Security review pack
Everything your security reviewer needs
Answers to the questions vendor and IT security reviews ask about the Screshot Chrome extension, on one page you can save as PDF. Last reviewed October 7, 2026.
1. Summary
| Product | Screshot, a Chrome extension for capturing, blurring and annotating screenshots |
| Distribution | Chrome Web Store, extension ID ikhdemckhflgmlijkaomcpdmljegkakh |
| Users | 20,000+ on the Chrome Web Store |
| Price | Free for individuals and organizations |
| Customer data processed by Screshot | None. Screenshots are created, edited and saved on the user's device |
| Network requests during capture and editing | None |
| User accounts | None in the extension |
| Certifications | None today (no SOC 2 or ISO 27001) |
| Security contact | contact@screshot.com |
2. Data flow
- The user starts a capture with the toolbar icon, a keyboard shortcut or the right-click menu. Chrome then grants temporary access to that one tab (activeTab).
- Chrome renders the visible area. For a full page, the extension scrolls the tab, stitches the parts in memory and restores the page.
- The image opens in a page packaged inside the extension (chrome-extension://). It loads no remote code, fonts or analytics.
- The user blurs, crops and annotates. Blur is written into the pixels.
- The user copies the image to the clipboard or downloads a PNG. Closing the tab discards it.
To verify: open chrome://extensions, enable Developer mode, inspect Screshot's service worker and watch the Network tab while capturing. No requests leave the browser.
3. Permissions
| Permission | Used for | Cannot |
|---|---|---|
activeTab | Capture the tab in front of you, only at the moment you click the icon or use a shortcut. | Read other tabs, run in the background, or see your browsing history. |
scripting | Scroll the tab you are capturing during a full-page capture, then put it back exactly as it was. | Run on any page you did not ask Screshot to capture. |
contextMenus | Add "Capture visible area" and "Capture full page" to the right-click menu on the Screshot icon. | Change menus on web pages or read what you click. |
No host permissions and no access to history, cookies, downloads or storage.
4. Data inventory
| System | Personal data | Where it is kept |
|---|---|---|
| Extension | None collected, stored or transmitted | Not applicable |
| Website analytics | Pages viewed, approximate location, browser and device (cookies) | Google Analytics, on the website only |
| Cloud sharing waitlist | Email, optional company and team size, if a person signs up | Sanity, in records that are not publicly readable |
| Messages to us | Whatever a person includes in an email | Our email provider |
5. Subprocessors
The extension uses no subprocessors. The website uses these services:
| Service | Purpose | Scope |
|---|---|---|
| Vercel | Hosts the www.screshot.com website | Website only |
| Google Analytics | Aggregate visit statistics | Website only |
| Sanity | Blog content and the cloud sharing waitlist | Website only |
6. Questionnaire answers
- Does the product store, process or transmit customer data?
- No. The extension has no server component. Screenshots never leave the user's device unless the user copies or downloads them.
- Which network connections does the extension make?
- None during capture, editing, copy or download. It opens screshot.com pages in normal tabs only for the welcome guide after a manual install and the optional uninstall survey.
- Does it include analytics, telemetry or third-party scripts?
- No. Nothing is loaded from remote servers, and there is no analytics or crash reporting in the extension.
- Which browser permissions does it request?
- activeTab, scripting, contextMenus. None triggers an install warning, and there are no host permissions. See the table above.
- Can it read other tabs, browsing history or cookies?
- No. activeTab gives access only to the tab the user chooses to capture, only at that moment.
- Is data encrypted in transit and at rest?
- There is no data in transit or at rest on our side for the extension. The website is served over HTTPS only.
- Does it support SSO, SCIM or role-based access?
- Not needed: there are no accounts. Access is controlled by deploying or blocking the extension through Chrome policy.
- How is it deployed and removed?
- Force-install with the Google Admin console, Microsoft Intune, Group Policy or a macOS profile, and remove it from the same policy. See the deployment guide.
- How are updates delivered and reviewed?
- Through the Chrome Web Store, which reviews each version. If a new version requests a permission that shows a warning, Chrome disables it until the user or admin approves.
- Can admins control which version runs?
- Chrome policy can allow, block or force-install the extension by ID. Pinning a specific version is not supported by the Chrome Web Store.
- Has the product had an independent penetration test?
- Not yet. We will share results with customers under NDA once one is complete.
- How do you handle vulnerabilities?
- Report them to contact@screshot.com. We acknowledge reports and ask for reasonable time to fix before public disclosure.
- How will you notify us of security incidents or material changes?
- We publish changes to permissions or data handling on the security page and privacy policy before releasing the version that makes them.
7. Upcoming changes
We are building optional cloud upload and share links. When they launch, a screenshot will be uploaded only when a user clicks Share on it, and each link will start visible only to its owner. Before release we will update this pack with the new data flow, stored data and subprocessors, and we plan to add a Chrome policy so admins can keep sharing turned off. The commitments are listed in the security overview.
Need something that isn't here?
Send us your questionnaire and we will fill it in, or ask for a call with the team.
Get deployment help