Security evidence
Independent assessment status
FrootAI does not currently publish a completed third-party penetration-test report, vendor name, finding count, or pass result. Earlier planning placeholders are not security evidence.
What is available today
- public vulnerability reporting through GitHub Security Advisories;
- automated dependency, secret, release, and application contract checks;
- current architecture, privacy, processor, and signing disclosures in the Trust Center; and
- assessment status supplied on request without representing an unperformed engagement as complete.
Future publication rule
A vendor, date, scope, finding count, remediation status, or report-availability statement will appear here only after the engagement is completed and the disclosure is approved. Until then, no independent penetration-test assurance should be inferred.