Skip to main content
TrenithTools
HomeAll ToolsWatch TogetherStatusGuidesAI Studio
Connections
TRENITH TRUST CENTER

Device-first by architecture.

Security overview · Updated 18 July 2026

PrivacyTermsCookiesPrivacy choicesSecuritySubprocessorsCopyrightAccessibilityOpen source

Architecture

Device-labeled operations use browser APIs and locally loaded code. Public URL and allowlisted BYOK routes run on hosted infrastructure only for the requested transaction. Watch Together uses short-lived room signaling in Cloudflare D1 and peer-to-peer WebRTC for optional camera/microphone media, with a TURN relay only when configured and needed. Trenith’s public infrastructure uses Vercel, Cloudflare and Google Cloud services; secrets are scoped and kept outside client source.

Controls

Controls include TLS, security headers, restricted outbound destinations, private-network blocking on public URL tools, session-first credentials, optional AES-GCM browser vault encryption, consent defaults, dependency review and least-privilege operational access.

Your role

Use a supported updated browser, protect provider keys, use restricted keys and spending limits, verify custom endpoints, keep original files and remove shared-device vaults. No encryption can protect a key after it is sent to the provider you instruct us to call.

Watch Together encryption and recovery

The room invitation contains a random encryption secret in the URL fragment, which browsers do not send as part of ordinary HTTP requests. Chat, reactions, WebRTC negotiation and playback events are encrypted with AES-GCM before signaling storage. Participant display names, roles, provider choice, opaque token hashes and timestamps are not end-to-end encrypted because the service needs them to enforce membership, expiry and limits. WebRTC encrypts media in transit; direct peer connections can reveal network addresses to room peers unless relay-only infrastructure is configured. Never post an invitation publicly.

Certifications

Do not infer a certification from this page. Trenith does not claim Trenith Tools is currently certified to ISO 27001, SOC 2, PCI DSS or a sector-specific healthcare standard.

Report a vulnerability

Send a reproducible report to legal@trenith.in. Do not access other people’s data, disrupt the service, use destructive tests or publish an unremediated issue. We will acknowledge valid reports as resources permit; there is no standing bounty promise.

TrenithTools

Free media, document and AI-connected utilities built by Trenith Technologies Pvt Ltd.

ToolsMetadata removerAudioVideoPDFImages
PlatformWatch TogetherStreaming compatibilityTool statusChangelogAI StudioBYOK ConnectionsGuidesAbout TrenithBuild with Trenith ↗
TrustPrivacyTermsCookiesPrivacy choicesSecuritySubprocessorsOpen-source noticesCopyrightAccessibility
© 2026 Trenith Technologies Pvt LtdPrivate, device-first tools · Hyderabad, India