18 open-source AI Security vendors
Open-source software for AI Security that you can self-host, with auditable source code — regardless of the developer's headquarters.
- vendors scored
- 18
- European
- 3
- foreign-owned
- 4
- last checked
- 10 October 2026
Vendors, scored
Score per vendor: 0 = high exposure, 100 = sovereign
Sort
- Sovereignty score 92 out of 100Mistral ShieldstralFrance · Self-hosted / open source3B-parameter policy-adaptive safety classifier released by Mistral AI (France) under Apache 2.0 as open weights, for on-device content moderation. Mistral AI is a real company, so not a controlling-company-free project despite the open licence.
- Sovereignty score 92 out of 100TaoQ AINetherlands · Self-hosted / open sourceApplied AI research and engineering company specialising in AI security, agent red-teaming, and EU AI Act conformity with open-source security testing frameworks for intelligent systems.
- Sovereignty score 82 out of 100GiskardFrance · EU sovereignFrench open-source platform for AI testing, red-teaming and guardrails.
- Sovereignty score 69 out of 100Adversarial Robustness ToolboxUnited States · Self-hosted / open sourceOpen-source (MIT) Python library for machine learning security: attacks and defences against evasion, poisoning, extraction and inference; hosted under LF AI & Data.
- Sovereignty score 69 out of 100Garak (NVIDIA)United States · Self-hosted / open sourceOpen-source LLM vulnerability scanner from NVIDIA's AI Red Team probing for hallucinations, data leakage, prompt injection, and jailbreaks across 50+ probe modules. Controlled by NVIDIA, not a community-governed project.
- Sovereignty score 69 out of 100Langkit (WhyLabs)United States · Self-hosted / open source · owner in United StatesLangKit is WhyLabs' open-source toolkit for monitoring LLMs, extracting signals such as toxicity, PII, sentiment and jailbreak detection from prompts and responses; WhyLabs discontinued its commercial platform but LangKit remains available as open source.
- Sovereignty score 69 out of 100LLM Guard (Protect AI)United States · Self-hosted / open source · owner in United StatesLLM Guard is an open-source security toolkit from Protect AI (now part of Palo Alto Networks) offering input/output scanners against prompt injection, data leakage and harmful language in LLM applications.
- Sovereignty score 69 out of 100NVIDIA NeMo GuardrailsUnited States · Self-hosted / open sourceOpen-source toolkit from NVIDIA for adding programmable guardrails to LLM conversational systems, with support for self-hosted deployments. Controlled by NVIDIA, not a community-governed project.
- Sovereignty score 69 out of 100Portkey AIUnited States · Self-hosted / open source · owner in United StatesPortkey AI (San Francisco, US; acquired by Palo Alto Networks in 2026 for Prisma AIRS) is an open-source AI gateway with 60+ guardrails against jailbreaks, prompt injection and PII leakage.
- Sovereignty score 69 out of 100Presidio (Microsoft)United States · Self-hosted / open source · owner in United StatesPresidio is Microsoft's open-source framework for detecting, redacting and anonymizing personal data (PII) in text, images and structured data, widely used to prevent PII leakage in LLM pipelines.
- Sovereignty score 69 out of 100Project AsagoUnited States · Self-hosted / open sourceRed Hat-initiated open-source project (August 2026, Apache 2.0) translating NIST AI RMF, OWASP LLM Top 10 and EU AI Act requirements into technical governance controls for AI agents; participants include Red Hat, NVIDIA, IBM Research, MIT Lincoln Laboratory, Microsoft and the Alan Turing Institute — no single controlling party.
- Sovereignty score 69 out of 100VigilUnited States · Self-hosted / open sourceVigil is an open-source Python library and REST API (by researcher deadbits/Adam Swanda) that scans LLM prompts and responses for prompt injection, jailbreaks and prompt leakage; experimental alpha status with limited active maintenance.
- Sovereignty score 57 out of 100DeepchecksIsrael · Non-EU vendorOpen-source ML validation platform from Israeli company Deepchecks (Tel Aviv) providing comprehensive data and model testing from research to production.
- Sovereignty score 49 out of 100AktoUnited States · Non-EU vendorUS AI agent security platform: discovery, testing, red-teaming, posture management and guardrails for AI agents and APIs.
- Sovereignty score 49 out of 100Evidently AIUnited States · Non-EU vendorOpen-source ML and LLM observability framework for evaluating, testing, and monitoring AI systems and data pipelines with 100+ built-in metrics; backed by a real company, not a controlling-company-free project.
- Sovereignty score 49 out of 100Guardrails AIUnited States · Non-EU vendorOpen-source Python framework for validating and structuring LLM outputs with 50+ pre-built validators and an optional managed service with observability dashboards.
- Sovereignty score 49 out of 100PromptfooUnited States · Non-EU vendorOpen-source MIT-licensed LLM evaluation and red-teaming framework for testing prompts, models, and RAG pipelines, backed by a real VC-funded company.
- Sovereignty score 49 out of 100PyRIT (Microsoft)United States · Non-EU vendorOpen-source Python Risk Identification Tool from Microsoft enabling red team exercises to proactively identify risks in generative AI systems with multi-modal attack support. Controlled by Microsoft, not a community-governed project.
Assess your own stack in the assessment
Assess your stack →