Security & trust

Built to be trusted with your business.

Security and control aren't a settings page — they're built into Foreman, from how your keys are stored to what your AI team can do without checking with you first.

Your credentials Encrypted at rest
sk-live-••••••••••••4f2a AES-256-GCM
Isolated to your workspace never shared
Never returned to the browser server-only
The safeguards

Big-company protection. None of the setup.

Encrypted credentials

Your API keys and integration secrets are encrypted at rest with AES-256-GCM, and never handed back to the browser.

Workspace isolation

Every workspace is walled off — its data is strictly scoped and never bleeds into another.

Least-privilege access

Roles and fine-grained permissions decide who can do what, and the sensitive moves wait for explicit approval.

Secure sign-in

Sign in with Google or GitHub. Sessions are protected and set to expire.

Human-in-the-loop AI

Every output is a draft for you to review. Budget, strategy, and escalation calls pause for your approval, and agents are told never to invent data.

Trusted payments

Payments run through Stripe. Foreman never touches or stores your card details.

Compliance & data

The paperwork, out in the open.

See exactly how your data is handled, who touches it, and what we commit to.

Protection from request one.

Free to start, no card. The safeguards are on from your very first request. Foreman is in open beta and hardening as it grows.