Promptfoo

Security for AI acquired

Market readinessHow well the company can compete in its security market, scored across eight dimensions against public evidence. Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
DefensibilityHow well the company holds its position if competitors catch up on features, scored across seven dimensions against public evidence. Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure.
Founded 2024
Funding $23.4M
Last updated 2026-08-28

All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.

Executive Summary

Promptfoo sells AI security testing to teams building on language models. Its software attacks those applications to find flaws, scans models and source code, and adds real-time guardrails and a proxy for enterprise buyers. OpenAI now owns the company and will fold the testing into Frontier, its enterprise agent product. Other AI vendors teach the tool inside their own material: Anthropic gives it five of the nine lessons in its prompt-evaluation course, and Amazon Web Services publishes a workshop built on it. Promptfoo’s site claims 156 of the Fortune 500 use it. Enterprise revenue, a named paying-customer roster and deal terms stay undisclosed, so the size of the paid business is not visible.

Sourced Details

Description Promptfoo is an AI security platform that red-teams language-model applications and agents, scans models and source code for vulnerabilities, and offers real-time guardrails and an MCP proxy to enterprise buyers. [f1]
Acquisition OpenAI, announced 2026-03-09 [f2]
Founded 2024 [f3]
HQ San Francisco, California, United States [f4]
Funding $23.4M total [f5]
Latest funding Series A, 18.4M USD, July 2025, led by Insight Partners [f6]
Deployment Self-hosted [f7]

Products

Product What it does
Promptfoo Promptfoo: AI security platform spanning red teaming, evaluations, model and code scanning, real-time guardrails, and an enterprise MCP proxy, with an open-source CLI and library at its core.

Matrix Coverage

AI Defense Matrix

GovernIdentifyProtectDetectRespondRecover
AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain.
AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices.
AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD.
AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic.
AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes.
Training Data Datasets used for training, fine-tuning, and continued learning.
Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history.
AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools.

Promptfoo red-teams language-model applications and agents, scans model files and source code for vulnerabilities, and runs a proxy in front of Model Context Protocol servers. These capabilities are mapped to the AI Defense Matrix. [f8]

Market Readiness

How well the company can compete in its security market, scored across eight dimensions against public evidence.

Established 28 /40 Established: Market readiness of 25 to 30, the typical band where most analyzed companies land.
Dimension Score Rationale
Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. 3/5 The buyer and the problem are stated clearly, and CSO Online reports IDC placing prompt injection among the concerns enterprises name, but that pain is described rather than quantified, which is what the higher rung asks for. [s2, s16, s1]
Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. 4/5 Published documentation covers the attack generation and grading method in detail. The external validation is plural: an MIT-licensed repository with 24,625 stars, a Dreadnode-authored preprint characterising the tool, and Semgrep’s engineering write-up of using it to test the AI features behind its product. No third-party benchmark in the reviewed sources separates it from the peer frameworks the preprint names alongside it. [s2, s21, s18, s22]
Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. 4/5 Two distinct buyer-side signals sit inside the last year. The European Commission records the AI Act becoming applicable on 2 August 2026 with AI Office enforcement, and Article 55 requires documented adversarial testing for general-purpose models with systemic risk. Separately, CSO Online on 10 March 2026 reports IDC finding prompt injection among enterprise concerns and Counterpoint calling these tools table stakes. The enabler the record dates is regulatory: the AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026. [s25, s26, s16, s17]
Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. 4/5 The record now carries an exit in the same field, with OpenAI agreeing in March 2026 to acquire the company. The founders also carry prior in-domain builds, with Ian Webster leading language-model engineering at Discord and Michael D’Angelo running AI engineering at Smile Identity. Community standing is plural too, with over 323 open-source contributors and a place in Anthropic’s own course. [s11, s8, s17, s23]
GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. 4/5 Three outside organisations document the adoption on their own properties. Semgrep’s engineers ran their evaluation system on it for at least half a year and wrote it up, Anthropic builds five of the nine lessons in its prompt-evaluation course on it, and Amazon Web Services publishes a Bedrock workshop. Promptfoo’s press page calls the courses and workshops partnership work. The Fortune 500 share and developer counts are company figures relayed by TechCrunch, The Next Web and the acquirer, and no revenue, analyst placement or named paying customer appears, so the top rung is not reached. [s22, s23, s24, s10, s13, s17, s11, s9]
Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. 4/5 Roughly 23.4 million dollars across four rounds produced a team the founders put at 23 people, six documented product surfaces and an agreed sale to OpenAI, which is confirmed output per dollar and is multiply sourced. Terms were not disclosed and no revenue or margin appears, so an exit alone does not reach the top rung. [s19, s10, s13, s15, s1]
Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. 3/5 Outside sources do place the tool without vendor coaching, with an arXiv preprint slotting it into a named class of automated red-teaming frameworks. The category itself is still forming, with Counterpoint describing these tools as becoming table stakes, and the cited record settles no budget line for them. [s18, s16]
Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. 2/5 Absorption is documented rather than hypothetical here. OpenAI agreed to buy the company and says automated security testing will become a native part of Frontier, and The Next Web reports Anthropic shipping a comparable code-security scanner a month before the deal. [s11, s17, s10]
Business Risks OpenAI could favour the paid testing inside Frontier over the open-source project that 300,000 developers adopted, which would slow the free tool that feeds the paid one…
  • OpenAI could favour the paid testing inside Frontier over the open-source project that 300,000 developers adopted, which would slow the free tool that feeds the paid one.
  • Developers and teams that valued the tool belonging to no model provider could move to an independent alternative now that OpenAI owns it.
  • Rival labs could stop teaching or recommending a tool owned by OpenAI, which would cost Promptfoo the cross-lab standing that Anthropic’s own course currently shows.
  • Enterprise revenue and paying customer names are undisclosed, so the paid business could be far smaller than the free adoption suggests.
  • Incumbent providers are shipping comparable capability, with Anthropic launching Claude Code Security in February 2026 and OpenAI making automated red teaming native to Frontier, which could leave less room for a separate purchase.
  • The runtime products, Guardrails and the MCP Proxy, carry no named customer in the reviewed sources, so the move from development-time testing into production controls is unproven.
Problem & Market Promptfoo sells to the teams putting language models into production, and it names the developer and the security buyer alike…

