KAPTURE IT← Product pageSecurity
Kapture IT Security
Local-processing boundary
- Capture begins only after a user invokes Kapture IT on the active tab.
- The page controller measures, scrolls, checks, and restores the selected webpage.
- Browser screenshots are assembled in temporary extension memory.
- PNG and PDF files are generated locally.
- Downloads begin only after a user action.
- Screenshot pixels are not written to Kapture IT account storage or a Kalidonis capture-processing server.
Downloaded files are thereafter governed by the user’s device, browser, backup, synchronization, sharing, and organizational security controls.
Permission model
Kapture IT uses narrow browser permissions for user-facing functions:
| Permission | Security purpose |
|---|---|
activeTab | Limits normal capture access to the page selected through the extension action. |
scripting | Runs the packaged capture controller only when required. |
downloads | Saves requested outputs without uploading them to a server. |
Features that require website discovery will request optional HTTP/HTTPS access only for the domain entered by the user. Kapture IT does not request permanent required access to every website for ordinary capture.
Defensive controls
Kapture IT’s development and validation process includes controls intended to:
- prohibit remote executable code and dynamic code evaluation;
- reject unexpected or unnecessarily broad manifest permissions;
- verify the expected tab, window, URL, and page identity during capture;
- enforce browser screenshot throttling and bounded capture dimensions;
- detect certain blank, unstable, redirected, or changing captures;
- normalize filenames and restrict configured downloads to a safe relative folder;
- restore page styles and scroll position after capture;
- revalidate imported domain manifests before use; and
- produce local SHA-256 integrity evidence for supported exports.
An integrity record is a Kapture IT self-attestation and not an independent signature, timestamp authority, forensic certification, or guarantee of evidentiary admissibility.
Data minimization
The current extension has no account system, payment collection, behavioral analytics, advertising, or server-side screenshot history. Structural quality and WCAG preflight checks return generic status information rather than exporting page text or form values.
Any future Kapture IT Pro account and licensing service will undergo a separate security and privacy review before launch. Payment-card entry will be handled by the selected payment processor rather than the extension.
Secure use recommendations
- Install Kapture IT only from an official Kalidonis LLC marketplace listing.
- Keep the browser and extension updated.
- Review requested permissions when installing or updating.
- Treat downloaded captures as sensitively as the source webpage.
- Store confidential captures only in approved organizational locations.
- Redact personal or regulated information before sharing a capture.
- Remove Kapture IT if it is no longer needed or permitted by organizational policy.
Reporting a vulnerability
Report suspected Kapture IT vulnerabilities privately through the Kalidonis LLC contact page and identify the request as Kapture IT Security.
Include, when safe to do so:
- the affected Kapture IT version and browser;
- a concise description of the issue and expected impact;
- reproducible steps using non-sensitive test data; and
- any suggested remediation or supporting screenshots.
Do not include passwords, authentication tokens, payment information, customer data, or confidential webpage captures. Do not test against accounts, websites, or data you do not own or have explicit permission to assess. Avoid public disclosure while Kalidonis LLC investigates and addresses a reported issue.
Kalidonis LLC does not currently operate a paid vulnerability-reward program. Reports are reviewed on a reasonable-efforts basis.
Supported versions
Security fixes are delivered through extension updates. Users should run the newest version available from the applicable official marketplace. Older, unpacked, modified, or unofficial distributions may not receive support.
No absolute guarantee
No software or security process can eliminate all risk. This page describes the intended security design and current controls; it is not a warranty that Kapture IT is free of vulnerabilities or compatible with every website and environment.