Overview
Description
Garak protects your business by automatically stress-testing LLM applications for security vulnerabilities before attackers can exploit them. It probes for jailbreaks, data leaks, prompt injection, hallucination, and dozens of other failure modes in a single automated scan. The bottom line: catch weaknesses early with the industry-standard penetration testing toolkit for language models.
Technical scorecard
License
Apache-2.0
Commercial use
Yes
OpenAI-compatible API
No
REST API
No
Fine-tuning support
No
Quantization support
No
Docker available
No
GUI / no-code available
No
Telemetry
Unknown
Offline after setup
Yes
Data & Privacy
Does it send data online?
After setup, this listing is marked as usable offline. Confirm network behavior against the upstream project before regulated deployment.
Does it store history?
Not verified in this directory yet. Review the upstream docs for persistence, logs, and workspace storage.
License checks?
Commercial use is marked as allowed or likely allowed by the listed license.
Telemetry?
Unknown
Last verified: Jul 22, 2026. Maintainer verification should be treated as directory guidance, not legal advice.
Deploying garak in production?
Stop silent telemetry leaks before they trigger an unintended data leak. Get our Airgap Certainty Blueprint for garak.
Request Privacy and Telemetry AuditSetup & Installation
A developer can usually get this running with standard docs.
# Start with the official project repository
# https://github.com/NVIDIA/garak Hardware Requirements
Works Well With