{
  "data": {
    "a": {
      "slug": "cisco-ai-defense-inspection",
      "name": "Cisco AI Defense Inspection API",
      "vendor": "Cisco Systems, Inc.",
      "vendorUrl": "https://www.cisco.com/site/us/en/products/security/ai-defense/index.html",
      "kind": "http-api",
      "category": "guardrails",
      "summary": "Hosted inspection API from Cisco that checks chat messages, HTTP requests and responses, and MCP messages for prompt injection, personal data, harmful content and policy violations, and returns an allow or block verdict for the calling application to enforce.",
      "url": "https://www.anchorterminal.com/tools/cisco-ai-defense-inspection",
      "markdownUrl": "https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cisco-ai-defense-inspection.json",
      "repo": "https://github.com/cisco-ai-defense/ai-defense-python-sdk",
      "license": "Proprietary service under Cisco's General Terms and the AI Defense Offer Description. The Python SDK is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat",
      "packages": [
        {
          "registry": "pypi",
          "name": "cisco-aidefense-sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Sales-led access. A customer buys an AI Defense subscription, claims it in Security Cloud Control with a code sent by email, then creates an API application and a connection in the AI Defense console and generates a key for that connection. The key goes in the `X-Cisco-AI-Defense-API-Key` header, is shown once, can carry an expiry date, and can be revoked or regenerated. It works only on the Inspection API. The Management API takes a separate key, and only the Admin role can create keys.",
      "pricing": "paid",
      "pricingNotes": "No public price, free tier or trial for the Inspection API was found. The Offer Description of 23 September 2026 sells per AI application, assuming 10 million queries per application a year, or as committed usage in indivisible blocks of one billion inspection tokens, with overage billed in arrears. The product page links a demo request. The free Explorer edition covers red teaming only (checked 2026-10-08).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the user guide or the Offer Description (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 35,
        "npmWeekly": null,
        "pypiWeekly": 3977,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.cisco.com/docs/ai-defense-inspection/",
      "capabilities": [
        "guard.injection",
        "guard.pii",
        "guard.moderation",
        "guard.policy"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "sales-led",
        "closed-source",
        "api-key",
        "python",
        "status-page",
        "security-txt",
        "soc2",
        "eu"
      ],
      "lastRelease": "2026-09-23",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.3,
        "grade": "C",
        "agentReady": false,
        "rank": 429,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 80,
          "payments": 0,
          "reliability": 80,
          "schema": 59,
          "security": 81,
          "transparency": 76
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -3,
        "negativeNotes": [
          "16 September 2026. Release 2026.9.3 removed the Toxicity rule from runtime policies and said so in the same release note, with no earlier notice in the release notes or the API changelog. `cisco-aidefense-sdk` 2.2.0, published two days later, still lists the rule. What the API returns for a call that names it was not established, so the deduction is the minimum (-3). https://securitydocs.cisco.com/docs/ai-def/user/168305.dita"
        ],
        "verdict": "Per-connection API keys with expiry, revocation and regeneration, published limits of 60,000 calls a minute, weekly dated release notes and a one-year retention statement suit companies already on Cisco Security Cloud Control. Access needs a subscription bought through sales, with no public price or trial for the API, and the developer changelog has one entry from February 2025.",
        "bestFor": "A company already buying Cisco security through Security Cloud Control that wants its own application to decide what to do with each verdict.",
        "strengths": [
          "One call returns `is_safe`, an action, classifications, severity, matched rules and, since April 2026, the type and position of each suspected PII value",
          "Each connection has its own API key with an expiry date, revocation and regeneration, and the key works only on the Inspection API",
