WebRTC media encryption
ImplementedAudio and video are encrypted browser to browser with DTLS-SRTP. Keys are negotiated between the two endpoints; the signalling server never holds them and never sees a media frame.
How the media path works →Meeting software carries the most sensitive thing an organisation has: the conversation itself. These are the international standards Codexal Meet is built against, what each one means in the product, and exactly where it stands.
We do not claim certifications we do not hold. Codexal Meet is engineered to ISO/IEC 27001 and the SOC 2 Trust Services Criteria, and our controls are mapped to both — but neither has been audited by an external assessor yet, so neither says certified anywhere on this site. When that changes, the report will be linked here, not described here. Ask us for the current control documentation at info@codexal.co.
Transport security, privacy law, information security management, and accessibility. Each links to the page that shows the work.
Audio and video are encrypted browser to browser with DTLS-SRTP. Keys are negotiated between the two endpoints; the signalling server never holds them and never sees a media frame.
How the media path works →Every page, API call and signalling stream is HTTPS only. Plain HTTP is redirected permanently, and HSTS tells the browser never to try again.
Transport details →Standards-based connectivity, so a call works behind a corporate firewall. TURN relays are authenticated with short-lived credentials and carry the same encrypted stream — a relay cannot read it either.
Connectivity →Lawful bases recorded, data minimised by design, subject-access and erasure handled within 30 days, sub-processors published, and a Data Processing Agreement available to every customer.
GDPR & the DPA →Our home jurisdiction. Personal data of Jordanian users is processed on consent and contract, held in the region, and disclosed only where the law requires it.
Regional law →The administrative, physical and technical safeguards that a telehealth consultation needs: access control, audit trail, integrity, transmission security and minimum necessary.
HIPAA & telehealth →An information security management system with a risk register, an asset inventory, access reviews and an incident procedure — mapped control by control to the 93 Annex A controls. Not externally certified.
Control mapping →We operate against all five Trust Services Criteria and keep the evidence a Type II audit would ask for. No audit has been performed, so there is no report to hand you yet.
Trust Services Criteria →The application itself: parameterised queries, CSRF tokens on every state change, hashed passwords, hardened session cookies and a content security policy.
Application security →Live captions in every meeting, full keyboard operation, semantic markup for screen readers, AA contrast and no colour-only signals — tested with VoiceOver, NVDA and at 200% zoom.
Conformance statement →The European accessibility standard for ICT procurement, which incorporates WCAG 2.1 AA for web content and adds requirements for two-way voice and video — captions and keyboard control included.
Procurement notes →The US federal requirement, harmonised with WCAG 2.1 AA. We can complete a VPAT for a procurement process on request.
Request a VPAT →The same register we hand to a procurement team, in full.
Most of what is on this page is visible from inside a meeting. The room tells you when captions are on and who is transcribing. The host admits people by name. Nothing is recorded until someone presses record, and the room says so in red while it is.
The rest — retention timers, backups, access reviews — you cannot see, so we write it down and let you ask.
We answer with documents, not adjectives. A person replies within one working day.