Trust at FRAIM
Security
Last updated: September 14, 2026
Our Approach
FRAIM is designed to help people manage AI work without turning the management layer into a second system of record. We apply safeguards at the service, product, and workflow boundaries and review security as part of every production change.
Data Boundaries
Your source code and working context remain with the AI provider and tools you choose unless a FRAIM workflow explicitly sends information to a service you authorize. FRAIM limits collected service data to what is needed for authentication, billing, reliability, support, and the requested workflow.
Credentials and Access
- Credentials are never embedded in public marketplace packages or client-side website assets.
- Hosted authorization uses scoped access and established authentication flows.
- Local integrations are designed to reuse supported credential stores and least-privilege access.
- Access can be revoked by disconnecting an integration or rotating its credentials.
Application Safeguards
FRAIM uses transport security for hosted traffic, security headers, input validation, output encoding, dependency review, rate limits on sensitive endpoints, and automated tests around security-sensitive behavior. Secrets and private user content are excluded from public packages and source-controlled configuration.
Secure Development
Changes pass automated build and regression checks, targeted security review, and human approval before release. Security findings are assessed by severity, tracked to resolution, and revalidated after remediation.
Your Responsibilities
Keep your devices and provider accounts secure, protect credentials, grant only the access a workflow needs, review AI-assisted output before acting on it, and promptly revoke access you no longer use.
Report a Security Concern
Please report suspected vulnerabilities or security incidents privately to sid@wellnessatwork.me. Include the affected surface, reproduction steps, and potential impact. Do not include secrets or personal data in the initial report.