relaybridge Help centre

Security

This page is written for the person at your company whose job is to say no. It describes how Relay Bridge is built, who can see what, and — at the bottom — what we don't have yet. We'd rather lose a deal than have you find out we shaded something.

Last reviewed 29 July 2026 · questions to support@webpros.net

Nothing listens on your network

The Bridge — our program on a machine at your site — makes outbound connections only. There are no ports to open, no inbound firewall rules, and nothing of ours accepting connections on your LAN.

It reads your cameras locally, keeps recordings on your own disk, and sends us only what's asked for: live video while somebody is actually watching, motion snapshots, and a copy of the recording if you switch the cloud archive on.

If our service is unavailable, your site keeps recording and LAN-connected relays keep switching. That's deliberate: the cloud is where you watch and manage, not a dependency for the equipment to work.

Who can do what

LayerHow it works
Sign-inGoogle, or email and password, through Firebase Authentication. We never hold your password.
RolesOwner, admin, operator, viewer — enforced on every request, not just hidden in the interface. A viewer cannot change anything anywhere.
Two-factorOptional per person, and an owner can require it of all admins. It protects the dangerous actions — deleting footage, revealing a camera password, opening remote access, changing who's on the account — rather than nagging you at every sign-in.
Shared panel linksA link with no sign-in behind it, for a gate button on a phone. Set a PIN; repeated wrong entries lock it for a growing period. Delete the panel to revoke it instantly.
API and widget keysScoped to one device and one action. Secret keys are shown once and stored only as a hash.

Your footage and passwords

Being straight about one thing: this is not zero-knowledge. We have to hand a camera password to your Bridge so it can open the stream, so we can decrypt it. Anyone claiming otherwise about a system that logs into your cameras for you is mistaken.

Who at Web Pros can see your account

A named list of people, each added deliberately — nobody gets access by working here. Changing that list requires the changer's own two-factor code.

Every operator action is recorded, including simply looking at your account, and including someone being refused. The record is written both to our own database and to a logging system our operators cannot edit or delete. That second copy is the one that matters for an audit, and it's why we can answer "who looked at our footage" with a list.

Ask, and we'll give you the current list, or a report of access to your account over any period.

Reaching a device remotely

You can open a 15-minute session to a device's own web page — a camera's settings, say — through the Bridge's outbound tunnel. No VPN, no port forwarding, no software on your side.

How long things are kept

DataDefaultWho decides
Recording on your own Bridge disk14 days or a disk capYou, per camera
Cloud archive30 daysYou, per camera
Motion events and their snapshots30 daysYou, per camera (1–3650)
Clips and snapshots you savedUntil you delete themYou
Live videoNot stored at all
Event log, invoices, billing detailKeptUs — it's the audit and accounting record
What "deleted" meansDeleting a camera removes its footage, clips, snapshots and motion history from our storage. Deleted objects then persist in our backups for up to 14 days before being purged for good — a window that exists so an accidental deletion is recoverable. Nothing deleted stays visible or playable in the app. Your billing history is kept on purpose: it's the detail behind invoices you've already had.

Recovery

Database point-in-time recovery over a 7-day window, daily backups kept a week and weekly backups kept 14 weeks, delete protection on, and versioning on stored media. Installers are published with SHA-256 checksums generated by the build itself.

Companies involved

WhoWhat forWhat reaches them
Google CloudHosting, database, storage, video ingest, sign-inEverything
CloudflareDNS, TLS, custom domains, remote-access sessionsTraffic in transit
AnthropicDescribing what a motion snapshot shows; plain-language searchA single frame per event, and camera names. No continuous video. Only if you switch AI on.
Shelly (Allterco)Switching Shelly relaysDevice id and the on/off command. No video. Only if you use Shelly.
OpenStreetMapTurning a site address into map coordinates; map tilesThe address text you type
Amazon SESAccount emails — access requests to us, and "your account is ready" to youYour email address and the text of the message. No footage or device data.
StripeHolding a card and taking the monthly paymentYour billing contact and card details, which are entered directly with Stripe and never reach us. We hold only a customer reference and the last four digits.
Amazon RekognitionRecognising people you have enrolled — only if we have switched face recognition on for your account after talking it through with youA faceprint for each person you enrol, in a collection used for your account alone, plus the single frame being checked. Faces we do not recognise are compared and immediately discarded — nothing about them is stored. Off for every account by default.

No analytics or advertising trackers. No session recording. Your data is never used to train AI models.

What we don't have

Read this part

Reporting a problem

Email support@webpros.net with enough detail to reproduce it. We'll acknowledge within two business days. There's no bug bounty, but we do fix things, and we'll credit you if you'd like. Please don't test against other customers' accounts, and please don't fire other people's relays — those are real horns and lights on real sites.

Relay Bridge is a product of Web Pros. Our incident response, breach notification, retention and key-rotation procedures are written down; ask and we'll send them. Help centre · Sign in