Security
What happens to what you hand over
Last updated: July 28, 2026 · applies to redemo.io
To film your product we ask for something sensitive: the URL of your app and a login that works on it. That deserves a straight answer, not a trust badge. Here is exactly what we do with it — and, at the bottom, what we haven't built yet.
Use a demo account, not production
This is our first recommendation and we repeat it at onboarding: create a dedicated demo or staging account for Redemo, filled with demo data. Not your production admin, not a real customer's account, not something that can delete data or touch billing. Give it the smallest permissions that still let it walk through your storyboard.
If that account only ever sees fake data, handing it to us costs you nothing even in the worst case — and the video comes out better, because the data on screen is curated instead of redacted.
What we do with the credentials
- Stored encrypted at rest — not in tickets, spreadsheets, or chat messages.
- Used only by the recording pipeline, to log into your app for a render. They are not used for anything else.
- Access is limited to the pipeline and the founder who operates it. Redemo is a small operation — there is no support team browsing your account.
- Never shared with third parties, never sold, never used to sign in outside a render.
- Deleted when you cancel, or whenever you ask — email us and we remove them, then confirm it's done.
- Rotate them freely: change the password whenever you like and send us the new one. That's normal, not a problem.
What the recorder actually does
A headless browser (Playwright) opens your app in a clean, isolated session, signs in with the demo account, and follows the storyboard derived from your script: navigate, scroll, hover, type the values the script needs. It is navigation, not integration — we don't call your API, don't export data, don't change your settings and never perform destructive actions. Where a scene has to submit a form to show a feature working, that write happens inside the demo account you gave us, on the demo data you put there, and we tell you which steps write anything.
Nothing is installed in your codebase: no SDK, no snippet, no agent, no repository access. If a scene needs a form submitted to show a feature working, we do it inside the demo account with the demo data you provided, and we tell you which steps write anything. Recordings run from our own infrastructure. If you need to restrict the demo account by source IP, ask us and we will confirm what we can guarantee for your setup.
Where the data lives
Credentials, captured footage and rendered videos sit on our own servers, self-hosted in the EU — not with a third-party form or storage service. Traffic to redemo.io and to the pipeline is TLS-encrypted, and backups stay on the same EU infrastructure.
The AI presenter and voice are generated by a third-party provider. It receives your script text and the presenter and voice you picked — never your credentials, and never a session on your app.
Your videos stay yours
Renders are private to your account by default: they're tied to it, and the download links are yours. A hosted embed is, by design, watchable by anyone who has the link — so treat that link as public once you publish it. We never showcase a customer's video without written permission.
What we do not have — said plainly
Redemo is an early-stage product. Being straight with you matters more than looking mature, so:
- No SOC 2. No ISO 27001. No compliance certification of any kind.
- No third-party security audit or penetration test has been carried out.
- No SSO, SCIM, granular roles or customer-facing audit logs in the product yet.
- No bug bounty programme and no 24/7 on-call rota.
- Not an environment for regulated data: don't point Redemo at an app holding real patient records, cardholder data, or anything else you'd need a certified processor for.
Anyone at this stage claiming those badges would be inventing them. If one of them is a hard requirement before you can buy, tell us — that's genuinely useful to know, and we'll answer honestly whether it's on the roadmap or not.
Reporting a security issue
Found something — an exposed endpoint, a leaked link, a way to reach another account's renders? Email contact@redemo.io with "security" in the subject. That inbox is read every day and we'll come back to you within a couple of business days.
We will never threaten anyone reporting in good faith. In return, please don't run destructive tests, degrade the service, or touch other customers' data. There's no bounty to offer yet — we'll credit you publicly if you'd like.
Questions
Personal data is covered in the privacy policy, and the commercial side in the terms of service. Anything else, including a security questionnaire from your team: contact@redemo.io. Redemo is operated by Kiora (France).