NVIDIA NeMo Guardrails is an open-source toolkit for dialog rails, topic control, and Colang flows around LLM conversations. ValGuard is a hosted OpenAI-compatible validation proxy for deterministic packs on completions and playbook handoffs. Dialog rails and a JSON policy gate are different jobs. Teams often run both.
Quick answer
Choose NeMo Guardrails when you need conversational rails, topic flows, and open-source composition inside a Python dialog stack. Choose ValGuard when several services must share schema, PII, arithmetic, or compliance packs with shadow mode and rule IDs. Keep NeMo for dialog behavior. Put ValGuard on the completion path for fail-closed business rules. Longer coexistence notes: three-way validation layer guide.
Verdict
NeMo fits dialog-centric stacks that want Colang rails and open-source control of the conversation path. ValGuard fits org-wide completion gates, multi-language clients, and audit rows without operating NeMo as your only policy plane.
What each is built for
NeMo Guardrails steers what the assistant may discuss, how it refuses, and how dialog state advances. It is a rails framework, not a multi-tenant SaaS proxy.
ValGuard evaluates completions against deterministic rules before the next step. It does not replace dialog design. It does not claim to know truth.
Comparison table
| Capability | NeMo Guardrails | ValGuard | Who wins |
|---|---|---|---|
| Form factor | Open-source Python rails | Hosted proxy (+ Enterprise self-host) | NeMo for dialog OSS; ValGuard for managed gate |
| Dialog / topic rails | Strong | Not the product | NeMo |
| Schema / domain packs | Custom | Built-in packs | ValGuard |
| Shadow → enforce | Build yourself | Per-agent on every plan | ValGuard |
| Audit with rule IDs | Your logging | Per-rule rows | ValGuard for packaged evidence |
| Multi-language clients | Python-centric | OpenAI-compatible | ValGuard |
| Zero extra hop | In-process possible | Network hop | NeMo |
| Open-source core | Yes | Product (no public OSS runtime) | NeMo |
Where ValGuard is stronger
- Shared packs across Python, Node, and canvas HTTP nodes.
- Shadow mode and named rule IDs without building the control plane.
- Playbooks at handoffs with published benchmark overhead.
Where NeMo Guardrails is stronger
- Dialog rails and Colang flows for conversation design.
- Open-source ownership of the rail path.
- In-process deployment when you refuse a network hop.
Cost and latency
NeMo cost is engineer time and the infra you run. ValGuard is plan-priced. Engine packs are microseconds. HTTP path about 0.36 ms p50 with a mocked upstream. Model time dominates. Block/re-ask buffers the stream. See methodology.
Failure example
A support bot under NeMo stays on-topic and refuses medical advice. The same turn returns a refund JSON with a wrong amount. Dialog rails did their job. A ValGuard arithmetic or cross-field rule still needs to fail before payout.
Code
Minimal ValGuard gate after your NeMo (or other) dialog layer produces a structured action:
curl -s https://api.valguard.ai/v1/chat/completions \
-H "Authorization: Bearer $VG_API_KEY" \
-H "X-VG-Agent: refund-guard" \
-H "Content-Type: application/json" \
-d '{"model":"openai/gpt-4o-mini","messages":[{"role":"user","content":"Refund 500 on order 12"}]}'
Wire NeMo per its docs for rails. Do not expect ValGuard to replace Colang flows.
Choose NeMo Guardrails if
- Dialog rails and topic flows are the main risk
- You want open-source rails in one Python stack
- You will own deployment and audit wiring
Choose ValGuard if
- Business rules must gate tools and payouts across services
- You need shadow → enforce and rule IDs out of the box
- Clients are not all NeMo/Python
Using both
NeMo for conversation policy. ValGuard for completion and tool-bound business rules. Prefer P-sidecar style: rails first or after, one owner per failure action. See also vs Guardrails AI.
Objections
- Is ValGuard a NeMo alternative? Only for the completion-gate job, not for dialog rails.
- Latency. Quote three numbers; streaming caveat on block/re-ask.
- If ValGuard is down. Fail closed on that path. Trust.
- Data residency. SaaS vs Enterprise self-host.
- False positives. Shadow first.
- Misses. No rule signature means no catch.
FAQ
Do you replace NeMo? No. Different layer.
Guardrails AI vs NeMo vs ValGuard? Library/rails/proxy. Read the blog guide.
Can NeMo call ValGuard? Yes, if your NeMo path uses an OpenAI-compatible client pointed at the proxy.
Related
Next step
Quickstart. Keep NeMo for dialog. Put ledger rules on a ValGuard agent.