Promptfoo
Promptfoo is an AI security and evaluation platform providing automated red-teaming, vulnerability scanning, and compliance testing tools for enterprises deploying LLM applications. Its hybrid open-source and enterprise SaaS model served 156 Fortune 500 companies and 350,000+ developers before being acquired by OpenAI in March 2026.
- Company typePrivate
- Founded2024
- HeadquartersSan Francisco, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Promptfoo does
Promptfoo was a privately-held AI security and evaluation platform founded in 2024 in San Francisco by co-founders Ian Webster (CEO) and Michael D'Angelo. The company developed open-source and enterprise tools for testing, red-teaming, and securing large language model (LLM) applications and AI agents, addressing vulnerabilities including prompt injections, jailbreaks, data and PII leaks, business rule violations, and insecure tool use in agents. Its product suite comprised Red Teaming, Guardrails, Model Security, MCP Proxy, Code Scanning, and Evaluations, supported by industry-specific solutions for Financial Services (FINRA-aligned), Insurance, Telecommunications, and Real Estate.
The platform integrated directly into CI/CD pipelines (GitHub, GitLab, Jenkins) and agent frameworks (LangChain, LangGraph, CrewAI, OpenAI Agents SDK, Claude Agent SDK, Google ADK, Azure AI Foundry Agents), with support for multimodal AI workloads spanning text, code, audio, image, and video. Coverage extended to 50+ vulnerability types using LLM-as-judge grading and proprietary multi-turn attack strategies (Hydra, Crescendo, GOAT). The platform was multi-provider by design, testing applications built on OpenAI, Anthropic, AWS Bedrock, Google, Azure, and open-source models.
Promptfoo operated a hybrid go-to-market combining product-led growth via a free open-source CLI distributed through npm and GitHub (20.6k stars) with enterprise field sales targeting Fortune 500 customers across financial services, healthcare, telecommunications, retail, insurance, and travel. Revenue was generated through enterprise SaaS subscriptions with advanced features including team management, audit logging, compliance frameworks, and priority support. By mid-2025, the platform reported 156 Fortune 500 customers and 300,000-350,000 developer users, with SOC 2 Type II and ISO 27001 certifications supporting enterprise procurement. In March 2026, OpenAI announced its acquisition of Promptfoo to integrate the security testing capabilities into the OpenAI Frontier enterprise platform for AI agents.
Promptfoo firmographics
Firmographics- Name
- Promptfoo
- Legal name
- Promptfoo Inc.
- Website
- https://promptfoo.dev
- Company type
- Private
- Founded year
- 2024
- Operating status
- Acquired
- Headcount range
- 1–10 employees
- Short description
- Promptfoo is an AI security and evaluation platform providing automated red-teaming, vulnerability scanning, and compliance testing tools for enterprises deploying LLM applications. Its hybrid open-source and enterprise SaaS model served 156 Fortune 500 companies and 350,000+ developers before being acquired by OpenAI in March 2026.
- Ownership category
- akta.pro rank
Promptfoo industry classification
Industry- Product category
- AI Security Testing Software
- NAICS
- Custom Computer Programming Services (541511), Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151)
- SIC
- Services-Prepackaged Software (7372), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Prompt Security & Injection Defense (HDAAAKAE)
- akta.pro secondary industries
- Prompt Engineering, Orchestration & LLMOps Tooling (HDAAACAD), DevSecOps & Supply Chain Security (DevOps toolchain security) (BPAEAKAI), Web Application Security (WAF, RASP) (HDADACAA)
Keywords
Where Promptfoo is headquartered
LocationHeadquarters
- HQ city
- San Francisco
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Promptfoo business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- Enterprise SaaS Subscription: Enterprise-tier subscription model with advanced features including team management, audit logging, compliance frameworks, and priority support. Pricing based on usage volume and team size.
- Open Source Tools: Free open-source CLI and developer library distributed via npm (npx promptfoo@latest). Drives community adoption and top-of-funnel awareness.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Open Source / Free Tier |
| Subscription | Annual | Enterprise Tier |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels6 records
Promptfoo product offering
Product offeringCore offering
Promptfoo develops an AI security testing and evaluation platform consisting of an open-source CLI and an enterprise cloud product. The platform helps organizations discover and remediate vulnerabilities in LLM applications and AI agents through automated red teaming, real-time guardrails, model integrity scanning, MCP proxying, IDE/CI-CD code scanning, and prompt/model/RAG evaluation. It is used by developers and enterprise security teams to test for prompt injections, jailbreaks, data leaks, business rule violations, and insecure tool use.
