R
EPM Monitor
Trust Center

Security & Privacy at EPM Monitor

Our commitment to your data: what we collect, where it lives, who can access it, and how we keep it safe. Updated continuously โ€” last reviewed .

12/13
GDPR controls
Self-service DSAR
5/5
SOC 2 CCs mapped
Type II planning
TLS 1.3
Encryption in transit
DTLS-SRTP for live view
AES-256
Encryption at rest
Supabase / R2

Architecture & data flow

๐Ÿ“ฆ Where data lives
  • โ€ข Postgres (Supabase, EU/US regions)
  • โ€ข Screenshots: customer's own Google Drive OR Cloudflare R2
  • โ€ข Firebase RTDB (signaling + config push only โ€” never media)
๐Ÿ›œ Live screen view
  • โ€ข WebRTC peer-to-peer โ€” media never touches our servers
  • โ€ข DTLS-SRTP encryption end-to-end
  • โ€ข Session-bound, audited, optional consent prompt
๐Ÿ”‘ Authentication
  • โ€ข bcrypt(12) for passwords
  • โ€ข Optional TOTP 2FA for admins
  • โ€ข Session tokens with 12 h TTL, server-side hashed
  • โ€ข Google / Microsoft SSO supported

Sub-processors

We rely on the following processors. Each has a Data Processing Agreement signed.

VendorPurposeRegionCertifications
SupabasePostgres, Auth, Edge FunctionsUS / EU / Asia (selectable)SOC 2 Type II
Google WorkspaceCustomer's own Drive (screenshot storage)Customer-controlledSOC 2 / ISO 27001
CloudflareR2 (binary distribution), WorkersGlobal edgeSOC 2 Type II / ISO 27001
Firebase RTDBPush-config signaling (no media)Asia-SoutheastSOC 2 / ISO 27001

What we collect โ€” and what we don't

โœ“ We collect
  • โ€ข Active application name + window title
  • โ€ข URLs visited (in non-private windows)
  • โ€ข Active vs idle time (mouse/keyboard activity timing only)
  • โ€ข Periodic screenshots (configurable interval)
  • โ€ข USB device connect/disconnect events
  • โ€ข Clipboard contents only when matching a configured DLP pattern
โœ— We never collect
  • โ€ข Keystrokes
  • โ€ข Microphone audio
  • โ€ข Webcam video
  • โ€ข Personal device content
  • โ€ข Files from personal cloud accounts
  • โ€ข Banking credentials or stored passwords

Customer & employee rights

๐Ÿ“ค
Right to access
Self-service JSON export of all data on any employee via the Compliance dashboard.
๐Ÿ—‘
Right to erasure
One-click cascade-delete: activity, screenshots, DLP events, user โ€” atomic.
๐Ÿšซ
Right to object
Employees can object directly to the customer's DPO listed on the auto-rendered privacy notice.

Incident response

If you suspect a security incident:

๐Ÿ“ง security@reevtech.in
๐Ÿ“ž Acknowledge within 4 business hours
๐Ÿ“‹ Full notification within 72 hours as required by GDPR Art. 33

Documentation on request

Enterprise customers may request the following under NDA by emailing support@reevtech.in: