Skip to content

Security

The consultant's private history stays encrypted on their computer. This page lists every route by which content can leave it, what each route sends, and who decides.

How Overshow handles data

Encrypted on the consultant's computer

Data at rest uses SQLCipher encryption with a key derived from the platform keychain. There is no automatic cloud replica of the local capture index; only content a consultant explicitly publishes, with its source excerpts, enters the organisation repository.

Processed locally

Screen reading and full-text search run locally on Windows and macOS. Ask uses an on-device language model on the Mac. Built-in processing sends no screen images or queries to an AI provider.

Content leaves by named routes

Routine traffic covers account, billing, device registration and aggregate licence state. Publishing sends only approved content the consultant chooses to share, with its source excerpts, to the organisation repository. Microsoft 365 Copilot and connected AI apps are separate routes, each listed below with what it sends.

Every route out of the computer

Sharing with the engagement

What leaves
Content the consultant publishes, with its saved source excerpts and audit metadata. Never the full private history.
Where it goes
The organisation repository, for colleagues with access to the engagement. It passes through Overshow's web service on Vercel and is stored in Neon, UK (London).
Who decides
The consultant approves it, then publishes it with a separate action. Nothing is shared automatically.

Microsoft 365 Copilot on shared content

What leaves
Shared content and its source excerpts, for the engagements the person asking can access.
Where it goes
Your consultancy's Microsoft 365, where questions, returned excerpts, answers and citations are kept under its policies.
Who decides
Your consultancy enables the connection and grants access per engagement. Copilot needs the relevant Microsoft licence and administrator consent.

A consultant's own Copilot connection

What leaves
Copilot's questions and the bounded excerpts returned from the consultant's permitted history.
Where it goes
Microsoft 365, through Overshow's gateway on Cloudflare, which can read them in transit and does not store them. Your consultancy's Microsoft 365 keeps the questions, excerpts and answers under its policies.
Who decides
Your consultancy decides whether this connection is permitted. Within that, it stays off until the consultant turns it on under Settings, Connections, and it answers only while their computer is online.

AI apps (Mac only)

What leaves
Questions and returned source excerpts, sent to the provider of each cloud AI app the consultant connects. Local AI keeps the exchange on the computer.
Where it goes
The AI app's provider, under its own terms.
Who decides
Your consultancy decides which AI connections are permitted. Within that, the consultant connects each app under Settings, AI clients.

Other local clients

What leaves
The parts of the private history the consultant grants a local client, with secrets removed. It can read as far back as the plan's history allows, unless the consultant sets a shorter window.
Where it goes
That client on the computer, which may send what it reads on to its own provider.
Who decides
Your consultancy decides which AI connections are permitted. Within that, the consultant allows each client under Settings, Connections. Every read is logged, and access can be revoked at any time.

Exports and mirrors

What leaves
Files the consultant chooses to export or mirror.
Where it goes
A folder they choose, which may be cloud-synced.
Who decides
Only when the consultant exports or sets up a mirror.

Diagnostics

What leaves
A diagnostic the consultant reviews and attaches to feedback. It can include captured screen or transcript text.
Where it goes
Overshow, to investigate the report. The diagnostic passes through Overshow's web service on Vercel and is stored in Neon, UK (London).
Who decides
Only when the consultant reviews, attaches and submits it.

Web page titles

What leaves
A captured web address, sent to its own site to fetch the page title and link details.
Where it goes
The site the address belongs to.
Who decides
Off by default, and allowed site by site.

Sign-in, billing and updates

What leaves
Account, device and licence details. No captured work.
Where it goes
Overshow's servers, the payment provider and, with single sign-on, your identity provider (Google Workspace or Microsoft Entra ID).
Who decides
Needed to use the app.

Teams transcripts travel the other way. Selected Teams transcripts go into the consultant's private history. A transcript is never shared automatically. We agree the eligible Teams meetings with your consultancy during set-up, with your administrator's consent.

The specifics, for your reviewer.

The local database is encrypted using key material derived from a secret stored in the platform keychain. Screen images are discarded after text extraction. The Technology page describes optional audio recovery and the separate data transfer paths.

Technical summary
DatabaseSQLCipher, AES-256-CBC
Key derivationHKDF-SHA256, keychain secret
Search indexFTS5 full-text, on the computer
Screen framesRead, then discarded
Built-in AI processingOn device; no AI provider involved
Connected cloud AI appsOpt-in on the Mac; that app's provider receives its queries and returned snippets
Microsoft 365 CopilotOptional; conversations stay in your Microsoft 365
Teams transcriptsSelected meetings, into the private history
Shared content residencyUK (London)
Account records residencyUK (London)
Data processing agreementAvailable on request

Certified, verified, and registered.

TAC Security ESOF AppSec certification badge

Security

Cyber Essentials certifiedTAC Security ESOF AppSec certifiedCASA assessed

Platform verification

Google OAuth verifiedApple notarised for macOSMicrosoft Entra verified publisher

Privacy

UK GDPR compliantICO registeredAccount records stored in the UKDPA available

Account and device

Standard sign-in

Magic link by email, or Google and Microsoft Entra ID SSO. No passwords to manage or leak.

One active device

If another device is active, signing in shows a transfer choice. Access moves only after you confirm. Captured data stays on the original computer.

Clean uninstall

On a Mac, uninstall from Overshow's Settings or with the signed uninstaller and choose to erase your local data. On Windows, remove Overshow from Settings > Apps and delete its local application data folder. Either way the local capture index is gone. Content you published follows the organisation repository's separate retention and deletion controls.

Review it with us

Bring your security team. We will walk through the data flow, encryption and sub-processors.