Product overview
Promptfoo is an AI security and evaluation platform that provides a comprehensive suite of tools for testing and securing AI applications. The core product portfolio includes Red Teaming (automated vulnerability discovery), Guardrails (real-time protection), Model Security (model integrity scanning), MCP Proxy (secure MCP communications), Code Scanning (IDE/CI/CD integration), and Evaluations (prompt/model/RAG testing). These products work together as an integrated security testing platform built into the development workflow, with the CLI and open-source tooling serving as the foundation while enterprise features add team management and compliance capabilities. Industry-specific solutions (Financial Services, Insurance, Telecommunications, Real Estate) provide domain-aligned testing plugins. With the March 2026 acquisition by OpenAI, Promptfoo's technology is being integrated into the OpenAI Frontier platform for enterprise AI agent security.
Differentiator
Problem solved
Functional benefit
Products and services
- Red Teaming Automated red teaming platform that simulates real users to uncover application-specific vulnerabilities in LLM applications and AI agents, including direct and indirect prompt injections, jailbreaks, data and PII leaks, business rule violations, insecure tool use in agents, and toxic content generation. Covers 50+ vulnerability types with multi-turn attack strategies (Hydra, Crescendo, GOAT, Mischievous User). Used by security teams and developers to proactively identify and fix vulnerabilities before deployment.
- Guardrails Real-time protection layer against jailbreaks and adversarial attacks for deployed AI systems. Provides automated safeguards that intercept malicious prompts and adversarial inputs at inference time. Targeted at enterprises operating production AI applications that need runtime defense in addition to pre-deployment testing.
- Model Security Comprehensive security testing and monitoring for AI models across development and production environments, including static model scanning via ModelAudit to verify model integrity before deployment. Used by model developers and security teams to detect compromised or unsafe model artifacts.
- MCP Proxy Enterprise-grade secure proxy for Model Context Protocol (MCP) communications with access control and traffic monitoring for MCP server data. Used by enterprises deploying MCP-based AI agent architectures that need to govern and audit tool and data access.
- Code Scanning IDE and CI/CD-integrated scanning to find LLM vulnerabilities in codebase, including fork PR support and comment-triggered scans. Analyzes potential AI security issues in application code before they reach production, delivering remediation guidance directly in pull requests for developers.
- Evaluations Testing and evaluation framework for prompts, models, and RAG pipelines with configurable assertions and metrics including LLM-as-judge grading, context-faithfulness, context-recall, context-relevance, answer-relevance, and factuality. Enables systematic quality assessment and supports multi-modal evaluation across text, image, audio, video, and code.
Quantifiable outcome
- 156 Fortune 500 companies trust Promptfoo for AI security
- +2 more outcomes
Companies that use Promptfoo
Customer profileNamed customers11 records
Segments7 records
Ideal customer profiles2 records
Promptfoo technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration14 records
AI capability12 records
Feature6 records
Promptfoo partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- OpenAIflagshipOpenAI announced acquisition of Promptfoo in March 2026 to integrate its security testing technology into the OpenAI Frontier platform for AI agents. Promptfoo's technology will be integrated into OpenAI's enterprise AI platform to provide automated security testing capabilities.
Scale indicators6 records
Recent moves6 records
Expansion highlights6 records
Promptfoo competitors and assessment
Company assessmentDirect peers
- Lakera: Lakera is the closest direct competitor to Promptfoo, offering an AI security platform (Gandalf Agent) for LLM prompt injection defense, red-teaming, and guardrails. Both target enterprise security teams protecting production LLM applications with similar developer-focused tooling.
- Protect AI: Protect AI offers AI/ML security scanning (including LLM scanning via Guardian) and model supply-chain security. Acquired by Palo Alto Networks in 2024, it competes with Promptfoo on model and application-layer AI security testing for enterprise developers.