Promptfoo sells to the teams putting language models into production, and it names the developer and the security buyer alike. Its documentation frames the problem as vulnerabilities that adversarial inputs expose before a system reaches production, from prompt injection through information leakage in retrieval systems and misuse of the APIs an agent can call. The homepage addresses chief information security officers, security directors and developers in one section.

Independent reporting supports the demand behind that pitch. CSO Online, writing on 10 March 2026, cites IDC’s 2025 Asia/Pacific Security Study. That study places prompt injection and model manipulation among the concerns enterprises report. The same article quotes Counterpoint Research saying red teaming, governance and evaluation tools are becoming table stakes.

European regulation now names the same activity. The European Commission records that the AI Act became applicable on 2 August 2026, with the AI Office enforcing the rules for general-purpose models. Article 55 of that law requires providers of general-purpose models with systemic risk to conduct and document adversarial testing. [s2, s16, s25, s26, s1]

Product Capabilities Promptfoo documents six product surfaces…

Promptfoo documents six product surfaces. The site lists Red Teaming, Guardrails, Model Security, MCP Proxy, Code Scanning and Evaluations, so the range runs from development-time testing to controls that sit in front of a running application.

The testing method is published in full. The documentation describes generating a diverse set of malicious intents, wrapping each one in a prompt that tries to exploit the target, then grading the outputs with deterministic and model-graded metrics. Teams run it as a one-off report or continuously inside a build pipeline.

Two of the surfaces work at runtime. The MCP Proxy sits between users, AI applications and the Model Context Protocol servers they call, allowing only approved servers and logging every request. Guardrails offers real-time protection that the vendor says improves from red-team findings, and it can also test guardrail systems a customer already runs.

The open-source core is what a buyer can inspect. The repository carries an MIT licence and 24,625 stars, the about page counts over 323 open-source contributors, and the code scanner traces how user input reaches a model prompt across several files. [s1, s2, s3, s4, s6, s21, s8]

Competitive Positioning Independent research places Promptfoo inside a named class of tools…

Independent research places Promptfoo inside a named class of tools. A May 2026 arXiv preprint on agentic red teaming lists Microsoft’s PyRIT, NVIDIA’s Garak, Promptfoo and Meta’s Purple Llama CyberSecEval as the widely adopted automated red-teaming frameworks. It characterises Promptfoo as a configuration-driven tool that runs YAML-defined adversarial tests against model endpoints. Every author of that preprint gives an affiliation at Dreadnode, whose own AI red-teaming agent the paper introduces, so it reads as a rival’s account rather than neutral validation.

Model providers are building the same capability in house. The Next Web reports that Anthropic launched Claude Code Security in February 2026 aimed at similar vulnerability-scanning work, and OpenAI says automated security testing and red teaming will become a native part of its Frontier agent product.

