Media travels browser to browser, encrypted with keys our servers never hold. Everything else — accounts, agendas, transcripts — stays in the region, behind controls we can show you.
Codexal Meet is built on WebRTC. When two people join a meeting, their browsers perform a DTLS handshake with each other and derive the keys that encrypt the audio and video stream. That handshake happens end to end. Our signalling server carries the offer, the answer and the ICE candidates — the envelope, not the letter.
The practical consequence: there is no point in our infrastructure where a meeting could be listened to, because there is no point where the media exists in a form anyone could read.
Browsers exchange session descriptions and ICE candidates over an authenticated HTTPS channel. This is call setup — who is calling, on what codecs — and never media.
The two browsers authenticate each other's certificate fingerprints, which were carried in the signalling, and agree a key. Neither key nor fingerprint private half ever reaches a server.
Audio and video flow directly between participants, encrypted with the agreed key. If the network forces a relay, the relay forwards the same encrypted packets blind.
Every request is served over TLS 1.2 or better. A plain HTTP request is answered with a permanent redirect before anything else happens, so no page and no API call is ever available in the clear.
A Strict-Transport-Security header with a one-year max-age tells the browser to refuse plain HTTP to this domain for a year, which closes the gap on a first-visit downgrade.
A CSP restricts where scripts, styles, frames and connections may come from. Combined with X-Content-Type-Options and a strict Referrer-Policy, it limits what a successful injection could do.
The camera and microphone are granted by the browser to this origin only, on the user's explicit consent, and the page declares that policy rather than relying on the default.
HttpOnly so script cannot read them, Secure so they never leave over HTTP, SameSite so another site cannot ride on them, and cookie-only sessions so no identifier is ever put in a URL.
There is no advertising network, no session recorder and no analytics vendor watching the meeting pages. Nothing to leak, nothing to disclose in a cookie banner.
Connectivity uses the IETF stack a browser already implements: ICE to find a path between two endpoints, STUN to discover the public address, and TURN to relay when a symmetric NAT leaves no direct route.
TURN credentials are configured per deployment rather than shared publicly, and a relayed call is no less private than a direct one — the relay handles ciphertext.
Mapped to OWASP ASVS 4.0 Level 2 and the OWASP Top 10.
Accounts, meetings, agendas, transcripts and summaries are stored on servers in the Middle East. Enterprise customers can have a dedicated instance in a named region, which is how organisations with a residency clause in their own regulation usually buy.
There is no server-side recording. If a participant presses record, the file is written to that person's own device and the room shows a red indicator to everyone for as long as it runs.
Captions are transcribed in each participant's own browser and stored only so a summary can be written. The transcript is deleted after the retention period — 14 days by default, configurable per organisation.
Each person decides whether their microphone is transcribed, can turn it off mid-meeting, and the room shows the change to everyone. Muting also stops transcription.
When a meeting ends, the text of the captions and chat is sent to a language-model provider that writes the summary, decisions and action items. It processes that text on our behalf under contract and does not retain it or train on it.
The model never receives audio or video — only text that participants chose to have transcribed. Turn captions off and there is nothing to send.
Production access is limited to the engineers who need it, granted per person, and reviewed. There is no shared administrator login.
Daily encrypted database backups with periodic restore tests, because a backup nobody has restored is a hope, not a control.
A documented procedure with a named owner and a severity scale. Affected customers are notified within 72 hours of us confirming a personal data breach.
Server and dependency updates are applied on a regular cycle, and out of cycle for anything with a known exploit.
Maintained with owners and treatment plans, reviewed quarterly by engineering leadership under our ISO 27001 alignment.
Write to info@codexal.co with the detail. We acknowledge within two working days, and we do not pursue researchers who report in good faith.
Every standard, its status, and what we actually run against it.