Aval is an enterprise-grade safety classifier purpose-built for BFSI. It controls model behavior at runtime, ensures regulatory compliance, and detects malicious intent — with zero changes to your models.
Aval sits in front of every prompt and response, classifying intent across 22 safety axes spanning the FinProof BFSI threat taxonomy before anything reaches your customers.
Detects prompt injection, jailbreaks and malicious intent in real time — blocking what's harmful before it executes.
Aligned to RBI, SEBI, DPDP, ISO 27001 and SOC 2 from day one, with audit-ready evidence for every decision.
Trained on financial-services adversarial data so it distinguishes genuine attacks from legitimate banking queries.
Deploy as a guardrail layer in front of any LLM — no retraining, no fine-tuning, no architectural rework.
11.6ms inference on a single RTX 4090 — fast enough for real-time customer and agent workflows.
Every inference returns a structured confidence vector across safety axes — not a binary flag.
Zytra is the only platform that governs the KV cache layer — the one place where tenant data mixes and identity disappears.
Published research shows shared inference caches can leak up to 99% of a prompt through timing alone. Zytra detects cross-tenant leakage in real time — before it reaches your incident log.
Every cache access is signed, attributed, and recorded in a tamper-evident chain. When a regulator asks whether tenant A's data ever served tenant B, you show them proof, not a policy.
Subject erasure requests touch the cache too. Zytra tracks what entered the cache, scopes it to the right owner, and produces a signed deletion certificate — with honest disclosure of what was cleared and when.
Works alongside vLLM, llm-d, and other inference engines. No engine fork required.
On raw prompt-injection recall the field is close — Meta’s PromptGuard edges Aval (1.000 vs 0.994). What separates a benchmark from production is false positives, where Aval leads by a wide margin.
| Model | Size | HackaPrompt R | AgentHarm FPR | WildGuardMix F1 | Latency |
|---|---|---|---|---|---|
| Aval v1.5 | 184M | 0.994 | 0.5% | 0.303 | 11.6ms |
| PromptGuard-86M Meta | 86M | 1.000 | 96.9% | 0.095 | 8ms |
| LlamaGuard-3-1B Meta | 1B | 0.0% | 0% | 0.0 | ~60ms |
PromptGuard’s 96.9% AgentHarm FPR flags nearly every legitimate banking query as harmful — not deployable in production; Aval’s 0.5% reflects BFSI-specific training. HackaPrompt R (recall) and AgentHarm FPR come from different benchmark suites, so a high recall score does not imply a low false-positive rate. Meta’s PromptGuard is faster (8ms vs 11.6ms) but unusable at that FPR. Source: reproducible evaluation on the public FinProof set · RTX 4090.
Governance without friction across all four layers of AI infrastructure.
Centralized inventory of every model in production, with versioning and lineage tracking.
Runtime protection with Aval classifiers preventing hallucinations and prompt injection.
Real-time monitoring for data drift, performance degradation and behavioral anomalies.
Complete decision trails with SHAP/LIME explanations for every prediction.
Model, agent, application and network-level controls for comprehensive oversight.
Pre-configured for RBI, SEBI, DPDP Act, ISO 27001 and SOC 2 requirements.
One unified platform. Eight integrated capability groups. Deployed as SaaS, on-premise, or hybrid.
8 modules
Catalog · Discovery · Scan · Registration
7 modules
Risk Tiering · Compliance · Policy Packs · Controls
5 modules
Questionnaires · Evidence · Approvals · Collaboration
5 modules
Control Plane · SLA · Task Library · Stakeholders
6 modules
Evals · Red-team · Scanners · Benchmarks
5 modules
Policy Engine · Prompt Guard · Output Filters · Aval
8 modules
Agent Registry · Orchestration · Cost Tracking · Budgets
5 modules
Dashboards · Alerting · Audit Logs · Infra Config
See Aval running against your toughest adversarial prompts.