Ergocure AI — IT Requirements

Share this page with your IT / InfoSec team before rolling out the assessment to employees.

Ergocure AI is a fully browser-based SaaS ergonomics platform. No software installation, no VPN, no agent, no plugin. Employees access assessments via a secure link in their browser.

1 · URLs to whitelist

Main applicationhttps://app.ergocure.in

All employee-facing assessment pages and report access.

API + Edge Functionshttps://mpaabwssmbjxgcmubwld.supabase.co

Backend API, authentication, and real-time data. Includes Storage (photos stored server-side after capture).

Fontshttps://fonts.googleapis.com

Open Sans typeface. Also whitelist fonts.gstatic.com (font file CDN).

Font files CDNhttps://fonts.gstatic.com

All traffic is HTTPS (port 443). No HTTP or non-standard ports required.

2 · Network requirements

ProtocolHTTPS only (TLS 1.2+)
Port443
WebSocketswss://mpaabwssmbjxgcmubwld.supabase.co

Used for real-time updates in the ergonomist review panel. Not required for the employee assessment flow.

Outbound firewallNo inbound rules required

Ergocure AI is fully outbound from the employee's device. No inbound firewall changes needed.

3 · Supported browsers

Chrome88 or later

Recommended. Full support including live camera capture.

Microsoft Edge88 or later
Firefox85 or later
Safari (macOS)14 or later
Chrome for Android88 or later

Mobile assessments fully supported.

Safari for iOS14 or later (iPhone / iPad)

JavaScript must be enabled. No browser extensions or plugins are required or installed.

Third-party cookies: not required. The application uses first-party session cookies only.

4 · Device and camera

CameraRequired for photo / video capture methods

Employees grant camera access when prompted by the browser. Webcam (desktop) or front/rear camera (mobile) both supported.

MicrophoneNot required

No audio is captured or transmitted at any point.

Video dataProcessed on-device — never uploaded

All computer-vision analysis (pose detection, joint-angle measurement) runs inside the employee's browser using on-device ML. Raw video is never sent to our servers. Only anonymised numerical scores are transmitted.

No software installZero installation required

No desktop agent, no Chrome extension, no mobile app. Fully browser-based.

5 · Data and privacy summary (for InfoSec)

Data residencySupabase (AWS ap-south-1 — Mumbai)

All assessment data is stored in India. Supabase is SOC 2 Type II certified.

Employee identityEmail optional — assessments can be anonymous

The employer controls whether employees submit their work email. Anonymous submissions are fully supported.

Report accessOTP-gated (8-digit code, email delivery)

Employees access their final report via a one-time code sent to their registered email. No account creation required.

Pose photosFace-blurred before storage · retained 30 days

If posture photos are captured, faces are blurred on-device before upload. Photos are auto-deleted after 30 days.

SSO / corporate loginOn request — roadmap

SSO (Google Workspace / Microsoft Entra OIDC) is on our roadmap and can be scoped on request for enterprise deployments that require it. Contact your Ergocure account manager to discuss timelines.

6 · Questions

If your IT or InfoSec team has additional requirements — IP allowlisting, VAPT documentation, DPA / data processing agreement, or SSO configuration — contact your Ergocure account manager or email support@ergocure.in.

Ergocure AI · app.ergocure.in · Updated June 2026