Skip to content

Security

SceneRecap handles screen recordings, which can contain anything. Here is how we protect them.

Masked at capturePasswords & payment fields never leave the tab.
No keystroke loggingKeys are events, never recorded as text.
Encrypted everywhereTLS 1.2+ in transit, encryption at rest.
Hosted in the EUGoogle Cloud, Belgium & Frankfurt.

Capture

  • Recording is explicit and per-session; the extension requests tab/screen access only when you press record and holds no background capture permission.
  • Keystrokes are never logged as text. Interaction with a password or payment field is recorded only as sensitive_field_interaction — never the value, never the keys. The video is an unaltered capture of your screen, so review it before uploading.
  • Nothing uploads until you press Upload & analyze on the review page; you can save the clip to disk instead, any time, even signed out.
  • Recording is blocked in incognito windows and on browser-internal pages.

Transport and storage

  • TLS 1.2+ everywhere. Uploads go directly to private object storage via short-lived signed URLs.
  • Media is served through short-TTL signed URLs or a token-gated media proxy — object storage is never public.
  • Integration tokens are encrypted at rest with AES-256-GCM using a rotatable key; API keys and refresh tokens are stored as SHA-256 hashes.
  • Hosting in Google Cloud europe-west1 (Belgium) and media storage in europe-west3 (Frankfurt), both with encryption at rest.

Access

  • Passwordless sign-in (single-use magic links), rotating refresh tokens with reuse detection, and per-device session revocation.
  • Row-level tenancy: every workspace-scoped query goes through a repository layer that enforces membership and role.
  • Staff access to customer data is limited to a small admin console with audit logging.

AI

  • Only sampled frames, the interaction log and transcript are sent to the model by default — not the full video. Model outputs are schema-validated before use.
  • Google's paid Gemini API terms apply: prompts and outputs are not used to train Google's models.

Agent runs

The Repro Agent drives a browser against an origin at the customer’s request, so it is built to be impossible to point anywhere else. It only accepts origins the workspace has verified; it refuses private, loopback, link-local and cloud-metadata addresses, re-checking DNS immediately before navigation to defeat rebinding; targets are https-only and URLs with embedded credentials are rejected. The agent never enters credentials — a login wall ends the run as “blocked” rather than being worked around. Runs execute in an isolated, scale-to-zero worker pool that is separate from the pipeline that processes recordings. Performed takes run under the same rules in the same pool — verified origins only, no credential entry, an auth wall ends the take as blocked — and a take is always grounded in a real recording, staying a private draft until a human reviews and approves it.

Operations

  • Dependency scanning and secret scanning in CI; infrastructure defined in code.
  • Backups of the primary database; media stored redundantly by the cloud provider.
  • Coordinated disclosure: report vulnerabilities to contact@scenerecap.com. We acknowledge within 2 business days.

SOC 2 is on the roadmap; this page describes our current posture honestly rather than a certification.