Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions apps/web/app/(site)/Footer.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@ const complianceBadges: {
},
{
label: "HIPAA",
status: "in progress",
status: "compliant",
content: (
<text
x="22"
Expand Down Expand Up @@ -234,7 +234,7 @@ const ComplianceBadges = () => (
))}
</div>
<p className="mt-2 text-[11px] text-gray-9">
SOC 2 Type II & ISO 27001 compliant · HIPAA in progress
SOC 2 Type II, ISO 27001 & HIPAA compliant
</p>
</div>
);
Expand Down
2 changes: 1 addition & 1 deletion apps/web/app/(site)/pricing/page.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ import { buildMarketingMetadata } from "@/lib/og/url";
export const metadata: Metadata = buildMarketingMetadata({
title: "Pricing — Cap",
description:
"Simple, flexible pricing. Cap Pro includes unlimited cloud sharing, team features, and SOC 2 Type II & ISO 27001 compliance, with a Desktop License for unlimited local recording and editing.",
"Simple, flexible pricing. Cap Pro includes unlimited cloud sharing, team features, and SOC 2 Type II, ISO 27001 & HIPAA compliance, with a Desktop License for unlimited local recording and editing.",
path: "/pricing",
ogTitle: "Simple, transparent pricing",
ogTag: "Pricing",
Expand Down
2 changes: 1 addition & 1 deletion apps/web/components/UpgradeModal.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -141,7 +141,7 @@ const UpgradeModalImpl = ({
},
{
icon: <ShieldCheck className={iconStyling} />,
title: "SOC 2 Type II & ISO 27001",
title: "SOC 2, ISO 27001 & HIPAA",
description: "Independently audited security & compliance",
},
];
Expand Down
11 changes: 10 additions & 1 deletion apps/web/components/pages/FaqPage.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -45,12 +45,21 @@ const faqContent: FaqItem[] = [
{
title: "Is Cap SOC 2 compliant?",
answer:
"Yes. Cap is SOC 2 Type II and ISO 27001 compliant. You can request our reports and view our security practices in Cap's Trust Portal.",
"Yes. Cap is SOC 2 Type II, ISO 27001, and HIPAA compliant. You can request our reports and view our security practices in Cap's Trust Portal.",
link: {
text: "Visit the Trust Portal",
href: "https://trust.cap.so",
},
},
{
title: "Is Cap HIPAA compliant?",
answer:
"Yes. Cap is fully HIPAA compliant. We sign Business Associate Agreements (BAAs) with organizations handling protected health information, and every vendor in Cap's production infrastructure is covered by a BAA. For even more control, you can bring your own storage or self-host Cap entirely.",
link: {
text: "Learn about HIPAA-compliant recording",
href: "/hipaa-compliant-screen-recording",
},
},
{
title: "Is there a commercial license available?",
answer:
Expand Down
6 changes: 2 additions & 4 deletions apps/web/components/pages/HomePage/Header.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -222,15 +222,13 @@ const Header = ({ serverHomepageCopyVariant = "" }: HeaderProps) => {
<div className="flex flex-col text-center md:text-left w-full max-w-[650px]">
<div className="flex justify-center mb-4 md:justify-start">
<Link
href="/blog/soc2-type-ii-iso-27001"
href="/hipaa-compliant-screen-recording"
className="inline-flex gap-2 items-center px-3.5 py-1.5 rounded-full border transition-colors group bg-gray-2 border-gray-4 hover:bg-gray-3 hover:border-gray-5"
>
<span className="text-xs font-medium text-gray-12">
<span className="font-semibold text-blue-500">New</span>
<span className="mx-1.5 text-gray-7">·</span>
Cap is now SOC 2
<span className="hidden sm:inline"> Type II</span> &amp; ISO
27001 certified
Cap is now HIPAA compliant
</span>
<FontAwesomeIcon
icon={faArrowRight}
Expand Down
2 changes: 1 addition & 1 deletion apps/web/components/pages/_components/ComparePlans.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -114,7 +114,7 @@ const sections: FeatureSection[] = [
title: "Security, support & licensing",
rows: [
{
label: "SOC 2 Type II & ISO 27001 compliance",
label: "SOC 2 Type II, ISO 27001 & HIPAA compliance",
free: false,
desktop: false,
pro: true,
Expand Down
35 changes: 24 additions & 11 deletions apps/web/components/pages/seo/HipaaCompliantScreenRecordingPage.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -5,15 +5,20 @@ import type { SeoPageContent } from "../../seo/types";
export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
title: "HIPAA-Compliant Screen Recording for Healthcare Teams",
description:
"Cap enables HIPAA-compliant screen recording workflows for healthcare organizations. Self-host recordings on your own S3-compatible storage, keep PHI off third-party servers, and maintain full audit control. Open-source and auditable.",
"Cap is a HIPAA-compliant screen recorder for healthcare organizations. Sign a BAA and record with Cap Cloud, or self-host recordings on your own S3-compatible storage for complete control over PHI. Open-source and auditable.",

