Information security
Last updated: 15 August 2026.
This page is for whoever has to approve Walkstamp inside a company: how it works, what leaves your
machine, and what we do not have.
In one line: the tool has no processing server and never receives your video, your audio or your frames. That holds on every plan, and you do not have to take our word for it — you can check in thirty seconds, with the browser you already have open. Anyone on a paid plan gets an account, and there is exactly one thing it can store by your choice; it is spelled out below.
Why the question has a different shape here
Vendor assessments usually follow a checklist: where is the data held, who can access it, which certification do you hold, which processing agreement do we sign. That checklist assumes the vendor receives something.
In Walkstamp the entire process happens in your browser tab. The video is read from your disk by the browser itself, the images are extracted there, the audio is transcribed there, and the PDF, Word, ZIP and JSON files are assembled in the tab's memory and saved by the browser. There is no upload at any step. There is no temporary copy on our side, because there is no side of ours involved in the processing.
This does not make Walkstamp automatically approvable — it makes the conversation different. Instead of “trust their access controls”, the question becomes “does this really send nothing?”, which is a question you can answer yourself.
How to check, without trusting us
This is the most important part of the page, and it takes less time than reading it:
- Open the tool and press
F12to open the developer tools. - Go to the Network tab and leave it recording.
- Load a large video — deliberately, a multi-gigabyte one — and generate the PDF.
- Look at the column for bytes sent. It stays at zero. No request carries the video, the images or the text.
A test your own security team runs is worth more than any statement of ours, which is why it is here instead of a badge.
The offline version, for when that is still not enough
There is a single HTML file with the whole tool inside. You download it, disconnect the network, open the file, and it works. Nothing in it talks to any server.
And that is not a promise in prose: the process that produces that file fails the build if any measurement address is left inside it. It is a lock in the pipeline, not an intention. You can verify it by searching the downloaded file for “supabase” or “insights” — there are no matches.
In the offline version you lose automatic transcription (the speech model is downloaded on demand), text recognition from images, and the Google Drive button. Everything else works the same. It can also be stored in an internal repository, scanned by your team, and distributed without depending on us.
What leaves your machine, and when
Nothing of your content leaves without a gesture from you.
The video, the audio and the transcript never leave — no gesture sends them away, because there is no server to receive them. Everything else leaves only when you send it, and this is the complete list of what leaves, when, and what goes with it.
| Where to | When it leaves | What goes with it | What never goes |
|---|---|---|---|
| Vercel (hosting) | Always, on opening the page | The request for the page file, with IP and browser — as on any website. | Your content |
| Usage measurement | Opening the page | At fifteen milestones — eleven in the tool and four in the account —, the milestone name, the page language, the video source, the format downloaded, a band (“4-10”, never the exact number) and the plan. No cookie and no persistent identifier. Honours Do Not Track and Global Privacy Control. | Any person or session identifier; file name, size, duration, content |
| The account menu | Opening the page | The page language, to draw the account bar. Nothing else. | Anything of yours |
| The library that makes the PDF | Opening the page | Nothing. It is a download: the CDN learns that someone opened the page, and nothing more. In the offline package it comes embedded. | Your audio, your image, your text |
| The speech model | Choosing “transcribe while I record” | Nothing leaves. The model is DOWNLOADED and runs on your computer; the audio is not sent anywhere. | Your audio |
| Reading the text in the image | Clicking “read the text in the image” | Nothing leaves. The reader is DOWNLOADED and runs on your computer; the image is not sent. | Your image |
| Your account · carries content of yours | Signing in and saving a case script | Content of yours: the account e-mail, and the case script you save — case names, system, ticket, notes and the files you attach. Never video, audio or transcript. | Video, audio and transcript |
| Google Drive · carries content of yours | Clicking “send to Google Docs” | Content of yours: the document assembled in your browser — text and images —, for Google to turn it into a Drive document. Authentication uses the narrowest scope there is (drive.file). Only after you confirm the notice. | The rest of your Drive; and the file goes from your browser straight to Google, without passing through us |
| Sharing a link | Clicking share | The website address, and that is all. No part of your document goes with it. In the offline package this button becomes an e-mail. | Any part of your document |
None of these connections carries video, audio, images or transcripts. The PDF library comes from jsDelivr along with the page; it is the offline package that embeds it.
There is one exception, and it is in the table rather than hidden: the Send to Google Docs button is the only function where the generated document leaves the computer. It exists because many teams review evidence in Drive, and it asks for explicit confirmation before sending — if you do not want it, you do not click it, and nothing changes. If your policy forbids taking the content to Google, note that the button only appears when Drive credentials are configured, and the offline version does not have it.
One case tends to surprise people: translation of the transcript does not leave here either. It uses the translator the browser itself embeds, running on your device — not the Google Cloud API, which would require a key of ours in the code and would send your text to a server. Where that translator does not exist, what the tool offers is the speech model translating as it listens, also on your computer. In neither path is the text transmitted.
The paid account, and the one exception
Using the tool requires no account, and that has not changed: signed out, /app
records, transcribes and generates documents exactly the same. Anyone on a paid plan gets an account
holding the sign-in e-mail, the invoices, the support tickets, the team seats and — if you use the
test run screen — the list of cases to run.
On that screen, marking a case done stores a receipt: the case code, the system, the ticket, the date, the name of the generated file and the fingerprint of every frame. Those are numbers. No image, no transcript, no step text. It is what lets you take a PDF months later and check that it is the same one — which is why it exists.
