Home / Companies / Promptfoo / Blog / August 2024

August 2024 Summaries

2 posts from Promptfoo

Filter
Month: Year:
Post Summaries Back to Blog
Promptfoo has introduced new Enterprise features aimed at enhancing the development and security of large language model (LLM) applications for larger teams. These features build on recent advances in adversarial machine learning techniques and integrations with popular LLM providers, and are designed to address the unique requirements of enterprise customers, such as additional oversight, reporting, and compliance measures. Key offerings include continuous monitoring and real-time alerts for vulnerabilities, comprehensive scanning capabilities with customizable plugins, and enhanced collaboration tools that integrate seamlessly with CI/CD pipelines. The platform also supports on-premise or private cloud deployments for maximum data security, and provides enterprise-level support with features like single sign-on, priority support, and named account managers. These enhancements aim to facilitate collaboration between development and security teams and provide higher visibility into the security status of LLM applications.
Aug 21, 2024 316 words in the original blog post.
The announcement introduces three new red teaming plugins specifically designed to address security vulnerabilities in Large Language Model (LLM) agents with access to internal APIs, focusing on Broken Object Level Authorization (BOLA), Broken Function Level Authorization (BFLA), and Server-Side Request Forgery (SSRF). These plugins aim to identify and mitigate risks where LLM agents might be exploited to access unauthorized data, perform unauthorized actions, or fetch resources from malicious destinations. As LLMs become more integrated with internal systems, they present novel attack vectors that traditional security measures might not fully address, making such plugins crucial for maintaining robust security. Each plugin generates adversarial inputs tailored to specific application infrastructures, employing strategies optimized for LLMs to thoroughly test for potential vulnerabilities. To implement these plugins, users are guided to update configuration files or consult detailed documentation for setup and testing procedures.
Aug 14, 2024 484 words in the original blog post.