Security Policy
Reporting Security Vulnerabilities
We take security seriously at promptfoo. If you discover a security vulnerability, please report it responsibly.
How to Report
- Email: security@promptfoo.dev
- GitHub: Use GitHub Security Advisories for private disclosure
- Do NOT open a public issue for security vulnerabilities
What to Include
- A description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Any suggested remediation
Response Timeline
- Acknowledgment: Within 24 hours
- Initial assessment: Within 3 business days
- Fix timeline: Depends on severity
- Critical: 7 days
- High: 14 days
- Medium: 30 days
- Low: Next release cycle
Supported Versions
| Version | Supported |
|---|---|
| Latest | Yes |
| < Latest | Best effort |
Security Considerations
LLM Provider Keys
promptfoo requires API keys for LLM providers. We recommend:
- Store keys in environment variables (
OPENAI_API_KEY,ANTHROPIC_API_KEY) - Use
.envfiles for local development (never commit to version control) - Use CI/CD secret management for automated evaluations
Test Data
- Do not include sensitive or personal data in test configurations
- Use synthetic data for prompt testing
- Be cautious with test outputs — LLM responses may contain unexpected content
Red Teaming
promptfoo's red teaming capabilities intentionally generate adversarial inputs. When using red teaming:
- Run in isolated environments
- Review generated attacks before sharing results
- Follow your organization's responsible AI testing policies
- Do not use red teaming outputs for malicious purposes
Plugin Security
Custom evaluation scripts run with the same permissions as the promptfoo process. Only run trusted evaluation scripts and review third-party configurations before execution.
Dependency Management
We regularly audit and update dependencies. Security vulnerabilities in dependencies are addressed according to severity using the response timeline above.