Kapture ITKAPTURE IT← Product page

Security

Kapture IT Security

Last updated: August 25, 2026 · Published by Kalidonis LLC

Kapture IT treats every captured webpage as potentially sensitive. The currently released extension performs screenshot capture and export locally in the browser. It does not upload screenshot pixels to Kalidonis LLC, contain advertising or analytics SDKs, or load remote executable code.

Local-processing boundary

Downloaded files are thereafter governed by the user’s device, browser, backup, synchronization, sharing, and organizational security controls.

Permission model

Kapture IT uses narrow browser permissions for user-facing functions:

PermissionSecurity purpose
activeTabLimits normal capture access to the page selected through the extension action.
scriptingRuns the packaged capture controller only when required.
downloadsSaves requested outputs without uploading them to a server.

Features that require website discovery will request optional HTTP/HTTPS access only for the domain entered by the user. Kapture IT does not request permanent required access to every website for ordinary capture.

Defensive controls

Kapture IT’s development and validation process includes controls intended to:

An integrity record is a Kapture IT self-attestation and not an independent signature, timestamp authority, forensic certification, or guarantee of evidentiary admissibility.

Data minimization

The current extension has no account system, payment collection, behavioral analytics, advertising, or server-side screenshot history. Structural quality and WCAG preflight checks return generic status information rather than exporting page text or form values.

Any future Kapture IT Pro account and licensing service will undergo a separate security and privacy review before launch. Payment-card entry will be handled by the selected payment processor rather than the extension.

Secure use recommendations

Reporting a vulnerability

Report suspected Kapture IT vulnerabilities privately through the Kalidonis LLC contact page and identify the request as Kapture IT Security.

Include, when safe to do so:

Do not include passwords, authentication tokens, payment information, customer data, or confidential webpage captures. Do not test against accounts, websites, or data you do not own or have explicit permission to assess. Avoid public disclosure while Kalidonis LLC investigates and addresses a reported issue.

Kalidonis LLC does not currently operate a paid vulnerability-reward program. Reports are reviewed on a reasonable-efforts basis.

Supported versions

Security fixes are delivered through extension updates. Users should run the newest version available from the applicable official marketplace. Older, unpacked, modified, or unofficial distributions may not receive support.

No absolute guarantee

No software or security process can eliminate all risk. This page describes the intended security design and current controls; it is not a warranty that Kapture IT is free of vulnerabilities or compatible with every website and environment.