Security
What stays with you,
what we keep, and what is not done yet.
What stays on your machine
Claude Code, Codex and Cursor run on your own computer, under your own accounts. Friday never holds their sign-in keys, and it never meters them.
Your files are read and changed by those tools on your machine, in the folder you chose. Friday does not copy your repository to run them.
What Friday stores
What an agent does in a session is stored so the team can watch it live and wind it back later: the messages, the agent’s replies, the commands it ran and what they printed, and the changes it made. If an agent prints a secret, that line is in the record, so keep secrets out of the folders you point an agent at.
If you attach a folder to a session that has no machine connected, that working copy is stored on Friday’s server for the session. Your account details are stored, and card payments are handled by Stripe, so a card number never reaches Friday.
Who can do what in a session
Everyone in a session is an owner, an editor or a viewer. Viewers watch. Editors can suggest and, when they hold the wheel, steer. Each agent has one driver at a time, and an owner can always stop a run.
Invite links can be turned off or replaced at any moment, and a person you remove is out at once: they are disconnected, they cannot come back with the link, and they lose the control of any agent they were driving. Access is checked on every action, not only when someone joins.
What an agent may do
Plan reads and proposes and changes nothing. Manual edits files and asks before it runs a command. Auto runs freely, for work you trust. The person whose machine it is changes this, and everyone in the session can see which one is on.
A request to run something goes to the person driving that agent, and the whole session sees it.
How it is protected
Traffic is encrypted in transit. Sign-in cookies are signed, HttpOnly and time-limited. Passwords are salted and hashed with scrypt, and repeated failed sign-ins are rate-limited. The control token that decides who may steer an agent is enforced by a single atomic database operation, so permission checks cannot be raced.
What is not finished
Access tokens for tools you connect, such as GitHub or Slack, are stored in your workspace in our database and are not yet encrypted at rest. That work is planned. If it matters to your organisation, wait for it before connecting sensitive systems.
Automatic deletion of expired sessions and self-service account deletion are still being built. Until they ship, email [email protected] and we will delete your account, your workspace and its sessions by hand, at no charge.
We have not had an independent security audit, and we do not hold a SOC 2 or ISO 27001 certificate. If you need either, tell us and we will say plainly where we are.
How we look at the website
The public website counts every visit anonymously, with nothing stored on your device. There are no advertising or cross-site trackers. What is collected, and the two optional questions we may ask, are set out in the privacy policy.
Found something, or need an answer?
Report a vulnerability to [email protected] before disclosing it publicly and we will work with you on a fix. For anything about your data, write to [email protected].