Security
Security
How Sharefrost is built to keep what's on your screen on your device.
Design
- Local matching. Detection and hiding run inside your browser. Page text, URLs and detected values are never sent anywhere.
- No remote code. Templates and team rule sets are JSON data, validated locally. We ship no remote kill switch because it would be remote code.
- Minimal access. No site access at install. Per-site access is requested only when you save a rule.
- Inputs untouched. Sharefrost never changes what's in a form field or an editable area. It only covers what's displayed.
- Signed licenses. Pro licenses are signed tokens verified inside the extension, so Pro keeps working offline.
- Tenant isolation. Team data is scoped to your workspace, and only our server functions write licenses, seats and audit records.
Reporting a vulnerability
Email security@sharefrost.com. We'll reply as soon as we can, and ask for a 90-day coordinated disclosure window. Please don't access other people's data, and don't include real customer data in reports.
Our security.txt has the same details.
Security questionnaires
Evaluating Sharefrost for your company? Team and Enterprise customers can request our security questionnaire answers at sales@sharefrost.com.