Security and compliance
MeetStream security keeps meeting data under your control. Everything is encrypted in transit and at rest. Write it straight to your own storage. MeetStream is ISO 27001 certified.
Certifications and compliance
| Item | Status, 2 September 2026 |
|---|---|
| ISO/IEC 27001:2022 | Certified. Certificate 630036. Issued by Amtivo Group Limited (British Assessment Bureau) to MeetStream Technologies Pte Ltd. First certified 19 August 2025. Valid to 18 August 2028. You can see it on the Trust Center. No lead gate. |
| SOC 2 Type 2 | Under audit. This row changes on the day the report is issued. |
| GDPR | Compliant. The DPA is on the Trust Center. The bot is visible and named, so the room knows. Calendar access is read-only. A deletion webhook lets you clear data per bot. |
| HIPAA | Not held. We do not sign Business Associate Agreements today. Tell us if you need one. |
We keep the documents a security review asks for. We share them during vendor checks. Email info@meetstream.ai to start one.
The Trust Center
Everything we publish on security lives at trust.meetstream.ai. You will find the certificate, the policies, the list of sub-processors and the audit status.
Send a reviewer there before the first call. There is no lead form in the way.
Certificate and reports
The ISO 27001 certificate as issued. Plus the SOC 2 report when the audit ends.
- Certificate 630036
- Amtivo Group / British Assessment Bureau
- Valid to 18 August 2028
Policies and sub-processors
The policies a vendor review asks for, and who handles data for us.
- Information security policy
- Sub-processor list
- Incident response
Legal
The agreements that govern the service.
- Terms of use
- Privacy policy
- Security documentation on request
Encryption
All data is encrypted in transit and at rest. Every artefact, on every call.
Data residency and bring your own storage
With your own storage, every artefact goes straight to your own bucket. Use Amazon S3, Alibaba Cloud OSS, or any S3-compatible endpoint.
You set retention, lifecycle, Object Lock and access rules there. A write-only mode keeps reads on your own side.
- Your recordings go straight to your own bucket
- Your region, your retention, your access rules
- Write-only mode: MeetStream writes, and reads stay with you
Retention and deletion
| Control | What it does |
|---|---|
| Thirty days free | The default life of stored media |
| Retention per bot | One setting changes that to whatever you need |
| Delete endpoint | Clears any bot media on demand |
| Deletion webhook | Fires when media expires or is removed, and the bot is marked expired |
The deletion webhook is your signal to clear caches. For your own rules end to end, use bring your own storage.
Access control
API keys and roles in the dashboard govern access. Your team decides who can see recordings, transcripts and account settings.
Scope and rotate keys as your needs change. Keys for transcription and voice models live there too.

Privacy and transparency
Calendar access is read-only. A user's calendar stays exactly as it is.
The data processing agreement is on the Trust Center. So are the policies and the sub-processor list a GDPR review asks for.
Terms, privacy policy and security documents
How do I report a vulnerability?
Email info@meetstream.ai with the details. We will reply within two business days. Found a security issue? We want to hear from you. Reporting it keeps every team on MeetStream safer.
Frequently asked questions
Is MeetStream SOC 2 compliant?
SOC 2 Type 2 is under audit, and the report goes to the Trust Center on the day it is issued. We share security documents for vendor reviews on request. The Trust Center at trust.meetstream.ai holds what is public today.
Is MeetStream ISO 27001 certified?
Yes. Certificate 630036, ISO/IEC 27001:2022. Amtivo Group Limited (British Assessment Bureau) issued it to MeetStream Technologies Pte Ltd. First certified 19 August 2025. Valid to 18 August 2028. You can see it on the Trust Center.
Is MeetStream HIPAA compliant?
MeetStream holds ISO/IEC 27001:2022 certification, and HIPAA certification is separate from it. We do not sign Business Associate Agreements today. Tell us if you need one and we will share the roadmap.
Is meeting data encrypted?
Yes. We encrypt all data in transit and at rest. That covers recordings and transcripts. Live media over the secure WebSocket is encrypted too.
Where are recordings stored?
You choose. With bring-your-own storage, recordings and media go straight to your own bucket, in your region and account, under your retention and access rules. Otherwise MeetStream holds the media in encrypted storage and you fetch it through the API.
Is MeetStream GDPR compliant?
Yes. A data processing agreement is on the Trust Center. The bot always joins as a visible, named participant, and calendar access is read-only. Delete data per bot through the API, and a deletion webhook confirms it.
Who can access my data?
API keys and role-based access in the dashboard control access. Your team decides who can view recordings, transcripts and account settings. You can scope and rotate keys as needed.
Build on infrastructure you can verify
One API to join, record, stream and transcribe meetings. You can check the certificate number. The audit status is stated plainly.