Security

Last updated 11 October 2026

How we protect your workspace's data, and how to tell us about a security problem.

How we protect data

  • Encryption: all traffic uses HTTPS. The database and file storage are encrypted at rest by our providers.
  • Files: screenshots, traces and videos are in a private bucket, uploaded and downloaded only through signed links that expire within minutes.
  • Workspace isolation: every read and write is scoped to the workspace and project it belongs to, and automated tests check that one workspace can't reach another's data.
  • Sign-in: passwords are stored as salted hashes; API tokens are stored hashed, shown once, and can be revoked any time under Account → API tokens. Sign-in sessions expire after 30 days.
  • Roles: owners, members and viewers get different permissions in each workspace.
  • Local logins stay local: logins saved by the CLI stay on your computer, readable only by your user, and are never uploaded. The extension hands them to the CLI over 127.0.0.1 after a pairing code.
  • Backups: the database is backed up continuously with point-in-time restore.
  • Error monitoring is set up not to collect user details, cookies, headers or request bodies.
  • Retention: files are deleted automatically after your plan's history window.

Our hosting and infrastructure providers are listed on the subprocessors page.

Report a vulnerability

If you think you've found a security problem in Bug Smash, the CLI or the extension, email support@bugsmash.dev with “Security” in the subject, the steps to reproduce it, and what you think the impact is. We'll reply within 3 business days and keep you updated until it's fixed.

While you look, please:

  • use only your own accounts and workspaces, and stop as soon as you reach anyone else's data;
  • don't run denial-of-service, spam or social-engineering tests, or test physical security;
  • give us reasonable time to fix the problem before telling anyone else.

If you follow these rules in good faith, we won't take legal action against you over your research, and we'll credit you if you'd like. We don't run a paid bug bounty at the moment.