Security

Reporting, scope, and what you can verify yourself

Reporting a vulnerability

Email support@framekeep.app. Include what you did, what happened, and the version — the app reports it under Settings → About, and the adapter under npx.cmd framekeep-mcp --version.

Report privately first, and give us a chance to fix it before it is public.

Research done in good faith against your own machine and your own recordings is welcome, and we will not pursue you for it. Do not test against anyone else's data.

What is in scope

  • The Framekeep desktop app for Windows.
  • The adapter published on npm as framekeep-mcp.
  • This website.

Out of scope: the AI clients Framekeep talks to, and whatever they do with frames after you approve them — that is governed by whoever makes the client. Also out of scope: reports that a scan failed to find something. That is a known limit, described below, and not a vulnerability.

What you can check yourself

These are properties, not promises — each one is something you can watch for rather than take our word on.

  • No account, and no server of ours. There is nothing to sign in to, and no endpoint on our side for anything to be sent to.
  • One kind of outbound request. Downloading a speech-to-text model, and only when you ask for one. No telemetry, no crash reports, no identifiers.
  • The clipboard is read when you paste, and never otherwise. There is no background clipboard watcher, and the codebase carries a test that fails if one is ever added.
  • Frames stay locked until you approve them. Asking again does not unlock a recording; the adapter refuses, and tells your AI to come back to you.

The limit worth stating plainly

The scan is a helper, not a guarantee. It reads text off pixels, and small or unusual text is genuinely hard to read. Framekeep does not claim to catch every secret in every frame, and any product that claims that about a screen recording is guessing.

What it does guarantee is the gate: nothing is served to your AI until a person has looked at it. That is the part with tests behind it, and it is why the review screen has no skip button.

Disclosure

When a security fix ships, it is named in the changelog with the version that carries it.