badge: "HIPAA Compliance",
badge: "HIPAA Compliant",

featuresTitle: "Built for HIPAA-Compliant Screen Recording Workflows",
featuresDescription:
"Cap gives healthcare teams the recording capabilities they need with the data controls HIPAA requires",

features: [
{
title: "HIPAA Compliant with Signed BAAs",
description:
"Cap is fully HIPAA compliant. We sign Business Associate Agreements with healthcare organizations, and every vendor in Cap's production infrastructure, from cloud storage to transcription, is covered by a BAA. Combined with SOC 2 Type II and ISO 27001, Cap Cloud is ready for PHI out of the box.",
},
{
title: "Self-Hosted Storage — PHI Never Leaves Your Infrastructure",
description:
Expand Down Expand Up @@ -47,7 +52,7 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
{
title: "AI Transcription Under Your Control",
description:
"Cap's AI captioning is optional. If your HIPAA policies restrict audio transcription through external APIs, simply leave auto-captions disabled. The recording and sharing workflow functions fully without any AI processing.",
"Cap's AI captioning runs through a BAA-covered transcription provider, so captions are available even in regulated workflows. Auto-captions also remain fully optional: if your policies restrict any external audio processing, leave them disabled and the recording and sharing workflow functions fully without AI processing.",
},
{
title: "Self-Hostable Platform",
Expand Down Expand Up @@ -84,8 +89,15 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {

comparisonTable: {
title: "Cap vs Other Tools for HIPAA Screen Recording",
headers: ["Feature", "Cap (Self-Hosted)", "Loom", "Zoom", "Camtasia"],
headers: ["Feature", "Cap", "Loom", "Zoom", "Camtasia"],
rows: [
[
"HIPAA compliant",
{ text: "Yes, signed BAA", status: "positive" },
{ text: "Enterprise only", status: "warning" },
{ text: "BAA available", status: "warning" },
{ text: "N/A", status: "neutral" },
],
[
"Self-hosted storage",
{ text: "Yes — any S3", status: "positive" },
Expand Down Expand Up @@ -145,9 +157,9 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
],
},

comparisonTitle: "How Cap Enables HIPAA-Compliant Recording",
comparisonTitle: "HIPAA-Compliant Recording Out of the Box",
comparisonDescription:
"Most screen recorders store recordings on third-party servers by default — Cap gives healthcare teams the controls to change that",
"Cap is HIPAA compliant with signed BAAs, and self-hosted storage gives healthcare teams even more control over where PHI lives",