- Robust Intelligence: Robust Intelligence provides an AI firewall and continuous validation platform for production AI systems. Acquired by Cisco in 2024, it overlaps with Promptfoo's model security and continuous monitoring offerings for enterprise AI deployments.
- HiddenLayer: HiddenLayer offers AI threat detection, model scanning, and red-teaming services for AI/ML applications. It directly competes with Promptfoo on adversarial robustness testing and AI security posture management for enterprises.
- Calypso AI: Calypso AI provides an AI security and observability platform with red-teaming, prompt evaluation, and policy enforcement capabilities. It competes directly with Promptfoo in serving enterprise security teams evaluating LLM applications.
- Arthur AI: Arthur AI is an AI observability and security platform that monitors, evaluates, and protects production LLM applications. It competes with Promptfoo on the observability/guardrail side and increasingly on evaluation and red-teaming for enterprise AI deployments.
Emerging players
- Mindgard: Mindgard offers an AI security testing platform (DynaGuard) specializing in red-teaming for generative AI and LLM applications. It overlaps with Promptfoo on automated adversarial testing but focuses more narrowly on the red-team attack surface.
- TrojAI: TrojAI (formerly from Unlearn.AI spinoff) provides AI model security evaluation and adversarial robustness testing. It has partial overlap with Promptfoo's model security and red-teaming offerings, particularly for ML model risk assessment.
Broad incumbents
- NVIDIA NeMo Guardrails: NVIDIA's NeMo Guardrails is an open-source toolkit for adding programmable guardrails to LLM applications. As an incumbent platform offering, it overlaps with Promptfoo's Guardrails product but is bundled with NVIDIA's broader enterprise AI stack.
- Microsoft Azure AI Content Safety: Azure AI Content Safety provides prompt shield, jailbreak detection, and content moderation APIs as part of Microsoft's cloud AI platform. It competes with Promptfoo on guardrails and prompt security, leveraging Azure's distribution scale.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Promptfoo social profiles
Digital presencePromptfoo compliance and trust
Trust signalCompliance2 records
Promptfoo financial estimates
Financial estimateRevenue estimate
Valuation estimate
Promptfoo leadership team
Management profileNumber of profiles
Profiles2 records
Promptfoo funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Promptfoo M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Promptfoo
What does Promptfoo do?
Promptfoo develops an AI security testing and evaluation platform consisting of an open-source CLI and an enterprise cloud product. The platform helps organizations discover and remediate vulnerabilities in LLM applications and AI agents through automated red teaming, real-time guardrails, model integrity scanning, MCP proxying, IDE/CI-CD code scanning, and prompt/model/RAG evaluation. It is used by developers and enterprise security teams to test for prompt injections, jailbreaks, data leaks, business rule violations, and insecure tool use.
Is Promptfoo a public or private company?
Promptfoo is a private company. It is classified as corporate owned and is currently acquired.
When was Promptfoo founded?
Promptfoo was founded in 2024. It employs 1 to 10 people.
Where is Promptfoo based?
Promptfoo is headquartered in San Francisco, United States, in the North America region.
How does Promptfoo make money?
Two revenue lines are on record. Enterprise SaaS Subscription is the primary driver. The others are open Source Tools.
Who are Promptfoo's main competitors?
Direct peers on record are Lakera, Protect AI, Robust Intelligence, HiddenLayer, Calypso AI and Arthur AI. Emerging players are Mindgard and TrojAI. Broad incumbents are NVIDIA NeMo Guardrails and Microsoft Azure AI Content Safety.
Does Promptfoo have an API?
Yes. Promptfoo provides a Node.js API (evaluate()) for programmatic evaluation of prompts, models, and RAG pipelines. The API supports custom assertions, provider configuration, and test case management. Additionally, Promptfoo offers an MCP (Model Context Protocol) Proxy product for secure MCP communications. Developer documentation is at www.promptfoo.dev/docs/api-reference.
What industry is Promptfoo in?
Promptfoo's product category is AI Security Testing Software. Its primary akta.pro industry code is HDAAAKAE, Prompt Security & Injection Defense, with a secondary code of HDAAACAD, Prompt Engineering, Orchestration & LLMOps Tooling. Its NAICS code is 541511 and its SIC code is 7372.