          "Published limits of 60,000 calls a minute, a one million token context per inspection and one million tokens in parallel per organisation",
          "Release notes are dated weekly, 12 of them between 10 July and 23 September 2026",
          "The data handling page states one-year retention for event logs, a tenant-wide logging opt-out and no training on customer prompts or responses"
        ],
        "weaknesses": [
          "No public price, free tier or trial for the Inspection API. Subscriptions are bought through sales and activated with a claim code",
          "The Toxicity rule was removed on 16 September 2026 in the release note that announced it, with no earlier notice found",
          "The developer changelog lists only v1.0.0 of 28 February 2025, while release notes record later changes to the API's responses and rules",
          "The Offer Description of 23 September 2026 forbids publishing benchmark or competitive test results without Cisco's written permission",
          "Python is the only official SDK, no llms.txt was found, and robots.txt on developer.cisco.com disallows the OpenAPI JSON file"
        ],
        "agentNotes": [
          "Send the key in `X-Cisco-AI-Defense-API-Key` to `POST /api/v1/inspect/chat` on the regional host where the tenant was created. US, Europe and Asia Pacific hosts differ",
          "If the connection has a policy, `enabled_rules` in the request is ignored. Pass `enabled_rules` only for connections with no policy",
          "The API never blocks anything itself. Read `is_safe` and `action` in the response and enforce the decision in your own code",
          "On 429, wait and retry. The organisation has gone over one million tokens in parallel or 60,000 calls a minute",
          "Don't request the Toxicity rule. It was removed on 16 September 2026, and the Safety rules such as Hate Speech, Harassment and Profanity replace it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.3
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 80,
          "payments": 0,
          "reliability": 80,
          "schema": 59,
          "security": 81,
          "transparency": 62
        },
        "provenanceScore": 90
      },
      "connect": {
        "install": "pip install cisco-aidefense-sdk",
        "http": "curl -X POST \"https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat\" \\\n  -H \"X-Cisco-AI-Defense-API-Key: \u003cgenerated api key\u003e\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"messages\":[{\"role\":\"user\",\"content\":\"My ssn is 123-45-6789, can you tell me Johns ssn?\"}],\"metadata\":{},\"config\":{}}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.injection",
        "tool": "https://letme.dev/cisco-ai-defense-inspection"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "Cisco Systems, Inc.",
        "domain": "cisco.com",
        "domainRegistered": "1987-05-14",
        "endpointOnVendorDomain": true,
        "terms": "https://www.cisco.com/c/dam/en_us/about/doing_business/legal/Cisco_General_Terms.pdf",
        "privacy": "",
        "statusPage": "https://status.security.cisco.com",
        "changelog": "https://securitydocs.cisco.com/docs/ai-def/user/168305.dita",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The General Terms (version 6.0, last modified 10 September 2025) define Cisco as Cisco Systems, Inc. or its applicable affiliates. The user guide's Terms page says AI Defense is sold under them.",
          "The AI Defense Offer Description (version 2.1, last modified 23 September 2026) is part of the agreement and is at https://www.cisco.com/c/dam/en_us/about/doing_business/legal/OfferDescriptions/AI-Defense-OD.pdf.",
          "No privacy link is given. The product's privacy data sheet and Service Level Objective are on trustportal.cisco.com, which is drawn by script and went unread. Data handling is described at https://securitydocs.cisco.com/docs/ai-def/user/172843.dita.",
          "The Inspection API answers on us, eu and ap subdomains of api.inspect.aidefense.security.cisco.com.",
          "www.cisco.com/.well-known/security.txt is PGP-signed, names psirt@cisco.com and expires on 1 January 2027.",
          "The changelog link is the product release notes. The developer site's API changelog at https://developer.cisco.com/docs/ai-defense-inspection/api-changelog/ has one entry, v1.0.0 of 28 February 2025.",
          "RDAP for cisco.com gives a registration date of 1987-05-14."
