Skip to main content
EVOKORE// SKILLS / SECURITY
promptfoo/promptfoosecuritysha 13DC341E2F1C

SECURITY

security policy

Security Policy

Reporting Security Vulnerabilities

We take security seriously at promptfoo. If you discover a security vulnerability, please report it responsibly.

How to Report

What to Include

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact assessment
  • Any suggested remediation

Response Timeline

  • Acknowledgment: Within 24 hours
  • Initial assessment: Within 3 business days
  • Fix timeline: Depends on severity
    • Critical: 7 days
    • High: 14 days
    • Medium: 30 days
    • Low: Next release cycle

Supported Versions

VersionSupported
LatestYes
< LatestBest effort

Security Considerations

LLM Provider Keys

promptfoo requires API keys for LLM providers. We recommend:

  • Store keys in environment variables (OPENAI_API_KEY, ANTHROPIC_API_KEY)
  • Use .env files for local development (never commit to version control)
  • Use CI/CD secret management for automated evaluations

Test Data

  • Do not include sensitive or personal data in test configurations
  • Use synthetic data for prompt testing
  • Be cautious with test outputs — LLM responses may contain unexpected content

Red Teaming

promptfoo's red teaming capabilities intentionally generate adversarial inputs. When using red teaming:

  • Run in isolated environments
  • Review generated attacks before sharing results
  • Follow your organization's responsible AI testing policies
  • Do not use red teaming outputs for malicious purposes

Plugin Security

Custom evaluation scripts run with the same permissions as the promptfoo process. Only run trusted evaluation scripts and review third-party configurations before execution.

Dependency Management

We regularly audit and update dependencies. Security vulnerabilities in dependencies are addressed according to severity using the response timeline above.