Giskard
Open-source LLM red teaming, now with an EU guardrail layer.
Overview
Paris-based open-source (Apache 2.0) scanner and enterprise Hub for red-teaming and evaluating LLMs and AI agents against OWASP, MITRE ATLAS and NIST risks. May 2026's Giskard Guards adds an EU-sovereign runtime guardrail for production agents.
Pricing
Pricing shown for reference only. These figures reflect RECATOOLS research as of 11 Jul 2026 and may be out of date or incomplete. This is not financial or purchasing advice — always confirm the current price on the provider’s official website before making any decision.
- 50+ attack probes
- Local scans
- No SSO/collaboration
- Continuous red teaming
- RAG evaluation
- SSO + team collaboration
- On-prem option
Use cases
What you can produce with Giskard
- Automated vulnerability scan report covering 40-50+ adversarial probe categories with risk prioritisation
- RAGET-generated RAG test dataset with correctness, groundedness, and relevance scores
- CI/CD pipeline integration that gates LLM model deployments on passing safety thresholds
- SOC 2 Type II and HIPAA-compliant enterprise platform with RBAC, audit trails, and SSO
- On-premise or private-cloud Giskard Hub deployment with EU data residency option
- Real-time runtime guardrail blocking for production AI agents via Giskard Guards (2026)
- Structured red teaming report aligned to OWASP Top 10 for LLMs, MITRE ATLAS, and NIST AI RMF
ASEAN Perspective
Giskard in Southeast Asia
Giskard's compliance posture — SOC 2 Type II, HIPAA, and GDPR alignment — maps reasonably well onto Singapore's MAS TRM Guidelines and emerging AI governance frameworks in Malaysia and Thailand, making it a defensible choice for ASEAN financial institutions deploying LLM-powered customer-facing tools. However, the company has no disclosed regional office, data centre, or named customer in Southeast Asia, and its EU-sovereign infrastructure focus means ASEAN teams may face data residency friction for markets with strict localisation rules such as Indonesia. The open-source tier is freely available to ASEAN developers and is used indirectly through Databricks' AI Red-teaming toolkit, which has broader APAC distribution. Organisations with cross-border EU-ASEAN operations will find Giskard's compliance depth useful, but pure ASEAN deployments should evaluate whether on-premise self-hosting (supported) adequately addresses local data sovereignty requirements.
Giskard's free, Apache 2.0 scanner (5,200+ GitHub stars) covers 50+ adversarial attack types mapped to OWASP, MITRE ATLAS and NIST — genuinely rare generosity in AI security tooling, where most competitors gate everything behind a sales call. Its GOAT-derived multi-turn jailbreak technique demonstrated a 97% attack success rate against Llama 3.1 in five turns, and enterprise Hub customers (AXA, BNP Paribas, Michelin, Google DeepMind, Doctolib) validate production use. May 2026's Giskard Guards — an EU-sovereign runtime guardrail with on-premise deployment and EU AI Act compliance packs — is a genuine move into full-lifecycle agent security.
Hub pricing is entirely sales-gated, the OSS scanner needs your own LLM API key so scan costs stack on top of any Giskard fee, and named customers skew hard toward European finance and manufacturing with no ASEAN presence. Best fit for compliance-heavy EU and global enterprises; solo developers get real value from the free library alone.
What people say
Giskard's open-source scanner (Apache 2.0, 5,200+ GitHub stars) is free to run against your own models, unusual generosity in AI security tooling where most competitors gate everything behind a demo call. It covers 50+ adversarial attack types mapped to OWASP, MITRE ATLAS and NIST, and the GOAT multi-turn jailbreak technique it absorbed from Meta's own research demonstrated a 97% attack success rate against Llama 3.1 in five turns — a data point that says as much about frontier model fragility as it does about Giskard's tooling.
Enterprise customers are the real validation: AXA, BNP Paribas, Michelin, Google DeepMind and Doctolib all use the paid Hub for continuous red teaming, RAG evaluation and SSO-gated team collaboration. May 2026's Giskard Guards launch — an EU-sovereign runtime guardrail platform with on-premise deployment and ready-made EU AI Act compliance packs — pushes the company from pre-production testing into full-lifecycle agent security, a genuinely differentiated move for a Paris-based vendor.
Hub pricing is entirely sales-gated with no published numbers, the OSS scanner needs your own LLM API key to run (so scan costs stack on top of any Giskard fee), and named customers skew hard toward European finance and manufacturing — no ASEAN logos, no regional infrastructure. Best fit for compliance-heavy EU and global enterprises building production LLM agents; solo developers get real value from the free library alone.
Summary of public user & expert reviews, compiled by RECATOOLS.
Notable facts
- Giskard is named after R. Giskard Reventlov, an Asimov robot programmed to protect humanity — a deliberate nod to the founders' AI safety mission.
- The GOAT multi-turn jailbreaking technique Giskard implements in its scanner was originally developed by Meta researchers, achieving 97% attack success on Llama 3.1 — Giskard built the tooling that operationalises it commercially.
- Giskard received a EUR 3M strategic investment from the European Commission EIC Accelerator, one of few AI security startups to receive EU public funding at that scale.
- The OSS v3 library (April 2026) was rebuilt entirely from scratch, dropping scikit-learn and PyTorch as hard dependencies to make it lightweight enough for CI/CD pipelines.
Frequently asked questions
About this listing
This entry was compiled from publicly available data including Giskard's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Giskard unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Giskard directly →
Spotted something out of date? Suggest an update →
Giskard in the news
More in Security & Safety