Promptfoo alternatives, 2026.Q3: every real option, ranked
The short answer
Edition v2026.Q3 · pricing and status verified 2026-08-06.
sandbox-runtime is the strongest Promptfoo alternative for most — putting a hard filesystem and network boundary around any agent process — coding agents especially — without containers or a cloud bill. Then: NVIDIA NeMo Guardrails · Amazon Bedrock Guardrails · Lakera Guard. Below, all 26 real options in the guardrails category, with pricing and honest watch-outs — plus the 8 "alternatives" other lists still recommend that are dead, renamed, or sunsetting.
Why people look past Promptfoo at all: It tests; it does not enforce. A green promptfoo run is not a runtime control, and nothing here blocks a live request. The OpenAI acquisition also puts the category's most-used neutral scanner inside a frontier lab — the OSS pledge is a pledge, not a governance structure.
The top Promptfoo alternatives, ranked
2sandbox-runtimeAnthropic (Apache-2.0, beta research preview)
Free · Apache-2.0 · no service, no accountBest for Putting a hard filesystem and network boundary around any agent process — coding agents especially — without containers or a cloud bill.
Watch Explicitly a "beta research preview": Windows support is alpha, and the API is not stable. It does nothing about content — no injection detection, no PII, no topic control. And a sandbox with an over-broad network allowlist is theatre; the config is the product.
3NVIDIA NeMo GuardrailsNVIDIA (Apache-2.0)
Free · Apache-2.0 · self-hosted; NemoGuard NIM microservices require NVIDIA AI Enterprise licensing (not publicly priced)Best for Teams that want programmable, self-hosted rails — including rails on tool calls — rather than a hosted moderation endpoint.
Watch Colang is a language you have to learn, and the config surface sprawls fast. Every rail is another LLM call, so latency and token cost stack; teams routinely ship with rails disabled in the hot path. The best detectors are NVIDIA NIMs behind enterprise licensing, so the free tier is the scaffolding, not the models.
4Amazon Bedrock GuardrailsAWS
Usage-based, no subscription: content filters & denied topics $0.15/1k text units · sensitive-info filters $0.10 · contextual grounding $0.10 · Automated Reasoning $0.17 per policy · word filters and regex free · standalone InvokeGuardrailChecks prompt-attack $0.08/1k (1 text unit = 1,000 characters)Best for Shipping a managed filter today without building one — including in front of models you don't host on AWS.
Watch The headline numbers — "blocks up to 88% of harmful content", "99% accuracy" on Automated Reasoning — are AWS's own, with no independent benchmark to check them against. Per-1k-character billing gets expensive on long agent contexts, every enabled policy is a separate charge and a separate round trip, and you're inside an AWS account. It filters text, not actions: it will not stop an agent from calling the wrong tool.
5Lakera GuardLakera → Check Point Software (announced Sep 16, 2025)
Not published — enterprise via Check Point sales; SaaS and self-hosted deployment optionsBest for Startups selling into enterprises that want a named vendor, an SLA and a real adversarial dataset behind the injection filter.
Watch No public pricing at all — the least startup-friendly entry on this list, and you're now buying from a large network-security vendor whose roadmap answers to CloudGuard, not to you. All performance figures are first-party. Detection percentages on prompt injection are also structurally soft: there is no accepted public benchmark, so >98% is a claim about Lakera's own test set.