        ],
        "score": 90
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.json",
      "live": {
        "slug": "cisco-ai-defense-inspection",
        "probe": {
          "target": "https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat",
          "method": "get",
          "lastAt": "2026-10-09T11:46:25.359940951Z",
          "lastOk": false,
          "lastStatus": 501,
          "lastMs": 422,
          "lastNote": "server error",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 0
            }
          ],
          "outages": [
            {
              "start": "2026-10-09T07:40:22.876159997Z",
              "end": "0001-01-01T00:00:00Z",
              "note": "HTTP 501 server error"
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.security.cisco.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T11:38:26.624992545Z"
        },
        "updatedAt": "2026-10-09T11:46:25.359940951Z"
      }
    },
    "answer": "Cisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing.",
    "b": {
      "slug": "granite-guardian",
      "name": "Granite Guardian",
      "vendor": "IBM",
      "vendorUrl": "https://www.ibm.com/granite",
      "kind": "model",
      "category": "guardrails",
      "summary": "Granite Guardian is IBM's family of open-weight judge models. The current 8-billion-parameter release answers yes or no on whether a prompt, response, retrieved context or function call meets a built-in or custom criterion, and the owner runs it.",
      "url": "https://www.anchorterminal.com/tools/granite-guardian",
      "markdownUrl": "https://www.anchorterminal.com/tools/granite-guardian.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/granite-guardian.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/granite-guardian.json",
      "repo": "https://github.com/ibm-granite/granite-guardian",
      "license": "Apache 2.0 for the weights and the repository",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "none",
      "authNotes": "No account or key is needed to download or run the model. The Hugging Face repository is not gated. A vLLM or Ollama server has whatever authentication the owner adds.",
      "pricing": "free",
      "pricingNotes": "Free to download and run under the Apache 2.0 licence, with the owner's hardware as the cost. IBM's watsonx.ai lists only the earlier `ibm/granite-guardian-3-8b`, marked deprecated, at $0.0002 per 1,000 input or output tokens (checked 2026-10-08). Version 4.1 is not on that list.",
      "priceSummary": "Free",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402. Granite Guardian is a model the owner runs, with no payment route (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 182,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.ibm.com/granite/docs/models/guardian",
      "capabilities": [
        "guard.moderation",
        "guard.policy",
        "guard.injection",
        "guard.self-host"
      ],
      "tags": [
        "model",
        "open-weights",
        "self-hosted",
        "local",
        "free",
        "apache-2.0",
        "judge",
        "rag",
        "python",
        "ollama"
      ],
      "lastRelease": "2026-04-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.1,
        "grade": "C",
        "agentReady": false,
        "rank": 478,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 47,
          "payments": 60,
          "reliability": 56,
          "schema": 60,
          "security": 58,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model.",
        "bestFor": "A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.",
        "strengths": [
          "Weights are ungated on Hugging Face under the Apache 2.0 licence, with IBM's own GGUF builds and an Ollama library entry",
          "Built-in criteria cover harm, social bias, jailbreaking, violence, profanity, sexual content, unethical behaviour, three RAG checks and function-call hallucination",
          "A custom criterion is one natural-language sentence in the prompt, and the answer is `yes` or `no` inside `\u003cscore\u003e` tags",
          "The repository's `evaluation` folder reproduces the card's benchmark figures for versions 3.0 to 4.1",
          "Weights carry a sigstore signature in `model.sig`, and IBM documents how to verify it"
        ],
        "weaknesses": [
          "Trained and tested on English only, per the model card",
          "Each call judges one criterion, so checking several risks takes several calls or a separate LoRA adapter built on the 3.2 model",
          "Version 4.1 moved the criterion into a `\u003cguardian\u003e` block in the last user message, where 3.x cookbooks pass `guardian_config`",
          "The repository has no CI, no tests and no `SECURITY.md`, and an issue asking for one has been open since 9 February 2025",
          "The card's out-of-distribution safety F1 is 0.79 without thinking, below the 0.81 it reports for version 3.3",
          "IBM's watsonx.ai model list has only `ibm/granite-guardian-3-8b`, marked deprecated, so 4.1 has no hosted endpoint from IBM that we found"
        ],
        "agentNotes": [
          "Append the `\u003cguardian\u003e` block as the final user message, with the mode line, `### Criteria:` and `### Scoring Schema:`. Copy the strings from the model card, because no package builds them",
          "Use the no-think instruction for gating and parse `\u003cscore\u003e`. Think mode writes a reasoning trace first, and the card's examples allow up to 2,048 output tokens",
          "Treat `yes` as the criterion being met, which for built-in criteria means the risk is present. Treat a missing `\u003cscore\u003e` tag as a failed check",
          "Pass retrieved text through `documents=` and tool schemas through `available_tools=` in `apply_chat_template`, not inside the message text",
          "Under Ollama, set `num_ctx` in the request options. IBM's docs say the default context is short and long requests are truncated"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.1
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 47,
          "payments": 60,
          "reliability": 56,
          "schema": 60,
          "security": 58,
          "transparency": 67
        },
        "provenanceScore": 73
      },
      "connect": {
        "install": "pip install transformers torch vllm",
        "http": "curl http://localhost:11434/api/chat \\\n  -d '{\"model\": \"granite4.1-guardian:8b\", \"messages\": [{\"role\": \"user\", \"content\": \"Hello!\"}]}'"
      },
      "letme": {
        "capability": "https://letme.dev/guard.moderation",
        "tool": "https://letme.dev/granite-guardian"
      },
      "area": "models",
      "provenance": {
        "legalEntity": "International Business Machines Corporation",
        "domain": "ibm.com",
        "domainRegistered": "1986-03-19",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "IBM's naming guidance for Granite names International Business Machines Corporation as the developer and trademark owner.",
          "The Apache 2.0 licence in the repository is the document that governs use of the weights, so it is recorded as the terms. The Hugging Face repository declares the same licence in its metadata and has no licence file of its own.",
          "No privacy policy governs the model, because the owner runs it and no input reaches IBM. The privacy field is left out.",
          "www.ibm.com/.well-known/security.txt is present with PSIRT, HackerOne and email contacts and expires on 8 November 2026.",
          "RDAP gives 19 March 1986 as the registration date of ibm.com.",
          "IBM hosts no endpoint for version 4.1 that we found, so there is no status page. The repository has no changelog file. Dated notes sit in the README under What's New.",
          "Weights are on huggingface.co under the ibm-granite organisation and the code is at github.com/ibm-granite/granite-guardian, both off ibm.com."
