Recording encryption is optional and independent of the storage location. Enable it separately in Desktop Recorder and Audio Recorder to protect agent-local, downloaded, pending-upload, and external-storage recordings.
How it works
- Each recording uses a random AES key wrapped with the active public key. The matching console private key is required for playback.
- Normal recording sends only the public key to agents. Back up the separate desktop and audio keys as
DesktopRecorder.key and AudioRecorder.key. - Losing every private-key copy makes the affected recordings unrecoverable.
Configure encryption
- Select Encrypt recordings on the appropriate recorder tab.
- Click Back up key... and protect the backup with a strong password.
- Click Apply settings. New recordings are encrypted whether local or external storage is selected.
Existing recordings
The first, unlabeled list column shows the lock and download indicators. The lock is always first.
- Select recordings and click Encrypt or Decrypt. Downloading first is not required.
- External-storage files are converted directly there. Agent-only files are converted while the agent is connected.
- Manual remote decryption transfers the required private-key material through the authenticated encrypted console-agent connection for that operation; it is not saved in agent recorder configuration.
- Use Save unencrypted... to export copies without changing stored originals.
- Use Encrypt all recordings... to enable encryption and convert accessible console and external-storage archives in the background. Originals are removed only after verification.
- Use Decrypt all recordings... to disable encryption and convert accessible archives.
Key rotation
Back up both keys, click Rotate key..., save the new backup, and apply settings. The console rewraps each small per-file AES key in the background while retaining previous keys for offline agents and failed migrations.
External storage configuration