Security
We protect your meetings with industry-standard measures across transport, storage and access.
- Encryption in transit: all traffic between your device and our servers uses HTTPS/TLS (certificates issued by Let's Encrypt).
- Encryption at rest: recordings and the database are stored on Amazon Web Services with provider-managed encryption and access controls.
- Passwords: hashed with bcrypt; we never store plaintext passwords.
- Session security: access uses short-lived signed tokens (JWT, 7-day expiry) rather than exposing your credentials.
- Least-privilege AI processing: audio and text are sent to OpenAI only to transcribe and summarise, and are not used to train models.
- Access controls: your meetings are scoped to your account; you can delete any meeting at any time.
No system is perfectly secure. To report a security issue, email [SET: security email].