← Back to Heario

Security

Last updated: June 2026

Our Approach

Heario is built with a local-first architecture — your audio and meeting content are processed on your device and sent only to the AI provider you configure. We minimise the data that ever reaches our servers.

Data in Transit

  • All communication between Heario and external services uses TLS 1.2 or higher
  • API keys you enter are stored locally in an encrypted config file on your device
  • We never transmit your API keys to our servers

Overlay Protection

Heario's answer overlay uses the Windows SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE) API — the same mechanism used by banks and DRM software. This excludes the window from all screen-capture pipelines at the OS level, before any application (Zoom, Teams, OBS) can access the frame buffer.

Payment Security

Payments are handled entirely by Stripe, a PCI DSS Level 1 certified payment processor. Heario never sees, stores, or logs your card details.

Open Source

The Heario application is open source. You can audit the code directly on GitHub. We believe transparency is the strongest security guarantee we can offer.

Responsible Disclosure

If you discover a security vulnerability in Heario, please report it privately before public disclosure. Email jackoreilly10@hotmail.com with the subject line "Security Disclosure". We will acknowledge your report within 48 hours and work with you to resolve the issue promptly.

🛡 Found a vulnerability? Email jackoreilly10@hotmail.com — we take every report seriously.