Skip to main content
Favicon of Promptfoo

Promptfoo

What is Promptfoo?

Promptfoo is an AI security testing platform for AI product, security, and platform teams that generates application-specific attacks, runs evaluations, and turns findings into remediation guidance. It combines Red Teaming, Guardrails, MCP Proxy, Code Scanning, Evaluations, and Automated PR review, and is used by OpenAI, Anthropic, Shopify, Discord, Okta, Fidelity, and Fortune 500 companies. Plans run Community Free Forever, Enterprise Custom, and On-Premise Custom.

Last verifiedHow we evaluate

Screenshot of Promptfoo website

At a glance

Best for
Promptfoo is best for AI product teams who need continuous security testing before release.
Pricing
Community Free Forever; Enterprise Custom; On-Premise Custom

What it does and why teams pick it

Promptfoo is a CLI/library that runs declarative evaluation configs against LLM prompts, comparing outputs across providers (OpenAI, Anthropic, Azure, Bedrock, Ollama, and others), and a separate red-teaming mode that generates adversarial probes to find prompt injection, jailbreak, data-leak, and other vulnerabilities in a live LLM application. Evaluations run 100% locally — prompts and results don't leave the machine unless you choose to share them — and there's no agent or SDK to install in the target app; it tests black-box or gray-box against anything reachable over HTTP. It plugs into CI/CD for regression testing on every prompt or model change. Source: GitHub README (https://github.com/promptfoo/promptfoo) and Promptfoo docs (https://www.promptfoo.dev/docs/intro/).

Adoption and project health

25,234 GitHub stars and 2,331 forks as of 2026-09-18 (https://api.github.com/repos/promptfoo/promptfoo), with 346+ recorded contributors (https://www.promptfoo.dev/about). The npm package took 2,633,102 downloads in the 30 days ending 2026-09-16 (https://api.npmjs.org/downloads/point/last-month/promptfoo), and the repo shipped a release (0.123.0) as recently as 2026-09-10 with a further code push on 2026-09-17, so this is an actively maintained project, not a dormant one. Promptfoo itself claims (unverified by us) more than 350,000 developers have used it, 130,000 monthly active, and adoption at over 25% of the Fortune 500 — company claim, stated on its own blog (https://www.promptfoo.dev/blog/promptfoo-joining-openai/) and repeated in OpenAI's acquisition announcement.

The OpenAI acquisition

On 2026-03-09 OpenAI announced it had agreed to acquire Promptfoo, to fold its testing/red-teaming technology into OpenAI Frontier, OpenAI's platform for building AI "coworkers" (https://openai.com/index/openai-to-acquire-promptfoo/). Promptfoo's own announcement confirms the open-source project will remain open source and MIT-licensed, and that the team — co-founders Ian Webster (CEO) and Michael D'Angelo (CTO), plus a roughly 23-person company — will continue supporting existing users (https://www.promptfoo.dev/blog/promptfoo-joining-openai/). Both announcements describe the deal as subject to "customary closing conditions"; we found no independent source confirming the acquisition has since closed, and the GitHub organization, npm package, and release cadence are all still running under the standalone promptfoo name as of 2026-09-18. For a buyer, the practical question isn't whether the code still works — it does, and is still shipping — but whether you're comfortable with an AI-security testing tool being owned by one of the model vendors (OpenAI) it's used to independently evaluate. That's a trade-off to weigh, not a defect.

Pricing

Community is free and open source (MIT), with all evaluation features, all model-provider integrations, and red teaming up to 10,000 probes per month included at no charge; it can run locally or be self-hosted (https://www.promptfoo.dev/pricing). Enterprise (fully managed SaaS) and Enterprise On-Prem (self-hosted with a dedicated runner, for complete data isolation) add team/SSO/RBAC, continuous monitoring, a compliance dashboard, and priority support with an SLA — but neither publishes a price; both require contacting sales for a custom quote (https://www.promptfoo.dev/pricing). That means a buyer can start free and stay free for a meaningful amount of red-teaming before hitting the probe cap, but can't get a real number for anything beyond Community without a sales call.

Security and license posture

The core package is MIT-licensed, confirmed against the repo's own LICENSE file (https://raw.githubusercontent.com/promptfoo/promptfoo/main/LICENSE) — no source-available or BSL clause. No open vulnerabilities were found for the promptfoo npm package in OSV.dev or in GitHub's security-advisories feed for the repo, checked 2026-09-18 (https://api.osv.dev/v1/query, https://api.github.com/repos/promptfoo/promptfoo/security-advisories — both empty). Promptfoo publishes a Trust Center (Vanta-hosted, at https://trust.promptfoo.dev) and a public status page (https://status.promptfoo.dev), though we could not verify current uptime figures from the status page — it returned an internal data-fetch error at time of check rather than a working history.

How much does Promptfoo cost?

PlanPriceWhat's included
CommunityFree Forever
  • All LLM evaluation features
  • All model providers and integrations
  • Red teaming (10k probes/month)
  • Custom integration with your own app
  • Run locally or self-host on your own infrastructure
  • Vulnerability scanning
  • Community support
EnterpriseCustom
  • All Community features
  • Custom red teaming limits
  • Team sharing & collaboration
  • Continuous monitoring
  • Centralized security/compliance dashboard
  • Customizable attack profiles and target settings
  • SSO and granular permission profiles
  • Promptfoo API access
  • Managed cloud deployment
  • Professional services support
  • Priority support & SLA guarantees
On-PremiseCustom
  • All Enterprise features
  • Deployment on your own infrastructure
  • Complete data isolation
  • Dedicated runner
  • Assigned deployment engineer

Frequently asked questions

What is Promptfoo?

Promptfoo is an AI security testing platform for AI product, security, and platform teams that generates application-specific attacks, runs evaluations, and turns findings into remediation guidance. It combines Red Teaming, Guardrails, MCP Proxy, and Code Scanning, and is used by OpenAI, Anthropic, Shopify, Discord, Okta, and Fidelity. Plans run Community Free Forever, Enterprise custom, and On-Premise custom.

How much does Promptfoo cost? Is it free?

Promptfoo has a free plan, with paid tiers including Enterprise at Custom, On-Premise at Custom.

What is Promptfoo used for? Who is it for?

Promptfoo is used for Red Teaming, Guardrails, and MCP Proxy. It's built for Security directors, Developers, and Platform teams.

Does Promptfoo have an API and what does it integrate with?

Promptfoo doesn't publish a public API.

Editor's read

Check whether your workflow needs the 10k probes/month Community ceiling or the custom red teaming limits in Enterprise. If you also need complete data isolation, that is only listed on On-Premise.

Share:

Sponsored
Favicon

 

  
 

Explore other Security AI Agents

Favicon

 

  
  
Favicon

 

  
  
Favicon