Fiddler AI
Fiddler AI is an enterprise AI Control Plane that evaluates, monitors and governs autonomous agents, LLM applications and predictive ML models, enforcing inline guardrails in under 80 ms through proprietary models running inside the customer's own environment.
What is Fiddler AI?
Fiddler AI is an enterprise platform that its publisher, Fiddler Labs, Inc., describes as the AI Control Plane, the system of trust for first-party and third-party agents from the creation layer to production. Founded in 2018 and based in California, the company started with machine learning explainability, moved into model observability, and now positions itself around the control of autonomous agents.
The platform rests on four building blocks, continuous evaluation, agentic observability, policy enforcement through guardrails, and governance for GRC teams, layered on top of its original ML observability capabilities. Observation follows a hierarchy of application, session, agent, trace and span, so a symptom can be followed down to the span that caused it, with automated root cause analysis across that hierarchy.
The main technical differentiator the vendor puts forward is the Centor Models, formerly Trust Models: fast proprietary evaluators that run inside the customer's own environment instead of calling an external LLM API. Fiddler claims this cuts the total cost of ownership of evaluation by up to 98%, and its homepage advertises 99% accuracy in blocking jailbreaks, enforcement latency under 80 ms and zero data leaving the customer network. Guardrails work inline in both directions, detecting and redacting PII, PHI and secrets in the prompt before it reaches the model and in the tool response before it reaches the agent context, including API keys, .env files and tokens. The same controls extend to coding agents, in the IDE, the CLI and at the MCP boundary, with human approval required for high-risk decisions.
Instrumentation is announced as native OpenTelemetry with no SDK required, with native support for LangGraph, Amazon Bedrock, AWS Strands Agents and Google ADK. Deployment can be SaaS, inside the customer VPC, on-premise, or on AWS GovCloud for the public sector, with more than 100 pre-built metrics. Governance runs through a unified executive dashboard that keeps every decision and every policy enforcement traceable. The scale claimed reaches more than 30 million traces a day at a Fortune 20 conglomerate. Fiddler is cited by Forrester in its Agentic Control Plane Solutions Landscape for Q2 2026, by Gartner in its February 2026 Market Guide for AI Evaluation and Observability Platforms, and by IDC and CB Insights.
What it does
- Evaluate agents continuously, from testing through to production
- Trace behavior across application, session, agent, trace and span
- Enforce policies inline in under 80 ms
- Detect and redact PII, PHI and secrets on both input and output
- Produce time-stamped audit evidence for compliance
- Track tokens, cost, latency and adoption by developer, team and model
- Run automated root cause analysis across the agentic hierarchy
When to use Fiddler AI / When not to
A quick filter to help you decide if Fiddler AI is the right fit.
When to use Fiddler AI
- Large enterprises and regulated sectors running autonomous agents in production, where model and agent behavior has to be proven rather than assumed
- Platform, MLOps and LLMOps engineers who want continuous evaluation, monitoring and inline policy enforcement in a single system
- Financial services teams working on credit, cards, wealth management, fraud and trading, alongside healthcare, insurance, government and defense organizations
- Risk, compliance and governance functions that must produce audit evidence aligned with GDPR, HIPAA, NAIC, SR 11-7, ISO/IEC 42001, the NIST AI RMF or the EU AI Act
- Data science and security teams operating at high volume, up to the 30 million traces a day the vendor reports at a Fortune 20 conglomerate
When not to use Fiddler AI
- Buyers who want to subscribe and pay online: the Enterprise plan goes through sales and the Developer plan through a demo request
- Teams looking for a framework to build agents or for a model provider: Fiddler is an observability and governance layer, not a creation tool
- Engineers who want one-trace-at-a-time debugging, an approach the vendor explicitly positions against in favor of a system-wide performance experience
- Mobile-first users: no iOS or Android application exists, the product is used through the web app and the API only
- Small teams with light volumes or non-English requirements: the free plan is limited to real-time guardrails and no interface language other than English is announced
How to use Fiddler AI
A typical end-to-end flow, from setup to results.
