Registry › Compare › AiSOC vs Garak

AiSOC vs Garak

AiSOC leads on trust: 84.9/100 (Grade A) against 65.6/100 (Grade B), a 19.3-point gap. AiSOC leads on supply-chain integrity and provenance; Garak leads on adoption and rests on broader evidence. Note: AiSOC's evidence coverage is thinner (coverage B vs A) — its score rests on fewer independent signal types.

A AiSOC 84.9

Open-source AI Security Operations Center: alert fusion, LLM-agent triage, MITRE ATT&CK investigation, and a replayable decision ledger for every agent step. Self-hostable, runs with no API keys, MIT licensed. Ships an MCP server for Claude, Cursor and Continue.

beenuar/AiSOC · #93 overall · #3 Security & Guardrails · coverage B (3/5)

Choose AiSOC if supply-chain integrity and provenance matter most.

  • +8.2Safety / Integrity: OSSF Scorecard 5.6 against 4.7
  • +7.2Identity / Provenance: package provenance attested, against none
  • +1.6Maintenance: last push today, against 1d ago
  • +0.8Transparency: OSSF Scorecard 5.6 against 4.7
B Garak 65.6

the LLM vulnerability scanner

NVIDIA/garak · #477 overall · #7 Security & Guardrails · coverage A (4/5)

Choose Garak if adoption matters most.

  • +3.4Adoption: 9.1k weekly downloads against 316
  • A vs BEvidence coverage: 4 of 5 independent signal types, against 3

Where they differ

17.6
Safety / IntegrityAiSOC +8.2
9.4
18.0
Identity / ProvenanceAiSOC +7.2
10.8
13.3
TransparencyAiSOC +0.8
12.5
20.0
MaintenanceAiSOC +1.6
18.4
11.4
AdoptionGarak +3.4
14.8
+4.6
Runtime calibrationAiSOC +4.9
-0.3

Full evidence table

An independent, evidence-based trust comparison of AiSOC and Garak, two Security & Guardrails projects in the HVTracker registry. Scores come from public, checkable signals — supply-chain provenance, OSSF Scorecard, maintenance, and adoption — not popularity.

Full evidence

Signal AiSOCbeenuar/AiSOC GarakNVIDIA/garak
HVTrust score 84.9 65.6
Evidence grade A B
Coverage grade B A
Overall rank #93 #477
Rank in Security & Guardrails #3 #7
GitHub stars 2.4k 9.5k
Last updated today 1d ago
Build provenance Yes No
OSSF Scorecard 5.6 / 10 4.7 / 10
License MIT Apache-2.0
Downloads 316/wk 9k/wk
Trust dimensions (points earned)
Safety / integrity / 25 17.6 9.4
Identity & provenance / 18 18.0 10.8
Transparency / 17 13.3 12.5
Maintenance / 20 20.0 18.4
Adoption / 20 11.4 14.8
Runtime capability surface (full matrix)
MCP server Implemented —
External providers — 8 — Amazon Bedrock, Anthropic, Cohere, …
Requires API keys Yes Yes
Plugin surface plugins plugins
Provenance drift Match Match
Open in the live compare tool → AiSOC profile Garak profile More Security & Guardrails →

How to read this: HVTrust (0–100) weighs supply-chain signals (provenance, OSSF Scorecard, signed commits, open license) alongside real-world adoption, scaled by an evidence-confidence factor. Grade bands: A ≥ 80, B ≥ 65, C ≥ 50, D < 50. Signals refresh daily. Full methodology v4.4 →