comparison: [
{
Expand Down Expand Up @@ -212,7 +224,8 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
migrationGuide: {
title: "How to Set Up HIPAA-Compliant Screen Recording with Cap",
steps: [
"Create a HIPAA-eligible AWS S3 bucket in your AWS account — ensure your AWS account is covered by an AWS BAA",
"Fastest path: use Cap Cloud under a signed BAA. Contact the Cap team via cap.so/support to get your BAA executed, then record and share as normal",
"Prefer self-hosted storage? Create a HIPAA-eligible AWS S3 bucket in your AWS account — ensure your AWS account is covered by an AWS BAA",
"Configure Cap's storage settings to point to your AWS S3 bucket using your AWS access key and secret",
"Download Cap for Mac or Windows — installation takes under 2 minutes",
"Disable AI auto-captions in Cap settings if your HIPAA policy restricts external audio transcription",
Expand All @@ -228,12 +241,12 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
{
question: "Can Cap be used for HIPAA-compliant screen recording?",
answer:
"Cap supports HIPAA-compliant workflows when configured with self-hosted storage. By connecting Cap to your own AWS S3 bucket (covered under your AWS BAA) or another HIPAA-eligible S3-compatible storage provider, all recorded video files are stored on your infrastructure — not Cap's servers. Combined with optional AI caption disabling and password-protected links, Cap gives healthcare organizations the controls needed for compliant screen recording workflows.",
"Yes. Cap is HIPAA compliant. We sign Business Associate Agreements (BAAs) with healthcare organizations, and every vendor in Cap's production infrastructure is covered by a BAA. For teams that want additional control, Cap also supports self-hosted storage: connect your own AWS S3 bucket (covered under your AWS BAA) and all recorded video files are stored on your infrastructure rather than Cap's servers.",
},
{
question: "Does Cap store recordings on its own servers?",
answer:
"By default, Cap uploads recordings to Cap's cloud storage. However, Cap fully supports custom S3-compatible storage — connect your own AWS S3, Cloudflare R2, or private MinIO instance and all recordings go directly to your bucket. With self-hosted storage enabled, no recording data touches Cap's infrastructure.",
"By default, Cap uploads recordings to Cap's cloud storage, which is HIPAA compliant and covered by BAAs with every infrastructure vendor. Cap also fully supports custom S3-compatible storage — connect your own AWS S3, Cloudflare R2, or private MinIO instance and all recordings go directly to your bucket. With self-hosted storage enabled, no recording data touches Cap's infrastructure.",
},
{
question:
Expand All @@ -244,7 +257,7 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
{
question: "Can I disable AI transcription in Cap for HIPAA compliance?",
answer:
"Yes. Cap's AI auto-captions are optional and can be disabled entirely in settings. If your HIPAA policies restrict sending audio data to external transcription APIs, simply leave auto-captions off. Cap's core recording, uploading to your S3 bucket, and sharing workflow operates fully without AI processing.",
"Yes. Cap's AI auto-captions are optional and can be disabled entirely in settings. Cap Cloud transcription runs through a BAA-covered provider, so captions are available even in regulated workflows. If your HIPAA policies restrict any external audio processing, simply leave auto-captions off and Cap's core recording, uploading, and sharing workflow operates fully without AI processing.",
},
{
question: "Does Cap support AWS S3 for HIPAA-eligible storage?",
Expand All @@ -265,7 +278,7 @@ export const hipaaCompliantScreenRecordingContent: SeoPageContent = {
{
question: "What screen recording tools are HIPAA-compliant?",
answer:
"A screen recorder can support HIPAA-compliant workflows if it allows you to control where recordings are stored, restricts third-party access to data, and provides auditable behavior. Cap with self-hosted S3 storage meets these requirements. Tools that only offer cloud storage on the vendor's serverslike standard Loom — require additional BAA agreements and vendor review. Local-only recorders like Camtasia avoid cloud storage entirely but lack Cap's async sharing capabilities.",
"Cap is HIPAA compliant, with signed BAAs available and a fully auditable open-source codebase. Tools that only offer cloud storage on the vendor's servers, like standard Loom, restrict HIPAA support to enterprise plans and require additional vendor review. Local-only recorders like Camtasia avoid cloud storage entirely but lack Cap's async sharing capabilities. Cap also supports self-hosted S3 storage for teams that want recordings to stay entirely within their own infrastructure.",
},
],

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -255,7 +255,7 @@ export const selfHostedScreenRecordingContent: SeoPageContent = {
{
question: "Is self-hosted Cap suitable for HIPAA compliance?",
answer:
"Cap with self-hosted AWS S3 storage (covered under your AWS BAA) can support HIPAA-compliant recording workflows. With self-hosted storage, no recording content passes through Cap's servers, keeping PHI within your HIPAA-covered infrastructure. AI auto-captions can be disabled if your policies restrict external audio transcription. See our dedicated HIPAA-compliant screen recording guide for full details.",
"Yes. Cap is HIPAA compliant, and self-hosting adds an extra layer of control. With self-hosted AWS S3 storage (covered under your AWS BAA), no recording content passes through Cap's servers, keeping PHI within your HIPAA-covered infrastructure. AI auto-captions can be disabled if your policies restrict external audio transcription. See our dedicated HIPAA-compliant screen recording guide for full details.",
},
{
question:
Expand Down
2 changes: 1 addition & 1 deletion apps/web/content/blog/soc2-type-ii-iso-27001.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,7 @@ This was months of work across the whole team. Huge thanks to everyone who helpe

## What is next

We are not stopping here. HIPAA readiness is in progress for healthcare teams, and we already offer signed BAAs for enterprise customers alongside our [DPA](/dpa). If your organization has specific compliance requirements, [talk to us](/support).
We are not stopping here. Since publishing this post, Cap has become fully HIPAA compliant for healthcare teams, and we offer signed BAAs alongside our [DPA](/dpa). If your organization has specific compliance requirements, [talk to us](/support).

As always: if you want a screen recorder your security team will approve, that your engineers can audit, and that never locks your data in, Cap is built for you.