Every other live option in guardrails
| Tool | Maker | What it is | Entry |
|---|---|---|---|
| Google Model Armor | Google Cloud | Runtime screening for prompts, responses and agent interactions — injection/jailbreak, indirect injection, PII, malicious URLs, malware in files; inline for Gemini Enterprise Agent Platform and LangChain | 2M tokens/mo free, then $0.10/M |
| Meta LlamaFirewall | Meta (PurpleLlama) | The agent-native open guardrail: PromptGuard 2 (injection classifier), AlignmentCheck (audits agent chain-of-thought for goal hijacking), CodeShield (static analysis over 8 languages). Research-grade cadence | free (open weights) |
| Llama Guard 4 / Prompt Guard 2 | Meta | Open-weight input/output safety classifiers — the default self-hosted moderation models when you can't send text to a vendor | free (open weights) |
| Guardrails AI | Guardrails AI, Inc. | The original validator framework (7.1k stars, Apache-2.0, v0.10.2 Jun 4 2026) plus Guardrails Hub; company has broadened into an "AI reliability platform" around Snowglobe simulation | free OSS + Hub |
| OpenAI Guardrails | OpenAI | MIT-licensed drop-in client wrapper (Python + TS): moderation, jailbreak, PII, URL allowlist, NSFW, off-topic, hallucination-vs-vector-store. Still labelled preview, ~223 stars — thin next to NeMo | free (pays OpenAI API costs) |
| OpenAI Moderation API | OpenAI | Free harm classifier — the zero-effort baseline, and still where a lot of teams stop; no injection or agent-action coverage | free |
| Cisco AI Defense | Cisco (built on Robust Intelligence) | Model validation + runtime guardrails + AI-aware SASE; expanded for "the agentic era" in Feb–Mar 2026. Ships an open mcp-scanner | enterprise quote |
| Zenity | Zenity | Agent-action control: reads agent intent and allows/modifies/blocks before execution across Copilot, ChatGPT Enterprise, Gemini, Claude, Bedrock and Vertex. $125M Series C led by Norwest, Aug 3 2026; 230+ staff, revenue tripled two years running | enterprise quote |
| HiddenLayer | HiddenLayer | Model scanning, AI detection & response; one of the oldest pure-play AI security vendors ($50M Series A, 2023) and now a rare uncaptured independent | enterprise quote |
| WitnessAI | WitnessAI | Employee-facing AI usage policy and guardrails — governs which AI your staff use, adjacent to but not the same as bounding your own agents | enterprise quote |
| Pillar Security | Pillar Security | End-to-end AI app security with runtime guardrails; $9M seed (Apr 2025), known for the "Rules File Backdoor" coding-agent research | enterprise quote |
| NeuralTrust TrustGate | NeuralTrust | Open-source Go AI gateway with inline guardrails — the most-cited migration path for teams stranded by LLM Guard's archival | free OSS + paid cloud |
| garak | NVIDIA | OSS LLM vulnerability scanner (~2.8k stars) — probe-based, CLI-first, complements rather than competes with promptfoo | free |
| PyRIT | Microsoft AI Red Team | Python risk-identification toolkit used by Microsoft's own red team; the most extensible of the OSS attack frameworks and the least turnkey | free |
| DeepTeam | Confident AI | OSS red-teaming framework from the DeepEval team; strong OWASP-mapped attack coverage, tied to the DeepEval ecosystem | free |
| Giskard | Giskard | OSS testing + LLM scan with an EU-AI-Act framing; publishes the clearest independent OWASP Agentic Top 10 walkthroughs | free OSS + Hub |
| Mindgard | Mindgard | Automated AI red-teaming as a service, Lancaster University spinout; continuous testing rather than one-off pentest | enterprise quote |
| Gray Swan AI | Gray Swan | Public jailbreak arenas and paid red-team events used by frontier labs — the closest thing to a neutral adversarial benchmark supplier | contest + enterprise |
| E2B | E2B | Firecracker-microVM sandboxes for agent code execution — the hosted answer when sandbox-runtime's local model isn't enough | free $100 credit · Pro $150/mo + $0.000014/vCPU-s |
| Daytona | Daytona | Sub-second agent sandboxes, the main E2B alternative; competes on cold-start and per-second price | free tier + usage |
| Docker MCP Gateway / Runlayer | Docker · Runlayer | MCP gateways that centralise auth, routing and allowlists for tool servers; Runlayer raised $11M in the thin MCP-security funding wave (~$40M total across four startups) | free / usage |
| Auth0 for AI Agents / Permit.io | Okta · Permit.io | Scoped, delegated credentials and fine-grained authorization for agents — the permission half of "scope it like a new hire", covered lightly by every guardrail framework here | free tier + usage |
The "Promptfoo alternatives" to avoid — no longer what they were
Listicles still recommend these. As of 2026-08-06, they are not what the listicles think.
