Security starts with knowing what you capture
Samelogic deliberately records browser context for a handoff. Review the safeguards and limits below before capturing a sensitive workflow.
Claims you can evaluate
This page describes current product behavior and its limits. It does not substitute for a current security review, contract, or independent assurance report.
Implemented capture and access behavior is stated separately from operational commitments.
Sensitive-workflow guidance names what can still appear in a capture.
Need a security review?
Ask us for the current deployment, subprocessors, retention, deletion, and assurance details that apply to your evaluation.
hi@samelogic.comProduct safeguards you can inspect
These controls reduce accidental exposure while preserving the browser context a receiving engineer needs.
Input masking by default
Step Replay uses recorder-level masking for input values while a browser path is captured.
Redacted export steps
Fill and select values are redacted from artifact export steps instead of being written into the step manifest.
Authenticated project access
Private project routes check for an authenticated project owner or member before returning replay content.
Revocable replay links
A project member can return a public replay to private, removing receiver access through that link.
Input values are masked by default
The recorder masks values typed into input controls. This is a safeguard, not comprehensive content redaction.
Artifact steps omit entered values
Fill and select values are redacted from artifact export steps. Other captured context remains subject to review.
Masking is not blanket PII detection
A useful browser handoff can contain page context beyond form values. Review the workflow before recording and inspect the result before sharing.
- Visible page content and metadata may still be captured
- URLs, element text, attributes, screenshots, console details, and selected network context can contain sensitive information
- Use a controlled or staging environment and avoid secrets, personal data, and regulated workflows unless your organization has approved the capture
Access follows the handoff
Keep private project work scoped to your team, and treat a public replay link as intentionally shared receiver access.
Project membership
Private replay content requires authenticated project ownership or membership.
Membership controls
Workspace and project membership can be managed separately to keep access aligned with the handoff.
Receiver access
A public replay is accessible through its link until a project member returns it to private. Share only with intended recipients.
Vulnerability Reporting
If you believe you have found a security issue in Samelogic, email us with a clear description and safe reproduction steps. Do not include secrets or customer data.
Report a Vulnerability