Giskard vs Promptfoo
Both are eval frameworks tools. Here is how they actually differ on price, billing model and deployment.
Giskard
Apache-2.0 testing and red-teaming library for LLM agents, strongest on adversarial security testing rather than quality metrics. The v3 rewrite requires Python 3.12+, which quietly rules it out for a lot of infrastructure.
Promptfoo
The de-facto open-source CLI for LLM eval and red-teaming, driven by declarative YAML. MIT-licensed, ~23.5k stars, and acquired by OpenAI in March 2026 - still open source, now part of OpenAI Frontier.
| Giskard | Promptfoo | |
|---|---|---|
| Category | Eval Frameworks | Eval Frameworks |
| Our rating | 4/5 | 4/5 |
| Starting price | Not published (Hub) | $0 |
| Billing meter | No usage metering | No usage metering |
| Free plan | Yes | Yes |
| Free self-hosting | Yes, free | Yes, free |
| Best for | Teams that need adversarial testing and red teaming for LLM agents, especially in security-conscious or regulated settings, and who are on Python 3.12 or later. | Security and CI teams who want config-driven LLM eval plus serious red-teaming, from an OSS tool with no seat cost |
Our verdict on Giskard
Giskard occupies a different niche from most of this category and does it well. Where Ragas measures RAG quality and DeepEval gates CI, Giskard attacks your system - automated red teaming and adversarial vulnerability scanning against LLM agents, including black-box systems you did not build. That is a genuinely underserved capability, and it is Apache 2.0. Two things will decide whether you can use it. The v3 rewrite requires Python 3.12 or later, which quietly disqualifies any infrastructure pinned to 3.10 or 3.11 - a constraint we have not seen flagged in a single comparison, and one that will surface after you have already committed. And LLM-as-judge checks may require external API calls, so air-gapped environments need to check carefully what leaves the network. The v3 rewrite is also still maturing, with some v2 features not fully ported. Treat it as a security testing tool that complements a quality-focused framework, not as a replacement for one.
Full Giskard review →Our verdict on Promptfoo
The clearest pick if red-teaming and security testing are part of your eval story, and its YAML-in-git approach fits CI cleanly. The OpenAI acquisition in March 2026 is the thing to weigh - the commitment to stay MIT is on the record, but you are now betting on OpenAI's stewardship of the project. For the free tier alone it is still an easy yes.
Full Promptfoo review →Frequently Asked Questions
What is the main difference between Giskard and Promptfoo?
Giskard: Teams that need adversarial testing and red teaming for LLM agents, especially in security-conscious or regulated settings, and who are on Python 3.12 or later. Promptfoo: Security and CI teams who want config-driven LLM eval plus serious red-teaming, from an OSS tool with no seat cost Both sit in Eval Frameworks, so the decision usually comes down to billing model and deployment rather than raw capability.
Which is cheaper, Giskard or Promptfoo?
It depends entirely on your workload shape, because they meter differently - Giskard bills on no usage metering and Promptfoo bills on no usage metering. Published starting prices are Not published (Hub) and $0 respectively, but those numbers are not comparable until you apply them to the same traffic. Use our cost calculator to model both against your own request volume and span count.
Can I self-host Giskard or Promptfoo?
Giskard: Yes, free. Promptfoo: Yes, free. Free self-hosting means no licence fee, not no cost - you still own the infrastructure, upgrades and on-call.