---
title: iorad Browser Extension Overview
description: A technical overview of the iorad browser extension for IT and security teams, including permissions, data, capture behavior, encryption, and controls.
image: https://learning.iorad.com/hubfs/features_and_pricing.png
---

[![iorad](https://learning.iorad.com/hubfs/Iored%20Theme%202021/Images/iorad%20logo%20DONT%20DELETE.png)](https://www.iorad.com/)

- Product
  
  #### Individual
  
  [Tutorial Privacy Control who views your tutorials](https://www.iorad.com/pricing/feature/tutorial-privacy) [Mask Data Control who views your tutorials](https://www.iorad.com/pricing/feature/mask-data) [Basic Audio Text-to-speech & custom voiceovers](https://www.iorad.com/pricing/feature/basic-audio)
  
  #### Team
  
  [Branding Add custom branding](https://www.iorad.com/pricing/feature/custom-branding) [Premium Audio Neural voiceovers and CC](https://www.iorad.com/pricing/feature/premium-audio) [Collaboration Co-edit and publish tutorials](https://www.iorad.com/pricing/feature/team-collab) [Analytics See tutorial performance](https://www.iorad.com/pricing/feature/analytics)
  
  #### Enterprise
  
  [Translations Automatic language translation](https://www.iorad.com/pricing/feature/translations) [Team Accounts Allocate separate accounts](https://www.iorad.com/pricing/feature/team-collab) [Encrypt & Anti-Track Strict compliance & additional data protection](https://www.iorad.com/pricing/feature/encrypt-and-anti-track)
  
  [All plans & Features →](https://www.iorad.com/features)
- Resources
  
  #### Support
  
  [Help Center](https://www.iorad.com/resources/help-center) [Learning Hub](https://learning.iorad.com) [Schedule Demo](https://www.iorad.com/demo)
  
  #### Customers
  
  [Testimonials](https://www.iorad.com/testimonials) [Case Studies](https://learning.iorad.com/customer-stories?_ga=2.48225895.1718347252.1788801042-1263284910.1780521832)
  
  #### Marketplace
  
  [Partnerships](https://www.iorad.com/partner-programs) [Integrations](https://www.iorad.com/connectIntegrations) [Services](https://www.iorad.com/services)
  
  #### Company
  
  [Privacy Policy](https://www.iorad.com/privacypolicy) [About Us](https://www.iorad.com/meet-the-team)
- Use Cases
  
  [EDU](https://www.iorad.com/use-cases/education) [Customer Training](https://www.iorad.com/use-cases/customer-training) [Sales Enablement](https://www.iorad.com/use-cases/sales-enablement) [Learning & Development](https://www.iorad.com/use-cases/learning-and-development)
  
  [HR](https://www.iorad.com/use-cases/human-resources) [Product Management](https://www.iorad.com/use-cases/product-management) [I.T.](https://www.iorad.com/use-cases/information-technology) [Operations](https://www.iorad.com/use-cases/operations)
  
  [All Use Cases →](https://www.iorad.com/use-cases)
- [Pricing](https://www.iorad.com/pricing)

[Try it Free](https://www.iorad.com/signup) [Sign In](https://www.iorad.com/login)

# IT Security Overview of the iorad Browser Extension

[Learning Hub](https://learning.iorad.com/) → [Thought Leadership](https://learning.iorad.com/thought-leadership) →  IT Security Overview of the iorad Browser Extension

![features\_and\_pricing](https://learning.iorad.com/hubfs/features_and_pricing.png)

The iorad browser extension is a screen capture tool that records clicks and keystrokes as an employee walks through a software workflow, then converts the recording into an interactive step-by-step tutorial automatically. IT and security teams often review the extension before approving organization-wide deployment.

This overview covers what the extension captures, what it ignores, and the permissions it requires.

1. iorad captures on-screen interactions during an active recording session only.
2. iorad does not run in the background, does not transmit keystrokes outside of recording mode
3. iorad does not access browser history or stored credentials. All captured data is scoped to the tutorial being created.

