promptfoo
Promptfoo is an AI security testing platform that helps developers and enterprises find and fix vulnerabilities in LLM applications through automated red teaming, guardrails, and evaluations.
At a Glance
Pricing
Free forever open-source plan for individual developers and small teams.
Engagement
Available On
Listed Mar 2026
About promptfoo
Promptfoo is an open-source AI security testing platform used by 127 of the Fortune 500 to proactively identify and remediate vulnerabilities in LLM applications, agents, and RAG pipelines. It provides automated red teaming, real-time guardrails, model security testing, and prompt/model evaluations — all integrated directly into developer workflows and CI/CD pipelines. Backed by Andreessen Horowitz and Insight Partners, Promptfoo is built by practitioners who scaled generative AI to hundreds of millions of users. With over 300,000 open-source users and 134,000+ weekly downloads, it represents the world's largest AI security community.
- Automated Red Teaming — Run
npx promptfoo@latest redteam setupto generate thousands of context-aware attacks including prompt injections, jailbreaks, PII leaks, and business rule violations tailored to your application. - Real-Time Guardrails — Deploy runtime protection against jailbreaks and adversarial attacks to shield production AI applications from live threats.
- Model Security Testing — Conduct comprehensive security assessments across foundation models and custom deployments to benchmark safety and compliance.
- LLM Evaluations — Test and compare prompts, models, and RAG pipelines with configurable YAML-based test suites and view results locally or in the cloud.
- MCP Proxy — Secure Model Context Protocol communications with a dedicated proxy layer for agent frameworks.
- Code Scanning — Find LLM vulnerabilities directly in your IDE and CI/CD pipeline before they reach production.
- CI/CD Integration — Connect to GitHub, GitLab, Jenkins, and more to run continuous security testing as part of your development lifecycle.
- Compliance Dashboards — Verify adherence to industry frameworks (HIPAA, FINRA, etc.) with centralized reporting and issue tracking.
- Threat Intelligence — Leverage real-time attack data from a community of 300,000+ developers, with contributors from OpenAI, Google, Microsoft, and Amazon.
- Enterprise Controls — SSO, granular permissions, team-based access control, webhooks, and managed cloud or on-premise deployment options.
Community Discussions
Be the first to start a conversation about promptfoo
Share your experience with promptfoo, ask questions, or help others learn from your insights.
Pricing
Free Plan Available
Free forever open-source plan for individual developers and small teams.
- All LLM evaluation features
- All model providers and integrations
- Red teaming (10k probes/month)
- Custom integration with your own app
- Run locally or self-host on your own infrastructure
Enterprise
For teams that need advanced features, collaboration, and enterprise-grade security.
- All Community features
- Custom red teaming limits
- Team sharing & collaboration
- Continuous monitoring
- Centralized security/compliance dashboard
- Customizable attack profiles and target settings
- SSO and granular permission profiles
- Promptfoo API access
- Managed cloud deployment
- Professional services support
- Priority support & SLA guarantees
Enterprise On-Premise
For organizations that require full control over their infrastructure with complete data isolation.
- All Enterprise features
- Deployment on your own infrastructure
- Complete data isolation
- Dedicated runner
- Assigned deployment engineer
Capabilities
Key Features
- Automated red teaming
- Real-time guardrails
- Model security testing
- LLM evaluations
- MCP proxy
- Code scanning
- CI/CD integration
- Compliance dashboards
- Threat intelligence
- SSO and access control
- On-premise deployment
- Continuous monitoring
- Remediation guidance in PRs
- RAG pipeline evaluation
- 50+ vulnerability types coverage
