How we protect your footage.
Security at Vextica is structural, not a checkbox. Here's plainly what we do — and what we deliberately can't do.
End-to-end encryption
Live streams are encrypted between your camera and your viewing device. When P2P isn't possible and traffic passes through a relay, it stays encrypted in transit — the relay forwards opaque bytes it can't read.
Zero-knowledge cloud vault
If you turn on cloud recording, footage is encrypted on your device before upload, with a key derived on your device and never sent to us. The practical result: even under legal compulsion, we cannot produce decrypted footage, because we never hold the means to decrypt it.
What we store — and don't
- We store the minimum account metadata needed to sync your setup and bill paid plans.
- We do not store plaintext video, decryption keys, or motion snapshots on our servers.
- We run no advertising SDKs and embed no third-party trackers.
Account protection
- Passwords are hashed with a modern memory-hard algorithm; we never see them in the clear.
- Optional two-factor authentication via authenticator apps.
- Per-camera sharing with revocable, time-limited access links.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email security@vextica.app with details and reproduction steps. We acknowledge reports within 72 hours, won't pursue legal action for good-faith research, and credit reporters who wish to be named.
Encryption is on by default for every plan, including Free. There's no premium tier of privacy — it's the floor, not an upsell.
Privacy you don't have to pay for.
End-to-end encryption ships with every plan — including the free one.
No card. No account. Just the app.