OpenAI will acquire AI security testing platform Promptfoo, with integration planned for the generative AI giant’s agentic builder platform.
Founded in 2024 by CEO Ian Webster, previously of Discord, and CTO Michael D’Angelo, ex-VP of engineering at Smile Identity, Promptfoo has raised $22 million in funding to date with a total valuation of around $119 million. No financial details were revealed in the OpenAI announcement.
Promptfoo specializes in aiding developers test security applications, with the company claiming an active user base of 130,000 developers out of 350,000 developers to have used in total, with customers including 25% of the Fortune 500.
In their announcement of the deal, Webster and D’Angelo stressed Promptfoo would remain open source and support models beyond OpenAI’s, while its 23-strong staff will go on to be absorbed into OpenAI operations.
There, according to OpenAI’s own announcement, they will build out OpenAI Frontier, the vendor’s platform for building and operating AI agents. The Sam Altman outfit positioned the deal as helping enterprises systematically test agent behavior, discover risks before deployment, and keep clear records in support of oversight, governance, and accountability.
“OpenAI gives our work more resources and access to research at the model and inference layers that supercharge our goal of helping everyone ship secure, reliable AI. This is the fastest and most impactful path forward for the work we started at Promptfoo,” Webster and D’Angelo wrote. “The team will continue working with customers and users to ensure continuity of service and support [and] continue to maintain the open-source suite as a best-in-class red teaming, static scanning, and evals tool for any AI model or application. Promptfoo will continue to support a diverse range of providers and models, reflecting the way real teams build and deploy AI systems.”
The deal comes after OpenAI hired Peter Steinberger, the developer behind the OpenClaw agentic system, to accelerate its AI agent roadmap.
OpenClaw broke out this year with its ability to let AI agents call, coordinate, and delegate tasks to other agents automatically, sharing tools, memory, and workflow. In tandem with its uptake was a streak of security concerns, with researchers like Zenity Labs discovering how indirect prompt injection can be used to establish persistent attacker control inside OpenClaw. Snyk meanwhile found almost 80 confirmed malicious payloads on the ClawHub registry, a central hub for discovering and installing skills for customizing OpenClaw.
SDxCentral also discovered something afoot when it revealed bots powered by OpenClaw were actively sharing tips on how to circumvent security guardrails for carrier IPs via a forum exclusively populated by AI agents.
Comments