- Start from the commercial entry point: fill in the Request demo form, or contact sales for the Enterprise plan
- Open the public documentation on docs.fiddler.ai and follow its get started in under 10 minutes path
- Choose the onboarding track that matches your use case: Agentic Observability, Experiments, Guardrails, LLM Monitoring or ML Observability
- Onboard a first GenAI application, documented as the first step
- Instrument through native OpenTelemetry, or use the Fiddler LangGraph, Fiddler Strands and Fiddler Evals SDKs, the Python client or the full REST API
- Connect the data sources needed for observability: S3, BigQuery, Snowflake, Kafka and Airflow
- Set up access control: SSO with Okta or Google Workspace, RBAC, API keys and OAuth 2.0
- Turn on real-time guardrails inline, at the gateway already in place
- Route alerts to Datadog, PagerDuty, webhooks or email
- On the Enterprise plan, run the tailored onboarding with the named Customer Success Manager before scaling to production
Pros & Cons
Pros
- Evaluation and guardrails run in the customer's own environment through the Centor Models, with no external LLM API call: predictable cost and no data leaving the network
- Inline real-time enforcement on both the request and the response path, not only after-the-fact detection, with 100% trace coverage instead of sampling
- One system for autonomous agents, LLM applications and predictive ML, covering the creation layer with coding agents as well as production
- Model-agnostic and cloud-agnostic, with Azure OpenAI, Amazon Bedrock, LangGraph and more than 100 providers supported
- Audit evidence aligned with several regulatory frameworks, backed by SOC 2 Type II certification and HIPAA compliance
- Flexible deployment up to on-premise and AWS GovCloud, and a genuine free plan that already includes real-time guardrails
- Verifiable references such as Nielsen, the U.S. Navy and Integral Ad Science, plus citations by Forrester and Gartner
Cons
- Enterprise pricing is not public: buying requires going through the sales team
- No free trial is advertised and no self-service sign-up is visible, the Developer plan itself going through a demo request
- The trust center is JavaScript-rendered, so neither a DPA nor a sub-processor list can be consulted, and the SOC 2 Type II report is shared only under NDA
- The privacy policy dates from 11 May 2022 and is limited to the website, not to the platform
- No GDPR compliance claim, no Article 27 representative and no dedicated GDPR contact address
- No published position on training models with customer data, and no documented opt-out option
- No mobile application, no interface language other than English, and several headline figures (99%, under 80 ms, 98% lower evaluation TCO) are unaudited vendor claims
Pricing & Plans
Fiddler AI is sold on a freemium basis. A permanent Free plan is available at no cost and covers real-time guardrails. The lowest paid entry point is the Developer plan, billed on usage at USD 0.002 per trace, so the total depends on the volume of traces processed. Enterprise pricing is not published and is quoted on request through the sales team. No free trial and no annual discount are mentioned. On cost, the vendor argues that evaluation requires no external LLM API call and claims up to 98% lower evaluation total cost of ownership than foundation models, with an evaluation TCO calculator offered on the site. Under the terms of use, subscriptions renew automatically for a term identical to the initial one unless cancelled.
- real-time guardrails with enforcement under 80 ms
- protection against hallucinations
- toxicity
- PII and PHI exposure
- prompt injection and jailbreaks
- powered by contextual and specialized Centor Models
- everything in Free
- plus unified agentic and predictive observability
- testing and experimentation
- custom evaluators and bring-your-own-judge
- visual insights
- RBAC and SSO
- SaaS deployment
- everything in Developer
- plus enterprise-grade guardrails
- infrastructure scalability
- flexible SaaS
- VPC or on-premise deployment
- white-glove support with dedicated channels
- a named Customer Success Manager and tailored onboarding
Data, GDPR & hosting
A consolidated view of how Fiddler AI handles your data.
GDPR overview
Fiddler Labs, Inc. never claims GDPR compliance for itself. GDPR appears only as one of the audit frameworks its product helps customers document, alongside HIPAA, NAIC and SR 11-7: the platform generates evidence for audit trails, which is a customer capability, not a statement about the vendor's own processing. No Article 27 EU representative is designated, no data protection officer is named and no GDPR contact address is published. The privacy policy, dated 11 May 2022, has no data subject rights section, is written around US law and announces transfers of personal information to the United States. No DPA or sub-processor list is publicly accessible, the trust center being JavaScript-rendered. The documented certifications are SOC 2 Type II and HIPAA compliance.
Who owns the data?
Fiddler Labs, Inc. publishes no clause claiming ownership of customer data, and none was found transferring rights over it to the vendor. The security page classifies all customer data as confidential, requiring the highest degree of controls, prohibits support staff from accessing, downloading or storing customer data on their devices, and keeps development and production environments separate, with customer data never loaded into development. One caveat matters: the privacy policy in force is dated 11 May 2022 and, by its own scope, addresses the website and marketing activities rather than data processed inside the platform, so the ownership and handling of platform data are governed by contract, not by any public document.
Reuse rights
On the website side, the privacy policy dated 11 May 2022 covers contact details, communications, marketing data, job applications and technical data. Declared uses are operating and improving the site, communicating with users, research and development, marketing and targeted advertising, recruitment and legal compliance. Data may be shared with service providers, advertising partners, marketing partners, professional advisers, authorities and an acquirer in a corporate transaction, and Fiddler Labs may create aggregated, de-identified or anonymized data that it can share with third parties. Cookies, local storage and pixels are used, with Google Analytics named, and Do Not Track signals are not honored. Nothing published states whether customer data processed inside the platform is used to train models, and no opt-out is documented.