Our recommendation is to share this security overview with your IT team so they can begin their review. Browser extensions are sometimes blocked by default in enterprise environments, and early approval ensures your team can start a trial without unnecessary delays.

## 1. What the iorad browser extension is

The iorad Capture Extension enables users to generate step-by-step tutorials by capturing interactions on any website. Its single goal is to streamline the documentation process by turning user actions into structured, shareable walkthroughs in seconds.

It is a user-initiated capture tool available in the Chrome Web Store, Microsoft Edge Add-ons, and Firefox Add-ons Store. The extension does not monitor, analyze, or passively collect browser activity. It only runs during active, user-initiated sessions and never gathers background data, open tabs, cookies, or network activity.

## 2. How it works

**Capture**: Users record clicks, inputs, and navigation steps on any webpage  
**Generate**: The extension automatically converts these actions into a visual tutorial with screenshots and annotations  
**Publish or Share**: Tutorials are saved to the user’s iorad account and can be edited, embedded, or shared

Everything is built to reduce time-to-documentation from hours to minutes.

## 3. What the extension captures

When a user starts a recording session, the extension may collect:

- Screenshots of the active browser tab
- Mouse clicks, keystrokes, and scrolling needed to document the process
- DOM element metadata (such as ID or class) to label elements automatically
- Instructional content added by the user

Capture is limited to the browser tab and occurs only during an active session.

## 4. What the extension does not capture

The extension does not:

- Access cookies, tokens, session storage, or backend application data
- Monitor browser activity in the background or between sessions
- Scrape data, capture API responses, or observe user behavior across tabs
- Include telemetry or persistent monitoring components

Everything captured is part of a user-controlled tutorial session.

## 5. Why permissions are needed

Each browser permission supports a specific feature and is strictly scoped to the extension’s function.

![](https://learning.iorad.com/hs-fs/hubfs/Screenshot%202026-05-08%20at%209-16-05%E2%80%AFPM%201-png.png?width=740&height=624&name=Screenshot%202026-05-08%20at%209-16-05%E2%80%AFPM%201-png.png)

## 6. Data handling

### What is collected

- Email address for authentication (via OAuth)
- OAuth tokens securely handled by Google
- Clicks, keystrokes, and screenshots during active tutorial creation
- On-screen page content that the user chooses to capture

### What is not collected

- Health, financial, or personal data unless shown during a tutorial
- Browser history, system-level information, or real-time behavior
- Content from non-active tabs or background pages
- Any telemetry or analytics data outside of explicit capture events

### Where data is sent

- **To iorad**: Tutorial content is uploaded to your account after capture
- **To Google**: OAuth authentication requests are securely exchanged
- **Nowhere else**: Data is not shared, sold, or transmitted to third parties

## 7. Data flow and storage

### During capture

All tutorial data remains local in the browser until the user completes and saves it.

### When saved

Data is encrypted in transit and at rest using:

- TLS 1.2 or higher during upload
- AES-256 encryption at rest
- Google Cloud Platform with ISO 27001, SOC 1, SOC 2, and SOC 3 certifications

Each customer account is isolated with role-based access and audit logging.

## 8. Security architecture

iorad follows a secure-by-design framework including:

- SOC 2 Type 2 certified controls
- Annual third-party penetration testing
- Secure SDLC practices and version-controlled deployments
- Role-based access control (RBAC) with least privilege enforcement
- Centralized logging with 24/7 monitoring
- Encryption key management via Google Cloud KMS
- No use of customer data for machine learning or AI training

## 9. Compliance and regulatory alignment

iorad meets and supports compliance for:

- SOC 2 Type 2
- GDPR and CCPA privacy frameworks
- FERPA, COPPA, and student data protections
- WCAG 2.1 AA accessibility
- Data Processing Agreements (DPA) and custom DPIAs upon request
- Full transparency into subprocessor usage and data flows

## 10. Incident response and business continuity

- Documented Incident Response Plan with notification timelines
- Annual testing of Business Continuity and Disaster Recovery Plans
- RTO of 4 hours and RPO of 24 hours or less for core services
- High availability and redundancy with uptime exceeding 99.9 percent

## 11. Deployment and IT controls

iorad supports secure and scalable deployment options:

