Draft, not yet reviewed. This document still contains unfilled placeholders and has not been reviewed by a lawyer. Do not rely on it, and do not accept paying customers against it.
Security
Last updated 6 October 2026
How BugShot is built to protect the data it holds. The measures below are the same ones listed in Annex II of the Data Processing Agreement, described in plainer terms.
Isolation between customers
Tenant separation is structural rather than a check that could be forgotten. Every function that reads customer data requires an account identifier and joins through project ownership, and there is deliberately no way to fetch a report or issue by identifier alone. Automated tests attempt to read, modify and erase one account's data from another on every run, and the build fails if any of them succeed.
Authentication
Sign in is passwordless. We send a single use link that expires in 15 minutes, and we store only its hash, so a copy of our database could not be replayed to sign in as anyone. Sessions are held in signed, HTTP only cookies with SameSite protection, and state changing requests are additionally origin checked.
Encryption
Everything is transported over TLS. Database and object storage are encrypted at rest by the provider. Destination credentials you configure, such as Slack webhook URLs, are separately encrypted with AES-GCM before they are written, and are never displayed back to you.
Screenshot access
Screenshots are not publicly readable. They are served only through expiring, HMAC signed URLs, and a tampered signature returns nothing. When a report is deleted the image is removed from object storage in the same operation, which is asserted by an automated test rather than assumed.
Privacy by default in the widget
The widget blurs the contents of every input, textarea and select before capture, and always blurs password fields regardless of configuration. Query strings are stripped from every recorded address because they routinely carry tokens and search terms. Request and response bodies and headers are never recorded. Interaction history notes which field was used, never what was typed into it. The redaction tool destroys pixels by downsampling rather than applying a reversible blur.
The widget sets no cookies and writes nothing to browser storage.
Abuse and availability
Each project has an origin allowlist. Submissions are rate limited per address, capped in size and restricted by image type, and every field is revalidated server side rather than trusted. Plan quotas bound the volume any single account can generate.
Retention
Reports and screenshots are deleted automatically once past the plan's retention window. Submitting IP addresses are dropped after 30 days. Deletion is performed explicitly at every level rather than relying on database cascade behaviour, so nothing is left behind after a customer has been told it is gone.
Accountability
Every action that destroys data, exports it in bulk, or changes who can reach it is recorded with the actor and the subject, and is visible to you on the Data page.
What we do not have yet
We would rather tell you than have you discover it in a questionnaire. BugShot does not currently hold a SOC 2 report or ISO 27001 certification, has not had an independent penetration test, and does not offer EU data residency or single sign on. If any of these are required for your procurement process, contact us before deploying so we can tell you honestly where we are.
Reporting a vulnerability
Email [SECURITY CONTACT EMAIL] with enough detail to reproduce the issue. We will acknowledge within three business days and keep you updated until it is resolved. Please give us reasonable time to fix it before publishing, and do not access data belonging to anyone other than yourself while testing. We will not pursue legal action against researchers acting in good faith under these terms.