The Next Web reports that developer adoption was built on the premise that the tool belonged to the developer community rather than to any one vendor. The open-source suite tests applications built on any model, and the founders committed to keep maintaining it for any model or application. A model provider owns the company now. [s18, s17, s11, s10, s8]

Go-to-Market & Traction Promptfoo runs a free-to-paid motion and publishes the free half…

Promptfoo runs a free-to-paid motion and publishes the free half. The Community tier costs nothing, covers evaluation features and caps red teaming at 10,000 probes a month, run locally or self-hosted. Enterprise and On-Premise tiers are quoted on request and add collaboration, a compliance dashboard, single sign-on and managed or isolated deployment.

The reach figures all come from the company. Its site states that 156 of the Fortune 500 use Promptfoo in their AI development lifecycle, and the March 2026 acquisition post reports more than 350,000 developers having used it and 130,000 active each month.

Third parties document adoption of a different kind. Anthropic devotes five of the nine lessons in its own prompt-evaluation course to Promptfoo. Amazon Web Services publishes a Bedrock workshop built on it. Semgrep’s engineering team wrote up using it to test the AI features behind its product.

The paid business stays private. No named paying customer appears in the reviewed sources, enterprise revenue is undisclosed, and SecurityWeek reports the acquisition terms were not disclosed either. CB Insights records roughly 23.4 million dollars raised over four rounds, and the company has filed two Form D notices with the Securities and Exchange Commission. [s7, s1, s10, s23, s24, s22, s15, s19, s20]

Team & Credibility The founders built AI products at scale before starting the company…

The founders built AI products at scale before starting the company. Ian Webster ran language-model engineering and developer platform work at Discord, where AI products reached 200 million users under safety, security and policy standards. Michael D’Angelo was vice president of engineering and head of AI at Smile Identity, where he scaled machine learning to serve over 100 million people.

The exit is the strongest verifiable outcome on their record. OpenAI announced on 9 March 2026 that it is acquiring the company, roughly two years after the commercial launch that The Next Web dates to 2024 with a 5 million dollar seed round from Andreessen Horowitz.

The company also publishes research and holds community standing. Its press page lists coverage of its DeepSeek censorship work by Ars Technica, TechCrunch, Gizmodo and the Stanford Cyber Policy Center. It also runs a public Language Model Security Database that summarises primary-source AI security research. Over 323 open-source contributors work on the project.

The funding leaves a public regulatory trail. Promptfoo, Inc. appears in the Securities and Exchange Commission submissions record with two Form D exempt-offering notices. [s8, s17, s11, s9, s27, s20]

Trust Readiness Promptfoo publishes company attestations through an inspectable trust centre…

Promptfoo publishes company attestations through an inspectable trust centre. The rendered portal lists ISO 27001:2022 and SOC 2, and names an ISO 27001 certificate, a SOC 2 Type II report and an external penetration-test report alongside a request-access control.

Where the testing data sits depends on which tier a customer buys. The Community tier runs locally or self-hosted, and the On-Premise tier adds deployment on the customer’s own infrastructure with complete data isolation. The same trust centre lists Google Cloud Platform as a subprocessor for cloud-hosted infrastructure and AI services, and OpenAI as a subprocessor for application AI functionality. The reviewed record does not say which testing data reaches either.

The acquisition reshapes the deeper question. OpenAI owns the company and will fold the testing into a competing agent product. The MIT licence leaves an exit from the open-source core, and the commercial roadmap depends on OpenAI. [s12, s7, s11, s8, s21]

Competitors Dreadnode, NVIDIA, Meta, Anthropic, OpenAI…
Company Relationship Note Compare
Dreadnode competes with A Dreadnode-authored preprint on agentic red teaming positions its own platform against library-driven frameworks and names Promptfoo among them.
NVIDIA competes with That same preprint names NVIDIA’s Garak alongside Promptfoo among the automated red-teaming frameworks it calls widely adopted. N/ANVIDIA is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product.
Meta competes with The same preprint names Meta’s Purple Llama CyberSecEval in that framework set, so the two address the same evaluation buyer. N/AWe scored these companies at different scopes, so the totals measure different things.
Anthropic competes with The Next Web reports Anthropic launched Claude Code Security in February 2026 aimed at similar vulnerability-scanning work.
OpenAI adjacent The acquirer, which says automated security testing will become a native part of its Frontier agent product. N/AWe scored these companies at different scopes, so the totals measure different things.

