We use cookies to ensure you get the best user experience on our website.Find Out More

Enterprise Trust & Security

Shakebug Security & Trust Center

Built with privacy by design. Protecting developer and end-user data at every layer.

  • Data Encryption: TLS encryption in transit & AES-256 database encryption at rest
  • Privacy by Design: Developer controls for sensitive data, header filtering & screen blurring
  • Enterprise Governance: Logical tenant isolation, GDPR aligned, DPA on request & SOC 2 roadmap

Logical tenant scoping • Self-Hosted option available for private networks

Security & Data Principles
Active Controls
Transit Encryption HTTPS / TLS (TLS 1.2 & 1.3)
Enforced
Database Storage Encrypted Database at Rest
AES-256
Privacy Controls Header Filtering & Screen Blurring
Configurable
Tenant Scoping Application-Level Data Scoping
Isolated
TLS In Transit
AES-256 At Rest
Sensitive Data Filtering
Logical Tenant Isolation
GDPR & CCPA Aligned
SOC 2 Roadmap

Data Security & Encryption Standards

We apply cryptographic protection to ensure your application telemetry, screenshots, and crash data remain secure during transmission and while stored.

TLS Encryption in Transit

All communication between client applications, web browsers, and Shakebug API endpoints is encrypted using standard HTTPS/TLS protocols.

  • Standard TLS (TLS 1.2 and TLS 1.3) protecting all REST endpoints and WebSockets
  • Secure data transport preventing interception of telemetry packets
  • HTTP Strict Transport Security (HSTS) headers applied
  • Payments processed exclusively via Stripe (PCI-DSS Level 1 compliant); Shakebug never stores payment card numbers

AES-256 Encryption at Rest

Shakebug stores data in a database encrypted at rest to safeguard stored bug reports, crash logs, and telemetry.

  • AES-256 bit encryption applied to production database volumes
  • Stored bug reports, crash stack traces, sessions, and logs remain encrypted at rest
  • Separation of administrative infrastructure access from database operations
  • Automated database backups held in encrypted storage
🛡️ Shakebug Telemetry Security Pipeline
STEP 1

Client App

Bug or crash occurs in your app. Telemetry is gathered locally.

→
STEP 2

Privacy Controls

Sensitive headers excluded & screen elements blurred if needed.

→
STEP 3

TLS Transit

Encrypted transmission over HTTPS / TLS to Shakebug gateway.

→
STEP 4

Tenant Validation

Payload verified and scoped to your Project & Account ID.

→
STEP 5

Encrypted Storage

Stored in AES-256 encrypted production database.

Data Privacy Controls & Redaction

Ensure sensitive customer inputs and private credentials are kept safe with built-in developer and user privacy controls.

Screen Blurring & Visual Redaction

Shakebug enables end-users and testers to redact sensitive information before submitting a bug report.

  • In-app annotation and blur tools allowing users to obscure sensitive screen areas (e.g., passwords or card fields)
  • Developers can disable screenshot or video capture on specific sensitive views or screens
  • Screen recordings can be toggled on or off depending on privacy requirements
  • Diagnostic data is focused strictly on reproducing technical bugs and crashes

Network Header & Payload Filtering

Prevent internal tokens and credentials from being unintentionally captured in network diagnostic logs.

  • Filter out sensitive HTTP request and response headers (such as Authorization, Cookie, or Token)
  • Configure SDK data collection to omit private payload parameters
  • Custom event logging gives you complete control over which attributes are attached
  • No sensitive payment card data is ever collected or processed by Shakebug SDKs

Developer Privacy Configuration

Configure privacy and header exclusion options across platforms:

Initialize Shakebug with privacy controls in iOS:

// Initialize Shakebug with privacy & network filtering
let config = ShakebugConfig()
config.redactedHeaderKeys = ["Authorization", "Cookie", "X-Api-Key"]

// Screen blur and annotation are available to users prior to submission
Shakebug.shared.start(withKey: "YOUR_APP_KEY", config: config)

Configure Android SDK privacy and header exclusions:

// Initialize Shakebug Android SDK with header exclusions
val config = ShakebugConfig.Builder()
    .addRedactedHeaders(listOf("Authorization", "Cookie", "Bearer"))
    .build()

Shakebug.init(applicationContext, "YOUR_APP_KEY", config)

Flutter SDK privacy and telemetry configuration:

import 'package:shakebug/shakebug.dart';

// Wrap your app with ShakebugSDK; users can blur & redact sensitive screen areas
ShakebugSDK(
  androidAppKey: 'YOUR_ANDROID_APP_KEY',
  iosAppKey: 'YOUR_IOS_APP_KEY',
  allowToReportBugByShakingMobiles: true,
  allowCrashReport: true,
  child: const MyApp(),
);

React Native privacy configuration:

import { Shakebug } from 'shakebug-react-native';

Shakebug.start("YOUR_APP_KEY", {
  redactHeaders: ['Authorization', 'Cookie'],
  enableScreenBlur: true
});

Web JavaScript SDK privacy options:

import { Shakebug } from '@shakebug/web';

Shakebug.init({
  apiKey: 'YOUR_APP_KEY',
  redactedHeaders: ['Authorization', 'Cookie'],
  maskSensitiveFields: true
});

Data Control & Retention Policies

Maintain full governance over your telemetry lifecycle with transparent retention windows by subscription tier and on-demand deletion mechanisms.

