Tenant isolation
Every tenant-owned table carries an organization_id and is protected by row-level security policies enforced at the database layer, not just the API.
We describe our technical controls plainly and accurately. We do not claim SOC 2, GDPR, HIPAA, or other regulatory compliance certifications until the corresponding organizational programs and legal review are complete — a claim we make explicitly so you can plan around it.
Every tenant-owned table carries an organization_id and is protected by row-level security policies enforced at the database layer, not just the API.
Recordings, exports, and share downloads are never stored in public buckets. Access uses short-lived, scoped signed URLs.
Every capture method — bot, desktop, browser — carries an explicit, visible recording indicator and consent reminder. We do not perform silent recording.
Provider credentials never ship to browser or desktop bundles. Desktop uploads use short-lived tokens minted by an authenticated backend.
Access, sharing, exports, role changes, integration writes, and MCP tool calls are recorded to an immutable audit log reviewable by organization admins.
Raw audio, transcripts, and summaries each have independent, configurable retention. Deletion is a verified job across database, storage, and derived search indexes.