Security

At Add Screenshots, we prioritize security and privacy. Below are some key security measures we have implemented to ensure the safety of your data.

HTTPS / TLS Encryption (Secure Transmission)

We use HTTPS and TLS encryption across all of our APIs and services, ensuring that data is encrypted in transit to protect it from interception.

No Screenshot Storage (Privacy First)

Add Screenshots does not store screenshots on our disks or in our persistent storage. Screenshots are kept in memory during processing to guarantee privacy. The only exception is the optional caching feature, which stores the screenshot temporarily in Cloudflare's cache.

Web Application Firewall (WAF) and DDoS Protection

Our APIs are secured by Cloudflare's Web Application Firewall (WAF) to block malicious requests, and we leverage Cloudflare's DDoS protection to denial-of-service attacks.

Resiliency and Availability (Stateless Architecture)

By routing traffic through 20+ regions and 500+ deployments, we ensure high availability and fault tolerance. If one instance goes down, requests are automatically retried on another instance.

Session Isolation (Incognito Mode)

When processing screenshots, we use a incognito session / unique context for each request, ensuring that one client's session data cannot interfere with another's.

API Key Authentication (IP/Country Restrictions)

API requests are authenticated via API keys, which can be restricted by IP addresses or countries, providing additional layers of security.

Principle of Least Privilege (Access Control)

We follow the principle of least privilege access, meaning that our staff and systems are only granted the minimum level of access necessary to perform their roles, reducing the risk of unauthorized access.

Infrastructure Security (IaaS by Azure)

Our infrastructure is built on top of Microsoft Azure, where the underlying operating system is managed and patched by Azure, minimizing vulnerabilities and ensuring up-to-date security.

User Authentication & Multi-Factor Authentication (MFA)

User credentials are encrypted using one-way encryption (hashing), and users can enable Multi-Factor Authentication (MFA) for enhanced security on their accounts.

Activity Logging (Monitoring and Alerts)

We log all account-related activities, enabling us to monitor and flag any suspicious activity. Alerts can also be generated to notify users of potential threats.

Privacy Commitment (No Third-Party Sales)

We are committed to protecting your privacy. Add Screenshots does not sell or trade your information with third parties. We only collect data that is essential for providing our services.

Payment Security (Stripe Integration)

Add Screenshots does not handle or store credit card information. All payment processing is securely managed by Stripe, a PCI-compliant payment provider.

Police-Vetted Staff (Trusted Personnel)

All staff at Add Screenshots undergo thorough police vetting to ensure that only trusted personnel have access to sensitive systems and data.