AccountMade

Security / Promptfoo

Promptfoo: open-source adoption and enterprise evaluation

Promptfoo's open-source CLI makes evaluation concrete before procurement. Enterprise review begins when tests, findings and policies must be shared, governed, integrated into CI/CD or run inside controlled infrastructure.

Accountmade Research · Updated · 4 sources

How a buyer can evaluate the product

The Community edition is open source and supports local evaluation and red teaming. Public pricing currently describes a community probe allowance, so a team can reproduce an initial test without an enterprise contract.

A security buyer needs model and provider scope, attack libraries, custom policies, CI enforcement, finding review, evidence retention, role control, data flow, on-premise deployment, support and remediation ownership.

Enterprise and On-Premise use custom quotes. Enterprise pages add collaboration, policy and support capabilities; additional red-team probes can be purchased. The buyer should obtain the probe definition, included volume and infrastructure boundary in writing.

Sources: Promptfoo pricing · Promptfoo documentation · Promptfoo Enterprise

Evidence a buyer can inspect

Public pages reviewed on 2026-09-08. A source being public does not establish product performance.
Buyer questionPublic evidenceHow to use itSource
Can a test be reproduced?CLI configuration, assertions, providers and red-team workflows are documented publicly.Check a versioned config into a test repository.Docs
What is the free boundary?Community is open source and the pricing page states a monthly probe allowance.Count planned probes and recurring CI frequency.Pricing
What changes in enterprise?Enterprise pages describe team workflows, support and deployment options.Map collaboration, data and policy requirements.Enterprise docs
What does a finding prove?A test result records behavior under a chosen prompt, model and configuration.Retest after model, prompt or guardrail changes.Evaluation docs

Sources: Promptfoo pricing · Promptfoo documentation · Promptfoo Enterprise · Promptfoo red teaming

What to apply

The strongest enterprise bridge is a reproducible test portfolio with named owners and release gates. A count of probes or attacks is not a security outcome; buyers need coverage rationale, result triage and evidence that fixes are retested.

Method and limits

We reviewed the listed first-party pages on 2026-09-08 and compared them with the July 2026 research record. We assessed what a technical buyer can verify before contacting sales; we did not test the product or validate vendor-reported customer outcomes.

  • We did not execute red-team tests against a live application.
  • Model behavior and provider safeguards can change after capture.
  • Enterprise and on-premise prices, minimums and probe overages were not public.

Sources: Promptfoo pricing · Promptfoo documentation · Promptfoo Enterprise · Promptfoo red teaming

Sources and dates

  1. Promptfoo pricingReviewed 2026-09-08
  2. Promptfoo documentationReviewed 2026-09-08
  3. Promptfoo EnterpriseReviewed 2026-09-08
  4. Promptfoo red teamingReviewed 2026-09-08

Found an error or a changed source? Send a correction.

Apply this to your company

Prepare materials for your next buyer conversation.

Accountmade helps technical B2B teams prepare demo decks, technical blueprints, business cases and security materials.

Explore Accountmade →