Security posture

Security & Responsible Disclosure

Foundry/API uses product-scoped credentials, signed webhooks, destination validation and data-minimization controls. No security statement should be interpreted as a certification or contractual SLA.

Last updated · 21 July 2026

Credentials

RapidAPI requests are isolated through provider secrets. Direct API keys are product-scoped, stored as SHA-256 hashes, displayed once and invalidated when their entitlement is revoked.

Network protections

Public-URL workflows validate destinations, redirects and private-network ranges. File workflows validate size, declared type and file signatures before processing.

Billing webhooks

Stripe webhook payloads are accepted only after signature verification. Unsigned requests are rejected before fulfillment state is changed.

Reporting

Use the support form with the Security topic. Do not include live secrets, passwords, payment data or exploit payloads. Include a concise description, affected endpoint and safe reproduction steps.

Current limitations

TrackPulse automated scheduling remains under platform validation. The assisted pilot is positioned around on-demand checks and signed webhook delivery rather than an unverified scheduling commitment.