Last updated March 30, 2026
Security Overview
This Security Overview describes measures StaffRecorder ("we," "us") uses to help protect the Service. It supplements our Privacy Policy and Terms of Service. This page is informational only and does not create contractual commitments, service-level agreements, or warranties beyond those documents.
1. Shared responsibility model
Security is a shared responsibility:
- StaffRecorder secures the platform, application, and cloud infrastructure we control
- Customers secure accounts, credentials, team access, devices, networks, and lawful use of recordings
- Third parties (e.g., Google, cloud providers) secure their own services under their terms
We are not responsible for security failures caused by weak passwords, shared credentials, unpatched customer devices, misconfigured agency settings, or unauthorized sharing of recordings by Customer personnel.
2. Security principles
- Agency-scoped data isolation between customer accounts
- Least-privilege access for internal and automated systems
- Defense in depth across application, database, and infrastructure layers
- Authentication required for dashboard, admin, and protected API endpoints
3. Infrastructure
StaffRecorder runs on managed cloud infrastructure with industry-standard physical and network protections. Application data is stored using managed database and authentication services with encryption and access logging capabilities.
4. Authentication and access control
- Email/password and Google OAuth authentication
- Secure session handling for web access
- Role-based permissions (owner, manager, employee) within each agency
- Separate platform administration from customer agency data
- Row-level security enforcing agency and role boundaries at the database layer
- Bearer token authentication for desktop and protected API routes
Customers must revoke access for departed employees, use strong passwords, and limit administrative roles.
5. Encryption and data protection
- In transit: HTTPS/TLS for web and API traffic; encrypted desktop uploads
- At rest: Cloud provider encryption; sensitive OAuth tokens (e.g., Google Drive) encrypted before storage
- Recordings: Stored in access-controlled systems; media access requires authentication or time-limited signed URLs where applicable
6. Application security
- Server-side authorization before data access or changes
- Input validation on public and authenticated endpoints
- Restricted database access via security-definer functions and explicit grants
- Public marketing and contact endpoints separated from authenticated areas
- Dependency updates and production build verification
No system is perfectly secure. We cannot guarantee that unauthorized access, data loss, or service interruption will never occur. Our liability for security incidents is limited as set forth in our Terms of Service.
7. Google Drive integration
When an agency connects Google Drive, we store encrypted OAuth tokens and use Google APIs only for configured backup operations. Customers control Google account permissions and are responsible for securing their Google accounts and shared folders.
8. Customer endpoint security
Customers should:
- Install the desktop app only on trusted, managed workstations
- Keep OS and app versions current
- Remove access when staff leave
- Use screen locks, disk encryption, and endpoint protection appropriate to their environment
- Not install on shared or public computers where sensitive data may be exposed
9. Monitoring and incident response
We monitor logs and platform health to detect abuse and potential incidents. If we become aware of a security incident affecting Customer data, we will investigate and notify affected Customers as required by applicable law or contract. We are not liable for incidents beyond the limits in our Terms of Service.
10. Backups and availability
Infrastructure providers maintain redundancy and backup capabilities. Customers may configure Google Drive backup for recordings. Customers remain solely responsible for business continuity, disaster recovery, and retention policies.
11. Compliance and audits
Unless stated in a signed written agreement, StaffRecorder does not represent compliance with SOC 2, ISO 27001, HIPAA, PCI-DSS, or other certification frameworks. Customers in regulated industries must evaluate suitability independently. We do not permit unrestricted on-site audits without a prior written enterprise agreement.
12. Prohibited security testing
You may not perform vulnerability scanning, penetration testing, or security research against the Service without our prior written authorization. Unauthorized testing may result in account termination and legal action.
13. Responsible disclosure
Report suspected vulnerabilities to info@staffrecorder.com with sufficient detail to reproduce the issue. Do not publicly disclose, exploit, or access data beyond what is necessary to demonstrate the issue. We will not pursue legal action against good-faith researchers who comply with these guidelines.
14. Contact
Security inquiries: info@staffrecorder.com