Product AI notes Pricing For teams Developers & API Security Standards & compliance
Start free Sign in
Trust · Standards & compliance

The standards behind every meeting.

Meeting software carries the most sensitive thing an organisation has: the conversation itself. These are the international standards Codexal Meet is built against, what each one means in the product, and exactly where it stands.

How to read this page

Three words, used precisely.

Implemented Running in the product today, and you can verify it from your own browser. Aligned We operate to the standard, documented internally — no third-party certificate. On the roadmap Committed, scheduled, not there yet.

We do not claim certifications we do not hold. Codexal Meet is engineered to ISO/IEC 27001 and the SOC 2 Trust Services Criteria, and our controls are mapped to both — but neither has been audited by an external assessor yet, so neither says certified anywhere on this site. When that changes, the report will be linked here, not described here. Ask us for the current control documentation at info@codexal.co.

The standards

Nine frameworks, four categories.

Transport security, privacy law, information security management, and accessibility. Each links to the page that shows the work.

Transport & media security

WebRTC media encryption

Implemented
RFC 3711 · RFC 8827 · RFC 8829

Audio and video are encrypted browser to browser with DTLS-SRTP. Keys are negotiated between the two endpoints; the signalling server never holds them and never sees a media frame.

How the media path works →

TLS 1.2+ everywhere

Implemented
RFC 8446 · RFC 6797 HSTS

Every page, API call and signalling stream is HTTPS only. Plain HTTP is redirected permanently, and HSTS tells the browser never to try again.

Transport details →

ICE / STUN / TURN

Implemented
RFC 8445 · RFC 5389 · RFC 8656

Standards-based connectivity, so a call works behind a corporate firewall. TURN relays are authenticated with short-lived credentials and carry the same encrypted stream — a relay cannot read it either.

Connectivity →

Privacy & data protection

GDPR

Aligned
Regulation (EU) 2016/679

Lawful bases recorded, data minimised by design, subject-access and erasure handled within 30 days, sub-processors published, and a Data Processing Agreement available to every customer.

GDPR & the DPA →

Jordan PDP Law

Aligned
Law No. 24 of 2023

Our home jurisdiction. Personal data of Jordanian users is processed on consent and contract, held in the region, and disclosed only where the law requires it.

Regional law →

HIPAA safeguards

Aligned
45 CFR §164 Subparts C & E

The administrative, physical and technical safeguards that a telehealth consultation needs: access control, audit trail, integrity, transmission security and minimum necessary.

HIPAA & telehealth →

Information security management

ISO/IEC 27001

Aligned
ISO/IEC 27001:2022 · Annex A

An information security management system with a risk register, an asset inventory, access reviews and an incident procedure — mapped control by control to the 93 Annex A controls. Not externally certified.

Control mapping →

SOC 2

On the roadmap
AICPA TSP section 100

We operate against all five Trust Services Criteria and keep the evidence a Type II audit would ask for. No audit has been performed, so there is no report to hand you yet.

Trust Services Criteria →

OWASP ASVS

Aligned
ASVS 4.0 Level 2 · Top 10

The application itself: parameterised queries, CSRF tokens on every state change, hashed passwords, hardened session cookies and a content security policy.

Application security →

Accessibility

WCAG 2.1 Level AA

Implemented
W3C Recommendation

Live captions in every meeting, full keyboard operation, semantic markup for screen readers, AA contrast and no colour-only signals — tested with VoiceOver, NVDA and at 200% zoom.

Conformance statement →

EN 301 549

Aligned
V3.2.1 · EU procurement

The European accessibility standard for ICT procurement, which incorporates WCAG 2.1 AA for web content and adds requirements for two-way voice and video — captions and keyboard control included.

Procurement notes →

Section 508

Aligned
29 U.S.C. §794d

The US federal requirement, harmonised with WCAG 2.1 AA. We can complete a VPAT for a procurement process on request.

Request a VPAT →
Control register

What each standard asks for, and what we run.

The same register we hand to a procurement team, in full.

