Guardana is an open-source AI security framework built to adapt to your system. Use 47 built-in checks or add your own YAML/Python rules, evaluators and targets for application-specific risks. Scan artifacts, probe models, agents and MCP servers, analyze real execution traces and block releases on security regressions. Run it locally, in pytest or CI/CD — no mandatory cloud, account or telemetry.
Hey Product Hunt 👋
Guardana actually started as something we needed for our own work.
While building and running our own AI models and AI-powered systems across different projects, I kept looking for a security framework that we could adapt to the way we actually build.
I didn’t want just another fixed scanner or a large collection of jailbreak prompts.
I wanted something we could use as a security framework around the whole development lifecycle:
— a solid set of security checks out of the box
— the ability to add our own rules for project-specific risks
— custom evaluators when generic grading simply isn’t enough
— support for different models, agents and infrastructure
— something we could run locally during development
— put into pytest and CI/CD as an actual security gate
— and keep using against deployed systems afterwards
Most importantly, we needed to be able to adapt the security logic to the actual application.
Because a healthcare agent, an internal company assistant, a coding agent and an AI system with access to production tools do not have the same threat model.
That became Guardana.
Today Guardana is an Apache-2.0 open-source AI security verification framework covering multiple layers of an AI system:
🛡️ Build-time security
Scan model files, repositories, dependencies, prompts, templates and supply-chain risks.
🎯 Runtime verification
Probe live models and agents for prompt injection, jailbreaks, unsafe behavior and tool-related vulnerabilities.
🔌 MCP security
Verify MCP servers and parts of their authorization and tool surface.
🔎 Execution trace analysis
Analyze what an AI system actually did — model calls, tools, retrieval, identities and scopes, approvals, memory and side effects.
↔️ Security regression testing
Compare releases and detect when a change to a model, prompt, tool or deployment makes the system less secure.
🧩 Extensibility
Create your own rules, evaluators, targets and private security packs without having to fork the project.
And the same engine can be used from the CLI, pytest, CI/CD or scheduled health checks.
One design principle has remained important from the beginning:
“Couldn’t verify” must never silently mean “secure.”
If an evaluator cannot determine the outcome, a capability is missing, the target is unavailable or the test cannot execute correctly, Guardana keeps that uncertainty visible instead of quietly producing a green check.
We built Guardana because we wanted this flexibility for our own AI projects.
Now we’re opening it up because I suspect many other teams are running into the same problem: generic security checks are useful, but sooner or later every serious AI system needs security rules that understand its own architecture, permissions, tools and business logic.
Guardana is:
— Apache-2.0
— no account required
— no mandatory telemetry
— no mandatory cloud
— designed for private and self-hosted environments
— extensible with your own security logic
We’ve already shipped 14 small releases and we’re still moving quickly.
I’d especially love feedback from people building real AI systems:
What project-specific security rule or evaluator would you need before you could use something like Guardana as a real deployment gate?
And if you’re running self-hosted models, agents, MCP servers or your own AI infrastructure, I’d love to hear where Guardana still falls short.
Report
No reviews yetBe the first to leave a review for Guardana