Security
Security& privacy
We take security seriously. Here's exactly what we do to protect your data today.
Current Security Measures
What we actually implement today to keep your data safe
HTTPS Encryption
All data transmitted between your browser and our servers is encrypted using industry-standard TLS.
Ephemeral Audio Input
Audio is held in private temporary storage only while an analysis is active and is deleted when the job reaches a terminal state.
Secure API
API keys are hashed and rate-limited to prevent abuse. Each key has usage monitoring.
GDPR Compliant
We follow GDPR principles: minimal data collection, user consent, and data deletion rights.
Technical Implementation
Authentication & Authorization
- • NextAuth.js for secure session management
- • JWT tokens with secure HTTP-only cookies
- • Bcrypt password hashing with salt rounds
- • Rate limiting on authentication endpoints
Data Handling
- • Private temporary audio storage during active processing
- • Automatic deletion at terminal completion, failure, or cancellation
- • No training on user data without separate explicit consent
- • Minimal metadata collection
Infrastructure
- • Hosted on secure cloud infrastructure
- • Regular security updates applied
- • Monitoring for suspicious activity
- • Database encryption at rest
Planned Security Enhancements
As we grow, we're committed to continuously improving our security posture:
- SOC 2 Type II certification
- Independent third-party penetration testing
- ISO 27001 alignment
- A dedicated in-house security function
Security Questions?
If you have any security concerns or questions about how we protect your data, please don't hesitate to contact us.