Desktive
Trust
Security overview
Practices we can verify in the product today — not a certification claim. See the Privacy Policy for data handling.
Desktive handles workplace activity data, so security matters. This page summarizes controls that exist in the current cloud app and agent architecture. We do not display ISO, SOC, GDPR “certified,” or similar badges unless they are factually true.
Encryption in transit
Production traffic to the Desktive cloud is served over HTTPS/TLS so data is encrypted in transit between clients (browser, agent) and our servers.
Authentication
- User accounts authenticate with email and password
- Passwords are stored hashed (not as plaintext)
- Signed-in sessions are managed by the application session system
- Desktop login flows use the cloud account rather than a separate shadow password store
Additional enterprise authentication options such as organization-wide SSO or mandatory 2FA can be configured for enterprise deployments.
Organization isolation
Customer data is scoped to organizations. Authorization checks gate access to members, activity, reports, settings, and screenshots so users should only see data for organizations and roles they belong to. Cross-organization access is treated as a defect if it occurs.
Screenshots and sensitive media
- Screenshot capture is controlled by organization settings
- Image access goes through authorized application routes — not public open directories
- Delivery can use short-lived signed URLs or streamed responses depending on configuration
Application safeguards
- CSRF protection on cookie-based web forms
- Server-side validation on API and form inputs
- Rate limiting on sensitive upload paths (for example screenshots)
- Role and permission checks in the cloud product for admin actions
Infrastructure and access
The Service runs on modern cloud hosting with restricted operator access for maintenance and support. We keep operational logs to investigate incidents and reliability issues.
What we do not claim (yet)
- ISO 27001, SOC 2, or similar audit certifications
- A formal public bug-bounty program
- Customer-managed encryption keys or on-prem deployment
If those become true later, we will update this page with specifics — not vague badges.
Your responsibilities
- Use strong unique passwords and protect admin accounts
- Configure tracking and screenshot policies appropriately for your workforce
- Keep the Windows agent and browsers reasonably up to date
- Notify us promptly of suspected unauthorized access
Report a security issue
If you believe you found a vulnerability in Desktive, please contact us with “Security” in the subject and enough detail to reproduce the issue. Please avoid accessing other customers’ data while testing.