Trust

Security at BugMojo

Last updated: July 7, 2026

BugMojo captures some of the most sensitive artifacts in software — session replays, console output, and network activity from real applications. We designed the product so that sensitive data is minimized before it ever leaves the browser, and protected in transit and at rest once it does. This page summarizes how.

Client-side PII redaction

Personally identifiable information is redacted in your browser, before any data leaves the page. By default the extension masks input values and password fields during recording, so masked content is never transmitted to or stored by BugMojo. You control redaction rules, and capture is always user-initiated — the extension only runs capture scripts when you start a capture.

Encryption

All traffic to and from BugMojo is encrypted in transit with HTTPS/TLS. Capture artifacts — recordings, logs, and screenshots — are stored as files in cloud object storage (AWS S3), encrypted at rest, and uploaded through short-lived presigned URLs rather than exposing any storage credentials to the browser.

Access control & isolation

Data is scoped to your workspace and its members. Access to the product uses authenticated sessions, and integrations and AI agents connect through scoped API keys that you can create and revoke at any time. Console and network logs are stored as separate, compressed objects rather than inline in the primary database, limiting blast radius.

Infrastructure & subprocessors

BugMojo runs on established cloud infrastructure. We use a small set of vetted subprocessors to operate the service — cloud hosting and object storage (AWS), transactional email (Resend), and error monitoring (Sentry). See the full list of subprocessors and our Privacy Policy for how data is shared and retained.

Data retention & deletion

You can delete individual captures, issues, or your entire account at any time; deletion removes the associated stored artifacts. Quick Capture links expire automatically — anonymous captures after 24 hours and free-tier captures after 30 days — so ephemeral data doesn’t linger.

The browser extension

The extension contacts only the BugMojo API — no other hosts — to authenticate and upload the bugs you capture. It requests the minimum permissions needed to capture the active tab on demand, shows a consent dialog on first use, and stores your session and preferences locally on your device.

Responsible disclosure

If you believe you’ve found a security vulnerability, we want to hear from you. Please email security@bugmojo.com with details and steps to reproduce. Give us a reasonable window to investigate and fix the issue before any public disclosure, and please don’t access or modify data that isn’t yours while testing. We appreciate good-faith research and will acknowledge your report.

For full terms — including our safe-harbor commitment, scope, and expected response times — see our Vulnerability Disclosure Policy.

Contact

Security questions or a due-diligence review? Email security@bugmojo.com.