Add analyzed competitors to compare them side by side with Promptfoo.

Strategy Deep Dive

A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.

Defensibility

Contested 13 /21 Contested: Defensibility of 13 to 14, the typical band, where a moat exists but is under pressure. reinforce or reposition

What a rival would have to reproduce here is reach. Promptfoo publishes its testing logic under an MIT licence, so a buyer can read the attack plugins and the graders, and the record names no private corpus behind them. The research database the company curates is open to browse as well. Its reach is harder to assemble. More than 300,000 developers use the free tool by the company’s count, over 323 open-source contributors work on it, and Anthropic teaches it inside its own course. That reach is a head start rather than a lasting edge, because it grew while the tool belonged to no model provider and OpenAI owns it now. Customers run the tool locally or on their own infrastructure, and no certification or mandate in the cited record makes replacing it expensive.

Dimension Score Rationale
Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. 1/3 Customers buy software, run locally, self-hosted, on their own infrastructure or in a Promptfoo-managed cloud deployment. The paid tiers add support staff and a deployment engineer around that software, and no human judgment or accountability for what the tests find is part of what Promptfoo sells.
Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. 2/3 Wiring the scanner into a build pipeline builds real friction, and the MCP Proxy and Guardrails put the product in front of live traffic. The cited record does not size what leaving would cost, and the vendor advertises no lock-in over an MIT-licensed core.
Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. 1/3 The trust centre publishes Promptfoo’s own ISO 27001:2022 and SOC 2 Type II, which a funded competitor can obtain through ordinary enterprise preparation. The product maps findings to OWASP, NIST and the EU AI Act for the customer, and holds no authorisation that a replacement would have to clear.
Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. 3/3 Generating application-specific attacks across prompt injection, jailbreaks and broken authorization, grading the responses reliably, tracing data flows to a model prompt across files, and filtering live traffic in real time is specialised adversarial machine-learning and application-security work.
Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. 3/3 The Next Web, relaying the company’s own Series A figures, reports over 30 Fortune 500 companies running the enterprise deployment in production, with customers spanning telecoms, financial services, retail and media. The vendor also sells dedicated offerings into financial services, insurance, telecommunications and real estate. Those buyers are unnamed and the counts are the company’s, which bounds the evidence without changing the class.
Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. 2/3 The product spans development-time testing and two runtime surfaces, a proxy in front of Model Context Protocol servers and real-time guardrails. That is more than one application, and the cited record shows no application depending on it to run.
Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. 1/3 The plugin catalogue and graders ship under an MIT licence, and the Language Model Security Database summarises published research on an open page. The guardrails page describes refining defenses from actual attack data and the homepage names threat intelligence from a 300,000-user community, and both describe a flow rather than an accumulated artifact the record shows the vendor holding.
Strategic Market Segmentation Promptfoo publishes a free tier an engineer can install without a purchase, and it quotes the Enterprise and On-Premise tiers on request…

Promptfoo publishes a free tier an engineer can install without a purchase, and it quotes the Enterprise and On-Premise tiers on request. The Community tier costs nothing and runs locally or self-hosted, and the product and pricing pages carry a demo request. The company reports more than 350,000 developers having used it and 130,000 active each month.

The paid segment is the large enterprise that wants governance over that use. Promptfoo’s site states that 156 of the Fortune 500 use the tool in their AI development lifecycle, and the Enterprise tier adds team access control, a compliance dashboard, single sign-on and service-level guarantees.

Regulated industries get their own front doors. The site sells financial-services testing aligned to FINRA rules, insurance testing on policyholder data and coverage accuracy, telecommunications testing for voice and text agents, and fair-housing testing for real estate. The Next Web, relaying the company’s own Series A figures, reports over 30 Fortune 500 enterprise deployments and customers spanning retail, telecoms, financial services and media.

Product Capabilities & AI Advantages Promptfoo generates attacks tailored to a specific application and grades what comes back…

Promptfoo generates attacks tailored to a specific application and grades what comes back. The documented process creates malicious intents, wraps each in a prompt that tries to exploit the target, and scores the outputs with deterministic and model-graded metrics. Plugins cover harmful content, broken object-level and function-level authorization, and competitor endorsement, and the tests map to the OWASP LLM Top 10, the NIST AI Risk Management Framework and the EU AI Act.

Two newer surfaces work while an application is running. The MCP Proxy sits between users, AI applications and the Model Context Protocol servers they call, permitting only approved servers and logging every request with alerts for sensitive-data exposure. Guardrails offers real-time protection that the vendor says learns from red-team findings.

