LLMVERIFY · OPEN SOURCE · POWERED BY HAIEC

Verify model interactions before they reach users.

Local-first verification and guardrails for LLM inputs and outputs, including prompt-injection risk, PII redaction, hallucination risk signals, JSON quality and runtime health.

Built for teams shipping AI features who need guardrails that work without sending data to third parties.

v1.6.1MITLocal-firstZero telemetry

The Problem

You're shipping AI features. Your LLM outputs need validation before they reach users-prompt injection detection, PII redaction, hallucination risk scoring. The standard options are:

  • Cloud APIs that require sending your data to third parties
  • Complex ML pipelines that add latency and infrastructure overhead
  • Manual regex that's brittle and doesn't scale

Most teams end up with a patchwork of solutions-or skip validation entirely and hope nothing goes wrong.

What llmverify Does

A single npm package that handles the common LLM safety checks. No cloud dependencies. No ML infrastructure. Just import and use.

Prompt Injection Detection

Pattern-based detection for 9 attack categories including jailbreaks, system prompt exfiltration, and tool abuse. OWASP LLM Top 10 aligned.

PII Redaction

25+ patterns including emails, SSNs, credit cards, API keys (AWS, GitHub, Stripe), JWT tokens, and private keys. Regex-based pattern matching with explicit limitations.

Hallucination Risk Scoring

Heuristic-based risk indicators that flag overconfident language, fabricated entities, and contradictions. Returns confidence intervals, not false certainties.

Runtime Health Monitoring

Wrap any LLM client to track latency, token rate, and behavioral drift. Get alerts when your model degrades before users notice.

JSON Repair & Validation

Auto-fix common JSON formatting errors from LLM outputs. Trailing commas, unquoted keys, truncated responses-handled automatically.

Model-Agnostic Adapters

Unified interface for OpenAI, Anthropic, Groq, Google AI, DeepSeek, Mistral, Cohere, and local models. Switch providers without changing application code.

Quick Start

Install
npm install llmverify
Basic Usage
import { verify, isInputSafe, redactPII } from 'llmverify';

// Verify AI output safety
const result = await verify({ content: aiOutput });
if (result.risk.level === 'critical') {
  console.log('Block this content');
}

// Check user input for prompt injection
if (!isInputSafe(userInput)) {
  throw new Error('Potential attack detected');
}

// Redact PII before displaying
const { redacted } = redactPII(aiOutput);
console.log(redacted); // "Contact [REDACTED] at [REDACTED]"

Limitations

llmverify uses heuristics, not AI. It provides guardrails and risk indicators. It does not establish ground truth, guarantee the absence of hallucinations, or replace human review for high-stakes decisions.

-Prompt-injection detection is pattern-based. Novel or obfuscated injections can evade detection.
-PII detection is regex-based. It catches standard formats but misses obfuscated, image-embedded, or encoded PII.
-Hallucination risk signals are heuristic. They cannot definitively prove hallucinations. Ground-truth verification requires a source document you provide.
-Every result carries an explicit limitations array stating what was and was not checked.

This is a guardrail layer, not a replacement for human review on high-stakes decisions. If a claim matters, verify it yourself. llmverify narrows the risk surface; it does not eliminate it.

Framework Alignment

llmverify provides technical evaluation and monitoring checks aligned with selected frameworks. This is baseline mapping, not certification:

OWASP LLM Top 10

Security

NIST AI RMF

Risk Management

EU AI Act

Compliance

ISO 42001

AI Management

Privacy Guarantee

What We Do

  • • Zero network requests
  • • Zero telemetry
  • • Zero data collection
  • • Open source-verify yourself

What We Never Do

  • • Train on your data
  • • Share with third parties
  • • Track without consent
  • • Phone home for any reason

Run tcpdump while using it-you'll see zero network traffic.

Why I Built This

I built AI governance frameworks for large-scale enterprise deployments. I saw what happens when teams ship AI features without proper guardrails, and I saw the compliance overhead that comes with enterprise-grade solutions.

Most teams do not need a full ML pipeline for basic safety checks. They need something that works out of the box, runs locally, and does not require a PhD to configure.

llmverify is that tool. The limitations section is honest about what it can and cannot do. It covers the common case for teams who need to ship safely without overengineering.

How It Works

1

Install the Package

Run npm i llmverify in your project. Zero dependencies, zero config required.

2

Import & Wrap

Import llmverify and pass your LLM output through the verify function. Works with OpenAI, Anthropic, or any LLM provider.

3

Configure Checks

Enable the checks you need: prompt injection detection, PII redaction, hallucination risk scoring, JSON validation. All run locally.

4

Monitor Results

Get structured risk scores and flags for every LLM response. Block, log, or alert based on your own thresholds.

Use Cases

Chatbot Safety

Detect prompt injection attacks in user messages before they reach your LLM. Block jailbreak attempts and keep your chatbot within its intended behavior.

RAG Pipeline Validation

Validate LLM outputs in retrieval-augmented generation pipelines. Check for hallucination risk when the LLM generates answers from your knowledge base.

AI Agent Guardrails

Add safety checks to autonomous AI agents before they take actions. Verify outputs for PII leaks, prompt injection, and hallucination before executing tool calls.

Customer Support AI Monitoring

Monitor LLM-powered customer support responses for PII leaks and hallucination risk. Ensure your AI assistant never exposes sensitive customer data or fabricates answers.

Frequently Asked Questions

Is llmverify an AI model?

No. llmverify is a deterministic rule-based library. It uses pattern matching, regex, and heuristic scoring - not a neural network. This means results are reproducible, fast, and require no GPU or model inference.

Does it send data anywhere?

No. llmverify makes zero network requests. All processing happens in your Node.js process. You can verify this with tcpdump or any network monitor - there is zero telemetry, zero data collection, zero phone-home behavior.

What LLM providers are supported?

llmverify is provider-agnostic. It works with any LLM output - OpenAI, Anthropic, Google, Mistral, local models via Ollama, or any custom LLM. You pass the output text to llmverify, and it returns structured verification results.

How accurate is prompt injection detection?

llmverify uses pattern-based detection which catches common injection patterns (ignore previous instructions, role-play attacks, encoding tricks). It is not 100% - novel or sophisticated attacks may evade detection. It covers common attack patterns for teams who need basic guardrails without deploying a separate ML model.

Can I use it in production?

Yes. llmverify is MIT licensed and production-ready. It is used in production by teams shipping AI features. The API is stable and backward-compatible. However, it should be used as one layer in a defense-in-depth strategy, not your only safety measure.

How does it compare to Langfuse or guardrails AI?

Langfuse is an observability platform that requires a server and database. guardrails AI is a Python library with ML-based validation. llmverify is a zero-dependency npm package that runs locally with deterministic checks. Choose llmverify for lightweight, local-first guardrails. Choose Langfuse for full observability. Choose guardrails AI for ML-based validation in Python.

HAIEC DEVELOPER SECURITY

Secure the code. Protect the tenant boundary. Verify the model interaction.

Get Started

MIT licensed. Zero config. Works with any LLM provider.

AI Advisor →