Subscription Tier Retention Windows

Shakebug manages telemetry retention based on your active subscription plan:

  • Basic (Free): 10-day data retention window
  • Standard ($75/mo): 90-day data retention window
  • Premium ($125/mo): 180-day data retention window
  • Enterprise: Custom retention schedules or self-hosted indefinite retention on your own servers

On-Demand Data Deletion Controls

Manage and delete data whenever needed to comply with user requests or internal retention policies:

  • Dashboard Item Deletion: Delete individual bug reports, crash logs, or sessions from the dashboard
  • Account Deletion: Delete your complete account via Profile → Danger Zone → Delete My Account
  • Grace Period: Deleted accounts enter a 14-day grace period, after which all project data is permanently erased
  • End-User Erasure: End-users can request deletion of their records by contacting support@shakebug.com

Data Retention & Governance Matrix

Plan Tier Data Retention Hosting Infrastructure Data Deletion Controls Export Options
Basic (Free) 10 Days Managed Cloud Dashboard UI Controls CSV / PDF
Standard 90 Days Managed Cloud Dashboard UI Controls CSV / PDF / Integrations
Premium 180 Days Managed Cloud Dashboard UI Controls CSV / PDF / Integrations
Enterprise Custom (Up to 365+ Days) Cloud or Self-Hosted On-Premise Dashboard + Support Assistance Bulk Export & Custom Integrations

Infrastructure & Compliance Standards

Built with logical multi-tenant data boundaries, GDPR alignment, and a clear roadmap for security certifications.

Logical Multi-Tenant Isolation

In our cloud environment, customer records share a secure multi-tenant database partitioned by logical access boundaries.

  • All database queries are strictly scoped by Organization ID and Project ID
  • Strict application-level permission checks prevent any cross-tenant data access
  • Role-based access controls (RBAC) allow you to manage team permissions within your organization
  • Need physical isolation? Choose Shakebug Self-Hosted / On-Premise to run on your own dedicated servers and private database

SOC 2 Alignment Roadmap

Shakebug is actively aligning its engineering and organizational processes with the SOC 2 Trust Services Criteria.

  • Structured roadmap working toward SOC 2 Security and Confidentiality principles
  • Regular dependency vulnerability scanning and package audits
  • Code review workflows and controlled deployment pipelines
  • Responsible security disclosure process for reporting vulnerabilities to support@shakebug.com

📜 Data Processing Addendum (DPA) Available Upon Request

Need a signed Data Processing Addendum for GDPR or CCPA compliance? Shakebug provides a standardized DPA with Standard Contractual Clauses (SCCs). Our team reviews and executes DPAs with customers upon request.

Trust & Security FAQs

Is data encrypted both in transit and at rest?

Yes. All data transmitted between user devices, browsers, and Shakebug endpoints is encrypted in transit over HTTPS using standard TLS (TLS 1.2 and TLS 1.3). Telemetry and user records stored in Shakebug's production database and cloud storage are encrypted at rest using AES-256.

How does Shakebug help prevent sensitive data and PII from being exposed?

Shakebug provides developer-level and user-level privacy controls. In-app reporting allows users to blur sensitive visual areas (such as passwords, payment details, or personal information) on screenshots before submitting. Developers can also filter out sensitive HTTP request headers (like Authorization tokens and session cookies) from network logs.

How does multi-tenant data isolation work in Shakebug?

In Shakebug's managed cloud service, customer data is stored in a multi-tenant database where every record is logically isolated and strictly scoped to your Organization and Project ID. For enterprises requiring complete physical infrastructure and database isolation, Shakebug provides a dedicated Self-Hosted / On-Premise deployment option that runs entirely inside your own private network.

What are Shakebug's data retention policies by subscription tier?

Data retention follows your subscription tier: Basic (Free) retains telemetry for 10 days; Standard retains telemetry for 90 days; Premium retains telemetry for 180 days. For Enterprise customers, retention windows can be customized, or data can be kept indefinitely when self-hosted on your own infrastructure.

How can we delete data or fulfill user erasure requests?

Customers can delete bug reports, crashes, or projects directly from their Shakebug dashboard. Account holders can also permanently delete their entire account via Profile > Danger Zone > Delete My Account. For end-user data subject deletion requests, customers or end-users can email support@shakebug.com and our team will process the erasure.

How can an enterprise customer get a signed Data Processing Addendum (DPA)?

Shakebug provides a standard Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs) to support GDPR and CCPA obligations. If your legal team requires an executed DPA, simply email support@shakebug.com with your organization details. Our team will review, countersign, and return the executed agreement.

What is Shakebug's SOC 2 compliance status?

Shakebug is actively working toward SOC 2 alignment as part of our continuous security roadmap. We follow established security best practices including regular code reviews, automated dependency and vulnerability scans, and strict internal role-based access control.

Protect your app and user data with confidence

Get started with our free plan or talk to our team for custom enterprise requirements.

Sign up free Schedule Demo

No credit card required • Encrypted in Transit & at Rest