Oct 24, 2025 · 43m · latent-space

Breaking AI to Fix It: Ian Webster's Journey from Discord's Clyde to Promptfoo's $18M Series A

Ian Webster · 30m spoken
0:00 / 0:00
▶ Watch on YouTube →

gold bands on the timeline = statements, start to end. Hover to read, click to jump. CC turns on captions

In this interview, Promptfoo creator Ian Webster discusses the evolution of AI application security, explaining how automated synthetic red teaming and shifting testing left into CI/CD pipelines safeguard enterprise LLMs, RAG systems, and Model Context Protocol integrations.

How this conversation actually went

Every chapter scored 0–10 on four independent dynamics. Hover any point for the reasoning behind the score. How this is scored →

The hosts as informed peer 6.0 Guest teaching 4.6 Guest disagreement 2.0 The hosts pushing back 1.4
05100:0015:0030:003:26–9:48 · The hosts as informed peer 5/10 From Generic Evals to Application Security Alessio and Swix ask probing questions about why Ian pivoted Promptfoo from generic evals to application security. Ian explains that general evals are a commoditized bloodbath, drawing a clear conceptual line between foundation model safety and application-level access control risks.9:48–22:28 · The hosts as informed peer 4/10 Promptfoo Architecture and Automated Red Teaming Walkthrough Ian conducts a detailed walkthrough of Promptfoo's architecture, demonstrating its automated red teaming engine and multi-turn synthetic attack generation. The hosts largely act as active listeners asking clarifying operational questions regarding paper tracking and black-box discovery limitations.22:28–30:43 · The hosts as informed peer 8/10 Vulnerability Remediation and Enterprise Market Dynamics Alessio demonstrates deep venture and market expertise by comparing Promptfoo's bottom-up developer motion to domain-specific security tools like Sublime, Push, and Dropzone. Ian details how Promptfoo monetizes through full enterprise vulnerability lifecycle management rather than fear-based sales.30:43–35:09 · The hosts as informed peer 5/10 The Limitations of Guardrails and Shifting Left to CI/CD Ian offers a sharp critique of guardrail startups, calling runtime guardrails a commoditized band-aid that large enterprises cannot rely on. He emphasizes shifting security left into CI/CD and developer IDEs before long-running agent workflows make front-door black-box testing obsolete.35:10–41:31 · The hosts as informed peer 8/10 Securing Model Context Protocol and Tool Integrations Alessio and Ian exchange technical insights on securing the Model Context Protocol (MCP). Alessio details building his own MCP client (Kernel Jim) and potential attack vectors in resource pre-loading and model sampling, while Ian explains sandboxing and enterprise on-prem requirements.3:26–9:48 · Guest teaching 4/10 From Generic Evals to Application Security Alessio and Swix ask probing questions about why Ian pivoted Promptfoo from generic evals to application security. Ian explains that general evals are a commoditized bloodbath, drawing a clear conceptual line between foundation model safety and application-level access control risks.9:48–22:28 · Guest teaching 6/10 Promptfoo Architecture and Automated Red Teaming Walkthrough Ian conducts a detailed walkthrough of Promptfoo's architecture, demonstrating its automated red teaming engine and multi-turn synthetic attack generation. The hosts largely act as active listeners asking clarifying operational questions regarding paper tracking and black-box discovery limitations.22:28–30:43 · Guest teaching 3/10 Vulnerability Remediation and Enterprise Market Dynamics Alessio demonstrates deep venture and market expertise by comparing Promptfoo's bottom-up developer motion to domain-specific security tools like Sublime, Push, and Dropzone. Ian details how Promptfoo monetizes through full enterprise vulnerability lifecycle management rather than fear-based sales.30:43–35:09 · Guest teaching 6/10 The Limitations of Guardrails and Shifting Left to CI/CD Ian offers a sharp critique of guardrail startups, calling runtime guardrails a commoditized band-aid that large enterprises cannot rely on. He emphasizes shifting security left into CI/CD and developer IDEs before long-running agent workflows make front-door black-box testing obsolete.35:10–41:31 · Guest teaching 4/10 Securing Model Context Protocol and Tool Integrations Alessio and Ian exchange technical insights on securing the Model Context Protocol (MCP). Alessio details building his own MCP client (Kernel Jim) and potential attack vectors in resource pre-loading and model sampling, while Ian explains sandboxing and enterprise on-prem requirements.3:26–9:48 · Guest disagreement 1/10 From Generic Evals to Application Security Alessio and Swix ask probing questions about why Ian pivoted Promptfoo from generic evals to application security. Ian explains that general evals are a commoditized bloodbath, drawing a clear conceptual line between foundation model safety and application-level access control risks.9:48–22:28 · Guest disagreement 1/10 Promptfoo Architecture and Automated Red Teaming Walkthrough Ian conducts a detailed walkthrough of Promptfoo's architecture, demonstrating its automated red teaming engine and multi-turn synthetic attack generation. The hosts largely act as active listeners asking clarifying operational questions regarding paper tracking and black-box discovery limitations.22:28–30:43 · Guest disagreement 2/10 Vulnerability Remediation and Enterprise Market Dynamics Alessio demonstrates deep venture and market expertise by comparing Promptfoo's bottom-up developer motion to domain-specific security tools like Sublime, Push, and Dropzone. Ian details how Promptfoo monetizes through full enterprise vulnerability lifecycle management rather than fear-based sales.30:43–35:09 · Guest disagreement 4/10 The Limitations of Guardrails and Shifting Left to CI/CD Ian offers a sharp critique of guardrail startups, calling runtime guardrails a commoditized band-aid that large enterprises cannot rely on. He emphasizes shifting security left into CI/CD and developer IDEs before long-running agent workflows make front-door black-box testing obsolete.35:10–41:31 · Guest disagreement 2/10 Securing Model Context Protocol and Tool Integrations Alessio and Ian exchange technical insights on securing the Model Context Protocol (MCP). Alessio details building his own MCP client (Kernel Jim) and potential attack vectors in resource pre-loading and model sampling, while Ian explains sandboxing and enterprise on-prem requirements.3:26–9:48 · The hosts pushing back 1/10 From Generic Evals to Application Security Alessio and Swix ask probing questions about why Ian pivoted Promptfoo from generic evals to application security. Ian explains that general evals are a commoditized bloodbath, drawing a clear conceptual line between foundation model safety and application-level access control risks.9:48–22:28 · The hosts pushing back 1/10 Promptfoo Architecture and Automated Red Teaming Walkthrough Ian conducts a detailed walkthrough of Promptfoo's architecture, demonstrating its automated red teaming engine and multi-turn synthetic attack generation. The hosts largely act as active listeners asking clarifying operational questions regarding paper tracking and black-box discovery limitations.22:28–30:43 · The hosts pushing back 2/10 Vulnerability Remediation and Enterprise Market Dynamics Alessio demonstrates deep venture and market expertise by comparing Promptfoo's bottom-up developer motion to domain-specific security tools like Sublime, Push, and Dropzone. Ian details how Promptfoo monetizes through full enterprise vulnerability lifecycle management rather than fear-based sales.30:43–35:09 · The hosts pushing back 1/10 The Limitations of Guardrails and Shifting Left to CI/CD Ian offers a sharp critique of guardrail startups, calling runtime guardrails a commoditized band-aid that large enterprises cannot rely on. He emphasizes shifting security left into CI/CD and developer IDEs before long-running agent workflows make front-door black-box testing obsolete.35:10–41:31 · The hosts pushing back 2/10 Securing Model Context Protocol and Tool Integrations Alessio and Ian exchange technical insights on securing the Model Context Protocol (MCP). Alessio details building his own MCP client (Kernel Jim) and potential attack vectors in resource pre-loading and model sampling, while Ian explains sandboxing and enterprise on-prem requirements.