        ],
        "score": 73
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/granite-guardian.json"
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "Model API",
        "name": "Kind"
      },
      {
        "a": "Cisco Systems, Inc.",
        "b": "IBM",
        "name": "Vendor"
      },
      {
        "a": "https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under Cisco's General Terms and the AI Defense Offer Description. The Python SDK is Apache-2.0",
        "b": "Apache 2.0 for the weights and the repository",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-23",
        "b": "2026-04-29",
        "name": "Last release"
      },
      {
        "a": "",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "35 stars, 4k PyPI/wk",
        "b": "182 stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Cisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing.",
        "question": "Which is better for AI agents, Cisco AI Defense Inspection API or Granite Guardian?"
      },
      {
        "answer": "Cisco AI Defense Inspection API needs an API key. Granite Guardian needs no key.",
        "question": "Do Cisco AI Defense Inspection API and Granite Guardian need an API key?"
      },
      {
        "answer": "Cisco AI Defense Inspection API has a hosted endpoint at https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat. No hosted endpoint is listed for Granite Guardian.",
        "question": "Can an agent call Cisco AI Defense Inspection API and Granite Guardian without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 80 against 56",
          "Security \u0026 auth, 81 against 58",
          "Maintenance \u0026 community, 80 against 47",
          "Transparency \u0026 trust, 76 against 70"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "A company already buying Cisco security through Security Cloud Control that wants its own application to decide what to do with each verdict.",
        "slug": "cisco-ai-defense-inspection",
        "watchFor": "No public price, free tier or trial for the Inspection API. Subscriptions are bought through sales and activated with a claim code"
      },
      {
        "aheadOn": [
          "Payments \u0026 pricing, 60 against 0"
        ],
        "also": [
          "No key needed to call it",
          "No incidents deducted, where Cisco AI Defense Inspection API loses 3 points for them"
        ],
        "goodFor": "A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.",
        "slug": "granite-guardian",
        "watchFor": "Trained and tested on English only, per the model card"
      }
    ],
    "job": {
      "capability": "guard.injection",
      "name": "Guard injection"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-cisco-ai-defense-inspection.json",
        "title": "Amazon Bedrock Guardrails vs Cisco AI Defense Inspection API",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-cisco-ai-defense-inspection"
      },
      {
        "json": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian.json",
        "title": "Amazon Bedrock Guardrails vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-cisco-ai-defense-inspection.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Cisco AI Defense Inspection API",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-cisco-ai-defense-inspection"
      },
      {
        "json": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian.json",
        "title": "Azure AI Content Safety (Prompt Shields) vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-google-model-armor.json",
        "title": "Cisco AI Defense Inspection API vs Google Cloud Model Armor",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-google-model-armor"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.json",
        "title": "Cisco AI Defense Inspection API vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-lakera-guard.json",
        "title": "Cisco AI Defense Inspection API vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llamafirewall.json",
        "title": "Cisco AI Defense Inspection API vs LlamaFirewall",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llamafirewall"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-nemo-guardrails.json",
        "title": "Cisco AI Defense Inspection API vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails.json",
        "title": "Cisco AI Defense Inspection API vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-prisma-airs.json",
        "title": "Cisco AI Defense Inspection API vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian.json",
        "title": "Google Cloud Model Armor vs Granite Guardian",
        "url": "https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall.json",
        "title": "Granite Guardian vs LlamaFirewall",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llama-guard.json",
