Security

Hindset is in private development. Here’s the current security posture, stated plainly.

Last updated September 22, 2026
In short
  • Local-only: no servers hold your recordings.
  • No accounts, so no passwords to leak.
  • Report issues directly to the founder.

Current posture

Hindset runs entirely on your machine. There are no Hindset accounts, cloud storage, or remote processing, so there’s no server-side copy of your sessions to protect or lose.

Data integrity

Workspace writes are protected against stale overwrites, previous saves can be recovered, and backups are checksummed. Restores go into a separate workspace instead of replacing your live one.

Permissions

Screen capture and key timing only run during a recording you start. On Linux, key timing needs input-group membership, which you grant yourself and can revoke.

Reporting a vulnerability

Email mason@maselabs.com with “Security” in the subject. Please include steps to reproduce and don’t include other people’s data. A formal disclosure policy will be published before public availability.

Before public release

Signed installers, a documented update path, a full threat model and a disclosure process will be published before Hindset is publicly available.