- Install via Chrome, Edge, and Firefox extension stores
- Mass deploy using Group Policy (GPO), Jamf, Intune, or other MDM tools
- Restrict usage by domain, IP, or allowlist policies
- Track usage and content creation with enterprise audit logs
- Provide onboarding materials and IT support documentation

## 12. Summary for security reviewers

- Extension runs only when users initiate capture
- Captures only screen content and inputs, not system or browser-level data
- Provides redaction tools and full user control of content
- Encrypts data in transit and at rest with enterprise-grade security
- Maintains SOC 2 Type 2 certification and regulatory compliance
- Does not use or repurpose customer data outside tutorial creation
- Permissions are narrowly scoped and justified

## Additional documentation and resources

Available upon request or during onboarding:

- SOC 2 Type 2 Report
- Network and Data Flow Diagrams
- Extension Permission Matrix
- Application Security Architecture Overview
- Security Whitepaper
- SDLC and Change Logs
- Penetration Test Summary
- DPA and Subprocessor List
- DPIA Template
- Incident Response and BCP Plans
- Student Privacy and Accessibility Policies

![Company Logo](https://learning.iorad.com/hubfs/iorad%20icon.png)

#### Support

- [Help Center](https://www.iorad.com/resources/help-center)
- [Learning Hub](https://learning.iorad.com/)
- [Schedule Demo](https://www.iorad.com/demo)
- [Releases](https://www.iorad.com/release)
- [FAQ](https://www.iorad.com/faq)

#### Pricing

- [Business](https://www.iorad.com/pricing/business)
- [Education](https://www.iorad.com/pricing/education)
- [Non-Profit](https://www.iorad.com/pricing/non-profits)

#### Company

- [About](https://iorad.com/about)
- [Leadership](https://www.iorad.com/leadership)
- [History](https://www.iorad.com/history)
- [Culture](https://www.iorad.com/culture)
- [Careers](https://www.iorad.com/careers)

#### Explore iorad

- [What is iorad](https://www.iorad.com/tutorialbuilder)
- [Features](https://www.iorad.com/features)
- [Compare iorad](https://www.iorad.com/compare)
- [How to use iorad](https://learning.iorad.com/use-cases)
- [Testimonials](https://www.iorad.com/testimonials)

#### Connect

- [Partners](https://www.iorad.com/partner-programs)
- [Integrations](https://www.iorad.com/connectIntegrations)
- [Helping Hands](https://www.iorad.com/helping-hands)
- [Services](https://www.iorad.com/services)
- [Adoption Curve](https://learning.iorad.com/the-adoption-curve)

#### Fine Print

- [Terms of use](https://www.iorad.com/termsconditions)
- [Privacy Policy](https://www.iorad.com/privacypolicy)
- [Cookie Policy](https://www.iorad.com/cookiepolicy)
- [Accessibility](https://www.iorad.com/accessibility)
- [System Status](https://status.iorad.com/)

© Copyright 2026 – iorad Inc. All rights reserved.

[![LinkedIn](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/LinkedIn.png)](https://www.linkedin.com/company/iorad) [![Facebook](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Facebook.png)](https://www.facebook.com/iorad) [![Instagram](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Instagram.png)](https://www.instagram.com/iorad) [![YouTube](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/YouTube.png)](https://www.youtube.com/@iorad) [![Twitter](https://learning.iorad.com/hubfs/Social%20Media%20Icons%20(iorad)/Twitter.png)](https://twitter.com/iorad)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Raymond Chuma-Onwuoku",
    "url" : "https://learning.iorad.com/author/raymond-chuma-onwuoku"
  },
  "dateModified" : "2026-06-18T00:45:06.935Z",
  "datePublished" : "2026-05-08T12:20:02.000Z",
  "headline" : "iorad Browser Extension Overview",
  "image" : [ "https://learning.iorad.com/hubfs/features_and_pricing.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://learning.iorad.com/thought-leadership/iorad-browser-extension-overview",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://learning.iorad.com/hubfs/iorad_logo_colour_2021%20(1).png"
    },
    "name" : "iorad"
  }
}
```