FRAIM
Pricing Resources Sign in Sign Up

Trust at FRAIM

Security

Last updated: September 14, 2026

Our Approach

FRAIM is designed to help people manage AI work without turning the management layer into a second system of record. We apply safeguards at the service, product, and workflow boundaries and review security as part of every production change.

Data Boundaries

Your source code and working context remain with the AI provider and tools you choose unless a FRAIM workflow explicitly sends information to a service you authorize. FRAIM limits collected service data to what is needed for authentication, billing, reliability, support, and the requested workflow.

Credentials and Access

  • Credentials are never embedded in public marketplace packages or client-side website assets.
  • Hosted authorization uses scoped access and established authentication flows.
  • Local integrations are designed to reuse supported credential stores and least-privilege access.
  • Access can be revoked by disconnecting an integration or rotating its credentials.

Application Safeguards

FRAIM uses transport security for hosted traffic, security headers, input validation, output encoding, dependency review, rate limits on sensitive endpoints, and automated tests around security-sensitive behavior. Secrets and private user content are excluded from public packages and source-controlled configuration.

Secure Development

Changes pass automated build and regression checks, targeted security review, and human approval before release. Security findings are assessed by severity, tracked to resolution, and revalidated after remediation.

Your Responsibilities

Keep your devices and provider accounts secure, protect credentials, grant only the access a workflow needs, review AI-assisted output before acting on it, and promptly revoke access you no longer use.

Report a Security Concern

Please report suspected vulnerabilities or security incidents privately to sid@wellnessatwork.me. Include the affected surface, reproduction steps, and potential impact. Do not include secrets or personal data in the initial report.