Security

We protect your meetings with industry-standard measures across transport, storage and access.

  • Encryption in transit: all traffic between your device and our servers uses HTTPS/TLS (certificates issued by Let's Encrypt).
  • Encryption at rest: recordings and the database are stored on Amazon Web Services with provider-managed encryption and access controls.
  • Passwords: hashed with bcrypt; we never store plaintext passwords.
  • Session security: access uses short-lived signed tokens (JWT, 7-day expiry) rather than exposing your credentials.
  • Least-privilege AI processing: audio and text are sent to OpenAI only to transcribe and summarise, and are not used to train models.
  • Access controls: your meetings are scoped to your account; you can delete any meeting at any time.

No system is perfectly secure. To report a security issue, email [SET: security email].