Product AI notes Pricing For teams Developers & API Security Standards & compliance
Start free Sign in
Trust · SOC 2

The criteria, without the certificate.

SOC 2 is not a badge you earn once; it is an auditor's opinion on controls you already operate. We operate them and keep the evidence. The audit itself has not happened, and until it does there is nothing to hand you but this page.

Codexal Meet has no SOC 2 report — Type I or Type II. No CPA firm has examined our controls, so there is no opinion, no bridge letter and no report under NDA. What we do have is the control set below, the evidence that it operates, and a plan to commission the examination. If a report is a hard requirement in your process, tell us early and we will tell you honestly where the timeline stands rather than letting an evaluation run on a maybe.

Common criteria · CC1–CC9

Security

The one criterion every SOC 2 engagement includes. Everything else is optional; this is not.

Criterion
What we run
Status
Control environmentCC1
Security is owned by engineering leadership with a named accountable individual. Confidentiality terms and background screening apply to everyone with production access.
Aligned
CommunicationCC2
Security commitments are published rather than promised in sales calls — this page, the security architecture and the control register are the same documents we use internally.
Implemented
Risk assessmentCC3
A risk register with likelihood, impact, owner and treatment, reviewed quarterly and on architectural change.
Aligned
MonitoringCC4
Internal security review on every release. Third-party penetration testing is scheduled but has not been performed.
On the roadmap
Control activitiesCC5
Change control on production, review before release, and separated development and production environments with no production data in development.
Aligned
Logical accessCC6
Unique accounts, least privilege, hardened session cookies, bcrypt password storage, rate-limited authentication, high-entropy meeting identifiers, and a waiting room that admits people by name.
Implemented
EncryptionCC6.1, CC6.7
DTLS-SRTP between browsers for media, TLS 1.2+ with HSTS for everything else, and encrypted volumes at rest.
Implemented
System operationsCC7
Authentication, admission and security-relevant failures are logged. A documented incident procedure defines severity, ownership and a 72-hour notification commitment.
Aligned
Change managementCC8
Every production change is reviewed, versioned and reversible. Server configuration lives in version control next to the application.
Implemented
Vendor riskCC9
Sub-processors are assessed before adoption, carry our data protection terms, and are named publicly on the GDPR page.
Aligned
A1

Availability

Criterion
What we run
Status
CapacityA1.1
Summary workers run concurrently with atomic job claiming, so a hundred meetings ending together drains as a queue rather than failing as a spike.
Implemented
Backup and recoveryA1.2
Daily encrypted backups rotated at 30 days, with periodic restore tests and a documented recovery objective.
Aligned
Resilience of the callA1.2
A meeting is peer to peer. If our signalling tier has a problem, calls already established keep running — the architecture removes us from the critical path once a call is up.
Implemented
Recovery testingA1.3
Restores are exercised rather than assumed. Formal, evidenced disaster recovery exercises are part of the audit preparation.
On the roadmap
PI1

Processing integrity

For a meeting platform this is mostly about one thing: is the recap an honest record of what was said?

Criterion
What we run
Status
Accurate inputPI1.2
Each participant's own browser transcribes their own microphone, so every line of the transcript carries a reliable speaker instead of a guess from a mixed audio stream.
Implemented
Complete processingPI1.3
Summary jobs are queued, claimed atomically and retried on failure with a bounded attempt count, so a meeting is summarised once — never twice, never silently zero times.
Implemented
Accurate outputPI1.4
The recap is delivered to the attendees of that meeting and nobody else, and it is attached to the meeting record so it can be read again later.
Implemented
Stated limitationsPI1.1
We say plainly, in the product and in the terms, that an AI summary can be wrong and should be checked before it is acted on. Overstating machine accuracy is itself a processing integrity failure.
Implemented
C1

Confidentiality

Criterion
What we run
Status
Identification and protectionC1.1
Meeting content is our most sensitive class. Media is encrypted end to end and never stored; transcripts are stored only to produce a summary and only when someone opted in.
Implemented
DisposalC1.2
Transcripts are deleted on a retention timer, 14 days by default. Account deletion removes the account and its meetings, and clears backups within 30 days.
Implemented
Confidentiality commitmentsC1.1
Confidentiality terms bind every employee and contractor with access, and every sub-processor by contract.
Aligned
P1–P8

Privacy

The privacy criteria and GDPR overlap almost entirely. Both are answered in detail on the GDPR page.

Criterion
What we run
Status
NoticeP1
The privacy policy states what is collected and why, in the words a participant would use, and the room shows when captions and recording are on.
Implemented
Choice and consentP2
Captions are opt-in per person and reversible mid-meeting. A guest gives a name; an email address is optional.
Implemented
CollectionP3
We collect what a meeting needs and no more. There is no server-side recording, no tracker and no advertising identifier.
Implemented
Use, retention, disposalP4
Meeting data is used to run the meeting and write its recap, kept to a published schedule, and deleted on that schedule.
Implemented
AccessP5
Individuals can request a copy of their data or its deletion, answered within 30 days.
Aligned
Disclosure to third partiesP6
Sub-processors are named publicly, contractually bound, and limited to what each needs. Customer content is never sold or used for advertising.
Implemented
QualityP7
Account details can be corrected in Settings; a summary can be corrected by the people who were in the meeting.
Implemented
Monitoring and enforcementP8
Privacy complaints go to a named address, are investigated and answered, and complainants keep the right to go to their supervisory authority instead.
Aligned
Questions

What vendor review teams ask.

Can we see your SOC 2 report?
There is no report to see. No CPA firm has examined our controls, so there is no Type I, no Type II and no bridge letter. The control set that an examination would look at is published in full on this page, and we will send the supporting documentation under NDA.
When will Codexal Meet be SOC 2 certified?
SOC 2 is an attestation rather than a certification, and we have not committed publicly to a date because a date we might miss is worse than no date. The controls are in place and evidence is being collected. Ask us and we will tell you where the preparation actually stands.
What can you give us instead of a report?
The control register on this page, the security architecture, the ISO 27001 control mapping, a completed security questionnaire, and our Data Processing Agreement. For most evaluations that is the same information a report would summarise — with the honest caveat that nobody independent has checked it.
Which Trust Services Criteria do you operate against?
All five: security, availability, processing integrity, confidentiality and privacy. Security is the mandatory one; we include the other four because a meeting platform that ignores processing integrity is a platform whose recaps you cannot rely on.

Send the questionnaire anyway.

We would rather answer 200 questions honestly than show you a badge.