speaking balance: gold is the hosts, purple is the guest (3 minute bins)

0:00 · the hosts 0% · guest 100%0:00 · the hosts 0% · guest 100%3:00 · the hosts 0% · guest 100%3:00 · the hosts 0% · guest 100%6:00 · the hosts 0% · guest 100%6:00 · the hosts 0% · guest 100%9:00 · the hosts 0% · guest 100%9:00 · the hosts 0% · guest 100%12:00 · the hosts 0% · guest 100%12:00 · the hosts 0% · guest 100%15:00 · the hosts 0% · guest 100%15:00 · the hosts 0% · guest 100%18:00 · the hosts 0% · guest 100%18:00 · the hosts 0% · guest 100%21:00 · the hosts 0% · guest 100%21:00 · the hosts 0% · guest 100%24:00 · the hosts 0% · guest 100%24:00 · the hosts 0% · guest 100%27:00 · the hosts 0% · guest 100%27:00 · the hosts 0% · guest 100%30:00 · the hosts 0% · guest 100%30:00 · the hosts 0% · guest 100%33:00 · the hosts 0% · guest 100%33:00 · the hosts 0% · guest 100%36:00 · the hosts 0% · guest 100%36:00 · the hosts 0% · guest 100%39:00 · the hosts 0% · guest 100%39:00 · the hosts 0% · guest 100%42:00 · the hosts 0% · guest 100%42:00 · the hosts 0% · guest 100%
Sharpest disagreement ▶ 31:10 Critique of runtime guardrail startups

Ian bluntly dismisses reliance on runtime guardrails as an unviable security strategy ('fuck it, we'll do it live, the guardrail will catch it') and labels guardrails an easily commoditized feature by hyperscalers.

Hardest push from the hosts ▶ 23:47 Swix challenges cybersecurity sales tactics

Swix challenges the cybersecurity market's tendency toward fear-based marketing and endless liability checklists, prompting Ian to explain why open source credibility is essential against cynical enterprise buyers.

Biggest teaching moment ▶ 7:33 Foundation safety vs corporate application risk

Ian educates the hosts on the misalignment between foundation model labs (optimizing for maximum helpfulness) and enterprise applications (which require strict domain constraints against recommending competitors or off-label actions).

