Local-first. Bounded by default.

Most AI coding tools either ship your code to a cloud sandbox or run with full ambient authority on your machine. Bolt Foundry does neither. We built a local-first app with explicit workspace boundaries, isolated runtime execution, and host-owned secrets.

Below are the threats we track and how we handle them. If something your team cares about is missing, tell us.

Threats we're tracking

We watch for these risks every time we ship. This list will grow. If we're missing something, flag it.

Machine-wide overreach

Main-process compromise

Secret leakage into runtime

Unrestricted network egress

Silent workspace mutation

Hidden state in your workspace

Opaque operating state

Supply-chain drift

Questions teams ask before they hand authority to an AI tool

    Is this a compliance page?
    Is every hardening step already finished?
    How is this different from cloud-hosted AI coding tools?
    How is this different from tools that run with ambient machine authority?
    What if I care about a threat you have not listed here?
Missing something?

See a gap? Tell us.

We'll either show you how we handle it or add it to our threat model. Reach out and we'll schedule a security walkthrough with your team.

Talk to us about security

If your team needs to understand the trust boundaries before adopting AI tooling, we want that conversation. Join the list and we will set up time to walk through the security model with your team.