Engineering

From the interface to the infrastructure.

How Fabcom Studios builds and runs its products, with FabStream as the working example. Everything on this page describes software that is in production today.

The stack

Five layers, one team.

01

Product

FabStream is a Windows desktop app: an Electron interface with GPU-accelerated compositing and FFmpeg for encoding, rendering two canvases at once. Websites, the account page and our internal admin tool are web apps on the same platform.

02

Identity

Optional accounts with e-mail codes or sign-in via Twitch, Kick, TikTok, Discord and Google. Licenses are activated per PC and confirmed with Ed25519-signed leases that keep working offline for up to 7 days.

03

Commerce

A 7-day trial inside the app, four plans, monthly and yearly subscriptions. Payments run through a merchant of record that handles invoices and sales tax worldwide – we never see card details.

04

Infrastructure

APIs, the database and scheduled jobs run on Cloudflare Workers and D1 – served close to users, with no servers to maintain; transactional e-mail goes out via Resend. License keys are stored as hashes and encrypted.

05

Delivery

Every release lists the SHA-256 of each file and ships a checksum list signed with Ed25519. The in-app updater installs a new version only after verifying that signature and the installer’s hash.

Privacy architecture

Your stream stays between your PC and the platform.

FabStream encodes on your computer and sends each destination directly to the platform. Fabcom Studios is not in that path – no relay server, no copy of your audio or video.

SourcesCamera · Microphone · ScreenCaptured locally
Your PCFabStreamMixes and encodes both formats
Direct · RTMP / RTMPSTwitch · YouTube · Kick · TikTok …Only the servers you enter
Fabcom StudiosReceives no audio and no video

Stream keys stay local

Encrypted with Windows DPAPI and stored only on your PC – never in settings files, never in cloud sync. If you connect Twitch or Kick, our server fetches the key from the platform and passes it to the app without storing it.

No telemetry

The app does not track how you use it. No account is needed for the Free plan.

What reaches our servers

License checks (paid plans), the optional account and cloud sync, and bug reports you send yourself. The update check asks GitHub and can be switched off. Privacy policy

Releases

Releases you can verify.

Downloads are only as trustworthy as the way they are checked. Every FabStream release can be verified independently – and the app verifies updates itself before installing them.

The direct-download installer is not Authenticode-signed yet. Windows SmartScreen may therefore warn on first launch; the checksums and the Ed25519 signature let you confirm the file is ours.

  1. SHA-256 for every fileListed in the release notes and in SHA256SUMS.txt.
  2. Signed checksum listSHA256SUMS.txt is signed with the Fabcom release key (Ed25519); the public key is in the repository’s SECURITY.md.
  3. Verified updatesThe updater checks the signature, the version and the installer hash. A file that fails any check is deleted, never started.
Performance

Measured, not promised.

FabStream runs one FFmpeg encode per format and shares it between every destination, the recording and the replay buffer. The numbers below come from the automated benchmark in the real app, with a local RTMP receiver.

AMD Ryzen 7 7800X3D · NVIDIA GeForce RTX 5070 Ti · NVENC · FabStream 1.3.0 · 2026-10-05 · 20 s per scenario
ScenarioOutputs / encodersRender fps (avg / min)Encoder speedDropped framesRAM
1080p60 16:9 + 1080p60 9:16, stream + recording4 / 260 / 59.91.01×0999 MB
1080p60 16:9 + 1080p60 9:16, stream + recording + replay buffer6 / 260 / 59.91.01×01046 MB

Encoder speed 1.0× means real time. Results on other hardware will differ; new measurements are added here as they are made.

Security

Report a vulnerability.

Security reports go directly to the people who build the software. Please write privately – not in a public issue – and include the product version and steps to reproduce. You will get an answer within a few days.

Machine-readable contact: /.well-known/security.txt

  • Stream keys, license keys and sign-in tokens are masked in every log
  • App interface sandboxed, with context isolation and a fixed list of checked commands
  • Websites: strict Content Security Policy, HSTS, no third-party trackers, no cookies
  • Session tokens stored only as hashes; license keys hashed and encrypted
Contact

Talk to Fabcom Studios.

Business, partnerships, press or security – write to us. Using FabStream? Product support is fastest through FabStream support.