Security Overview
The security boundaries and operational controls used across Fous API execution, access, provider adapters, organization wallets, and vulnerability handling.
Last updated
On this page
Security model
Fous API is designed to place a controlled execution layer between customer applications and third-party APIs. Security measures are selected according to risk and may evolve as the platform, provider network, and threat landscape change.
This overview describes current design principles and operational controls. It is not a certification, audit report, penetration-test result, or contractual service-level commitment. Customers that require specific controls should contact Fous before submitting regulated or highly sensitive data.
Access and credentials
- Fous API authenticates programmatic access with organization API keys.
- Fous Studio uses authenticated sessions and cross-site request-forgery protections for state-changing browser actions.
- Organization membership and roles scope access to organization resources and billing controls.
- Managed third-party provider credentials stay on the server side rather than being returned to customer applications.
- Logs and error handling are designed to avoid exposing authorization headers, cookies, passwords, secrets, tokens, and API keys.
Adapter and network boundaries
Requests are sent through registered adapters with fixed upstream destinations rather than accepting an arbitrary customer-supplied URL. Each adapter defines its expected input, request construction, execution constraints, and response or error mapping.
- Inputs and operation access are validated before provider execution.
- Each call specifies the API and operation to execute.
- Adapter execution uses bounded timeouts and provider-specific response handling.
- Upstream errors are mapped into the Fous response contract with sensitive details removed where appropriate.
- Provider availability and failure state can affect whether an operation can execute.
Billing integrity
The wallet flow is designed to prevent concurrent requests from silently overspending the same balance. Fous reserves 1 credit for an API call before execution and settles the final result through ledger-backed operations.
- Requests require sufficient available credits before execution.
- Reservation, settlement, and refund operations use identifiers intended to prevent duplicate application.
- Failed requests are designed to release or refund the applicable reservation.
- Interrupted reservations can be identified and reconciled by recovery processes.
Data protection and retention
Fous applies technical and organizational measures intended to protect account, credential, request, execution, and billing information. Production web and API endpoints should be accessed over HTTPS, and customers should never transmit credentials over an unencrypted connection.
Access to operational information is limited according to role and need. Retention varies by data type, customer instruction, security need, financial-record obligation, and legal requirement. See the Privacy Policy for more detail.
Because Fous sends requests to independent providers, the provider you select also receives the request data required to perform the task. Provider security, retention, and privacy practices are governed by that provider's terms and policies.
Customer security responsibilities
- Store Fous API keys in a server-side secret manager or protected environment variable, never in public source code or client-side applications.
- Use separate organizations or credentials where isolation is required, grant the minimum necessary access, and remove members who no longer need access.
- Rotate a key immediately if exposure is suspected and review relevant request and wallet activity.
- Choose the APIs and operations your application may execute.
- Validate provider results before using them in financial, medical, legal, safety-critical, or other high-impact workflows.
- Do not submit sensitive data unless you have assessed Fous, every eligible provider, and your own integration for that data.
Security incidents
Fous investigates credible security events and takes containment, remediation, recovery, and notification steps appropriate to the circumstances and applicable law. Incident scope and notification timing depend on the facts; this overview does not promise a fixed response or resolution time.
Report a vulnerability
If you believe you found a vulnerability affecting Fous, email [email protected].
Include
- A clear description of the issue, affected surface, and potential impact.
- Reproduction steps, request identifiers, and minimal proof-of-concept material when safe.
- A contact address where we can ask follow-up questions.
Please do not
- Access, change, destroy, or retain another person’s data.
- Disrupt service availability, conduct denial-of-service testing, or use social engineering.
- Include live API keys, passwords, session cookies, payment-card data, or unnecessary personal information in the report.
- Publicly disclose an unresolved issue before Fous has had a reasonable opportunity to investigate and address it.