Security

Security and disclosure

Updated · May 24, 2026Public document

Foreverse keeps a public path for security questions, responsible disclosure, and account protection. This page documents how to reach the security inbox and how we treat reports.

How to disclose

Email [email protected] with the subject line Security disclosure. Include reproduction steps, the affected surface (iOS app, Android app, web, API), and what you observed. We acknowledge security email within two business days.

Scope

  • The Foreverse Android app on Google Play, and Foreverse-managed beta builds (iOS).
  • Foreverse web pages on the production domain.
  • The Foreverse billing and account API.
  • BYOK provider routing as documented on the providers page.
Reports against BYOK provider services themselves (OpenAI, Anthropic, Google, etc.) should be routed to the provider. We can help triage if you are unsure where it belongs.

BYOK key handling

  • BYOK provider keys are stored encrypted on device.
  • Foreverse does not silently route BYOK requests through a proxy.
  • Keys are not synced to a third-party cloud unless you opt in to a future managed sync.
  • You can revoke a key at any time from Settings > Providers.

Account protection

Account and Pro purchases use email-verified sessions. Deletion requests are routed through a public path and verified against the account email. Device activations are bounded; the app surfaces the active devices in Settings.

Contact

[email protected] — security disclosures, account protection, and general security questions.

Security and Disclosure · Foreverse · Xinmeng