure modes before launch, along with synthetic data for fine-tuning and prompt optimization.

It fits engineering teams that want code-level control over output validation and a way to stress-test agents before release. It is a validation and testing layer, not an agent builder: it does not orchestrate workflows, retrieve knowledge, give agents memory or connect them to business systems. The framework is free; no price is published for Snowglobe or any hosted service.

Vendor details

Canonical URL

https://guardrailsai.com

Category

Agent infrastructure

Subcategory

Guardrails and validation

Funding status

Raised a $7.5M seed round in February 2024 from Zetta Venture Partners, Bloomberg Beta and Pear VC; the acquisition announcement also names Factory and Microsoft as investors. Harvey announced its acquisition of Guardrails AI on September 8, 2026.

Company status

acquired

Use cases & customers

Primary use cases

LLM input and output validationguardrails and safetyPII and prompt injection detectionstructured data generationagent simulation and pre-launch evaluation

Target customers

developersenterprise

Deployment options

self-hostedSaaS

Integrations

Calls 100+ LLMs through its LiteLLM integration with the customer's own keys, documents a LangChain integration, and exports OpenTelemetry traces and metrics to Grafana, MLflow, Arize, New Relic, Prometheus, Splunk or any OTLP endpoint. Validators are listed in the Guardrails Hub.

In practice

Your customer service bot occasionally leaks a customer's email or says something toxic. You wrap the LLM call in a Guardrails guard that runs PII detection and toxicity validators and stops any response that fails.

You need the model to return strict JSON your code can parse, but it sometimes returns prose. You define a Pydantic schema and a Guardrails guard that enforces the structure.

You are about to launch a support agent and want to know where it breaks first. You run Snowglobe's synthetic users against it to surface failure modes before real customers do.

Agentic Index coverage score

7.0 / 14 capabilities · 50%

Integrations & Tool Calling Partial

The framework connects to 100+ LLMs through LiteLLM, documents a LangChain integration and sends telemetry to Grafana, MLflow and Arize. These wrap model calls and move telemetry out; no connector lets an agent take authenticated action in an outside system. Validators that check SQL, URLs or code inspect what an agent produced rather than letting it act.

SourceGuardrails AI, guardrailsai.com/guardrails/docs/how-to-guides/using_llms, /guardrails/docs and /guardrails/docs/concepts/telemetryread 2026-09-25

Workflow Orchestration Not documented

A guard chains validators around one LLM call, which is a validation pipeline, not work in several steps or across agents; the customer's own code or framework, LangChain for example, runs the workflow. No workflow model is documented.

SourceGuardrails AI, guardrailsai.com/guardrails/docsread 2026-09-25

Knowledge Grounding & RAG Not documented

Inputs and outputs of an LLM call are checked, but the customer's documents are not indexed or retrieved for an agent to ground on. Provenance and relevance validators score an answer against sources the customer supplies, which checks output rather than providing a retrieval structure.

SourceGuardrails AI, guardrailsai.com/guardrails/docs and /hubread 2026-09-25

Human Oversight & Guardrails Full

Input and output guards run in the customer's application to detect, quantify and mitigate specific risks. They are built from validators for attacks and leaks (Detect Jailbreak, Detect Prompt Injection, Detect System Prompt Leakage, Detect PII and Secrets Present) and for content and scope (Toxic Language, Llama Guard, ShieldGemma and Restrict to Topic), each with an action on failure; the telemetry guide's example raises an exception. These guardrails stop an output outright; no human approval step is documented.

SourceGuardrails AI, guardrailsai.com/guardrails/docs, /hub and /guardrails/docs/concepts/telemetry; guardrailsai.com/hubread 2026-09-25

Security, Identity & Governance Partial

A SafeBase trust center at trust.guardrailsai.com lists SOC 2 and HIPAA items, with the type and report behind the portal. No access surface is documented: the framework runs inside the customer's own code, and no roles, permissions, SSO or SAML for Snowglobe or any hosted service appear. The security validators for PII, prompt injection and secrets are guardrails on outputs, not access controls.

SourceGuardrails AI, trust.guardrailsai.com and guardrailsai.com/guardrails/docsread 2026-09-25

Observability & Auditability Partial

OpenTelemetry instruments the framework: traces and metrics cover guard and LLM latency, guard success rates and validator pass and fail rates, with deep dives into single guard and validator calls, exportable to any OTLP endpoint such as Grafana, New Relic, Prometheus or Splunk, or a self hosted collector.

That covers export to existing monitoring and part of step by step inspection, but only for the guard layer the customer wraps around its LLM calls. No audit log separate from traces is documented, and no hosted dashboard or retention by plan; the Guardrails Pro dashboard does not appear on the current site.

SourceGuardrails AI, guardrailsai.com/guardrails/docs/concepts/telemetryread 2026-09-25

Memory & State Persistence Not documented

Guards validate each call on its own and keep nothing an agent reads as context later. No memory layer or state across runs is documented.

SourceGuardrails AI, guardrailsai.com/guardrails/docsread 2026-09-25

Deployment & Data Residency Full

The framework is Apache 2.0 open source, as the repository LICENSE confirms, and runs wherever the customer runs it: inside the application or as a self hosted Guardrails Server, with telemetry able to go to a collector inside the customer's own VPC. The change log records that the free hosted remote inference service for validators was discontinued in August 2026, so self hosting is how the framework is deployed.

