Security
Your logins, sessions and datastay yours.
Kaabist runs on infrastructure it operates itself, in the EU. Secrets are encrypted per organisation, job traffic leaves through a single guarded gateway, and every sensitive action is written to an audit log.
How we protect it
Six thingswe never cut corners on.
01
Encrypted per organisation
Stored passwords, sessions and provider credentials use envelope encryption: a data key per organisation, wrapped by a master key in OpenBao. Plain text never leaves the worker's memory.
02
Redacted before capture
Password fields are redacted before a page is snapshotted or screenshotted. Secrets never appear in logs, snapshots, screenshots or webhooks.
03
One way out
Job traffic reaches the internet only through Kaabist's egress gateway. It refuses private, loopback, link-local and metadata addresses, and connects only to the address it checked.
04
Isolated browsers
Browser contexts run with site isolation and no file system access. Files leave only through an explicit download step, capped at 20 MB.
05
Short-lived access
Live views and hosted pages use tokens scoped to one job that expire after 15 minutes. Screencast frames are never stored.
06
Everything sensitive is audited
Approvals, takeovers, key and role changes, sessions, billing, exports and deletions are logged with who did it, from where, and when.
Your data
In the EU by default.Deleted when you say.
The platform runs on servers in Germany, and the EU is the default region. Kaabist follows the GDPR, and KVKK for its entity in Türkiye.
An organisation can delete its data through the API: snapshots, results and sessions are purged within 24 hours.
The list of sub-processors and the data processing agreement are published with our legal pages.
Found a vulnerability? Write to [email protected].