RecBeam
Security

Your content stays under your control

A straightforward look at how RecBeam handles authentication, storage, and billing — including what it does not claim.

Google Sign-In

Authentication happens through Google. RecBeam never receives or stores your Google password.

Hashed session tokens

Your RecBeam session token is stored server-side only as a cryptographic hash, never in plain text.

Authenticated API access

Every library, upload and billing route requires a valid, verified RecBeam session.

Owner-scoped operations

Renaming, archiving, downloading or deleting a video or screenshot is only possible for the account that owns it.

Cloudflare infrastructure

RecBeam runs on Cloudflare Workers, with Cloudflare D1 for metadata and Cloudflare R2 for video and image storage.

Verified webhook signatures

Subscription changes from Lemon Squeezy are only accepted after verifying an HMAC signature over the exact request body.

Server-enforced plan limits

Recording length and video-count limits are enforced on RecBeam's server, not just in the extension's interface.

Temporary local recovery

A recording is kept locally only until its cloud upload is verified, or if that verification fails.

Permanent deletion

Deleting a video or screenshot removes the underlying file and breaks its public link immediately.

Share-link awareness

Share links are unlisted. Anyone with a public link can open it. Business owners can add a password, restrict access, or allow-list emails.

Billing through Lemon Squeezy

Subscription payments are processed by Lemon Squeezy, our Merchant of Record.

No direct card storage

RecBeam does not directly receive or store your complete payment-card details.

Security and privacy training

What the RecBeam team has been trained on for the standards that govern your recordings, and where to verify every certificate.

  • Certified Master SOC 2 Implementer Scytale · SOC 2 Academy 24 August 2026 · Verify with Scytale · Certificate (PDF)
    ID m8uqckmgsy
  • SOC 2 Compliance Start SOC2 (LowerPlane) · SOC 2 Compliance Course 25 August 2026
    ID SOC2-MT7RDUGM
  • GDPR: understanding and applying the rules Brevo · Certified Brevo GDPR Expert 24 August 2026 · Certificate (PDF)
    ID 6a8cb131c6d7b09a5e0c9b68
  • Introduction to security, compliance, and identity concepts Microsoft Learn 25 August 2026 · Certificate (PDF)
  • Introduction to Cybersecurity Cisco Networking Academy 25 August 2026 · Certificate (PDF)
    ID dd07b863-fca7-4961-be20-3471371847fc
  • Cybersecurity and Cloud Fundamentals 1.0 (NSE 1) Fortinet 26 August 2026 · Certificate (PDF)

These are training certificates completed by Ali Raza on the RecBeam team, as part of the team’s security and privacy training. They are shown in full so you can check the claim rather than take it on trust. They remain education rather than an independent audit: RecBeam itself does not hold SOC 2, ISO 27001, GDPR, HIPAA or PCI certification — see What RecBeam does not claim below.

What RecBeam does not claim

RecBeam does not offer end-to-end encryption or zero-knowledge storage. RecBeam does not hold SOC 2, ISO 27001, HIPAA, GDPR, or PCI certification. Payment processing (including any PCI-related compliance) is handled by Lemon Squeezy, our Merchant of Record. Staff training certificates are education, not an audit. If your use case requires a specific compliance certification, RecBeam is not currently the right fit. See also our Trust page.

Questions about security?

We're happy to answer them directly.

Contact us