You should not have to trust us
An instrument nobody can inspect is a vendor’s opinion, and an opinion is not evidence in front of a regulator. So the taxonomy is published, the detectors are open-weight and on Hugging Face, the probes are versioned with their seeds, and the method is open for anyone outside this company to check. Credentials ask you to trust us. This page is the argument that you need not. If you answer for what an agent does, that is the difference between a number you can put in front of a regulator and one you cannot.
What we work on
Published work
Each of these underwrites a mechanism you can go and check on a product page.
Published by Vijil researchers, and not part of the platform.
| Guardrail | Trust Score uplift | p50 call | p95 call |
|---|---|---|---|
| GCP Model Armor | +19.7 | 227.9 | 543.2 |
| Vijil Dome (Q3 ’26) | +17.6 | 20.7 | 55.9 |
| DeBERTa prompt injection | +15.7 | 24.1 | 47.9 |
| AWS Bedrock Guardrails | +14.0 | 320.7 | 495.4 |
| Vijil Dome (Q1 ’26) | +13.4 | 23.1 | 66.2 |
| Nvidia NemoGuard | +12.7 | 178.5 | 231.7 |
| Meta PromptGuard 2 | +3.6 | 24.7 | 57.1 |
Where it loses. GCP Model Armor scores a higher uplift than we do, +19.7 against our +17.6, and DeBERTa returns a lower p95 than we do, 47.9ms against our 55.9ms. On this table we are not the top line. On the report’s separate accuracy run over the same 15,000-prompt set, balanced accuracy is 97.7% against GCP’s 72.6% — a different measurement, stated separately because it is measured separately.
Where it wins. The combination. Dome is the most accurate guardrail on the curated set at 97.7% balanced accuracy, 25 points above GCP’s 72.6%. GCP is the one guardrail here that scores a higher trust uplift, and it spends 227.9ms at the median to do it against our 20.7ms. The only guardrail with a lower p95 than ours, DeBERTa at 47.9ms, reaches 62.0% accuracy. A guard in the request path is judged on both, because a fast guard that misses the attack is not protecting anything.
One limitation, stated plainly: the uplift column is measured with our own Trust Score, so we are scoring competitors with our instrument. The latency columns are not ours — they are wall clock, on the same hardware, through the same standard APIs.
Try to beat our detector
Benchmark our prompt-injection detector against yours. It is on Hugging Face, it is small enough to run on your own hardware, and we would rather hear where it loses than where it wins — which is the only kind of marketing this page’s readers should accept.