Security
This page is the source of truth for how CakeFlow handles your data. It's written for the security reviewer, not the marketing team — every claim on it is something we operate to, not aspire to.
The one thing to know
Screenshots stay in our infrastructure. The AI provider never sees them.
Two data types leave the browser extension when someone in your workspace records a workflow:
- A text-based action log — clicks, field names, page transitions, timestamps. This is what the AI reads.
- Screenshots — used to render the video and step images. These stay in the storage bucket in your chosen region.
The AI provider only ever receives the text. If you're evaluating CakeFlow specifically because a competing tool sends screenshots to a third-party model, that's the delta.
What we store
Screenshots
Captured during recording. Sensitive regions are masked before upload if you configure masking. Stored in your chosen region.
Action log (text)
Clicks, field names, page transitions, timestamps — structured, semantic events. This is what the AI assistant reads to answer questions.
Typed values
Text entered into non-sensitive fields, so generated steps read accurately ("type Registration approved in the notes"). Fields marked sensitive are excluded.
Account metadata
Workspace, user, and recording metadata needed to organise and serve content — nothing more.
What we don't store
- Contents of password fields, even temporarily.
- Payment card numbers.
- Keystrokes outside an active recording.
- Browsing activity outside the extension's recording window.
- Anything from tabs you didn't press "record" on.
Masking sensitive data
Masked by default
Password fields, payment card fields, and any field your platform marks as sensitive (for example, autocomplete="cc-number") are blocked from capture automatically.
User-defined regions
Draw a mask over any screen region before a recording uploads — for names, ID numbers, or anything else specific to your workflow. Masks apply to every frame that shows that region.
Where masking happens
Masking is applied client-side, in the extension, before the screenshot leaves the browser. Masked regions are never transmitted, not even encrypted.
Storage
Storage region
Choose EU, US, or AU at the workspace level. All screenshots and recordings for that workspace stay in the selected region. Region can't be changed silently — an admin has to do it, and existing content is migrated with an audit trail.
Encryption
- In transit: TLS 1.2+ everywhere. HSTS enforced on all our domains.
- At rest: AES-256, with keys managed by the cloud hosting provider's KMS.
Retention
Default retention is 90 days on paid plans (Free tier is 14 days). Configurable per workspace, including auto-delete after N days. Backups are held encrypted for up to 35 days and then rotated out.
Bring your own storage (Agency plan)
Agency-plan customers can point storage at their own S3 or R2 bucket. Screenshots never leave your infrastructure — we only process them. See the Agency plan →
Sub-processors
We use a small number of sub-processors. The AI provider listed below receives only the text-based action log — never screenshots.
| Name | Purpose | Country | Data touched |
|---|---|---|---|
| Cloud hosting provider | Application hosting, storage | Region you select (EU / US / AU) | Screenshots, action logs, account data |
| AI inference provider (Western entity) | Runs the language model behind the assistant | US or EU | Text-based action logs only — no screenshots |
| Transactional email provider | Account and notification emails | US | Name, email address |
| Payment processor | Billing | US / EU | Billing contact, tokenised payment method |
| Error monitoring | Backend exception tracking | EU | Stack traces, no workspace content |
The current, named sub-processor list is available on request under NDA. We notify workspace admins by email at least 30 days before adding or changing a material sub-processor.
A note on model choice
We may run open-weight models originating in China (Qwen, DeepSeek, Kimi, GLM) because they cost 5–30× less to run than comparable alternatives. When we do, inference is always routed through a Western inference host (for example, DeepInfra, Together, Fireworks, Baseten) — so the sub-processor of record is a US or EU company we can sign a DPA with.
We do not call Chinese AI vendors' APIs directly — doing so would block procurement with public universities in the UK, Australia, and Canada. Where the model weights originate doesn't matter for compliance; which server your data is sent to does.
Access control
- SSO (SAML / OIDC) for workspace login on the Agency plan.
- Role-based access: who can record, publish, view analytics, or manage billing.
- Audit log of who accessed or exported which recordings.
- Session management: configurable idle timeout, forced re-auth for sensitive settings.
- Internal access to customer data is logged and limited to on-call engineering, gated by production credentials rotated at least quarterly. Support engineers cannot read workspace content without an explicit, logged authorisation from a customer admin.
How we run the business
The stuff a reviewer looks for that isn't a product feature.
- Background checks on all engineering staff before production access.
- MFA required on every internal system.
- Least-privilege IAM, reviewed quarterly.
- Code review required for every change to production; no single-person deploys.
- Dependency scanning in CI, plus automated container image scans.
- Penetration testing by an independent firm annually, and after any material architecture change. Summary letter available under NDA.
- Vulnerability disclosure: email security@cakeflow.app. We respond inside 48 hours, and we won't take legal action against good-faith researchers.
- Incident response: on-call rota, defined severity levels, and a 72-hour breach notification commitment aligned with GDPR.
Export and deletion
- Export all recordings, videos, docs, and FAQ content at any time, from an active or cancelled workspace. See the Data export page for what's in the bundle.
- Deletion requests are processed within 30 days of confirmation.
- Auto-delete can be configured per workspace to remove recordings after a set number of days automatically.
Compliance
GDPR
We process personal data as a processor under GDPR. A Data Processing Addendum is available and signable from day one — download it below.
FERPA
We act as a school official / service provider processing education records on your institution's behalf, under the controls described on this page — storage region selection, masking, encryption, retention limits, and audit logging. We are not FERPA-certified; no such certification exists. These are the measures we take to support your institution's own FERPA compliance.
SOC 2
Not yet completed. We're targeting [Target date] for Type I and [Target date] for Type II. We'll publish our report here once available. In the meantime, we can share a completed CAIQ Lite or SIG Lite on request.
PCI DSS
CakeFlow is not designed to process cardholder data. Payment fields are masked by default. Don't record workflows that display raw card numbers.
HIPAA
CakeFlow is not HIPAA-eligible today. We do not sign BAAs. Don't use CakeFlow to record workflows containing protected health information.
ISO 27001 / ISO 27701
Not certified today. Our controls are structured to map cleanly to Annex A when we pursue certification.
Questions or a review to run
Reach the security team directly to start your institution's review.
