Security

Signing in

Passwords are stored as bcrypt hashes. Two-factor sign-in with an authenticator app can be optional or required for everyone. Sign-in attempts are rate limited.

Single sign-on

Use your existing accounts through any OpenID Connect provider, such as Microsoft Entra ID, Okta or Auth0.

Channel access

Users are placed in groups, and each group only sees the channels it's allowed to.

Audit log

Every sign-in, sign-out and failed attempt is written to an audit log with the user and IP address.

Stays on your network

You own the recorder and its database, and it lives on your network. Recordings stay there and aren't sent to an outside service.

Drive encryption

The server's drive can be encrypted when Debian is installed, using Debian's built-in full-disk encryption. Recordings on a removed or stolen drive can't be read.

Web protection

The web app is served over HTTPS behind Nginx, with session sign-in and CSRF protection on every form.