Security
A recorder sees
everything. So we
limit what it keeps.
Chronika records screens that show internal systems. This page says what it does about that, in plain terms, and where it stops.
No certifications are held. See “What we do not claim”.
01What we do
Six things, built in
Each of these is how the product works today, not a plan.
- 01
Passwords are blurred before upload
Password fields are detected and blurred in the screenshot on your computer, and what you type into them is not recorded. If a recorder cannot be sure a picture is clean, it leaves the picture out instead of uploading it. Detection is best-effort, so look over a guide before you share it.
- 02
Recorder tokens are hashed
A recorder connects with a personal token that is shown once. The server stores only its SHA-256 hash, so a copy of the database does not contain a usable token. You can disconnect any of your recorders at any time, and a suspended account’s tokens stop working.
- 03
Recorders act as you
A recorder has the permissions of the person who connected it: their workspaces and their role in each, and nothing more. A viewer’s recorder cannot upload, and a guide shared with you by name can be read but not recorded into.
- 04
Files go to members only
Screenshots and narration are served to signed-in members of the guide’s workspace, and to people a guide was shared with by name, for that guide’s files only. Anyone else gets them only through a guide’s public link, and only the pictures of what that link shows.
- 05
Public links you can turn off
A guide is private until an editor turns on a read-only link. Turning it off ends access through that link, and turning it on again makes a new one.
- 06
Trash before permanent delete
A deleted guide goes to Trash first. It is removed for good, with its screenshots and narration, when its author or an admin deletes it from Trash. A recording you discard while it is still being made is deleted straight away.
02In the browser
A strict policy for what the page may load
The web app sends a Content-Security-Policy and related headers with every response.
- Scripts, styles, fonts and frames come only from the Chronika server, and the page cannot be framed by another site.
- The browser may connect only back to the server (connect-src is “self”), so a flaw in a page cannot send data to another origin by fetch, XHR or WebSocket.
- Forms post only to the same server, and plugin content is blocked.
- The microphone, camera, location and payment features are switched off for the app.
- Pages and files carry a noindex header, so nothing the app serves is meant for a search index.
- Over HTTPS, the server also sends HSTS and asks the browser to upgrade insecure requests.
Two limits, stated openly. The policy keeps inline scripts allowed, because Next.js needs them to start a page. And the guide view shows a small icon for each website a guide used, which the browser fetches from DuckDuckGo’s icon service. That request carries the site’s host name. The calls to an AI provider, if you set one, are made by the server, not by the browser.
03Your data
Where it lives is your choice
Your guides are stored for your workspace and shown only to its members and to people you share a link with.
Guides, screenshots and narration are stored for your workspace. The recorders talk only to your Chronika address, and nowhere else.
AI is optional. The person who runs the server picks the provider (Anthropic, an OpenAI-compatible service, Google or Ollama, among others) with their own key, or sets it to none. With none, no recording is sent to any AI service. With a local provider such as Ollama, it stays on your hardware.
Sign-in is yours too: email and password, Microsoft Entra ID, Google or any OIDC provider, and invitation-only sign-up if you want it. See Enterprise.
What we do not claim
No certificates. Said plainly.
- We hold no SOC 2 report.
- We hold no ISO 27001 certificate.
- We make no HIPAA compliance claim.
- The Windows app is not code-signed yet.
The things listed above on this page are what the software does. They are not an audit. If your organization needs a certificate, a signed agreement or a security review before it can use Chronika, tell us what it needs and we will answer honestly.
04Questions
Security, answered
Does a password ever reach your server?
What happens if a recorder token leaks?
Who can see a screenshot?
Can screenshots show other sensitive information?
Where do I report a vulnerability?
Ready when you are
Ask us anything
Security questions, a review for your team, or a vulnerability report: write to us.