Security you can check, not just trust.

We’d rather show you how LayerT works than ask you to take our word for it. Here’s what’s true today, what isn’t yet, and where to read the detail.

A small cream paper vault door standing slightly open in a thick cream frame, with a round teal paper dial on its face.

Security

What’s true today, and what isn’t yet.

How it’s built
  • Signed policy, checked before it’s usedRules ship signed with Ed25519, and the browser’s own crypto checks them. Stale or tampered policy blocks rather than lets things through.
  • Every secret sealed with its own keyAES-256-GCM envelope encryption. Recordings are encrypted on the device, with a key made for that session.
  • Authenticator secrets stay on the serverCodes are made server-side. Revealing a password takes a second person, and it’s logged.
  • Separation of dutiesIT configures. Compliance grants lasting exceptions. Nobody approves their own request.
Limits, stated plainly
  • Chrome todayEdge, Firefox and Opera are coming. No Safari, mobile or desktop apps.
  • Sign-in control, not content scanningLayerT doesn’t inspect file uploads, documents or the clipboard.
  • Recording is off by defaultYour company confirms a lawful basis first, people are told on the page, and what they type is masked. A watermark deters and attributes; it can’t stop a phone camera.
  • Pre-launch, with no certifications yetLayerT produces the evidence your auditors ask for. Keys held in a cloud key service are on the roadmap.

How to tell a real LayerT prompt

LayerT never asks for your password. And when it’s on the page, its icon in your toolbar lights up. A website can copy a prompt, but it can’t draw in your toolbar.

The dot is on while LayerT is on the page

Found a vulnerability?

Please tell us privately, and give us a reasonable time to fix it before you publish. We won’t take legal action against good-faith research that respects people’s privacy and doesn’t disrupt our service.

Report to: security@layert.net. Our security.txt has the same details in machine-readable form.

Include what you found, how to reproduce it and what an attacker could do with it. We’ll confirm we’ve received it and keep you updated until it’s fixed.