Security
Hindset is in private development. Here’s the current security posture, stated plainly.
Last updated September 22, 2026- Local-only: no servers hold your recordings.
- No accounts, so no passwords to leak.
- Report issues directly to the founder.
Current posture
Hindset runs entirely on your machine. There are no Hindset accounts, cloud storage, or remote processing, so there’s no server-side copy of your sessions to protect or lose.
Data integrity
Workspace writes are protected against stale overwrites, previous saves can be recovered, and backups are checksummed. Restores go into a separate workspace instead of replacing your live one.
Permissions
Screen capture and key timing only run during a recording you start. On Linux, key timing needs input-group membership, which you grant yourself and can revoke.
Reporting a vulnerability
Email mason@maselabs.com with “Security” in the subject. Please include steps to reproduce and don’t include other people’s data. A formal disclosure policy will be published before public availability.
Before public release
Signed installers, a documented update path, a full threat model and a disclosure process will be published before Hindset is publicly available.
