SECURITY

A safer handoff, with explicit limits.

Footon reduces accidental disclosure by keeping raw context local, requiring review, and scanning again at publication. Automated scanning cannot guarantee that every sensitive value will be found.

Local first

The CLI drafts and sanitizes on your machine. Footon receives a thread only after you review and approve the exact sanitized copy.

Checked twice

The service validates the document shape and scans the approved copy again before storage. Owners can black out exact text or revoke a link.

Public links are unlisted, not private

Anyone with a working share URL can read it until revocation. Do not publish data you cannot safely disclose to every recipient of that URL.

Account protection

Footon uses one-time email codes, PKCE S256, short-lived access tokens, rotating refresh tokens, and operating-system credential storage in the CLI.

Report a vulnerability

Email support@footon.dev privately. Include impact, the affected version or URL, and safe reproduction steps. Never send live credentials or complete private transcripts.

Supported versions

Security fixes target the current release. Update to the latest Footon release before reporting a problem that may already be fixed.