Model and code security extend the same engine backwards. The model scanner analyses PyTorch, TensorFlow, Keras and Pickle files for malicious code and risky configurations before deployment. The code scanner uses agents to trace how user input reaches a model prompt across several files, then posts findings as pull-request comments.

The open-source base is what a security team can inspect. The repository carries an MIT licence and 24,625 stars, and over 323 open-source contributors work on it.

Sales Engagement & Go-to-Market Promptfoo runs a free-to-paid motion, and the free half carries the volume…

Promptfoo runs a free-to-paid motion, and the free half carries the volume. The Community tier covers evaluation features, all model providers and red teaming capped at 10,000 probes a month. The paid tiers add team access control, single sign-on, a centralised dashboard and managed or on-premise deployment, and both are quoted on request.

Every scale figure in the record belongs to the company. The site claims 156 of the Fortune 500, and the acquisition post reports more than 350,000 developers having used the tool and 130,000 active monthly. The Next Web relays the Series A figures of 125,000 developers and over 30 Fortune 500 enterprise deployments.

Outside organisations document adoption of a different kind. Anthropic gives Promptfoo five of the nine lessons in its own prompt-evaluation course, Amazon Web Services publishes a Bedrock workshop built on it, and Semgrep’s engineers wrote up using it against their production AI features.

What the record does not carry is the paid side. No named paying customer appears in the reviewed sources, enterprise revenue is undisclosed, and SecurityWeek reports that the acquisition terms were not disclosed, so the size of the commercial business stays out of view.

Pricing Model Promptfoo publishes the free tier and quotes the rest on request…

Promptfoo publishes the free tier and quotes the rest on request. Community is free forever and includes all evaluation features, every model provider and red teaming capped at 10,000 probes a month, run locally or self-hosted. Metering the free tier by probe volume signals that probes are the unit the company watches.

The Enterprise tier is custom-priced behind a demo request. It adds custom red-teaming limits, team sharing, continuous monitoring, a centralised security and compliance dashboard, single sign-on, API access and managed cloud deployment. Quoting Enterprise on request is the shape of a negotiated sale rather than a self-serve one.

The On-Premise tier charges for control rather than features. It carries all Enterprise features plus deployment on the customer’s own infrastructure, complete data isolation, a dedicated runner and an assigned deployment engineer. The page does publish two pricing factors: Enterprise pricing is customized on a team’s size and needs, and Enterprise customers can buy additional probes beyond the free 10,000 a month. Exact rates and the full formula stay behind a quote, so a buyer cannot size the cost of scaling before a sales call.

Product Delivery & Operations Promptfoo documents three deployment shapes…

Promptfoo documents three deployment shapes. Community runs locally or self-hosted on the team’s own infrastructure. Enterprise adds managed cloud deployment, and On-Premise adds deployment on the customer’s own infrastructure with complete data isolation.

The testing fits into existing development work. The documentation describes one-off runs that produce a report with suggested mitigations, and continuous runs inside a build pipeline that watch for regressions as an application changes. The code scanner adds a third placement, inside the editor and the pull request.

The paid tiers add people around the software, not in place of it. Enterprise lists professional services support, priority support and service-level guarantees, and On-Premise assigns a deployment engineer. The reviewed sources publish no uptime figure, so the reliability of the managed service cannot be checked from the record.

Earning Customers' Trust Promptfoo publishes company attestations on an inspectable trust centre…

Promptfoo publishes company attestations on an inspectable trust centre. The rendered portal lists ISO 27001:2022 and SOC 2, and names an ISO 27001 certificate, a SOC 2 Type II report and an external penetration-test report alongside a request-access control.

Where the data sits depends on the tier. Community runs locally or self-hosted and On-Premise adds complete data isolation, so a customer can keep testing inside its own environment. The same trust centre lists Google Cloud Platform as a subprocessor for cloud-hosted infrastructure and AI services, and OpenAI as a subprocessor for application AI functionality. The reviewed record does not say which testing data reaches either.

Ownership is now the harder trust question. OpenAI owns the company and will fold the testing into a competing agent product. The MIT licence leaves an exit for the open-source half, and the commercial roadmap depends on OpenAI.

Platform Strategy & Ecosystem Positioning Promptfoo positions itself as a testing layer for any AI application rather than a single-model tool…

Promptfoo positions itself as a testing layer for any AI application rather than a single-model tool. The Community tier lists all model providers and integrations, and the documentation covers integrations with build systems, so a team can test whatever it built on.

