Security
SceneRecap handles screen recordings, which can contain anything. Here is how we protect them.
Capture
- Recording is explicit and per-session; the extension requests tab/screen access only when you press record and holds no background capture permission.
- Keystrokes are never logged as text. Interaction with a password or payment field is recorded only as
sensitive_field_interaction— never the value, never the keys. The video is an unaltered capture of your screen, so review it before uploading. - Nothing uploads until you press Upload & analyze on the review page; you can save the clip to disk instead, any time, even signed out.
- Recording is blocked in incognito windows and on browser-internal pages.
Transport and storage
- TLS 1.2+ everywhere. Uploads go directly to private object storage via short-lived signed URLs.
- Media is served through short-TTL signed URLs or a token-gated media proxy — object storage is never public.
- Integration tokens are encrypted at rest with AES-256-GCM using a rotatable key; API keys and refresh tokens are stored as SHA-256 hashes.
- Hosting in Google Cloud europe-west1 (Belgium) and media storage in europe-west3 (Frankfurt), both with encryption at rest.
Access
- Passwordless sign-in (single-use magic links), rotating refresh tokens with reuse detection, and per-device session revocation.
- Row-level tenancy: every workspace-scoped query goes through a repository layer that enforces membership and role.
- Staff access to customer data is limited to a small admin console with audit logging.
AI
- Only sampled frames, the interaction log and transcript are sent to the model by default — not the full video. Model outputs are schema-validated before use.
- Google's paid Gemini API terms apply: prompts and outputs are not used to train Google's models.
Agent runs
The Repro Agent drives a browser against an origin at the customer’s request, so it is built to be impossible to point anywhere else. It only accepts origins the workspace has verified; it refuses private, loopback, link-local and cloud-metadata addresses, re-checking DNS immediately before navigation to defeat rebinding; targets are https-only and URLs with embedded credentials are rejected. The agent never enters credentials — a login wall ends the run as “blocked” rather than being worked around. Runs execute in an isolated, scale-to-zero worker pool that is separate from the pipeline that processes recordings. Performed takes run under the same rules in the same pool — verified origins only, no credential entry, an auth wall ends the take as blocked — and a take is always grounded in a real recording, staying a private draft until a human reviews and approves it.
Operations
- Dependency scanning and secret scanning in CI; infrastructure defined in code.
- Backups of the primary database; media stored redundantly by the cloud provider.
- Coordinated disclosure: report vulnerabilities to contact@scenerecap.com. We acknowledge within 2 business days.
SOC 2 is on the roadmap; this page describes our current posture honestly rather than a certification.