Security & trust

Built to be trusted with your business.

Security and control aren't a settings page — they're built into Foreman, from how your keys are stored to what your AI team can do without checking with you first.

Your credentials Encrypted at rest
sk-live-••••••••••••4f2a AES-256-GCM
Isolated to your workspace never shared
Never returned to the browser server-only
The safeguards

Big-company protection. None of the setup.

Encrypted credentials

Your API keys and integration secrets are encrypted at rest with AES-256-GCM, and never handed back to the browser.

Workspace isolation

Every workspace is walled off — its data is strictly scoped and never bleeds into another.

Least-privilege access

Roles and fine-grained permissions decide who can do what, and the sensitive moves wait for explicit approval.

Secure sign-in

Sign in with Google or GitHub. Sessions are protected and set to expire.

Human-in-the-loop AI

Agents draft; you approve what ships. Anything you haven't pre-authorized — budget, strategy, and escalation calls — pauses for your approval, and agents are told never to invent data.

You own your data

Agents run on your own hardware, so your messages, CRM, and files live with you — never replicated to Foreman's cloud, and never sold. Deletion is real: a verified request purges our cloud and your execution host.

Zero third-party tracking

No analytics or fingerprinting scripts ship in production. Cookie consent starts at "off," and we honor Global Privacy Control.

No training on your data

Bring your own AI keys or run local models so prompts never leave your machine. Foreman-managed model traffic is sent with training opt-out enforced.

Trusted payments

Payments run through Stripe. Foreman never touches or stores your card details.

Compliance & data

The paperwork, out in the open.

See exactly how your data is handled, who touches it, and what we commit to.

Security from your first request.

The safeguards are on from day one. Free to start, no card.