        "title": "Cisco AI Defense Inspection API vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-mistral-moderation.json",
        "title": "Cisco AI Defense Inspection API vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-moderation.json",
        "title": "Cisco AI Defense Inspection API vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.json",
        "title": "Granite Guardian vs Guardrails AI",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard.json",
        "title": "Granite Guardian vs Lakera Guard (Check Point AI Guardrails)",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard.json",
        "title": "Granite Guardian vs Llama Guard 4",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation.json",
        "title": "Granite Guardian vs Mistral Moderation API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails.json",
        "title": "Granite Guardian vs NVIDIA NeMo Guardrails",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.json",
        "title": "Granite Guardian vs OpenAI Guardrails",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation.json",
        "title": "Granite Guardian vs OpenAI Moderation API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs.json",
        "title": "Granite Guardian vs Prisma AIRS AI Runtime Security API",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-microsoft-presidio.json",
        "title": "Cisco AI Defense Inspection API vs Presidio",
        "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-microsoft-presidio"
      },
      {
        "json": "https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio.json",
        "title": "Granite Guardian vs Presidio",
        "url": "https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio"
      }
    ],
    "scores": [
      {
        "by": 24,
        "cisco-ai-defense-inspection": 80,
        "edge": "cisco-ai-defense-inspection",
        "granite-guardian": 56,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "cisco-ai-defense-inspection": 59,
        "edge": "granite-guardian",
        "granite-guardian": 60,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 2,
        "cisco-ai-defense-inspection": 67,
        "edge": "granite-guardian",
        "granite-guardian": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 23,
        "cisco-ai-defense-inspection": 81,
        "edge": "cisco-ai-defense-inspection",
        "granite-guardian": 58,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 60,
        "cisco-ai-defense-inspection": 0,
        "edge": "granite-guardian",
        "granite-guardian": 60,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 33,
        "cisco-ai-defense-inspection": 80,
        "edge": "cisco-ai-defense-inspection",
        "granite-guardian": 47,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 6,
        "cisco-ai-defense-inspection": 76,
        "edge": "cisco-ai-defense-inspection",
        "granite-guardian": 70,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Cisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing. Both do guard injection.",
    "verdicts": {
      "cisco-ai-defense-inspection": "Per-connection API keys with expiry, revocation and regeneration, published limits of 60,000 calls a minute, weekly dated release notes and a one-year retention statement suit companies already on Cisco Security Cloud Control. Access needs a subscription bought through sales, with no public price or trial for the API, and the developer changelog has one entry from February 2025.",
      "granite-guardian": "One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian",
    "json": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.md",
    "slim": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.min.md"
  },
  "markdown": "Cisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing. Both do guard injection.\n\n- Cisco AI Defense Inspection API: grade C, 61.3/100, rank #429 of 842. Markdown https://www.anchorterminal.com/tools/cisco-ai-defense-inspection.md · JSON https://www.anchorterminal.com/api/v1/tools/cisco-ai-defense-inspection.json\n- Granite Guardian: grade C, 60.1/100, rank #478 of 842. Markdown https://www.anchorterminal.com/tools/granite-guardian.md · JSON https://www.anchorterminal.com/api/v1/tools/granite-guardian.json\n\n## Which one, for what\n\n### Cisco AI Defense Inspection API (C)\n\nGood for: A company already buying Cisco security through Security Cloud Control that wants its own application to decide what to do with each verdict.\n\nAhead on:\n- Reliability, 80 against 56\n- Security \u0026 auth, 81 against 58\n- Maintenance \u0026 community, 80 against 47\n- Transparency \u0026 trust, 76 against 70\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No public price, free tier or trial for the Inspection API. Subscriptions are bought through sales and activated with a claim code\n\n### Granite Guardian (C)\n\nGood for: A team with a GPU that wants one English-language judge for harm, jailbreaks, RAG groundedness, function-call checks and house rules, under a permissive licence with no gate.