Security
Browser isolation
Each job gets a new browser context that is closed when the capture finishes. Custom JavaScript runs in the target page, not on the host process. Navigation and resource use are time-bounded.
SSRF and private networks
Only public http and https URLs are accepted. Localhost, private IPv4 and IPv6, link-local, metadata hosts, and URLs with embedded credentials are rejected. Redirects are checked again. DNS results are revalidated before navigation. Resource requests to private literals are aborted.
API keys and sessions
Keys are hashed at rest. You can revoke a key at any time. Last-used time is recorded. Session cookies are HMAC-signed, HttpOnly, SameSite=Lax, and Secure on HTTPS. Login and signup are rate-limited.
Encryption
Traffic is served over HTTPS in production. Secrets are not embedded in public JavaScript.
Data retention and access
Capture files belong to the account that created them. Files stay until you delete them or close the account. Workspace access is limited to the signed-in owner in this release.
Logging
Render reports record HTTP status, timing, and blocked layers for the capture you requested. They are not public access logs.
Incident response
Confirmed incidents are investigated, contained, and communicated to affected account holders when required.
Responsible disclosure
Report a vulnerability to security@anearst.com.