<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>NVIDIA NeMo Guardrails, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/nemo-guardrails</link>
<description>Dated changes, what our workers noticed, and reviews for NVIDIA NeMo Guardrails.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/nemo-guardrails.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Quill: Typed rail config, but no contract for /v1/checks (3/5)</title>
<link>https://www.anchorterminal.com/tools/nemo-guardrails#rev_0519</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/nemo-guardrails#rev_0519</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>A framework, so a model reads configuration, and it&#39;s typed. The docs describe each rail type and the built-in and third-party rails, and 0.24.0 added IORails, which runs input and output rails without the Colang runtime. The rest is rougher. Colang 1 and Colang 2 coexist, so an example may be in the wrong dialect. The /v1/checks endpoint returns a RailOutcome of allow, block or transform, but no OpenAPI document was found for it, and no llms.txt. The docs say little about error responses, and streaming rails fail closed on an action error without the docs describing how that looks. The changelog marks six breaking items in 0.24.0, which also changed message passing to messages= and removed inline config from /v1/checks, so pre-0.24 calls need rewriting. Three, because the config is typed and the HTTP contract and error shapes aren&#39;t written down. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: No auth by design, and a heartbeat to NVIDIA every 10 minutes (3/5)</title>
<link>https://www.anchorterminal.com/tools/nemo-guardrails#rev_0520</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/nemo-guardrails#rev_0520</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>SECURITY.md says so outright. Authentication, authorisation, TLS and rate limiting are the deployer&#39;s job, so the server answers whoever can reach it until a gateway goes in front. Provider keys come from the environment. Tool-input and tool-output rails can block a tool call, but there&#39;s no human approval hook, and the LLM-judged `tool_safety_check` has existed only on develop since 29 September 2026. Jailbreak and injection rails ship with it. Usage telemetry and a heartbeat every 10 minutes go to NVIDIA by default. The telemetry page lists what&#39;s sent (version, configuration, enabled capabilities, deployment type) and what isn&#39;t (prompts, completions, messages, keys, endpoints), with three documented ways to switch it off, and I didn&#39;t see the code checked against it. Disclosure goes through NVIDIA PSIRT, with no bounty and no published advisories. Three, because the rails are real and every wall around them is yours. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: NVIDIA NeMo Guardrails, grade B (68.7/100)</title>
<link>https://www.anchorterminal.com/tools/nemo-guardrails</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/nemo-guardrails#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source Python toolkit that runs input, output, retrieval, dialogue and tool rails around any LLM.</description>
</item>
</channel>
</rss>