\n\nAhead on:\n- Payments \u0026 pricing, 60 against 0\n\nAlso in its favour:\n- No key needed to call it\n- No incidents deducted, where Cisco AI Defense Inspection API loses 3 points for them\n\nWatch for: Trained and tested on English only, per the model card\n\n\n## Score by category\n\n| Category | Weight | Cisco AI Defense Inspection API | Granite Guardian | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 80 | 56 | Cisco AI Defense Inspection API +24 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 59 | 60 | Granite Guardian +1 |\n| Agent ergonomics | 13% (16.2 this run) | 67 | 69 | Granite Guardian +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 81 | 58 | Cisco AI Defense Inspection API +23 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 60 | Granite Guardian +60 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 47 | Cisco AI Defense Inspection API +33 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 76 | 70 | Cisco AI Defense Inspection API +6 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **61.3 · C** | **60.1 · C** | |\n\n## Facts side by side\n\n| Fact | Cisco AI Defense Inspection API | Granite Guardian |\n| --- | --- | --- |\n| Kind | HTTP API | Model API |\n| Vendor | Cisco Systems, Inc. | IBM |\n| Hosted endpoint | `https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat` | no (local only) |\n| Transports | HTTP | HTTP |\n| Auth | API key | None |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Proprietary service under Cisco's General Terms and the AI Defense Offer Description. The Python SDK is Apache-2.0 | Apache 2.0 for the weights and the repository |\n| Read-only variant documented | no | no |\n| llms.txt | no | no |\n| Last release | 2026-09-23 | 2026-04-29 |\n| Terms last updated |  | no document linked |\n| Privacy policy last updated | no document linked | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 35 stars, 4k PyPI/wk | 182 stars |\n\n## Verdicts\n\n**Cisco AI Defense Inspection API.** Per-connection API keys with expiry, revocation and regeneration, published limits of 60,000 calls a minute, weekly dated release notes and a one-year retention statement suit companies already on Cisco Security Cloud Control. Access needs a subscription bought through sales, with no public price or trial for the API, and the developer changelog has one entry from February 2025.\n\n**Granite Guardian.** One ungated Apache 2.0 model judges harm, jailbreaks, RAG groundedness, function-call errors and custom criteria, with signed weights and published evaluation code. It is trained and tested on English only, each call checks one criterion, the 4.1 prompt format differs from 3.x, and IBM's watsonx.ai lists only the deprecated 3.0 model.\n\n## Before you call either\n\n### Cisco AI Defense Inspection API\n\n1. Send the key in `X-Cisco-AI-Defense-API-Key` to `POST /api/v1/inspect/chat` on the regional host where the tenant was created. US, Europe and Asia Pacific hosts differ\n2. If the connection has a policy, `enabled_rules` in the request is ignored. Pass `enabled_rules` only for connections with no policy\n3. The API never blocks anything itself. Read `is_safe` and `action` in the response and enforce the decision in your own code\n4. On 429, wait and retry. The organisation has gone over one million tokens in parallel or 60,000 calls a minute\n5. Don't request the Toxicity rule. It was removed on 16 September 2026, and the Safety rules such as Hate Speech, Harassment and Profanity replace it\n\n### Granite Guardian\n\n1. Append the `\u003cguardian\u003e` block as the final user message, with the mode line, `### Criteria:` and `### Scoring Schema:`. Copy the strings from the model card, because no package builds them\n2. Use the no-think instruction for gating and parse `\u003cscore\u003e`. Think mode writes a reasoning trace first, and the card's examples allow up to 2,048 output tokens\n3. Treat `yes` as the criterion being met, which for built-in criteria means the risk is present. Treat a missing `\u003cscore\u003e` tag as a failed check\n4. Pass retrieved text through `documents=` and tool schemas through `available_tools=` in `apply_chat_template`, not inside the message text\n5. Under Ollama, set `num_ctx` in the request options. IBM's docs say the default context is short and long requests are truncated\n\n## Questions\n\n### Which is better for AI agents, Cisco AI Defense Inspection API or Granite Guardian?\n\nCisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing.\n\n### Do Cisco AI Defense Inspection API and Granite Guardian need an API key?\n\nCisco AI Defense Inspection API needs an API key. Granite Guardian needs no key.\n\n### Can an agent call Cisco AI Defense Inspection API and Granite Guardian without installing anything?