Security
Serious about security, honest about badges
What protects your data today, and exactly where we are on the certifications — no borrowed logos, no vague 'bank-grade' claims.
In place today
The controls protecting your workspace
Encryption
TLS in transit, encryption at rest — for sessions, screenshots and exports alike.
Role-scoped access
Five roles from owner to member; every view scoped, every access pattern logged.
Audit trails
Live-view sessions, policy changes and exports leave a trail — including ours.
Signed software
The macOS agent is signed and notarised with automatic updates; webhooks are HMAC-signed.
Data lifecycle
Retention windows delete screenshots on schedule; workspaces export or delete on request.
Least-privilege keys
API keys inherit workspace roles — a reporting key can't touch payroll.
The certification ledger
◷SOC 2 Type IIPreparing — controls being formalised; audit engagement planned around public launch.
◷Penetration testPlanned pre-launch; summary will be shared with customers on request.
◷Privacy / Terms / DPAPlain-language versions live now; formal documents ship with launch.
✓Encryption & RBAC & audit logsLive in the product today.
Security questionnaire? Send it — we answer line-by-line, including the lines where the answer is "not yet."
Keep exploring
Try it on your own data first
the best security review starts with your own timeline