The ecosystem runs on open source and other people’s platforms. The MIT-licensed repository carries 24,625 stars and over 323 open-source contributors, and the paid tiers add customized red-teaming plugins and organization-specific attack profiles. That reach comes through software other organisations run, and the paid tiers are sold through a demo request.

Two other organisations now teach the tool inside their own material. Anthropic’s courses repository gives Promptfoo five of its nine prompt-evaluation lessons, and Amazon Web Services publishes a workshop pairing it with Bedrock. One of the two, Anthropic, also ships a competing code-security scanner, which is what makes the ownership change a live question for the ecosystem.

Team & Execution Capability The founders built and shipped AI products at scale before starting the company…

The founders built and shipped AI products at scale before starting the company. Ian Webster ran language-model engineering and developer platform work at Discord, where AI products reached 200 million users under safety, security and policy standards. Michael D’Angelo was vice president of engineering and head of AI at Smile Identity, where he scaled machine learning to serve over 100 million people.

The company sold within roughly two years of commercial launch. The Next Web dates the commercial launch to 2024 with a 5 million dollar seed round from Andreessen Horowitz, and OpenAI announced the acquisition on 9 March 2026. The founders state the team reached 23 people across engineering, go-to-market and operations.

Published research and community work back the founders up. The press page lists coverage of the company’s DeepSeek censorship research by Ars Technica, TechCrunch, Gizmodo and the Stanford Cyber Policy Center. The company also runs a public Language Model Security Database summarising primary-source AI security research.

The funding leaves a regulatory trail. Promptfoo, Inc. appears in the Securities and Exchange Commission submissions record with two Form D exempt-offering notices.