Requirement
What Codexal Meet does
Status
Media confidentialityRFC 3711 · SRTP
Every audio and video stream is encrypted with DTLS-SRTP negotiated directly between participants' browsers. Our servers relay signalling only, and cannot decrypt a frame.
Implemented
Data in transitTLS 1.2+ · HSTS
HTTPS on every route with a permanent redirect from HTTP, HSTS with a one-year max-age, and modern cipher suites only.
Implemented
Data at restISO 27001 A.8.24
Databases and backups sit on encrypted volumes. Passwords are stored as bcrypt hashes, never reversibly.
Implemented
Access controlISO 27001 A.5.15 · HIPAA §164.312(a)
Unique account per person, role separation between user and administrator, session cookies that are HttpOnly, SameSite and Secure, and a waiting room so a host admits each participant by name.
Implemented
Data minimisationGDPR Art. 5(1)(c)
No meeting is recorded server-side. Captions are opt-in for each participant, transcripts are deleted on a retention timer, and a guest gives a name — an email only if they want the recap.
Implemented
Storage limitationGDPR Art. 5(1)(e)
Transcripts are purged after the retention period, 14 days by default and configurable per organisation. Summaries live with the meeting until the account is deleted.
Implemented
Application hardeningOWASP ASVS 4.0 L2
Prepared statements on every query, CSRF tokens on every state-changing request, output escaping by default, rate limiting on authentication, and security headers set at the web server.
Implemented
AccessibilityWCAG 2.1 AA
Live captions, complete keyboard operation with a visible focus ring, labelled controls for screen readers, AA contrast, and no signal carried by colour alone.
Implemented
Data residencyGDPR Ch. V · PDP Law Art. 15
Accounts, meetings, transcripts and summaries are held on servers in the Middle East. Enterprise customers can have a dedicated instance in a named region.
Implemented
Sub-processor transparencyGDPR Art. 28(2)
Every sub-processor is named on the GDPR page with its purpose and location, and customers are told before a new one is added.
Implemented
Data subject rightsGDPR Art. 15–22
Access, rectification, erasure, portability and objection, answered within 30 days from info@codexal.co.
Aligned
Breach notificationGDPR Art. 33 · HIPAA §164.410
A documented incident procedure with an owner, a severity scale and a 72-hour notification commitment to affected controllers.
Aligned
Risk managementISO 27001 Cl. 6
A maintained risk register with owners and treatment plans, reviewed each quarter by engineering leadership.
Aligned
Supplier assuranceISO 27001 A.5.19–A.5.23
Providers are reviewed before adoption and on renewal, and the contract with each one carries the data protection terms we owe our customers.
Aligned
Business continuityISO 27001 A.5.29–A.5.30 · SOC 2 A1.2
Daily database backups with periodic restore tests, and a documented recovery objective for the signalling and web tiers.
Aligned
Independent auditSOC 2 Type II · ISO 27001 certification
Evidence is collected and controls are documented for both, but no external assessor has issued an opinion. We will publish the report rather than describe it.
On the roadmap
Penetration testingSOC 2 CC4.1
Internal security review on each release. A third-party penetration test of the meeting and signalling path is scheduled.
On the roadmap
In practice

A standard you cannot see is a claim, not a control.

Most of what is on this page is visible from inside a meeting. The room tells you when captions are on and who is transcribing. The host admits people by name. Nothing is recorded until someone presses record, and the room says so in red while it is.

The rest — retention timers, backups, access reviews — you cannot see, so we write it down and let you ask.

  • Open the padlock in your browser. Check the certificate and the WebRTC statistics page: the media is DTLS-SRTP, not our word for it.
  • Turn captions off. Transcription stops for you immediately, and the room shows the change to everyone.
  • Admit people by name. The waiting room is on for every private meeting, not an option buried in a settings panel.
  • Ask for your data. An export or an erasure request is answered by a person within 30 days.
Questions

What procurement teams ask us.

Is Codexal Meet ISO 27001 certified?
No. Codexal Meet is built and operated against ISO/IEC 27001:2022, with our controls mapped to Annex A and a maintained risk register, but no external assessor has certified us. We will publish a certificate here when one exists rather than describe one that does not. The control mapping is on our ISO/IEC 27001 page.
Do you have a SOC 2 report?
Not yet. We operate against all five Trust Services Criteria and keep the evidence a Type II audit would require, and the audit is on our roadmap. Until it is complete there is no report to share, and we say so rather than implying otherwise.
Are Codexal Meet calls end-to-end encrypted?
Audio and video are encrypted between participants with DTLS-SRTP, the WebRTC standard defined in RFC 3711 and RFC 8827. In a peer-to-peer call the keys never leave the two browsers, so nobody in the middle — including us — can decrypt the media. Where a TURN relay is needed to get through a firewall, the relay forwards the same encrypted packets and cannot read them either.
Is Codexal Meet GDPR compliant?
We act as a data processor for the meeting content our customers put into the platform, and as a controller for account data. We provide a Data Processing Agreement, publish our sub-processors, minimise what we collect, delete transcripts on a retention timer and answer data subject requests within 30 days. Compliance is a shared responsibility: our GDPR page sets out which parts are ours and which are yours.
Where is our data stored?
Accounts, meetings, transcripts and summaries are stored on servers in the Middle East. Enterprise customers can request a dedicated instance in a named region, which is the usual route for organisations with a residency requirement in their own regulation.
Can we get a signed BAA for telehealth?
Talk to us. The technical safeguards a Business Associate Agreement relies on — access control, audit trail, transmission security and integrity — are already in the product and set out on our HIPAA page. The agreement itself is handled per customer under an Enterprise contract.
Do you complete security questionnaires?
Yes. Send yours to info@codexal.co. The control register on this page answers most of them already, and we would rather point you at a written answer than fill the same form twice.
How long do you keep meeting transcripts?
Fourteen days by default, after which they are deleted automatically. The retention period is configurable for organisations that need it shorter or longer. Summaries stay with the meeting so attendees can read them later, and go when the account is deleted.

Send us your security questionnaire.

We answer with documents, not adjectives. A person replies within one working day.