Keystroke logging is a feature in many monitoring products. It records every key pressed on a computer and stores the result, so a manager can later read what was typed. We get asked about it from time to time. Our answer is always the same: CyberWall Insights does not log keystrokes, and it never will.
This isn't a missing feature on a roadmap. It's a decision we made as a security company. Here's why.
What Insights records instead
To know whether someone is active, you only need to know that input happened. The Insights agent notes that there was keyboard or mouse activity during a period of time. It does not record which keys were pressed, in what order, or in which field. That's enough to calculate active and idle time, and it's all we collect about input.
Alongside that, Insights records the foreground application and window, and website names such as "office.com." It never captures full URLs, page content, email, documents or chat messages.
Reason 1: Keystroke logs are full of passwords
People type passwords all day. Into Windows, into Microsoft 365, into banking portals, into line-of-business apps. A keystroke log captures them. It may also capture multi-factor codes, credit card numbers and Social Security numbers typed into forms.
That turns your monitoring database into a collection of credentials. As a security team, we spend our days trying to keep credentials out of the wrong hands. Building a tool that gathers them in one place would work directly against everything we do for our clients.
Reason 2: Data you don't collect can't be breached
Every piece of data you store is something you have to protect, for as long as you keep it. The safest data is data that never existed. Collecting only activity levels, apps and site names keeps the sensitive surface small. If something ever went wrong, there would be no typed messages, passwords or personal details to expose.
Reason 3: It captures far more than work
Even on a company computer, people type personal things. A message to a doctor's office. A note to a spouse. A search about a health condition. A complaint to HR. A keystroke log records all of it, and once it's recorded, someone can read it.
Most managers don't want that information, and having it can create problems. Information about health, family or protected activity can complicate employment decisions and expose the business to claims. Our monitoring laws guide covers the notice side of the law. Talk to your attorney about the rest before collecting anything that sensitive.
Reason 4: It doesn't answer the questions managers actually have
When we built Insights, we listened to what our clients wanted to know:
- How much of the day is spent on productive work?
- Which apps and sites take up the most time?
- Are people starting and ending on schedule?
- Is any team overloaded or under-used?
- Are files leaving the company on USB drives?
None of these questions needs a record of what someone typed. Activity levels, application and site usage, schedule data and a short list of alerts answer them all. Reading through keystroke logs is slow, invasive and rarely leads to better decisions.
Reason 5: It destroys trust
Employees can accept a tool that measures how time is spent. They know their manager can already see whether they're at their desk or in a meeting. Recording every word they type is different. It feels like being read over the shoulder all day, because it is.
When people feel watched that closely, the best ones start looking for other jobs. The rest learn to work for the monitor instead of for the customer. Neither outcome helps your business.
"But what about investigations?"
Sometimes businesses face a real problem: suspected data theft, harassment or fraud. In those cases, a keystroke log can seem appealing. In practice, there are better tools:
- Alerts on risky actions, such as large USB copies or heavy file-sharing use, catch many data-loss situations as they happen.
- The activity log shows which apps and sites were in use at a given time, including lock, unlock and sleep events.
- Company systems already keep records. Microsoft 365 email, Teams and file activity can be reviewed through proper channels with legal guidance.
- Security monitoring, such as CyberWall Shield, watches for account compromise and threats.
- Professional help. Serious investigations should involve HR, an attorney and your IT or security provider.
What to tell employees
If you use Insights, you can tell your team something simple and true: "The software notes whether you're active, which apps you use and the names of websites you visit. It never records what you type." That one sentence answers the question most people are afraid to ask. Put it in your written policy too, so it's on record. Our policy template includes language you can adapt.
Where we draw other lines
Refusing keystroke logging is part of a broader stance we call "insight, not surveillance." Insights also never:
- Reads email, documents or chat content.
- Captures full URLs or page content.
- Takes screenshots while the screen is locked.
- Sells data.
Screenshots are available only as an optional add-on, off by default for every company, turned on by CyberWall at the customer's request, and deleted automatically after 7, 14 or 30 days. The agent can show employees a monitoring notice, so nobody is in the dark.
The short answer
We refuse to log keystrokes because it would put passwords and private lives in a database, increase the risk to our clients, damage trust between managers and employees, and still not answer the questions businesses actually ask. Measuring activity levels gives you the facts you need without any of that.
