AnchorMark
Trust

Built tenant-first, audited end-to-end.

Every domain table is scoped by organization. Every privileged write lands in an immutable audit log. SSO, SCIM, and DPA are first-class.

See pricing
Problem

Why this hurts today

Your security team is right to ask hard questions about a tool that captures screenshots and console logs from production. Vague answers, missing audit trails, and bolt-on tenant separation are exactly what kill procurement deals at the last meeting.

Solution

What AnchorMark does

AnchorMark is built tenant-first with row-level enforcement, KMS-managed secrets, and a documented incident response process. SSO/SCIM, audit logs, sub-processor disclosure, and a DPA are available without escalating to sales. Cross-tenant smoke tests run in CI so isolation cannot regress silently.

Capabilities

What you get when you turn this on.

Tenant isolation

organization_id enforced at route, query, and row level with CI smoke tests.

Encryption

TLS 1.2+ in transit; AES-256 at rest; KMS-managed keys.

Audit log

Immutable record of privileged writes with API export.

Sub-processor list

Public sub-processor page with notification on changes.

Field-level redaction

Mark sensitive inputs and the SDK blurs them in screenshots and strips them from console payloads.

Incident response

A documented IR runbook with status-page transparency for any reportable event.

Frequently asked questions

Where can I see your DPA?
Our DPA summary lives on the DPA page; the full executable version is available on request from sales.
Is data residency configurable?
Per-region data residency is on the roadmap and tracked publicly. EU-region storage is currently available; per-region project residency is in active development.
How do you isolate tenants?
Every domain row carries an organization_id, enforced at the API route, the query layer, and the database row level. A cross-tenant smoke test runs in CI so the isolation cannot regress silently.
Do you have SOC 2?
AnchorMark is on a SOC 2 Type II path; current attestation status and the sub-processor list are kept up to date on the security page.
Can I export the audit log to my SIEM?
Yes — the audit log streams to S3 or any HTTPS endpoint via the webhooks API. Splunk, Datadog, and Panther are commonly used downstream.
How is sensitive data kept out of screenshots?
Mark inputs with data-anchormark="redact" and the SDK blurs them in capture and strips them from console payloads. Workspace-wide redaction rules let you apply policies without per-page configuration.

Ship faster with feedback that already has the receipts.

Start a 14-day trial of the Team plan — no credit card required.

Compare plans