Security posture
Security & Responsible Disclosure
Foundry/API uses product-scoped credentials, signed webhooks, destination validation and data-minimization controls. No security statement should be interpreted as a certification or contractual SLA.
Last updated · 21 July 2026
Credentials
RapidAPI requests are isolated through provider secrets. Direct API keys are product-scoped, stored as SHA-256 hashes, displayed once and invalidated when their entitlement is revoked.
Network protections
Public-URL workflows validate destinations, redirects and private-network ranges. File workflows validate size, declared type and file signatures before processing.
Billing webhooks
Stripe webhook payloads are accepted only after signature verification. Unsigned requests are rejected before fulfillment state is changed.
Reporting
Use the support form with the Security topic. Do not include live secrets, passwords, payment data or exploit payloads. Include a concise description, affected endpoint and safe reproduction steps.
Current limitations
TrackPulse automated scheduling remains under platform validation. The assisted pilot is positioned around on-demand checks and signed webhook delivery rather than an unverified scheduling commitment.