Filesystem storage
Private betaStore recording objects and posters on the deployment's persistent filesystem.
Current private-beta Docker builds cover filesystem or S3-compatible storage, protected sharing, range playback, and moderation. Signed license enforcement, Cloudflare Worker deployment, and native Mac publishing remain engineering previews.
Capability matrix 1.0.0, updated 2026-07-18. No current Enterprise capability is labeled generally available.
Request private beta accessDeployment support
Beta and preview labels describe current availability. They are not production support or uptime commitments.
| Target | Status | Architecture | Storage / database | Current boundary |
|---|---|---|---|---|
| Docker image | Private beta | Linux x86-64 and ARM64 build targets | Filesystem; S3-compatible storage (AWS S3, MinIO, or R2 through its S3 API) SQLite | Single-container deployment with a persistent /data volume. Hardened Compose, Caddy TLS, backup/restore scripts, and multi-architecture CI definitions exist; upgrade, rollback, and recovery qualification remain open. |
| Cloudflare Worker | Preview | Cloudflare-managed runtime | Cloudflare R2 Cloudflare D1 | Requires customer-managed Worker, D1, R2, and KV resources. A provisioning script and template exist, but clean-account and upgrade qualification remain open. |
| Native Bun binary | Preview | Linux x86-64, Linux ARM64 | Filesystem; S3-compatible storage (AWS S3, MinIO, or R2 through its S3 API) SQLite | Cross-compile targets exist, but signed release artifacts, installers, service management, and architecture qualification are not published. |
Implemented today
Store recording objects and posters on the deployment's persistent filesystem.
Use AWS S3, MinIO, or Cloudflare R2 through the S3 API for Bun and Docker deployments; Workers use a native R2 binding.
Create owner-only private shares or bearer-link unlisted shares. Unlisted links are not organization-restricted access controls.
Serve seekable recording playback while keeping private objects behind the application authorization check.
The server enforces organization, named-user, email-domain, password, expiry, and download policies. Password-entry playback UX and full client qualification remain open.
Accept abuse reports and let moderator or administrator roles hide, restore, or soft-delete shares.
Source builds verify immutable vendor-signed, install-bound leases and degrade writes after the signed offline grace period. Clone-resistant hardware identity and operator issuance/recovery qualification remain unavailable.
Source builds can discover a server, authenticate with OAuth 2.0 PKCE, resume multipart uploads, and manage their published shares. This path is not yet a supported release artifact.
The Mac app reads managed server, SSO, storage-policy, and user-override preferences. A signed profile template and deployment qualification are still required.
Owner, administrator, moderator, publisher, commenter, and viewer roles enforce a fixed permission matrix. Custom roles and policy rules are not implemented.
Administrative and viewing events can be exported as NDJSON. Production webhook or streaming delivery, append-only guarantees, and scheduled delivery are not yet available.
Authenticated organization members can add timestamped comments and replies through the server API and viewer. Notification and release qualification remain open.
Organization name, logo, accent color, and support URL can brand the server shell. Verified custom-domain lifecycle management is not implemented.
The license service can issue an install-bound signed offline activation that the server verifies without check-in. Operator issuance, rotation, and recovery procedures are not yet a supported workflow.
Roadmap, not current product
These items require their named engineering and release gates before ScreenKite can advertise or sell them as available capabilities.
The current authentication implementation does not provide SAML identity-provider integration.
Release gates: ENT-030
Automated user and group provisioning is not implemented.
Release gates: ENT-031
No BYOK contract or key-rotation workflow is available in the current release.
Release gates: ENT-037
A Worker can run on Cloudflare's network, but no multi-region data, failover, or support guarantee is defined.
Release gates: ENT-015, ENT-040, ENT-045, ENT-052
ScreenKite does not currently operate a managed Enterprise hosting service or offer an uptime SLA.
Release gates: ENT-045
No independent SOC 2 report is currently offered.
Release gates: ENT-046
Sales can review deployment fit and current limitations. Managed hosting, security certifications, and uptime commitments are not part of the current release.
Contact [email protected]