Interval by plan
Capture frequency follows the plan:
| Plan | Capture interval |
|---|---|
| Basic | One capture every 15 minutes |
| Pro | One capture per minute |
| Enterprise | Real-time capture |
Where captures live
Each device has its own history, browsable by date and time. Images are encrypted at rest and retention follows whatever policy your company sets — from the legal minimum to whatever compliance requires.
Whoever opens the history is written to the audit trail: user, device consulted and time of access.
Computer vision analysis
On Enterprise, every capture runs through a computer vision model that looks for risk patterns before any person opens the image.
What the model looks for
- Sensitive data exposed outside the system it belongs to.
- Unauthorised transfer or storage tooling in use.
- A pattern consistent with database extraction.
- Production access outside the agreed window.
What happens on an alert
The security team gets the notification with the capture, the device, the timestamp and the reason it was flagged. From there, the response — from cutting a port to a precautionary lock — comes out of the same dashboard.
Good practice
Before turning it on
Screen monitoring is the most sensitive feature on the platform. Communicate the policy to the team, record the legal basis for processing and restrict access to the history to the people who genuinely need it — that is what RBAC is for.
Frequently asked questions
- Do captures cover the whole screen?
- Yes, the device's active screen at capture time. On multi-monitor machines, each screen is captured.
- Can I disable capture on some devices?
- You can. Capture is applied by policy, so a group of devices can be left out without affecting the rest of the fleet.
Up next
Productivity
The dashboard metrics, what each one measures and how to read them without guesswork.
Keep reading