Product AI notes Pricing For teams Developers & API Security Standards & compliance
Start free Sign in
Trust · ISO/IEC 27001

Built to 27001. Not certified to it.

Codexal Meet runs an information security management system modelled on ISO/IEC 27001:2022, with our controls mapped to Annex A. No external body has audited it, so this page says aligned, never certified.

Codexal Meet does not hold an ISO/IEC 27001 certificate. What exists is the management system a certificate attests to: a defined scope, a maintained risk register, an asset inventory, access reviews, an incident procedure and a documented Statement of Applicability against all 93 Annex A controls. If your procurement process requires a certificate, we will tell you we do not have one before you spend time on a questionnaire. If it allows evidence of an equivalent programme, everything below is available in writing.

Clauses 4–10

The management system itself.

Annex A gets the attention, but the clauses are what make it a system rather than a checklist.

Scope (Cl. 4)

The Codexal Meet platform: the web application, the signalling service, the database and the summary pipeline, plus the people and suppliers that operate them.

Leadership (Cl. 5)

Security is owned by engineering leadership at Codexal, with a named individual accountable for the policy and for decisions that accept risk.

Risk (Cl. 6)

A risk register with likelihood, impact, an owner and a treatment plan, reviewed each quarter and whenever the architecture changes.

Support (Cl. 7)

Written policies, security induction for new engineers, and documentation kept where the people who need it actually look.

Operation (Cl. 8)

Change control on production, security review before release, and supplier assessment before a new service is adopted.

Improvement (Cl. 9–10)

Incidents and near misses produce corrective actions with owners, and the register is updated rather than the incident being closed quietly.

Annex A.5

Organisational controls

Thirty-seven controls in the 2022 revision. These are the ones a customer is most likely to ask about.

Control
What we run
Status
Policies for information securityA.5.1
A written security policy set, approved by engineering leadership and reviewed annually or on significant change.
Aligned
Roles and responsibilitiesA.5.2–A.5.4
Security responsibilities are assigned by name, with separation between who requests production access and who grants it.
Aligned
Threat intelligenceA.5.7
Vendor advisories and CVE feeds for the components we run are monitored, and anything with a known exploit is patched out of cycle.
Aligned
Information classificationA.5.12–A.5.13
Meeting content is treated as the most sensitive class we hold, which is why it is minimised, opt-in and time-limited rather than merely protected.
Implemented
Access control policyA.5.15
Unique accounts, least privilege, role separation between user and administrator, and periodic access review of production.
Implemented
Identity and authenticationA.5.16–A.5.17
One identity per person, bcrypt password storage, rate-limited authentication, and SSO through the customer's identity provider on Enterprise.
Implemented
Supplier securityA.5.19–A.5.23
Providers are assessed before adoption and on renewal. Every sub-processor carries the data protection terms we owe customers, and each is named on the GDPR page.
Aligned
Incident managementA.5.24–A.5.28
A documented procedure with an owner, a severity scale, evidence handling and a 72-hour notification commitment to affected controllers.
Aligned
ContinuityA.5.29–A.5.30
Daily encrypted backups with periodic restore tests, and a documented recovery objective for the web and signalling tiers.
Aligned
Legal and contractualA.5.31–A.5.34
Obligations tracked under GDPR and Jordan's PDP Law, with privacy built into the product rather than bolted to the policy.
Aligned
Annex A.6

People controls

Control
What we run
Status
Screening and termsA.6.1–A.6.2
Background checks appropriate to the role, and confidentiality terms in every employment and contractor agreement.
Aligned
Awareness and trainingA.6.3
Security induction for new engineers and a refresh when a practice changes. Small team, direct conversations, written outcomes.
Aligned
Disciplinary processA.6.4
A defined response to a security policy violation, proportionate and documented.
Aligned
After employmentA.6.5
Access is revoked on the last working day, and confidentiality obligations continue afterwards.
Aligned
Confidentiality agreementsA.6.6
Signed by everyone with access to production or customer data, including contractors.
Aligned
Remote workingA.6.7
Company devices with disk encryption and screen lock, and production access only over authenticated channels.
Aligned
Annex A.7

Physical controls

Most of this belongs to our hosting provider, and we say so rather than describing a data centre we do not operate.

Control
What we run
Status
Physical perimeter and entryA.7.1–A.7.4
Delegated to the hosting provider, whose own certifications cover data centre access, monitoring and environmental protection. Codexal has no physical access to the servers.
Aligned
Equipment and mediaA.7.8–A.7.10
No customer data is held on removable media. Company laptops are encrypted at rest and lock automatically.
Implemented
Secure disposalA.7.14
Storage decommissioning is the provider's process; on our side, deletion is logical and verified against the live database and the backup rotation.
Aligned
Clear desk and screenA.7.7
Screen lock enforced on company devices; customer data is not printed.
Aligned
Annex A.8

Technological controls

The thirty-four controls where a meeting platform either does the work or does not. Most of these are verifiable from your own browser.

Control
What we run
Status
Endpoint devicesA.8.1
Company devices are encrypted, patched and locked. Meeting participants use their own browser — we require no agent and install nothing.
Implemented
Privileged accessA.8.2–A.8.5
Production access is granted per person, never shared, and reviewed. Authentication is rate limited and events are logged.
Implemented
Access to source codeA.8.4
Repository access is limited to the engineering team, with review required before a change reaches production.
Aligned
Capacity managementA.8.6
Signalling and summary workers scale with load, and the summary queue is drained by concurrent workers with atomic job claiming so a backlog cannot double-send.
Implemented
Protection against malwareA.8.7
No user-uploaded executable content is accepted or served. Company devices run endpoint protection.
Aligned
Vulnerability managementA.8.8
Dependencies are deliberately few and reviewed each release; advisories are tracked and patched on a cycle, or immediately where exploited.
Aligned
Configuration managementA.8.9
Server configuration is held in version control alongside the application, including the security headers that back our public claims.
Implemented
Information deletionA.8.10
Transcripts are deleted on a retention timer; account deletion removes the account and its meetings and works out of backups within 30 days.
Implemented
Data masking and minimisationA.8.11
Captions are opt-in per person, guest email is optional, and logs carry no meeting content.
Implemented
Data leakage preventionA.8.12
No server-side recording exists to leak. Media never touches our storage in any form.
Implemented
BackupA.8.13
Daily encrypted database backups, rotated at 30 days, with periodic restore tests.
Aligned
Logging and monitoringA.8.15–A.8.16
Authentication, admission and CSRF failures are logged with investigative context and without meeting content.
Aligned
CryptographyA.8.24
DTLS-SRTP for media, TLS 1.2+ for everything else, encrypted volumes at rest, bcrypt for passwords, and cryptographically random meeting identifiers.
Implemented
Secure developmentA.8.25–A.8.29
Security review in the development cycle, separated development and production environments, and no production data in development.
Aligned
Outsourced developmentA.8.30
Codexal Meet is built in-house by Codexal. There is no outsourced development to govern.
Not applicable
Secure codingA.8.28
Prepared statements, CSRF tokens, output escaping, hardened session cookies and secrets kept outside the web root — mapped to OWASP ASVS 4.0 Level 2 on the security page.
Implemented
Independent security testingA.8.29
Internal review every release. A third-party penetration test of the meeting and signalling path is scheduled, not yet done.
On the roadmap

Need the Statement of Applicability?

We send the control documentation to customers and to procurement teams evaluating us.