Security you can check, not just trust.
We’d rather show you how LayerT works than ask you to take our word for it. Here’s what’s true today, what isn’t yet, and where to read the detail.

Security
What’s true today, and what isn’t yet.
- Signed policy, checked before it’s usedRules ship signed with Ed25519, and the browser’s own crypto checks them. Stale or tampered policy blocks rather than lets things through.
- Every secret sealed with its own keyAES-256-GCM envelope encryption. Recordings are encrypted on the device, with a key made for that session.
- Authenticator secrets stay on the serverCodes are made server-side. Revealing a password takes a second person, and it’s logged.
- Separation of dutiesIT configures. Compliance grants lasting exceptions. Nobody approves their own request.
- Chrome todayEdge, Firefox and Opera are coming. No Safari, mobile or desktop apps.
- Sign-in control, not content scanningLayerT doesn’t inspect file uploads, documents or the clipboard.
- Recording is off by defaultYour company confirms a lawful basis first, people are told on the page, and what they type is masked. A watermark deters and attributes; it can’t stop a phone camera.
- Pre-launch, with no certifications yetLayerT produces the evidence your auditors ask for. Keys held in a cloud key service are on the roadmap.
How to tell a real LayerT prompt
LayerT never asks for your password. And when it’s on the page, its icon in your toolbar lights up. A website can copy a prompt, but it can’t draw in your toolbar.
Read the detail
Whitepapers written for security architects, engineers and privacy reviewers.
The LayerT security model
Who LayerT defends against, how, and what it deliberately leaves to other controls. A threat-by-threat walk-through with the residual risks stated.
Read the whitepaper Security and IT engineersShare access, not passwords
How LayerT brokers shared accounts: sealed storage, approval-gated grants, filling the vendor’s form without showing the password, and ending the session on time.
Read the whitepaper Security engineersFail-closed by design
Signed policy for in-browser enforcement: how rules are published, signed, delivered, verified and enforced, and why a stale policy blocks rather than lets things through.
Read the whitepaper Privacy, legal, complianceRecording sessions responsibly
What LayerT records when a company chooses to, what it never records, how recordings are encrypted and who can watch them. Written for privacy, legal and works-council reviewers.
Read the whitepaperFound a vulnerability?
Please tell us privately, and give us a reasonable time to fix it before you publish. We won’t take legal action against good-faith research that respects people’s privacy and doesn’t disrupt our service.
Report to: [email protected]. Our security.txt has the same details in machine-readable form.
Include what you found, how to reproduce it and what an attacker could do with it. We’ll confirm we’ve received it and keep you updated until it’s fixed.