Skip to main content
Favicon of Vijil

Vijil

What is Vijil?

Vijil is an enterprise AI agent trust platform for teams that need to evaluate, protect, and continuously improve agents across the full lifecycle. It combines VIJIL DEPOT, VIJIL DIAMOND, VIJIL DOME, and VIJIL DARWIN to test workflows, enforce policy in real time, and learn from production telemetry. It supports on-premises deployment, multi-language SDKs, and a REST API, and is used by SmartRecruiters, Google, Autonoma, and Digital Ocean.

Last verifiedHow we evaluate

Screenshot of Vijil website

At a glance

Best for
Vijil is best for enterprise AI teams that need to prove agent safety before production and keep it enforced afterward.
API
Yes — Vijil offers multi-language SDKs and a REST API for any stack.

What it actually does

Vijil sells three linked products. Evaluate is a QA/red-teaming engine: point it at an agent (via API, a local executor tunneled through ngrok, or a hosted endpoint) and it runs it against a library the vendor says exceeds 200,000 adversarial and benchmark prompts, then returns a 'Trust Score' broken into reliability, security, and safety sub-scores with per-failure explanations. Dome is a runtime guardrail layer — a Python library or Docker sidecar that filters inputs/outputs against natural-language policies you define, with a claimed sub-300ms latency add. Darwin, the newest piece, is pitched as reinforcement learning that adapts an agent's defenses from production telemetry and evaluation failures over time. A fourth capability, Discover, scans code repos and cloud infrastructure to inventory an org's agents, including unsanctioned ones.

What a first-hand test looked like

An ngrok engineer built a small git-log-summarizing agent and ran it through Vijil Evaluate. The tool caught a real vulnerability: the agent ignored injected 'noisy' user context and leaked confidential data when prompted to, dropping its passing score from 97.56 to 95.51 after the developer actually wired the injected context into the prompt (the first, higher score reflected the agent silently discarding Vijil's test inputs, which is not the same as passing them). That's a specific, reproducible account of the tool surfacing a real failure mode rather than rubber-stamping a pass — a useful signal for reliability-conscious buyers.

Independent evidence the guardrails aren't bulletproof

A 2025 Mindgard research paper testing prompt-injection and jailbreak evasion techniques (emoji smuggling, zero-width characters, homoglyphs, adversarial ML perturbations) against six commercial and open-source LLM guardrails — Microsoft Azure Prompt Shield, Meta Prompt Guard, Nvidia NeMo Guard, Protect AI v1/v2, and Vijil's own prompt-injection guardrail — found every one of them bypassable to some degree, with some attacks achieving 100% evasion against multiple vendors including Protect AI v2 and Azure Prompt Shield. Mindgard's overall finding was 'there is no best guardrail'; Vijil was one of six tested, not singled out as worst or best. Vijil's marketing claims Dome is 'up to 2x more accurate than Amazon Bedrock guardrails' — a vendor claim we could not independently verify.

Pricing

Vijil Evaluate publishes three tiers on its site. Individual/usage-based is free and includes 1,000 credits, 25+ benchmarks, Trust Score, the Garak red-teaming engine, a playground, and support for custom harnesses and agents, plus email/Slack support. Team is usage-based ('pay-per-eval', no dollar figure published) and adds shared harnesses, evaluations, billing, and API keys. Enterprise is an annual subscription, contact-sales only, adding on-prem deployment, MCP/A2A testing, SSO/RBAC, and dedicated 8x5 support. Academic and research use is free forever by application. A separate FAQ on the same page says the free trial runs '3 months,' which sits oddly next to the pricing table describing an always-free Individual tier with credits — worth clarifying with sales before assuming either applies to your use case. Dome, the runtime guardrail product, is offered free for 30 days on request but has no published tier ladder beyond that.

Company, funding, and continuity

Founded in 2023 by Vin Sharma (CEO, ex-GM/Director of Engineering at Amazon SageMaker) and Zdravko Pantic (Head of Engineering, ex-AWS AI, previously led PyTorch/TensorFlow/SageMaker Training teams). The company raised $17M in a round led by BrightMind Partners with participation from Mayfield and Gradient, announced November 25, 2025, bringing total raised to $23M. It was named to Gartner's 2025 Cool Vendors in Agentic AI Trust, Risk and Security Management (corroborated independently by SiliconANGLE citing the Gartner document) and claims a CB Insights 'Most Innovative AI Startups 2025' listing, which we could not independently verify beyond Vijil's own site. Advisors include Leon Derczynski (creator of the Garak red-teaming tool and NeMo Guardrails, and OWASP LLM Top 10 lead) and Ruslan Salakhutdinov (CMU professor, deep-learning researcher) — a notable technical bench for an evaluation-focused security startup.

Named production use

DigitalOcean published a detailed customer story describing Vijil working with its customer Autonoma to take an IoT troubleshooting agent from a hallucinating prototype to production in one week — including specifics like switching the base model from Mistral Nemo Instruct to Llama 3.1 8B to reduce prompt-injection susceptibility, and splitting English/German knowledge bases to fix language-switching failures. Vijil's own site names SmartRecruiters, DuploCloud, and DigitalOcean-platform developers as production users; we corroborated the DigitalOcean/Autonoma relationship independently but did not verify the SmartRecruiters or DuploCloud claims beyond Vijil's own marketing.

What's still thin

No independent review sites (G2, Capterra, TrustRadius) turned up coverage at this company's stage — normal for a two-year-old startup, but it means a buyer has no third-party satisfaction signal beyond the single DigitalOcean case study and the ngrok hands-on account. Vijil publishes no public changelog or status page, so there's no way to check release cadence or incident history from outside the product. The Darwin (continuous-learning) and Discover (agent-inventory) products are described only in marketing copy with no independent usage accounts found.

Frequently asked questions

What is Vijil?

Vijil is an enterprise AI agent trust platform for teams that need to evaluate, protect, and continuously improve agents across the full lifecycle. It combines VIJIL DEPOT, VIJIL DIAMOND, VIJIL DOME, and VIJIL DARWIN to test workflows, enforce policy in real time, and learn from production telemetry. It supports on-premises deployment, multi-language SDKs, and a REST API, and is used by SmartRecruiters, Google, Autonoma, and Digital Ocean.

What is Vijil used for? Who is it for?

Vijil is used for VIJIL DEPOT, VIJIL DIAMOND, and VIJIL DOME. It's built for AI platform teams, Security and GRC teams, and Product engineering teams.

Does Vijil have an API and what does it integrate with?

Vijil offers multi-language SDKs and a REST API for any stack. It integrates with LangChain, CrewAI, Google ADK, Agent Development Kit, Amazon Bedrock, and 11 more.

Editor's read

Check whether your deployment needs on-premises handling of prompts and data before you commit. Vijil says it supports on-premises deployment, so confirm that requirement is part of your intended setup and not just an optional preference.

Share:

Sponsored
Favicon

 

  
 

Explore other Security AI Agents

Favicon

 

  
  
Favicon

 

  
  
Favicon