Sources

Company Detail Sources (8)
Id Source Tier Accessed
f1 Promptfoo: homepage and product menu official 2026-08-28
f2 Promptfoo: pricing page with Community, Enterprise and On-Premise tiers official 2026-08-28
f3 Promptfoo blog: Promptfoo is joining OpenAI official 2026-08-28
f4 Promptfoo: about page with founder profiles and contributor count official 2026-08-28
f5 The Next Web: report on the Promptfoo acquisition, funding and adoption press 2026-08-28
f6 SecurityWeek: report on the OpenAI agreement to acquire Promptfoo press 2026-08-28
f7 AI Defense Matrix Catalog entry other 2026-06-09
f8 AI Defense Matrix Catalog mapping for Promptfoo other 2026-08-28
Profile Analysis Sources (27)
Id Source Tier Accessed
s1 Promptfoo: homepage and product menu
“Promptfoo simulates real users to uncover application-specific vulnerabilities: npx promptfoo@latest redteam setup”
official 2026-08-28
s2 Promptfoo: LLM red teaming documentation overview
“As architectures become more complex, problems can arise in the form of information leakage and access control (RAG architectures), misuse of connected APIs or databases (in agents), and more.”
official 2026-08-28
s3 Promptfoo: Guardrails product page
“Our system uses actual attack data to refine defenses, creating a feedback loop that makes your guardrails stronger with every attempted breach.”
official 2026-08-28
s4 Promptfoo: enterprise MCP Proxy product page
“Our MCP proxy sits between your users and AI applications and MCP servers, providing enterprise-grade security, monitoring, and access control.”
official 2026-08-28
s5 Promptfoo: Model Security product page
“Analyze model files for security risks before deployment Detect malicious code or backdoors Identify risky model configurations Flag suspicious operations Supported: PyTorch, TensorFlow, Keras, Pickle, JSON/YAML”
official 2026-08-28
s6 Promptfoo: Code Scanning product page
“IDE Integration Real-time scanning as developers write code Inline diagnostics and severity indicators One-click quick fixes AI-assisted remediation prompts Scan on save or on demand”
official 2026-08-28
s7 Promptfoo: pricing page with Community, Enterprise and On-Premise tiers
“Promptfoo API access Managed cloud deployment Professional services support Priority support & SLA guarantees”
official 2026-08-28
s8 Promptfoo: about page with founder profiles and contributor count
“Based in San Francisco, California, Promptfoo is now part of OpenAI. Promptfoo remains open source, and we continue to build tools for secure, reliable AI applications.”
official 2026-08-28
s9 Promptfoo: press center page
“Our groundbreaking research on AI censorship and content filtering in DeepSeek models has been widely covered by major technology and news publications.”
official 2026-08-28
s10 Promptfoo blog: Promptfoo is joining OpenAI
“We founded Promptfoo in 2024 to make it easy for developers to systematically test their AI applications.”
official 2026-08-28
s11 OpenAI: announcement of the agreement to acquire Promptfoo
“OpenAI March 9, 2026 Company OpenAI to acquire Promptfoo Accelerating agentic security testing and evaluation capabilities in OpenAI Frontier”
official 2026-08-28
s12 Promptfoo Trust Center: compliance, resources and subprocessors, rendered page
“Promptfoo's Trust Center Subscribe to updates Request access”
official 2026-08-28
s13 TechCrunch: report on OpenAI acquiring Promptfoo
“Promptfoo has raised just $23 million since its founding and was valued at $86 million after its most recent round in July 2025, according to PitchBook.”
press 2026-08-28
s14 CNBC: report on OpenAI acquiring Promptfoo
“The startup has 11 employees and has raised a total of $22.68 million with a post-valuation of $85.5 million as of July 2025, according to the deal-tracking service Pitchbook.”
press 2026-08-28
s15 SecurityWeek: report on the OpenAI agreement to acquire Promptfoo
“Financial terms of the acquisition have not been disclosed, but Promptfoo has raised more than $23 million and was reportedly valued at $86 million (based on PitchBook data) following an $18.4 million Series A funding round in July 2025.”
press 2026-08-28
s16 CSO Online: report on the Promptfoo acquisition and AI testing demand
“OpenAI to acquire Promptfoo to strengthen AI agent security testing News Mar 10, 2026”
press 2026-08-28
s17 The Next Web: report on the Promptfoo acquisition, funding and adoption
“its adoption by developers at companies across the AI industry - including, according to Promptfoo's own website, teams at Anthropic and Google - was built on the premise that the tool belonged to the developer community rather than to any one vendor.”
press 2026-08-28
s18 arXiv: Dreadnode-authored preprint on agentic AI red teaming
“arXiv:2605.04019v1 [cs.AI] 05 May 2026 Redefining AI Red Teaming in the Agentic Era: From Weeks to Hours”
research 2026-08-28
s19 CB Insights: Promptfoo funding profile
“Promptfoo has raised $23.4M over 4 rounds.”
research 2026-08-28
s20 SEC EDGAR: submissions record for Promptfoo, Inc.
“"act":["33","33"],"form":["D","D"]”
regulatory 2026-08-28
s21 GitHub API: repository record for promptfoo/promptfoo
“"stargazers_count":24625”
research 2026-08-28
s22 Semgrep engineering blog: article on evaluating LLM features with promptfoo
“Does your LLM thing work? (& how we use promptfoo)”
research 2026-08-28
s23 GitHub: Anthropic courses repository, prompt evaluations lesson index
“Promptfoo for evals: an introduction”
official 2026-08-28
s24 Amazon Web Services: Workshop Studio course on Bedrock and Promptfoo evaluation
“Mastering LLM Evaluation - A Hands-On Bedrock and Promptfoo Workshop”
official 2026-08-28
s25 European Commission: regulatory framework for AI page
“The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions:”
regulatory 2026-08-28
s26 EU Artificial Intelligence Act explorer: Article 55 text
“Article 55: Obligations for Providers of General-Purpose AI Models with Systemic Risk”
research 2026-08-28
s27 Promptfoo: Language Model Security Database index
