LLM Guardrails and PII Detection,
Open Source


A 300M-parameter multilingual model that runs LLM safety moderation and
PII detection in a single forward pass. Cutting latency by half with no drop in accuracy.
2-in-1
LLM safety
& PII checks
~50%
lower
latency
0.3B
params
encoder
RESEARCH
Two Safety Models. One forward pass.

Two jobs, one checkpoint. Run schema-conditioned safety moderation and span-level PII extraction without loading separate models - classification and extraction in one pass.
Learn more

Composable schema at inference. Pass any subset of the 42 PII labels or the safety tasks you need at inference time. No retraining, no prompt redesign.
Learn more

No regression on either task. The combined model matches GLiGuard on safety benchmarks and GLiNER2-PII on the SPY PII benchmark.
Deploy GLiNER2-Guardrails-PII-Multi
EFFICIENCY
Smaller, faster, built to self-host
Half the inference latency
Both tasks run in one pass on a shared encoder, roughly half the latency of running GLiGuard and GLiNER2-PII in sequence.
Multilingual coverage
Safety moderation and PII detection across seven languages: English, French, Spanish, German, Italian, Portuguese, and Dutch.
Stay on your infrastructure
Open weights. Run on-prem, air-gapped, or CPU-first for fast local inference, or deploy with Pioneer.
0.3B
Parameters,
one shared encoder
~50%
Lower latency
vs. two-model pipeline
42
PII entity types,
7 categories
7
Languages supported

GLiNER2-Guardrails-PII-Multi Benchmark Results
When evaluated against the two models it replaces, GLiGuard and GLiNER2-PII, GLiNER2-Guardrails-PII-Multi holds competitive performance while reducing latency.
Task
Benchmark
Specialist Model
GLiNER2-Guardrails-PII-Multi
Safety
Prompt harmfulness, avg F1
87.7 (GLiGuard)
87.4
Safety
Response harmfulness, avg F1
82.7 (GLiGuard)
83.1
PII
SPY legal Q&A, F1
47.5 (GLiNER2-PII)
47.0
PII
SPY medical, F1
46.7 (GLiNER2-PII)
47.5
PII
SPY average, F1
47.1 (GLiNER2-PII)
47.2