Security

Built to be trusted
on your gaming PC.

Flashback runs next to your games all day. Here is how we protect your PC, your clips, and your Cloud account, and how to tell us if you find a problem.

Found a vulnerability?Report it privately below.
01

Signed releases and updates

Installers and update packages are signed with Flashback's publisher certificate, and each release has a signed manifest that binds the exact file, size, and SHA-256 checksum. The app verifies all of it before installing and refuses anything that doesn't match. The checksum for every installer is published on the download page.

02

Your clips stay on your PC

Recording, editing, and your library are local. Flashback works without an account, and nothing is uploaded unless you choose Cloud sharing for a specific clip.

03

Cloud accounts without passwords

Cloud sign-in goes through Discord or Google, so Flashback never stores a password. Sessions use short-lived tokens that rotate, and signing out revokes them.

04

Private by default

Share links use long random addresses that aren't listed anywhere. Uploaded videos are served from a separate domain from the website and account pages.

05

Encrypted in transit and at rest

Every connection uses HTTPS with strict transport security. Cloud data and clips are stored on Cloudflare, which encrypts them at rest.

06

Payments handled by Stripe

Cloud plans are sold through Link, Stripe's checkout. Card details go to Stripe and never reach Flashback's servers.

07

Limited, logged staff access

The internal control center requires multi-factor sign-in. Each person sees only what their role needs, and every change they make is recorded in an audit log.

08

Defense in depth

Strict content security policies, rate limits on every public endpoint, and abuse checks on uploads and forms reduce the damage any single mistake could do.

Responsible disclosure

Report a vulnerability

Send the details through the support form with the Security type, or email flashback.business.support@gmail.com. Include what you found, how to reproduce it, and the version you tested. Please keep it private until we’ve fixed it.

We confirm receipt within three business days and keep you updated until it’s resolved. We won’t take legal action against good-faith research that follows this page: don’t access or change other people’s data, don’t degrade the service, and give us reasonable time to fix the issue before sharing it.

Flashback doesn’t run a paid bug bounty yet. A machine-readable contact is published at /.well-known/security.txt.