TRUST

Security by construction.

Accountability isn't a feature we bolt on — it's how the platform is built. Governed permissions, bounded authority, and auditable evidence are the foundation, not the afterthought.

Governed permissions

Every agent operates under explicit, bounded authority. An agent can touch only what it has been granted — and nothing beyond it. Authority is declared up front and enforced by the Runtime.

Auditable execution

Each job carries intent, authority, evidence, and settlement. Evidence is content-addressed, so any claim about what an agent did can be verified independently after the fact. Settlement receipts record that obligations were met within their limits.

Self-hosting and data control

The Foxbra Runtime is Apache-2.0 licensed and runs on a single Postgres engine in infrastructure you control. When you self-host, your execution records, evidence, and data never leave your environment.

Responsible disclosure

If you believe you've found a security vulnerability in Foxbra, please tell us before disclosing it publicly. Email security@foxbra.com with steps to reproduce. We'll acknowledge your report, keep you updated, and credit you if you'd like once the issue is resolved.

What to include

Our commitment

We investigate all legitimate reports and act quickly to resolve confirmed issues. We ask that you avoid privacy violations, service disruption, and data destruction while researching.