SourceGuardrails AI, guardrailsai.com/guardrails/docs, /guardrails/docs/concepts/telemetry and the repository LICENSEread 2026-09-25

Prebuilt Agents, Templates & Packs Partial

The Hub is a browsable catalog of prebuilt validators that the customer combines into its own guards, with ban list, toxicity, bias, competitor check, jailbreak, PII, prompt injection, provenance and valid JSON among dozens more. They are components the customer assembles, not packaged agents or workflows a buyer adopts as working units.

SourceGuardrails AI, guardrailsai.com/hubread 2026-09-25

Triggers & Channel Coverage Not documented

Guards run inline when the customer's code calls them, or when an application calls a self hosted Guardrails Server; nothing wakes on a schedule, webhook or channel event.

SourceGuardrails AI, guardrailsai.com/guardrails/docsread 2026-09-25

Model Flexibility & Routing Full

A Guard takes a model property and the customer's own API key in Guardrails' call API, and it supports 100+ LLMs, OpenAI and Anthropic among them, through its built in LiteLLM integration, with streaming and tool calling. So the customer picks the provider inside the vendor's own SDK.

SourceGuardrails AI, guardrailsai.com/guardrails/docs/how-to-guides/using_llmsread 2026-09-25

APIs, SDKs & MCP Extensibility Full

As a Python framework, its SDK is the product's interface: Guard objects, validators and actions on failure are documented with an API reference, and a Guardrails Server quickstart covers running guards as a standalone service. No MCP server is documented.

SourceGuardrails AI, guardrailsai.com/guardrails/docs (introduction, Guardrails Server quickstart, API reference)read 2026-09-25

Testing, Debugging & Optimization Full

Snowglobe, Guardrails AI's simulation product, generates evaluation datasets aimed at edge cases and risky outcomes, simulates large numbers of realistic synthetic users against the customer's agent, and quantifies failure modes before real users meet them. So the customer's agent is tested against datasets before production. Hub validators such as LLM Critic, Response Evaluator and QA Relevance also grade outputs against criteria.

SourceGuardrails AI, guardrailsai.com homepage and /blog/guardrails-ai-joins-harvey, and /hubread 2026-09-25

Browser & Computer Use Not documented

Neither the input and output validators nor Snowglobe's simulated users operate a browser or computer, and no capability of that kind is documented.

SourceGuardrails AI, guardrailsai.com homepage and /guardrails/docsread 2026-09-25

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-06·Deployment / data residencyVerified

Guardrails AI finalized the discontinuation of its free hosted remote inferencing service for validators. Concurrently, the company migrated Guardrails validators to standard PyPI packages, allowing developers to install them directly via pip rather than using the legacy Guardrails Hub CLI.

Bears on: Deployment / data residency

View source
View all 1 change for Guardrails AI →Tracked since Aug 2026 · Verified from public vendor sources

Pricing

Open source (Apache 2.0) · hosted products by conversation

Open source is free; managed Pro billing is not publicly disclosed

Free tier

Included quota

The open source framework is fully free and self hosted with no usage limits you run yourself. Guardrails Pro limits and quotas are not publicly listed.

What is public

The open source framework, the Apache 2.0 license, the Guardrails Hub and the self-hosting path are public and free. No hosted price is published.

Billing mechanics

The open source framework carries no license fee; you run it yourself and pay only for the compute it consumes. No price or billing unit is published for Snowglobe or any hosted service.

Cost watchouts

Validators that load local models need memory and GPU or CPU, and each validator adds latency to the request path. The change log records that the free hosted remote inference service for validators was discontinued in August 2026, so that compute now runs on the customer's side.

Variable cost rationale

Self hosting the open source framework has no license cost; the variable cost is the compute to run validators, now on the customer's side since hosted remote inference ended. Hosted product costs are not disclosed.

Additional watchouts

Harvey announced its acquisition of Guardrails AI on 8 September 2026 and the team is joining Harvey's product and engineering organization, so check the roadmap for the framework and Snowglobe before committing. Running validators at scale needs compute and observability you manage yourself.

Overage / add-ons

Not applicable to the self hosted open source framework. Managed Pro terms are not disclosed.

Sales call required

No, self serve available

Free / trial

Free and open source under Apache 2.0; pip install, self host

Lowest paid plan

None published; guardrailsai.com/pricing returns 404 and the homepage routes buyers to a call

Commercial notes

Open source led adoption among Python developers via pip and the validator hub, with a managed Pro tier and enterprise support as the commercial upgrade. Positioned to enterprises, startups, and government agencies.

Key ambiguities

Whether a managed Guardrails tier is still sold: guardrailsai.com/pricing returns 404 and the current homepage names only Snowglobe and the framework. Snowglobe's price and billing unit are not published.

Cancellation / refund

The open source framework has no contract. Guardrails Pro terms are arranged with the vendor.

Support SLA / resale

Community support for the open source framework; enterprise support and SLA on Guardrails Pro.

Missing data

Snowglobe pricing, any managed Guardrails tier and enterprise terms. The pricing page returns 404.

Agentic Index verified 2026-09-25

Alternatives to Guardrails AI

The closest documented capability profiles to Guardrails AI among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.