The exception, and it is yours: when you confirm the case as done, there is an optional
field to attach the complete session .json. That file has the frame images
inside it. Attaching it is the one thing in this product that puts content of yours on a server of
ours; it never goes on its own, the field starts closed, and what it means is written next to the
field — not in a terms page. Every attachment has a delete button, and deleting removes the file,
not just the row pointing at it. Your video and audio still never leave your browser, attachment
or no attachment.
What stays in your browser
None of your content is kept between visits. Of the evidence identification fields, only
system and executed by are held in sessionStorage — which the browser clears
when the tab closes — so they are not retyped for every case; a button clears them immediately. Test
case, ticket, result and the notes are not stored even while the tab lives. None of this is a cookie,
none of it is read by us, and none of it leaves your device.
Alongside the model there is a configuration note: which combination of library and file format manages to open the model on this machine. Version names, no content — and the button that deletes the model deletes the note with it.
The screens of a recording in progress are kept in the browser's private storage (OPFS), on your computer, so a tab crash does not erase the work — before this, a crash 110 minutes into a two-hour recording erased the two hours. They are deleted as soon as any document is generated, and after seven days in any case; and the “throw it away” button, which step 1 offers whenever there is a stored recording, erases whatever is already there, right then. None of it is sent anywhere — the F12 test still shows zero bytes sent.
Apart from that, what persists is the transcription model, cached by the browser itself so it is not downloaded again. It sits on your device, under your control, and is removed when you clear browsing data. We use no cookies — neither our own nor third-party ones.
What we do not have
This is the part almost no vendor writes, and precisely the part your team needs. We hold no security certification, and we are not in the process of obtaining one. Below is what each one means and why it does — or does not — apply to a tool that receives no data.
| Standard or certification | Do we hold it? | What that means here |
|---|---|---|
| ISO/IEC 27001 | No | It certifies the information security management system of an organisation that holds data. We do not hold yours. If your policy requires ISO 27001 from every vendor that receives data, it is worth recording that here there is no receiving — but whether the exception applies is your team's call, not ours. |
| SOC 2 (Type I or II) | No | It audits controls at a service organisation that processes customer data. There is no service processing anything: the processing is on your computer. |
| 21 CFR Part 11 (FDA) | No | It requires a validated closed system, an audit trail and electronic signatures. A document generator in a browser does not and cannot meet that on its own. In a Part 11 environment Walkstamp can produce the image, but the controlled record has to live in your validated system. |
| CSV / GAMP 5 | No | Computerised system validation happens in your environment, for your use. It is not something a vendor hands over finished. |
| SOX / ITGC | Not applicable as a certification | Walkstamp is not an IT control. It produces the evidence that feeds your control. The control is still yours to answer for. |
| HIPAA — business associate agreement | We do not sign one | We receive no data, so the relationship the agreement would formalise does not exist. If your policy requires an agreement with any tool that touches health data, even locally, talk to your compliance team — we are not going to say it is fine when that call is not ours. |
| LGPD / GDPR | Not a certification | There is no such thing as a “GDPR certificate”. Our position, legal bases and retention periods are described in the Privacy Policy. |
| Penetration test report | We have none | There is no infrastructure to test beyond static file hosting. What exists is the code that runs on your machine — and it is readable. |
| Cyber liability insurance | No | We are a small company and it would not be honest to imply coverage that does not exist. |
What exists instead
- The code that runs in your browser can be read: it is a page, and
Ctrl+Ushows all of it. There is no server-side code because there is no server. - The offline version can be downloaded, scanned, versioned and distributed by your own team.
- Verifying that nothing leaves takes thirty seconds and does not depend on believing us.
What remains your responsibility
- The generated document contains whatever was on your screen. If you recorded production data, the file that came out has production data — and where it goes next is your decision.
- Screen sharing captures everything on screen, including the window you left open behind. Prefer sharing a specific window when the content is sensitive.
- Automatic transcription downloads a speech model from a public CDN the first time. If your policy forbids external CDNs, use the offline version and type the notes by hand.
- Walkstamp produces the visual evidence. The approval trail stays in your change management system.
Who answers
Walkstamp is offered by Produtize Produtos e Serviços Inteligentes Ltda., Brazilian company registry (CNPJ) 48.417.292/0001-99.
To report a security issue, ask for clarification for a vendor assessment, or request the offline version: privacidade@walkstamp.com. There is no bug bounty programme, but we do answer.
This page describes how things work as of the date above. If anything changes in a way that affects what is written here, this page changes with it — and the date at the top is how you check that.
How it works underneath
- You ask. Type your email here. Nothing is decided at this moment: a message goes out to your mailbox, that is all.
- You click what arrived. That is what proves the address is yours — and it is the only moment anything resembling a session exists.
- You come back with the link ready. The key is signed on the server, with your email inside it, and handed over already wrapped in a Walkstamp address.
- From then on, no network at all. The key is checked inside the browser, against a public key that sits in the tool's own HTML. It works on a plane, on the client machine with the internet locked down, and on the computer IT will not let talk to our hosting.
Why the validity is short
Each key issued lasts 21 days on a team and 45 on the individual plan (14 on the trial), and the next one arrives by email before the previous expires. The administrator can shorten that window, from 1 to 90 days, in the team portal. This is not bureaucracy: it is what makes a leaked link die on its own. Since no server checks anything while you work, there is no revoke button — the deadline is the revocation. It is a trade we chose on purpose: we would rather have a leak that expires than a paid product that stops working when the internet drops.
Before you decide
From here, the two paths that usually come next: check a document the tool generated, or see the plans and what changes from one to the next.