30th July 2026

Security

LaunchBrightly is committed to maintaining the confidentiality, integrity, and availability of customer data. Our security program is built around industry best practices and modern cloud security principles — emphasizing least privilege access, encryption, system isolation, and data minimization.

For security inquiries or vendor assessments, contact us at infosec@launchbrightly.com.

Our Approach

The safest data is data we never need to touch. LaunchBrightly is deliberately designed with a minimal footprint: we operate externally, store as little as possible, and run entirely on AWS managed infrastructure. We apply the principle of least privilege across all systems and internal processes, ensuring access is granted strictly on a need-to-know basis.

Infrastructure & Hosting

LaunchBrightly is hosted on Amazon Web Services (AWS) in US regions, built on a fully serverless architecture primarily leveraging AWS Lambda and other managed AWS services.

A serverless architecture reduces our attack surface significantly — there are no persistent servers to patch or configure, and AWS Lambda functions are ephemeral by design, existing only for the duration of a request before being automatically terminated. Maintenance and patching of the underlying managed infrastructure, as well as infrastructure scaling, are handled by AWS. Functions are isolated and event-driven, limiting lateral movement in the event of an incident. All deployments are fully automated, reducing the risk of human error in production environments.

Access to infrastructure is restricted to authorized personnel and governed by strict AWS Identity and Access Management (IAM) policies. All administrative access is logged and auditable.

LaunchBrightly's infrastructure runs entirely on AWS, which maintains an extensive portfolio of third-party security and compliance certifications and attestations, including SOC 2 and ISO 27001. Additional information is available through AWS Compliance.

Data Encryption & Key Management

LaunchBrightly encrypts customer data both in transit and at rest.

  • In transit: TLS 1.2 or higher for all communications between clients and the platform
  • At rest: AES-256 encryption for all data stored within our infrastructure
  • Key management: AWS Key Management Service (KMS), backed by FIPS 140-2 validated hardware security modules (HSMs)

Encryption keys are tightly controlled and accessible only to authorized services via IAM policies.

Authentication & Access Control

User authentication is managed through AWS Cognito. LaunchBrightly does not store passwords or sign-in credentials — these are transmitted directly from the user's browser to AWS and never handled by our application layer.

Application-level permissions are governed by role-based access control (RBAC). Access to internal systems and production resources is limited to authorized personnel with a documented business need. All privileged access is logged and auditable.

Data Storage

Application data is stored in AWS DynamoDB within US regions. Access is controlled through fine-grained IAM policies — only authorized services and roles may read or write data. All data access occurs through authenticated and authorized service calls, and all data transmissions are encrypted.

How LaunchBrightly Works With Your Application

LaunchBrightly captures screenshots by operating externally — the way a regular authorized user would. Our platform logs into the demo, sandbox, or other customer-controlled account you provide, navigates your application, and captures screenshots. It does not require access to your internal systems, backend infrastructure, or production end-user databases.

This is a deliberate architectural choice: LaunchBrightly requires no privileged or direct internal system access. It operates through the ordinary application interface and within the boundaries of the authentication, permissions, and security controls you already apply to the account.

Demo account credentials provided for screenshot capture are encrypted immediately on receipt using AWS KMS. Credentials are never returned to the frontend after initial setup and are accessible only to authorized backend services.

Credential & Token Security

Third-party integrations are authenticated using OAuth or API tokens, depending on the integration. In both cases, credentials are encrypted immediately on receipt using AWS KMS with HSM-backed key management. Credentials are never returned to the frontend after initial setup — they are accessible only to backend services.

Customers retain full control over integration permissions and may revoke access at any time, either within LaunchBrightly or directly with the third-party provider.

Employee Access & Internal Controls

Access to customer data by LaunchBrightly personnel is restricted to authorized individuals with a legitimate business need, such as resolving a support request. Where feasible, we obtain written customer permission prior to accessing account-specific data for troubleshooting purposes. All such access is logged and auditable.

Emergency access without prior permission would occur only in rare cases of a critical system-level incident causing service disruption. All emergency access is logged and reviewed.

Your Data & Screenshots

You own your screenshots and all content generated through the platform. LaunchBrightly does not claim ownership over customer content.

You can export all screenshots from the platform at any time. You may request deletion of your account data at any time by contacting infosec@launchbrightly.com — deletion requests are processed promptly. Upon account termination, Customer Personal Data is deleted from active production systems within 30 days, subject to limited exceptions described in our Data Processing Agreement.

Privacy & Data Minimization

LaunchBrightly does not rely on the Personal Data of your customers or end users to provide our services. The Personal Data we ordinarily process is limited to basic business contact and account information, such as names and business email addresses, together with authentication or connection information required to access environments or integrations you authorize.

LaunchBrightly does not require access to production end-user databases, customer support conversations, support tickets, payment information, or similar customer records to perform screenshot automation. If Personal Data is present within an environment, screenshot, documentation system, or other content you authorize LaunchBrightly to access, that information may be processed incidentally to the extent necessary to provide the services.

We recommend using demo, sandbox, staging, test, or other appropriate non-production environments containing fabricated or non-sensitive information wherever practicable.

For international transfers of Personal Data subject to applicable transfer restrictions, LaunchBrightly uses appropriate lawful transfer mechanisms. These include the European Commission's Standard Contractual Clauses for applicable EEA transfers, applicable UK transfer safeguards, and the Standard Contractual Clauses as adapted for Swiss data protection law where required. Full details are available in our Privacy Policy and Data Processing Agreement.

Subprocessors

LaunchBrightly uses a limited number of subprocessors to provide and secure the platform. A current list of authorized subprocessors for Customer Personal Data is available in our Data Processing Agreement and upon request at infosec@launchbrightly.com.

Key subprocessors include:

Amazon Web Services (AWS)
Purpose: Cloud infrastructure, hosting, compute, application data storage, encryption and key management, authentication, and related infrastructure services
Location: United States

LaunchBrightly requires subprocessors that process Customer Personal Data on our behalf to be subject to appropriate data protection obligations. Customers may request an up-to-date subprocessor list at any time by contacting infosec@launchbrightly.com.

Payments

Payment processing is handled through Stripe. Payment card and billing information required to process payments is provided directly to Stripe and is not stored by LaunchBrightly. Payment details are transmitted directly to Stripe and do not reside in LaunchBrightly systems.

Secure Development Practices

Changes to production systems are deployed through automated pipelines, reducing the risk of manual configuration errors. Access to modify infrastructure or application code is restricted to authorized personnel. We maintain dependency management processes and apply security updates through managed cloud services and automated deployment workflows.

Incident Response

LaunchBrightly maintains an internal incident response process for identifying, containing, and remediating security incidents. In the event of a confirmed Personal Data Incident affecting Customer Personal Data, LaunchBrightly will notify affected customers without undue delay and provide reasonable information and cooperation to support their response.

To report a suspected security incident, contact infosec@launchbrightly.com.

Contact

For security inquiries, vendor assessments, or to request supporting documentation — including our Data Processing Agreement (DPA) and security one-pager — contact us at infosec@launchbrightly.com.