“Explore primary-source AI security research, evaluated models, attack techniques, and defensive evidence.”
official 2026-08-28
Deep-Dive Sources (27)
Id Source Tier Accessed
s1 Promptfoo: homepage and product menu
“Promptfoo simulates real users to uncover application-specific vulnerabilities: npx promptfoo@latest redteam setup”
official 2026-08-28
s2 Promptfoo: LLM red teaming documentation overview
“As architectures become more complex, problems can arise in the form of information leakage and access control (RAG architectures), misuse of connected APIs or databases (in agents), and more.”
official 2026-08-28
s3 Promptfoo: Guardrails product page
“Our system uses actual attack data to refine defenses, creating a feedback loop that makes your guardrails stronger with every attempted breach.”
official 2026-08-28
s4 Promptfoo: enterprise MCP Proxy product page
“Our MCP proxy sits between your users and AI applications and MCP servers, providing enterprise-grade security, monitoring, and access control.”
official 2026-08-28
s5 Promptfoo: Model Security product page
“Analyze model files for security risks before deployment Detect malicious code or backdoors Identify risky model configurations Flag suspicious operations Supported: PyTorch, TensorFlow, Keras, Pickle, JSON/YAML”
official 2026-08-28
s6 Promptfoo: Code Scanning product page
“IDE Integration Real-time scanning as developers write code Inline diagnostics and severity indicators One-click quick fixes AI-assisted remediation prompts Scan on save or on demand”
official 2026-08-28
s7 Promptfoo: pricing page with Community, Enterprise and On-Premise tiers
“Promptfoo API access Managed cloud deployment Professional services support Priority support & SLA guarantees”
official 2026-08-28
s8 Promptfoo: about page with founder profiles and contributor count
“Based in San Francisco, California, Promptfoo is now part of OpenAI. Promptfoo remains open source, and we continue to build tools for secure, reliable AI applications.”
official 2026-08-28
s9 Promptfoo: press center page
“Our groundbreaking research on AI censorship and content filtering in DeepSeek models has been widely covered by major technology and news publications.”
official 2026-08-28
s10 Promptfoo blog: Promptfoo is joining OpenAI
“We founded Promptfoo in 2024 to make it easy for developers to systematically test their AI applications.”
official 2026-08-28
s11 OpenAI: announcement of the agreement to acquire Promptfoo
“OpenAI March 9, 2026 Company OpenAI to acquire Promptfoo Accelerating agentic security testing and evaluation capabilities in OpenAI Frontier”
official 2026-08-28
s12 Promptfoo Trust Center: compliance, resources and subprocessors, rendered page
“Promptfoo's Trust Center Subscribe to updates Request access”
official 2026-08-28
s13 TechCrunch: report on OpenAI acquiring Promptfoo
“Promptfoo has raised just $23 million since its founding and was valued at $86 million after its most recent round in July 2025, according to PitchBook.”
press 2026-08-28
s14 CNBC: report on OpenAI acquiring Promptfoo
“The startup has 11 employees and has raised a total of $22.68 million with a post-valuation of $85.5 million as of July 2025, according to the deal-tracking service Pitchbook.”
press 2026-08-28
s15 SecurityWeek: report on the OpenAI agreement to acquire Promptfoo
“Financial terms of the acquisition have not been disclosed, but Promptfoo has raised more than $23 million and was reportedly valued at $86 million (based on PitchBook data) following an $18.4 million Series A funding round in July 2025.”
press 2026-08-28
s16 CSO Online: report on the Promptfoo acquisition and AI testing demand
“OpenAI to acquire Promptfoo to strengthen AI agent security testing News Mar 10, 2026”
press 2026-08-28
s17 The Next Web: report on the Promptfoo acquisition, funding and adoption
“its adoption by developers at companies across the AI industry - including, according to Promptfoo's own website, teams at Anthropic and Google - was built on the premise that the tool belonged to the developer community rather than to any one vendor.”
press 2026-08-28
s18 arXiv: Dreadnode-authored preprint on agentic AI red teaming
“arXiv:2605.04019v1 [cs.AI] 05 May 2026 Redefining AI Red Teaming in the Agentic Era: From Weeks to Hours”
research 2026-08-28
s19 CB Insights: Promptfoo funding profile
“Promptfoo has raised $23.4M over 4 rounds.”
research 2026-08-28
s20 SEC EDGAR: submissions record for Promptfoo, Inc.
“"act":["33","33"],"form":["D","D"]”
regulatory 2026-08-28
s21 GitHub API: repository record for promptfoo/promptfoo
“"stargazers_count":24625”
research 2026-08-28
s22 Semgrep engineering blog: article on evaluating LLM features with promptfoo
“Does your LLM thing work? (& how we use promptfoo)”
research 2026-08-28
s23 GitHub: Anthropic courses repository, prompt evaluations lesson index
“Promptfoo for evals: an introduction”
official 2026-08-28
s24 Amazon Web Services: Workshop Studio course on Bedrock and Promptfoo evaluation
“Mastering LLM Evaluation - A Hands-On Bedrock and Promptfoo Workshop”
official 2026-08-28
s25 European Commission: regulatory framework for AI page
“The AI Act entered into force on 1 August 2024 and became applicable on 2 August 2026, with some exceptions:”
regulatory 2026-08-28
s26 EU Artificial Intelligence Act explorer: Article 55 text
“Article 55: Obligations for Providers of General-Purpose AI Models with Systemic Risk”
research 2026-08-28
s27 Promptfoo: Language Model Security Database index
“Explore primary-source AI security research, evaluated models, attack techniques, and defensive evidence.”
official 2026-08-28

Disclaimer

This content is provided "as is" with no warranties.

This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.

The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.

Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.

The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.

To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.

Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.

Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.