| Tool | Status | What happened |
|---|---|---|
| Microsoft Foundry guardrails | renamed | Prompt Shields, spotlighting, PII, groundedness plus agent-era previews: task adherence, tool-call and tool-response scanning, network egress controls. Azure AI Foundry renamed Microsoft Foundry in 2026 |
| Prisma AIRS | acquired | Where Protect AI landed after the ~$500M acquisition completed Jul 22, 2025 — model scanning, runtime AI security, agent posture. Enterprise-only, no public pricing |
| Snyk Agent Scan / MCP-Scan | acquired | The team that publicly demonstrated MCP tool poisoning in Apr 2025, now Snyk Labs; scans MCP servers and agent skills for poisoned tool descriptions |
| Prompt Security | acquired | GenAI prompt/response inspection folded into SentinelOne's platform two years after founding — an early sign the standalone LLM-firewall category wouldn't stay standalone |
| Aim Security | acquired | AI security posture and runtime controls absorbed into a SASE platform — the same consolidation pattern as Lakera and Prompt Security |
| LLM Guard | dead | The category's most-forked OSS scanner suite — archived Jul 9, 2026, models on Hugging Face abandoned, final release v0.3.16 (May 2025). Migration path is Prisma AIRS; OSS successors are TrustGate and NeMo |
| Rebuff | dead | Early prompt-injection detector (1.5k stars) — archived May 16, 2025, before the acquisition even closed |
| Robust Intelligence | renamed | Acquired 2024; brand retired into Cisco AI Defense — the first of the AI-guardrail startups to be absorbed |
How to choose
- If your agent can run a shell, write files or reach the network
- Sandbox first, filter second. Adversa's GuardFall work (Jun 2026) bypassed pattern-based command guards in 10 of 11 open-source coding agents; sandbox-runtime or an E2B-class VM sandbox is the boundary that doesn't depend on reading intent correctly.
- If you have no guardrails and one afternoon
- Run Promptfoo's red-team against your own agent and fix what it finds. It's free, self-hosted, and the exercise tells you which of the other four picks you actually need — instead of buying a filter for a hole you don't have.
- If you want a managed filter and you're not on AWS
- Bedrock's ApplyGuardrail API or Google Model Armor both work in front of third-party models. Model Armor is the cheaper start — 2M tokens/month free, then $0.10 per million — and covers indirect prompt injection and malicious URLs; Bedrock wins if you need denied topics or formally verified policy.
- If your agent consumes MCP servers or third-party tools
- Treat the tool registry as untrusted input: pin and scan servers (Snyk agent-scan, ex-Invariant MCP-Scan), gate them behind an MCP gateway, and put an allowlist on egress. GitGuardian found 24,008 secrets in public MCP configs in 2026, 2,117 of them still valid.
- If a customer's security review is what's blocking the deal
- Buy a named vendor — Lakera Guard/Check Point, Prisma AIRS or Cisco AI Defense — and map your controls to the OWASP Top 10 for Agentic Applications (Dec 9, 2025). The document is what enterprise reviewers are grading against; the filter is what they'll ask to see evidence for.
This analysis is drawn from the Guardrails element dossier — the ranked top 5, the comparison matrix, and the complete field of 30 more tools live there, with every source. Data: gd.json (CC BY 4.0).
Every claim above is dated and sourced from the elems dossiers — 1,421 tools tracked across 58 categories, verified 2026-08-06, including the 276 we found dead, renamed, acquired, or sunsetting. Rankings are editorial, never paid — the charter.
Build your stack in 5 questions →