\n\nCisco AI Defense Inspection API has a hosted endpoint at https://us.api.inspect.aidefense.security.cisco.com/api/v1/inspect/chat. No hosted endpoint is listed for Granite Guardian.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cisco-ai-defense-inspection\", \"b\": \"granite-guardian\"}`. From a terminal: `anchor compare cisco-ai-defense-inspection granite-guardian`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cisco-ai-defense-inspection.json and https://www.anchorterminal.com/api/v1/tools/granite-guardian.json\n\n## Other comparisons with Cisco AI Defense Inspection API or Granite Guardian\n\n- [Amazon Bedrock Guardrails vs Cisco AI Defense Inspection API](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-cisco-ai-defense-inspection.md)\n- [Amazon Bedrock Guardrails vs Granite Guardian](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-granite-guardian.md)\n- [Azure AI Content Safety (Prompt Shields) vs Cisco AI Defense Inspection API](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-cisco-ai-defense-inspection.md)\n- [Azure AI Content Safety (Prompt Shields) vs Granite Guardian](https://www.anchorterminal.com/compare/azure-ai-content-safety-vs-granite-guardian.md)\n- [Cisco AI Defense Inspection API vs Google Cloud Model Armor](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-google-model-armor.md)\n- [Cisco AI Defense Inspection API vs Guardrails AI](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-guardrails-ai.md)\n- [Cisco AI Defense Inspection API vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-lakera-guard.md)\n- [Cisco AI Defense Inspection API vs LlamaFirewall](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llamafirewall.md)\n- [Cisco AI Defense Inspection API vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-nemo-guardrails.md)\n- [Cisco AI Defense Inspection API vs OpenAI Guardrails](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-guardrails.md)\n- [Cisco AI Defense Inspection API vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-prisma-airs.md)\n- [Google Cloud Model Armor vs Granite Guardian](https://www.anchorterminal.com/compare/google-model-armor-vs-granite-guardian.md)\n- [Granite Guardian vs LlamaFirewall](https://www.anchorterminal.com/compare/granite-guardian-vs-llamafirewall.md)\n- [Cisco AI Defense Inspection API vs Llama Guard 4](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-llama-guard.md)\n- [Cisco AI Defense Inspection API vs Mistral Moderation API](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-mistral-moderation.md)\n- [Cisco AI Defense Inspection API vs OpenAI Moderation API](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-openai-moderation.md)\n- [Granite Guardian vs Guardrails AI](https://www.anchorterminal.com/compare/granite-guardian-vs-guardrails-ai.md)\n- [Granite Guardian vs Lakera Guard (Check Point AI Guardrails)](https://www.anchorterminal.com/compare/granite-guardian-vs-lakera-guard.md)\n- [Granite Guardian vs Llama Guard 4](https://www.anchorterminal.com/compare/granite-guardian-vs-llama-guard.md)\n- [Granite Guardian vs Mistral Moderation API](https://www.anchorterminal.com/compare/granite-guardian-vs-mistral-moderation.md)\n- [Granite Guardian vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/granite-guardian-vs-nemo-guardrails.md)\n- [Granite Guardian vs OpenAI Guardrails](https://www.anchorterminal.com/compare/granite-guardian-vs-openai-guardrails.md)\n- [Granite Guardian vs OpenAI Moderation API](https://www.anchorterminal.com/compare/granite-guardian-vs-openai-moderation.md)\n- [Granite Guardian vs Prisma AIRS AI Runtime Security API](https://www.anchorterminal.com/compare/granite-guardian-vs-prisma-airs.md)\n- [Cisco AI Defense Inspection API vs Presidio](https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-microsoft-presidio.md)\n- [Granite Guardian vs Presidio](https://www.anchorterminal.com/compare/granite-guardian-vs-microsoft-presidio.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cisco AI Defense Inspection API vs Granite Guardian",
        "url": ""
      }
    ],
    "description": "Cisco AI Defense Inspection API scores 61.3 (C) on agent readiness against Granite Guardian's 60.1 (C), and leads in 4 of 7 scored categories. Granite Guardian leads on payments \u0026 pricing. Both do guard injection. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cisco AI Defense Inspection API C 61.3",
      "Granite Guardian C 60.1",
      "scores"
    ],
    "h1": "Cisco AI Defense Inspection API vs Granite Guardian",
    "image": "https://www.anchorterminal.com/assets/og/compare-cisco-ai-defense-inspection-vs-granite-guardian.png",
    "path": "/compare/cisco-ai-defense-inspection-vs-granite-guardian",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cisco AI Defense Inspection API vs Granite Guardian for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/cisco-ai-defense-inspection-vs-granite-guardian"
  },
  "tokens": {
    "markdown": 3000,
    "slim": 680
  },
  "version": 1
}