Expand Down
6 changes: 6 additions & 0 deletions apps/web/content/changelog/web/2026-08-13-hipaa-compliant.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,6 @@
---
title: HIPAA compliance
publishedAt: "2026-08-13"
---

Cap is now fully HIPAA compliant. We sign Business Associate Agreements (BAAs) with organizations handling PHI, and every vendor in Cap's production infrastructure is covered by a BAA. Learn more on the [HIPAA-compliant screen recording page](https://cap.so/hipaa-compliant-screen-recording), or view our security posture on the [trust portal](https://trust.cap.so).
4 changes: 2 additions & 2 deletions apps/web/data/homepage-copy.ts
Original file line number Diff line number Diff line change
Expand Up @@ -404,12 +404,12 @@ export const homepageCopy: HomePageCopy = {
{
question: "Is my data secure?",
answer:
"Security is core to Cap. Cap is SOC 2 Type II and ISO 27001 compliant, and as an open source project, our code is fully auditable and transparent — you can see exactly how your data is handled. End-to-end encryption for cloud storage, option to use your own infrastructure, and community-driven security reviews keep your content safe.",
"Security is core to Cap. Cap is SOC 2 Type II, ISO 27001, and HIPAA compliant, and as an open source project, our code is fully auditable and transparent — you can see exactly how your data is handled. End-to-end encryption for cloud storage, option to use your own infrastructure, and community-driven security reviews keep your content safe.",
},
{
question: "What about SOC 2, ISO 27001, GDPR, and HIPAA compliance?",
answer:
"Cap is SOC 2 Type II and ISO 27001 compliant. Cap Pro also lets you bring your own storage, including custom S3 buckets in any region or your own Google Drive, for GDPR compliance. For HIPAA and other regulations, our self-hosted option gives you complete control. We also offer signed BAAs for enterprise customers.",
"Cap is SOC 2 Type II, ISO 27001, and HIPAA compliant, with signed BAAs available for organizations handling PHI. Cap Pro also lets you bring your own storage, including custom S3 buckets in any region or your own Google Drive, for GDPR compliance. For teams that want complete control, our self-hosted option keeps everything on your own infrastructure.",
},
],
},
Expand Down
2 changes: 1 addition & 1 deletion apps/web/lib/seo-metadata.ts
Original file line number Diff line number Diff line change
Expand Up @@ -299,7 +299,7 @@ export const seoMetadata = {
title:
"HIPAA-Compliant Screen Recording — Secure Healthcare Recordings | Cap",
description:
"Cap enables HIPAA-compliant screen recording for healthcare teams. Self-host recordings on your own AWS S3 bucket, keep PHI off third-party servers, and audit every line of open-source code.",
"Cap is a HIPAA-compliant screen recorder for healthcare teams. Signed BAAs, SOC 2 Type II and ISO 27001 certified, plus self-hosting to keep PHI on your own storage.",
keywords: [
"hipaa compliant screen recording",
"hipaa screen recorder",
Expand Down
6 changes: 3 additions & 3 deletions apps/web/public/llms-full.txt
Original file line number Diff line number Diff line change
Expand Up @@ -89,8 +89,8 @@ Core principles:

- Storage targets: Cap Cloud, your own Google Drive (OAuth), any S3-compatible bucket, or fully local.
- S3-compatible providers: AWS S3, Cloudflare R2, Supabase, MinIO, DigitalOcean Spaces, Backblaze B2, Wasabi, and more.
- Security: end-to-end encryption for cloud storage; GDPR-friendly via bring-your-own storage in any region; HIPAA via self-hosting plus signed BAAs for enterprise.
- Compliance: SOC 2, HIPAA, and ISO 27001 (certifications in progress). Trust Portal: https://trust.cap.so.
- Security: end-to-end encryption for cloud storage; GDPR-friendly via bring-your-own storage in any region; HIPAA compliant with signed BAAs, plus self-hosting for full control.
- Compliance: SOC 2 Type II, ISO 27001, and HIPAA compliant. Trust Portal: https://trust.cap.so.
- Self-hosting documentation: https://cap.so/docs/self-hosting.

## Export
Expand Down Expand Up @@ -175,7 +175,7 @@ Early-adopter pricing is locked in for the lifetime of the subscription. Trusted
- **vs OBS Studio** — Simpler, no complex scene setup; instant cloud sharing and AI built in; native lightweight app.
- **vs Camtasia / ScreenFlow** — Free and open source, cross-platform, cloud sharing built in, lighter weight.
- **vs Vidyard / Panopto** — Open source, bring-your-own storage, transparent pricing, self-hosting option.
- **vs Zoom recordings** — Purpose-built async video with editing, analytics, and HIPAA-friendly self-hosting.
- **vs Zoom recordings** — Purpose-built async video with editing, analytics, and HIPAA compliance with signed BAAs.
- **vs Scribe** — Real screen video with narration and chapters vs static step screenshots.

## Use Cases & Solution Pages
Expand Down
Loading