OBS credentials
The default endpoint is loopback. The WebSocket password must remain local and may be remembered only through Windows-protected storage after explicit choice.
This page distinguishes current web behavior from planned desktop controls. Claims about the packaged app remain release-gated until its data flow and build are independently verified.
The default endpoint is loopback. The WebSocket password must remain local and may be remembered only through Windows-protected storage after explicit choice.
The free design keeps the raw file in the OBS recording directory, does not copy or upload it, and offers deletion after analysis.
Any evidence leaving the device requires separate consent, visible purpose, retention and deletion controls. That upload path does not exist yet.
The desktop release also requires a narrow command boundary, secrets outside the webview, dependency pinning, a reviewed FFmpeg distribution, credential-redaction tests and a security contact workflow.
Security questions or responsible disclosure: hello@streamertoolkits.com. We will acknowledge material reports and communicate affected-user actions if a confirmed incident requires them.