Favicon of NeMo Guardrails

NeMo Guardrails

A self-hosted LLM guardrails toolkit for Python apps. Control conversations, check model responses, and connect to LLaMa-2, Falcon or OpenAI models.

NeMo Guardrails is an open-source Python toolkit for developers who need control over how an AI assistant responds and uses tools. It runs within your application or as a self-hosted server, including in Docker. The library uses the Apache 2.0 license.

Its distinctive feature is programmable conversation control. Colang, its dialog language, lets developers define conversational paths for tasks such as authentication or customer support, restrict topics, and decide when particular checks should apply. Fact-checking can target specific kinds of questions rather than every exchange.

Checks cover user messages, retrieved documents, tool calls and results, and generated answers. They can reject content or mask sensitive information before it reaches the model or the user. Built-in checks address prompt injection and jailbreak attempts, content moderation, factual accuracy and hallucinations. NVIDIA safety models and integrations with ActiveFence, PolicyAI and AlignScore provide additional checking options. An evaluation tool tests topic restrictions, moderation and factual checks.

The toolkit works with models including LLaMa-2, Falcon and Vicuna, as well as OpenAI GPT models. It also integrates with LangChain applications. You host the guardrails layer yourself; requests sent to external inference or checking services fall under those services' privacy practices. The library sends anonymous usage telemetry to NVIDIA unless you opt out. That telemetry includes deployment and feature information, but excludes prompts, completions and API keys.

Similar to NeMo Guardrails