Security
Where your meeting data goes, including the parts we have not finished
Recording other people’s conversations is regulated. This page is the version we would want to read if we were the ones being asked to approve it.
The notetaker is visible or it does not record
Your meetings never train a model
How we handle recordings
The notetaker is visible or it does not record
It joins under its own name and stays in the participant list for the whole call. We do not ship a silent mode. Several jurisdictions require all-party consent to record, and Microsoft’s 2026 restrictions on third-party bots exist because of tools that hid.
Encrypted in transit and at rest
TLS on the wire. Recordings, transcripts and summaries are encrypted at rest in object storage and scoped to a single workspace.
Audio leaves the EU for transcription right now
Our servers run in Stockholm and the database is pinned to the EU. Speech-to-text and summarisation currently run with providers in the United States, which means meeting audio and transcript text cross the Atlantic. If that is not acceptable for your data, the self-hosted deployment is the answer and we would rather tell you now.
Run the whole thing on your own infrastructure
Single-tenant deployment where nothing leaves your network, including transcription. Available on request; the deployment guide is being written, so onboarding is hands-on for now.
Your meetings never train a model
Not ours, not a third party’s, and not as an opt-in you could switch on by accident. It is on the explicit list of things we are not going to build.
Retention windows are not built yet
Deleting a meeting removes the recording, transcript and summary together, today. What does not exist is automatic expiry. There is no per-workspace retention period and no delete-after-transcription. It is being built. Until it ships, nothing expires on its own.
Who else sees your data
Every third party that processes meeting content on our behalf, what they get, and where they run it.
| Sub-processor | What they process | Where |
|---|---|---|
| Deepgram | Meeting audio, for transcription | United States |
| OpenAI | Transcript text, for summaries | United States |
| Cloudflare R2 | Recordings, transcripts, summaries | EU / global edge |
| MongoDB Atlas | Account data and meeting metadata | EU (Stockholm) |
| Fly.io | The application and the notetaker | EU (Stockholm) |
| Vercel | This website | EU / global edge |
| Resend | Email addresses, for transactional mail | EU / United States |
| Stripe | EU / United States | |
| Calendar events, read-only | Global |
Being built
What we do not have yet
This list is here because a security page without one is a marketing page. It is accurate as of the date below.
Last updated: 2026-07-24
- No SOC 2 or ISO 27001 certification. If your procurement process requires one, we are not through it yet.
- No automatic retention or scheduled purge.
- No customer-managed encryption keys.
- No published penetration test.
Reporting a vulnerability
Send it to security@neurtask.com. You will get a human reply within two working days. We will not take legal action against anyone who reports a finding in good faith and gives us reasonable time to fix it.
Try it on your next call
Connect a calendar, let the notetaker join one meeting, and see what comes back. It takes about two minutes and costs nothing.
Free plan available. No card required.