Capture Desktop, Tablet, and Mobile together, so you can see how a Page truly responds across devices.
Security | WebMoment
Legal
Security
Security practices used to protect WebMoment and customer data.
Last updated July 16, 2026
Security
WebMoment treats security as an operational practice across the Services, customer Workspaces, Customer Data, API access, and the systems used to capture, store, and deliver web content.
This page summarizes current practices for access control, infrastructure, storage, monitoring, incident response, and responsible disclosure. These practices evolve as the Services grow. It is informational and does not create contractual security obligations, guarantees, warranties, or service-level commitments.
Security controls, operational procedures, and infrastructure practices help protect the Services and Customer Data.
These controls are reviewed and updated as the product, usage patterns, and operational risks change.
2. Encryption
HTTPS is used for data transmitted between browsers, APIs, and the Services.
Data stored by infrastructure providers may also be encrypted at rest where supported by those providers, using provider-managed encryption or equivalent storage protections.
3. Access Control
Access to Workspaces is role-based. Workspace owners and administrators control Workspace membership, roles, permissions, API Keys, and sharing settings.
Workspace members should use the access they are granted only for authorized purposes. Customers are responsible for:
inviting trusted users;
assigning appropriate roles;
removing users promptly;
reviewing Workspace settings;
protecting API Keys;
reviewing Shared Links and exports;
configuring retention and access controls that meet their requirements.
4. Authentication and MFA
Authentication controls depend on the product configuration and identity provider in use.
Where multi-factor authentication or similar account protection is available, users should consider enabling it for stronger account security.
5. API Key Security
API Keys authenticate requests to the API and should be treated as secrets. Customers should:
store API Keys securely;
avoid exposing keys in client-side code;
rotate keys when needed;
revoke unused keys;
use scoped or limited-access keys where available.
WebMoment may revoke API Keys that create security, abuse, or operational risk.
6. Infrastructure
The Services use cloud infrastructure and managed service providers for hosting, storage, databases, queues, notifications, authentication, and related functionality.
Providers may change over time as the Services evolve. Current subprocessors are listed where applicable in Subprocessors.
7. Storage
Customer Data may include Pages, Moments, Trackings, Replay archives, screenshots, uploaded assets, comments, metadata, Collections, and exports.
Storage access is restricted to systems and personnel with a business need. Customers remain responsible for configuring Workspace permissions, Shared Links, exports, retention policies, and other sharing settings appropriate for their own requirements.
8. Backups
WebMoment may maintain backups or provider-level recovery mechanisms for operational resilience.
Backups and recovery mechanisms primarily support operation of the Services. They are not a substitute for customer-managed exports, retention policies, or independent records where customers require separate copies.
9. Monitoring and Logging
Logs and telemetry may be collected to:
monitor service health;
troubleshoot errors;
detect abuse;
investigate security or operational incidents;
improve reliability and performance.
Logs may include IP addresses, request metadata, job events, API usage, and security events.
10. Incident Response
Procedures are maintained for evaluating and responding to security and operational incidents.
Incident response may include:
triage;
investigation;
containment;
remediation;
customer notification where appropriate or required;
post-incident review.
11. Vulnerability Disclosure
If you believe you have found a vulnerability in the Services, please report it through our contact page.
Please include:
affected endpoint or feature;
reproduction steps;
potential impact;
screenshots or logs where safe;
your contact information.
Submitting a report does not authorize unrestricted testing. Do not access, modify, delete, export, or disclose data that is not yours, and do not interfere with customer Workspaces or the Services.
12. Responsible Disclosure
Researchers must:
act in good faith;
avoid disrupting customers or degrading the Services;
avoid accessing unauthorized data;
avoid destructive testing;
avoid privacy violations;
comply with applicable law;
give WebMoment reasonable time to investigate.
WebMoment does not authorize testing that compromises third-party systems, attacks customer Workspaces, or interferes with the Services.
13. Availability
The Services are designed for reliable operation, but uninterrupted availability is not guaranteed unless a separate written agreement states otherwise.
Availability may depend on infrastructure, maintenance, third-party providers, abuse prevention, operational events, and other conditions outside WebMoment's direct control.
14. No Certifications Claimed
This document does not claim SOC 2, ISO, PCI, HIPAA, or other certifications unless separately stated in a signed agreement or official WebMoment compliance document.
15. Contact
Security questions may be sent through our contact page.