Ergocure AI is a fully browser-based SaaS ergonomics platform. No software installation, no VPN, no agent, no plugin. Employees access assessments via a secure link in their browser.
1 · URLs to whitelist
https://app.ergocure.inAll employee-facing assessment pages and report access.
https://mpaabwssmbjxgcmubwld.supabase.coBackend API, authentication, and real-time data. Includes Storage (photos stored server-side after capture).
https://fonts.googleapis.comOpen Sans typeface. Also whitelist fonts.gstatic.com (font file CDN).
https://fonts.gstatic.comAll traffic is HTTPS (port 443). No HTTP or non-standard ports required.
2 · Network requirements
HTTPS only (TLS 1.2+)443wss://mpaabwssmbjxgcmubwld.supabase.coUsed for real-time updates in the ergonomist review panel. Not required for the employee assessment flow.
No inbound rules requiredErgocure AI is fully outbound from the employee's device. No inbound firewall changes needed.
3 · Supported browsers
88 or laterRecommended. Full support including live camera capture.
88 or later85 or later14 or later88 or laterMobile assessments fully supported.
14 or later (iPhone / iPad)JavaScript must be enabled. No browser extensions or plugins are required or installed.
Third-party cookies: not required. The application uses first-party session cookies only.
4 · Device and camera
Required for photo / video capture methodsEmployees grant camera access when prompted by the browser. Webcam (desktop) or front/rear camera (mobile) both supported.
Not requiredNo audio is captured or transmitted at any point.
Processed on-device — never uploadedAll computer-vision analysis (pose detection, joint-angle measurement) runs inside the employee's browser using on-device ML. Raw video is never sent to our servers. Only anonymised numerical scores are transmitted.
Zero installation requiredNo desktop agent, no Chrome extension, no mobile app. Fully browser-based.
5 · Data and privacy summary (for InfoSec)
Supabase (AWS ap-south-1 — Mumbai)All assessment data is stored in India. Supabase is SOC 2 Type II certified.
Email optional — assessments can be anonymousThe employer controls whether employees submit their work email. Anonymous submissions are fully supported.
OTP-gated (8-digit code, email delivery)Employees access their final report via a one-time code sent to their registered email. No account creation required.
Face-blurred before storage · retained 30 daysIf posture photos are captured, faces are blurred on-device before upload. Photos are auto-deleted after 30 days.
On request — roadmapSSO (Google Workspace / Microsoft Entra OIDC) is on our roadmap and can be scoped on request for enterprise deployments that require it. Contact your Ergocure account manager to discuss timelines.
6 · Questions
If your IT or InfoSec team has additional requirements — IP allowlisting, VAPT documentation, DPA / data processing agreement, or SSO configuration — contact your Ergocure account manager or email support@ergocure.in.
Ergocure AI · app.ergocure.in · Updated June 2026