Data retention & training
Hosting summary
Fiddler production infrastructure is hosted in the cloud, in a service provider's environment, with physical security delegated to that provider. No hosting country or region is named for the SaaS offering: the United States is recorded here because the publisher is US-based and its privacy policy announces transfers of personal information to the United States, not because of an explicit platform hosting statement. Customers choose their deployment model, SaaS, their own VPC, on-premise, or AWS GovCloud for US public sector work, and in the customer-hosted models the hosting jurisdiction is the customer's own. The Centor Models that power evaluation and guardrails run inside the customer environment, so, in the vendor's words, prompts never leave that infrastructure, which the homepage sums up as zero data leaving your network. Encryption is TLS 1.2 or above in transit and AES-256 or above at rest, and customer data is backed up daily in encrypted form.
Things to keep in mind
Risks and trade-offs to weigh before adopting Fiddler AI.
- Automation bias: an executive dashboard and a claimed 99% jailbreak blocking rate can create a false sense of safety, whereas guardrails reduce risk without removing the human review that the vendor itself requires for high-risk decisions
- The performance figures put forward, 99% blocking, enforcement under 80 ms, up to 98% lower evaluation TCO and more than 30 million traces a day, are vendor claims that have not been publicly audited
- Cost drift: the Developer plan is billed at USD 0.002 per trace, so spend grows with trace volume, and Enterprise pricing is not published, which makes budget comparison impossible before talking to sales
- Contractual terms: subscriptions renew automatically for a term identical to the initial one unless cancelled, and the terms of use impose binding arbitration, a class action waiver and California law, with a 30-day opt-out sent by mail to support@fiddler.ai
- Compliance evidence cannot be checked independently: the trust center is unreadable without JavaScript, so no DPA or sub-processor list is available, and the SOC 2 Type II report is shared only under NDA
- Data governance gaps: the privacy policy dates from 11 May 2022 and covers only the website, no GDPR compliance is claimed, no Article 27 representative or GDPR contact exists, and nothing is published about training on customer data or an opt-out
- Administrative inconsistency: the postal address in the terms of use (Mountain View) differs from the one in the privacy policy (Palo Alto), and the channel for questions, complaints and claims is an individual founder address rather than a legal department
- Export control: the terms of use prohibit exporting or transferring the platform to destinations barred by United States law, so availability in sanctioned jurisdictions is contractually restricted even though no excluded country list is published
Setup & Integrations
Technical difficulty
Setup targets technical teams: AI and software engineers, data scientists, platform and DevOps teams. The documentation advertises a get started path in under 10 minutes, instrumentation is announced as native OpenTelemetry with no SDK needed, and a Python SDK and REST API cover advanced work. Enforcement plugs into the gateway already in place rather than adding a layer. Effort grows with scope: connecting warehouses and orchestration for ML observability, configuring SSO and RBAC, and VPC or on-premise deployment, which involves infrastructure teams. Enterprise customers get tailored onboarding and a named Customer Success Manager.
Deployment
Integrations
Behind Fiddler AI
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement Fiddler AI.
Frequently asked questions
What is Fiddler AI?
How much does Fiddler AI cost?
Is there a free plan or a free trial?
Does Fiddler AI provide an API?
Which tools does Fiddler AI integrate with?
Where is the data processed?
Which certifications does Fiddler AI hold?
Is Fiddler AI GDPR compliant?
Is my data used to train models?
How do I get started with Fiddler AI?
Should you pick Fiddler AI?
Fiddler AI positions itself as a single control plane rather than one more monitoring tool, and the product follows that framing: evaluation, observability, inline enforcement and governance sit in the same system, covering autonomous agents, LLM applications and predictive ML alike. Its clearest differentiator is architectural. The Centor Models run evaluation and guardrails inside the customer's own environment, with no external LLM call, which makes evaluation costs predictable and keeps prompts off third-party infrastructure. For large enterprises and regulated sectors that have to show their work, that combination is hard to assemble from separate tools.
The reservations concern what is not published. Enterprise pricing is only available through sales. The trust center that would carry the DPA and the sub-processor list is JavaScript-rendered and returned nothing readable. The SOC 2 Type II report is shared only under NDA. The privacy policy dates from 11 May 2022 and covers the website rather than the platform. Fiddler never claims GDPR compliance for itself, GDPR appearing only as one of the frameworks its product helps customers document, and the site takes no published position on whether customer data is used to train models, nor does it document an opt-out. The headline figures, 99% jailbreak blocking, enforcement under 80 ms, up to 98% lower evaluation TCO and more than 30 million traces a day, are vendor claims that have not been publicly audited.
Maturity is not in doubt: founded in 2018, USD 100 million raised, cited by Forrester, Gartner, IDC and CB Insights, with references such as Nielsen, the U.S. Navy and Integral Ad Science. Teams that need real control over agents in production, and that accept a sales-led purchase, will find a serious candidate here. Teams looking for self-service pricing or ready-made GDPR documentation will have to ask directly.
- Choosing a selection results in a full page refresh.
- Opens in a new window.