Skip to content
Promptfoo
OrganisationUS

Promptfoo

Developer tooling startup providing prompt-injection testing, acquired by OpenAI in March 2026 to fold into its Frontier safety platform.

Last refreshed: 17 April 2026 · Appears in 1 active topic

Key Question

Why did OpenAI need to buy a prompt injection testing tool?

Timeline for Promptfoo

#117 Apr

Mentioned in: Google closes $32bn Wiz deal; 38 M&A

Cybersecurity: Threats and Defences
View full timeline →
Common Questions
Why did OpenAI buy Promptfoo?
OpenAI acquired Promptfoo in March 2026 to fold its prompt-injection testing and LLM adversarial red-teaming capabilities into its Frontier AI safety platform, addressing the growing attack surface of deployed AI applications.Source: SecurityWeek / Lowdown
What is Promptfoo?
Promptfoo is a developer tooling startup and open-source framework for testing AI applications against prompt-injection attacks, jailbreaks and other adversarial inputs. It was acquired by OpenAI in March 2026.

Background

OpenAI acquired Promptfoo in March 2026 as part of a wave of 38 cybersecurity M&A transactions counted by SecurityWeek in that month alone. Promptfoo provided developer tools for testing large language model (LLM) applications against prompt-injection attacks, jailbreaks and other adversarial inputs, with an open-source product that had significant developer adoption.

Promptfoo was one of the most widely used open-source frameworks for adversarial testing of LLM applications, offering red-teaming capabilities alongside integration with popular AI development workflows. Its acquisition by OpenAI folds prompt-injection defence into the Frontier AI safety platform, giving OpenAI a tooling layer to verify that AI applications built on its models are resistant to adversarial manipulation.

The acquisition reflects a broader pattern: as AI applications enter production at scale, the attack surface of prompt injection and adversarial input has moved from theoretical research to an operational security concern. OpenAI's decision to acquire rather than build the tooling signals that Promptfoo had enough developer traction to be the reference implementation in the space.