Security

Last updated:

How we protect your account, your captures and your viewers' data.

The short version

  • Everything in transit uses HTTPS, and media is encrypted at rest in Cloudflare R2.
  • Masking and redaction tools help you keep sensitive data out of your captures.
  • Two-factor sign-in and SSO protect accounts.
On this page
  1. Safe capture
  2. Data protection
  3. Account security
  4. How we operate
  5. Incident response
  6. Report a vulnerability

Safe capture

  • Recordings stay on your device until you choose to upload them.
  • HTML capture masks form values, and you can add your own privacy rules for other elements.
  • The ArcDemo API, not your browser, fetches page assets. It blocks private and internal network addresses.

Data protection

  • All traffic to ArcDemo is encrypted in transit with TLS.
  • Captured media is stored in Cloudflare R2, which encrypts it at rest.
  • Media is served through signed, short-lived URLs.
  • The application runs with hosting provider and region.

Account security

  • Two-factor authentication and single sign-on (SSO).
  • Host-only, secure session cookies.
  • Role-based access in every workspace, plus password protection and access controls for shared demos.
  • Rate limits and bot checks on public forms and sign-in.

How we operate

  • Production access is limited to the staff who need it.
  • We monitor the application for errors and unusual activity.

Incident response

If an incident affects your data, we'll notify you within 48 hours, as set out in our Data Processing Agreement.

Report a vulnerability

Found a security issue? See our Security Disclosure policy or email security@arcdemo.io.