Open-source, framework-agnostic API security: one detection engine, thin adapters for the framework you already run.
The engine sits in-process - no proxy, no edge box - detecting and blocking injection, XSS, bot and behavioral attack patterns where your code runs. Self-hosted by design and GDPR compliant: telemetry is opt-in and nothing leaves your deployment.
| Language | Engine | Adapters |
|---|---|---|
| Python | guard-core | fastapi-guard - flaskapi-guard - djapi-guard - tornadoapi-guard |
| TypeScript | guard-core-ts | express - fastify - nestjs - hono |
| Rust | guard-core-rs | axum-guard-rs - actix-guard-rs - rocket-guard-rs - tower-guard-rs |
| Go | guard-core-go | gin-guard - fiber-guard - echo-guard - nethttp-guard - prest-guard |
| PHP | guard-core-php | laravel-guard - slim-guard - symfony-guard - psr15-guard |
guard-agent (Python) - guard-agent-ts - guard-agent-rs - guard-agent-go - guard-agent-php
- Guard-Core-MCP: an MCP server that answers Guard questions from the libraries installed in your interpreter
- SaaS Issues: public issue tracker for the Guard Core SaaS
- Website: https://guard-core.com
- Playground: https://playground.guard-core.com
- SaaS app: https://app.guard-core.com
The Python family is the reference implementation and ships from this org. The TypeScript, Rust, Go and PHP families are developed in the open and join this org as they reach parity.