Promptfoo

Automated testing platform that uses red teaming to identify and fix security vulnerabilities in AI applications before deployment

Also known as
promptfoo

Available worldwide · Popular in: US

What is Promptfoo?

A comprehensive LLM security testing solution that automatically scans for vulnerabilities such as prompt injections and jailbreaks through dynamic red teaming. Offers both open-source software for local testing and enterprise SaaS with team collaboration, continuous monitoring, and compliance dashboards.

Independently observed

Promptfoo pricing

Plans, per-tier features and add-ons, dated and linked to live pricing. Pricing changes often; always verify at source before you rely on it.

Pricing as of verify at live pricing ↗Independently observed
HybridFree tier

Free open-source Community tier; Enterprise and On-Premise plans with custom pricing

Community

Free
Free

Open-source version for individual developers and small teams

red_teaming_probes
10k/mo
  • All LLM evaluation features
  • All model providers and integrations
  • Red teaming (10k probes/month)
  • Custom integration with your own app
  • Run locally or self-host on your own infrastructure
  • Vulnerability scanning
  • Community support

Enterprise

Contact sales
Contact sales

Managed cloud platform with team collaboration, continuous monitoring, and compliance features

  • All Community features
  • Custom red teaming limits
  • Team sharing & collaboration
  • Continuous monitoring
  • Centralized security/compliance dashboard
  • Customizable attack profiles and target settings
  • SSO and granular permission profiles
  • Promptfoo API access
  • Managed cloud deployment
  • Professional services support
  • Priority support & SLA guarantees

On-Premise

Contact sales
Contact sales

Custom deployment for organizations requiring full control over infrastructure

  • Complete data isolation
  • On-premise deployment

What Promptfoo does

The capabilities that matter for prompt management, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Capabilities
Versioning model
UI hosted registry
Diff and rollback
-
Deploy without redeploy
-
Non engineer editing
Multi model playground
-
Ab testing
-
LLM judge or human eval
Multi step flows
-
Approval workflow
-
Tracing included
-
Self hostable
Deployment model
-
Pricing model
-
Independently observed

Platform & deployment

Independently observed
Platforms
  • CLI
  • Web
Deployment
  • Cloud / SaaS
  • Hybrid
  • On-premise
  • Self-hosted

Integrations (11)

Independently observed
  • OpenAI
  • Anthropic
  • Google (Gemini)
  • DeepSeek
  • MCP (Model Context Protocol)
  • CI/CD pipelines
  • Webhooks
  • Agent frameworks
  • CI/CD platforms
  • GitHub
  • Python providers

Promptfoo alternatives

Other prompt management we track, ranked by the same independent score.

All Promptfoo alternatives, ranked →

Independent · unbought · dated

The Vioscale score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Promptfoo, not the verdict.

Balanced composite 54 / 100
medium · 55%updating
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture650.074.7
Price level800.054.2
Capabilities870.054.2
Pricing transparency250.082.1
Integrations240.041.0
Reliability00.070.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Features

AttributeValueEvidence
CapabilitiesSoc2 type ii: Yes · Self hostable: Yes · Versioning model: UI-hosted registry · Non engineer editing: No · Llm judge or human eval: Yes · Llm as a judge prompt grading framework: Yesmediumsource · 2026-08-21 · 60%

Integrations

AttributeValueEvidence
Count6mediumsource · 2026-08-21 · 60%

Market

AttributeValueEvidence
AvailabilityHqCountry: US · PrimaryMarkets: … · AvailabilityScope: global · AvailableCountries: … · NotAvailableCountries: …highsource · 2026-08-21 · 75%

Pricing

AttributeValueEvidence
Free tierYesmediumsource · 2026-08-21 · 60%
Price levellowmediumsource · 2026-08-21 · 60%
TransparentNomediumsource · 2026-08-21 · 60%
Modelfreemiummediumsource · 2026-08-21 · 60%

Security

AttributeValueEvidence
Iso27001Yeshighsource · 2026-08-21 · 75%
Soc2Yeshighsource · 2026-08-21 · 75%