Trust
Security at DreamBeam
Current as of July 13, 2026
User-owned workspaces
Workspaces run on computers you connect. DreamBeam manages identity, configuration, workspace records, and the browser experience. It does not provide hidden shared compute for the free product.
Brokered credentials
Provider credentials are encrypted in platform storage. Workspaces use scoped DreamBeam broker access instead of receiving the stored upstream credential directly. GitHub requests are also handled through the platform integration boundary.
Account and workspace boundaries
Product access is owner-scoped. Suspended accounts are blocked at web, proxy, enrollment, node-socket, and terminal-socket boundaries, and active product channels are disconnected. Authentication and product authorization remain separate so an account can still manage identity and sign out after product access is suspended.
What DreamBeam stores
DreamBeam stores account data, workspace and integration configuration, durable chat history, automation records, first-party product events, and attachments when configured. Terminal traffic passes through DreamBeam for the live browser session but is not intentionally stored as a terminal transcript. See the Privacy Policy for the complete data-practice summary.
Data access
Support starts with sanitized metadata. Content access requires explicit, scoped permission or a valid legal request. Access is time-limited and logged. DreamBeam does not use workspace content to train models.
Report a security issue
Send vulnerability reports to [email protected]. Include the affected surface, reproduction steps, and potential impact. Do not access other users’ data, degrade the service, or publish sensitive details before there has been a reasonable opportunity to investigate.