← Back to blog

Getting a Demo Tool Past Security and Legal

August 21, 2026

A demo tool records your product while you are logged into it, which is enough to get a security review started at most companies above a certain size.

The review is usually shorter than expected, because the honest answers happen to be reassuring — but only if you have them ready.

The questions that actually get asked

  • Does it run inside our product? With an extension-based recorder, no — nothing is installed into your application, no SDK, no script tag. This is the answer that ends most reviews early.
  • What data leaves? Whatever was on screen when you recorded. Not your database, not an API connection — a capture of a screen.
  • Is a published demo public? Yes. A share link is a URL, and anyone with it can open it. Say so plainly; pretending otherwise fails the review later rather than sooner.
  • Can data be removed after the fact? Ask whether redaction destroys the original or merely covers it. Only the first is an answer.
  • Does the demo execute our code? It should not. A captured page rendered inert, with scripts stripped and sandboxed, is a much smaller surface than a live embed of your app.

The answer that pre-empts most of it

Record from a dedicated demo account containing invented data. That converts the review from "what happens to our customer data" into "what happens to data we made up", which is a different and much shorter conversation.

For health, financial or legal products it is not a nice-to-have. Real records in a public demo is a disclosure event regardless of how briefly it was up.

What Demorta does not have

SSO, SOC 2, a DPA negotiated by your legal team, or an enterprise security questionnaire process. If your reviewer requires those, we are not the right tool yet and saying so is faster than a month of email.

Being straight about that is deliberate. A tool at $15.99 a month is not carrying the compliance apparatus of one at fifty times the price, and pretending otherwise wastes the reviewer's time and yours.

How to prepare the ask

Go in with three things: what gets recorded, where it is stored, and who can see the result. Add the demo-account decision up front, because it removes the objection before it is raised.

Reviewers say no to vagueness far more often than to risk. A specific, modest, honestly-scoped request usually passes.

Frequently asked questions

Does interactive demo software need to be installed in our product?
Not with an extension-based recorder. Capture happens in the browser, so there is no SDK and no script tag inside your application, and nothing new running in production. That answer ends most security reviews early.
What data does a demo tool actually receive?
Whatever was visible on screen when you recorded — a capture of a screen, not a database or an API connection. Recording from a demo account with invented data means what leaves is data you made up.
Does Demorta have SSO or SOC 2?
No. If your security review requires SSO, SOC 2 or a negotiated DPA, Demorta is not the right tool for you yet, and knowing that early is faster than discovering it after a month of emails.

Keep reading

This is what Demorta does

Click through it — the same kind of demo you can record of your own product.

Try it on your own product

Record your first interactive demo free.

Five demos on the free plan, forever. No credit card, no trial countdown, no sales call. Install the Chrome extension, click through your product once, and you have a shareable link in about ten minutes.

Start free →