The host holds their own ▶ 28:04 Alessio maps out modern AI security architectural shifts

Alessio demonstrates authoritative domain expertise by contrasting first-wave top-down LLM proxy wrappers with bottom-up code-integrated tools across email, identity, and SOC workflows.

the scores for every segment, with the reasoning behind each
ChapterTopicThe hosts as informed peerGuest teachingGuest disagreementThe hosts pushing backWhy
From Generic Evals to Application Security 5411 Alessio and Swix ask probing questions about why Ian pivoted Promptfoo from generic evals to application security. Ian explains that general evals are a commoditized bloodbath, drawing a clear conceptual line between foundation model safety and application-level access control risks.
Promptfoo Architecture and Automated Red Teaming Walkthrough 4611 Ian conducts a detailed walkthrough of Promptfoo's architecture, demonstrating its automated red teaming engine and multi-turn synthetic attack generation. The hosts largely act as active listeners asking clarifying operational questions regarding paper tracking and black-box discovery limitations.
Vulnerability Remediation and Enterprise Market Dynamics 8322 Alessio demonstrates deep venture and market expertise by comparing Promptfoo's bottom-up developer motion to domain-specific security tools like Sublime, Push, and Dropzone. Ian details how Promptfoo monetizes through full enterprise vulnerability lifecycle management rather than fear-based sales.
The Limitations of Guardrails and Shifting Left to CI/CD 5641 Ian offers a sharp critique of guardrail startups, calling runtime guardrails a commoditized band-aid that large enterprises cannot rely on. He emphasizes shifting security left into CI/CD and developer IDEs before long-running agent workflows make front-door black-box testing obsolete.
Securing Model Context Protocol and Tool Integrations 8422 Alessio and Ian exchange technical insights on securing the Model Context Protocol (MCP). Alessio details building his own MCP client (Kernel Jim) and potential attack vectors in resource pre-loading and model sampling, while Ian explains sandboxing and enterprise on-prem requirements.

Statements from this episode (10)

Assertion Not checkable as stated
Ian Webster: Discord's Clyde was built as a social bot, not a helpful bot
“The interesting thing about Clyde was that it wasn't really meant to be a, necessarily a helpful bot, but instead more of a social bot, like a bot that would just like be in your channel and, you know, help people interact and that kind of thing.”
Ian Webster Oct 24, 2025 ▶ 2:12
Opinion
Webster: AI evaluation tools are table-stakes commodities facing a feature-parity bloodbath
“I think evals are our table stakes. I think that they're a commodity and everyone should be doing them. And yes, there are companies that are doing great in the eval space, but To me, it just seemed like a bloodbath, you know, like we would just be, had a grea…”
Ian Webster Oct 24, 2025 ▶ 6:13
Insight
Webster: Enterprises do not want AI models to be maximally helpful
“OpenAI Anthropic, everyone else, they're all building models that are like maximally helpful. And in Actually, most cases in a corporate environment, you don't want that to be maximum. You don't want the model to be like helpful in every way possible.”
Ian Webster Oct 24, 2025 ▶ 8:52
Prediction Not checkable as stated
Webster: Meaningful AI red teaming will require internal tracing and observability
“I think especially where, where things are headed, like with more complex rags and agents and so forth, you're going to have to have some type of observability or like internal tracing in order to have, to do meaningful automated red teaming.”
Ian Webster Oct 24, 2025 ▶ 14:21
Assertion Not checkable as stated
Webster: Over 10% of Fortune 500 companies use Promptfoo
“We have a bit over 10% of the Fortune 500 that, that use PromptFu right now.”
Ian Webster Oct 24, 2025 ▶ 25:19
Insight
Webster: Finding enterprise AI vulnerabilities is only 20% of the challenge
“The way that I think about it is that if you're in a big company, finding the issue is only, like, 20% of the challenge. And then the rest is you have to triage it. You have to like hook it into your task tracker and your SIM and like all these other systems. …”
Ian Webster Oct 24, 2025 ▶ 26:59
Opinion
Webster: AI guardrails are a commodity and easy to build
“Building a business on guardrails really scares me because there are so many incumbents that can come in and eat your lunch. And it's like, It's not actually that hard to build a guardrail. I don't know if I'm gonna make people angry by saying that maybe some …”
Ian Webster Oct 24, 2025 ▶ 32:20
Prediction Not checkable as stated
Webster: The future of AI security is in CI/CD, not runtime
“So the future is really, like, not in runtime, but Earlier in the software development lifecycle, ideally in CICD or before that.”
Ian Webster Oct 24, 2025 ▶ 32:54
Opinion
Webster: Most corporate MCP implementations are just glorified API wrappers
“The way that a lot of corporates are implementing MCP is just like a glorified API wrapper, not, not like super innovative just kind of checking the box.”
Ian Webster Oct 24, 2025 ▶ 37:28
Opinion
Webster: Big enterprises will likely require on-prem MCP tooling
“For the really big companies, something like this would probably have to be on prem, at least in my experience, just because there's, you can get caught up in security reviews and stuff like that for like quarters on, on end.”
Ian Webster Oct 24, 2025 ▶ 41:02
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 200 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.